On this page
- What offshore WordPress hosting means
- Choose a plan and a location for offshore WordPress hosting
- Keep the domain as safe as the server
- Install Nginx, PHP and MariaDB
- Install WordPress with
WP-CLI - Configure Nginx and HTTPS
- Make WordPress fast
- Secure and back up WordPress
- Sending mail from WordPress
- A CDN in front of an offshore site: what it changes
- Frequently asked questions

Offshore WordPress hosting means running your WordPress site on a server in another country, under that country's law. We do not sell shared or managed WordPress hosting. You install WordPress yourself on an offshore VPS with full root access, from $2.39
The steps cover
What offshore WordPress hosting means
Your site runs on a VPS in a country you choose for its law: with us, Iceland, Switzerland, Moldova, Romania, the Netherlands, Bulgaria or Malaysia. Three things change:
US DMCA notices are not actioned. The DMCA has no legal force in these countries: a notice is logged and answered, and nothing happens to the server. That is what "DMCA ignored WordPress hosting" accurately means.- Local law decides. A valid
court order from the server's country can require action. We inform you first so you can respond, unless a court forbids it. EU rules apply in EU locations. In Romania, the Netherlands and Bulgaria, a notice that meets theEU Digital Services Act 's notice-and-action requirements can also require action.
What does not change: illegal content stays illegal, your own country's law still applies to you, and spam, phishing, malware, attacks, fraud and child sexual abuse material lead to immediate action. Our
Choose a plan and a location for offshore WordPress hosting
Memory is the first limit a WordPress server reaches, and shops need the most: WooCommerce's cart, checkout and account pages hold each customer's own data, so a page cache must skip them and PHP builds them for every visitor.
| Site | Plan | vCPU, RAM, NVMe | Per month |
|---|---|---|---|
| Test site or small personal blog | Dinghy | 1, | $2.39 |
| Blog or business site | Sloop | 1, | $3.49 |
| Busy blog or several sites | Cutter | 2, | $5.49 |
| WooCommerce shop | Schooner | 4, | $12.49 |
| High traffic or several shops | Brigantine | 6, | $19.99 |
Pick the location closest to most of your readers with the latency estimates on our network page, then check its law on the locations page. A new VPS has a
Keep the domain as safe as the server
Your host controls the server, not the name. The registrar is the company you register the name through; the registry operator keeps the master database of a
ICANN's guidance on domain name seizures describes court orders that make a registry or registrar lock a name, stop it resolving or transfer it. According to IANA's records, the .com and .net registries are run by VeriSign Global Registry Services in Reston, Virginia. So a US
- The registrar: its country, its terms on complaints and court orders, and the identity it asks for.
- The
top-level domain: the Root Zone Database shows who operates it, and where. - WHOIS privacy: a privacy service keeps your contact details out of WHOIS, and a proxy service becomes the holder of record instead of you. Either way, the provider still holds your details, under its own law.
Install Nginx, PHP and MariaDB
Setting up WordPress on a VPS starts with the web server, PHP and the database. Order the VPS with sudo -iexample.com
apt update
apt install -y nginx mariadb-server php-fpm php-mysql php-curl php-gd php-imagick php-intl php-mbstring php-xml php-zip curl gnupg sudo
WordPress's Site Health screen then reports all required and recommended PHP modules as installed.
PHPV=$(php -r 'echo PHP_MAJOR_VERSION.".".PHP_MINOR_VERSION;')
cat > /etc/php/$PHPV/fpm/conf.d/90-wordpress.ini <<'EOF'
memory_limit = 256M
upload_max_filesize = 64M
post_max_size = 64M
EOF
systemctl restart php$PHPV-fpm
PHPV
DB_PASS=$(openssl rand -hex 24)
mariadb -e "CREATE DATABASE wordpress CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci"
mariadb -e "CREATE USER wordpress@localhost IDENTIFIED BY '$DB_PASS'"
mariadb -e "GRANT ALL PRIVILEGES ON wordpress.* TO wordpress@localhost"
Stay in this shell: the next step writes $DB_PASSwp-config.phpmariadb-secure-installationmysql_secure_installation
Install WordPress with WP-CLI
cd /tmp
curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar
curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar.asc
curl -L https://raw.githubusercontent.com/wp-cli/builds/gh-pages/wp-cli.pgp | gpg --import
gpg --fingerprint 63AF7AA15067C05616FDDD88A3A2E8F226F0BC06
gpg --verify wp-cli.phar.asc wp-cli.phar
php wp-cli.phar --info
chmod +x wp-cli.phar
mv wp-cli.phar /usr/local/bin/wp
gpg --fingerprintgpg --verifywww-data
install -d -o www-data -g www-data /var/www/example.com /var/www/.wp-cli
cd /var/www/example.com
sudo -u www-data wp core download
sudo -u www-data wp config create --dbname=wordpress --dbuser=wordpress --dbpass="$DB_PASS"
chmod 640 wp-config.php
sudo -u www-data wp core install --url=https://example.com --title="Example" --admin_user=YOUR_ADMIN_NAME --admin_email=ADMIN_EMAIL --skip-email
Because www-data.wp-cliwp-config.php
Configure Nginx and HTTPS
Point A records for example.comwww.example.com/etc/nginx/sites-available/example.com, with php8.2-fpm.sock
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
root /var/www/example.com;
index index.php;
client_max_body_size 64m;
location / {
try_files $uri $uri/ /index.php?$args;
}
location ^~ /.well-known/ {
try_files $uri =404;
}
location ~ /\. {
deny all;
}
location ~* /wp-content/uploads/.*\.php$ {
deny all;
}
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock;
}
}
- try_files
- Sends paths that are not files to
, for pretty permalinks.index.php - Deny rules
- Hidden files such as
, and PHP files in uploads, get error 403;.git stays open./.well-known/ fastcgi-php .conf- Returns 404 for PHP files that do not exist.
