> ## Content Index
> Fetch the complete content index at: https://www.magicpages.co/llms.txt
> Use this file to discover other available public pages before exploring further.

# Off-site backups to an SFTP server
- URL: https://www.magicpages.co/help/backups/off-site-backups-to-an-sftp-server/
- Published: 2026-10-06T07:55:09.000Z
- Updated: 2026-10-06T07:56:04.000Z
- Description: Sending your backups to a server you run, over SFTP. What to fill in, the access the user needs, and what the common connection errors mean.
- Author: Jannis Fedoruk-Betschki
- Tags: Help Center & Guides, Backups

If you have a server, a NAS or a storage box that accepts SFTP logins, your backups can go there. This article covers what to fill in, what the login needs to be allowed to do, and what the common errors mean.

If you haven't read it yet, [Off-site backups to your own storage](https://www.magicpages.co/help/backups/off-site-backups-to-your-own-storage/) explains what gets sent and how many copies are kept.

## Before you start

- It has to be **SFTP**, the file transfer that runs over SSH. Plain FTP and FTPS don't work.
- The server has to be reachable from the internet, by a public hostname or IP address. Addresses inside a private network, like `192.168.…` or `10.…`, are refused.
- Make a separate user for this, with access to the backup folder and nothing else.

## Filling in the form

In the **