- client_max_body_size
- Nginx's default of
1 MB would refuse larger uploads with error 413.
Enable the site in place of the default one, then switch to pretty permalinks:
ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
rm /etc/nginx/sites-enabled/default
nginx -t
systemctl reload nginx
sudo -u www-data wp --path=/var/www/example.com rewrite structure '/%postname%/'
If ufw is on from the hardening guide, also run ufw allow 80/tcpapt install -y snapdsnap install snapd
snap install --classic certbot
ln -s /snap/bin/certbot /usr/local/bin/certbot
certbot --nginx -d example.com -d www.example.com
certbot renew --dry-run
Certbot proves control of the domain, adds the certificate to the server block and redirects HTTP to HTTPS by default. The snap renews certificates automatically, and the dry run tests renewal. Certbot also asks for an email address, which you can skip with --register-unsafely-without-emailhttps://example.com/wp-admin/
Make WordPress fast
Run wp/var/www/example.comPHPVopcache.enable => On => On
php-fpm$PHPV -i | grep '^opcache.enable '
A page cache saves each page as static HTML and serves it to the next visitors. WP Super Cache, from Automattic, serves those files through PHP in its recommended Simple mode, so it needs no Nginx rules, and WooCommerce tells it to skip the cart, checkout and account pages:
sudo -u www-data wp plugin install wp-super-cache --activate
Turn caching on under Settings > WP Super Cache. When you are logged out, the end of a page's source then shows the comment Cached page generated by WP-Super-Cache. An object cache keeps data that WordPress would fetch from the database in memory, which helps the pages a page cache cannot serve. Redis and the Redis Object Cache plugin provide one:
apt install -y redis-server php-redis
systemctl restart php$PHPV-fpm
sudo -u www-data wp plugin install redis-cache --activate
sudo -u www-data wp redis enable
sudo -u www-data wp redis status
The status must read Connectedpm.max_children/etc/php/$PHPV/fpm/pool.d/www.conf
Secure and back up WordPress
Open only SSH, HTTP and HTTPS
apt install -y ufw
ufw limit 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
ufw status verbose
Answer y
Update automatically
Since WordPress 5.6, new installations update themselves to minor and major releases, and our test install had major updates on. Plugins and themes need switching on:
cd /var/www/example.com
sudo -u www-data wp plugin auto-updates enable --all
sudo -u www-data wp theme auto-updates enable --all
Update checks are
sudo -u www-data wp config set DISABLE_WP_CRON true --raw
echo '*/5 * * * * www-data cd /var/www/example.com && /usr/local/bin/wp cron event run --due-now --quiet' > /etc/cron.d/wordpress
Tighten file permissions
find /var/www/example.com -type d -exec chmod 755 {} +
find /var/www/example.com -type f -exec chmod 644 {} +
chmod 640 /var/www/example.com/wp-config.php
On Ubuntu, sudowww-datawp-config.phpwww-datawp-content/uploads
Limit logins and XML-RPC
Slow down password guessing: create /etc/nginx/conf.d/wp-login-limit.conf with this line,
limit_req_zone $binary_remote_addr zone=wplogin:10m rate=10r/m;
then add these blocks to the server block (php8.2-fpm.socknginx -t
location = /wp-login.php {
limit_req zone=wplogin burst=5 nodelay;
limit_req_status 429;
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock;
}
location = /xmlrpc.php {
deny all;
}
Each address gets six quick login requests, then one every six seconds: in our test, the seventh rapid request got error 429. The second block turns off the
Snapshots and off-server backups
Before large updates, request Take a snapshot under Server actions on your server's page; VPS plans include /var/www
mkdir -p /root/db-dumps
chmod 700 /root/db-dumps
mariadb-dump --single-transaction wordpress > /root/db-dumps/wordpress.sql
Sending mail from WordPress
Through PHP's mail function, WordPress hands password resets, comment notices and shop orders to /usr/sbin/sendmailwp_mail()
- An SMTP relay on
port 587 , the simpler way. Take a mail service with authenticated SMTP submission, add its SPF and DKIM records to your DNS, and connect WordPress with a plugin such as FluentSMTP, which is free and works with any SMTP server. Theport 25 block does not apply toport 587 . - Direct delivery on
port 25 . Request Openport 25 (outgoing mail) under Server actions on the server's page, saying what you will send and from which domain. Then request Set the reverse DNS (PTR) for your mail hostname, and publish SPF and DKIM records.
Either way, spam and phishing are
A CDN in front of an offshore site: what it changes
You do not need a CDN for protection: DDoS mitigation is included on our network, with
Take Cloudflare, Inc., of
So a CDN hides your server's address from the public, not from complainants. If you use one, configure Nginx's real IP module with the CDN's address ranges, or the login limit above will count the CDN's servers instead of your visitors.
Frequently asked questions
What is offshore WordPress hosting?
It is WordPress running on a server in another country, chosen for its law. To host a website offshore this way, you rent a VPS there and install WordPress on it. The host then follows local law:
Is offshore web hosting legal?
Yes. Renting a server abroad is legal almost everywhere; what can make it illegal is the use. Illegal content stays illegal offshore, the server's country decides what its host must do, and your own country's law still applies to you. Our article is offshore hosting legal covers data protection, sanctions and tax.
Can I host a WordPress site anonymously?
Partly. Our account is an email address and a password, paid in crypto, with no identity check, as on our
Do you offer managed WordPress hosting?
No. We do not sell shared or managed WordPress hosting. You get a VPS with full root access and install WordPress on it yourself, which takes about
How much RAM does WordPress need?
For one small site,
Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions.


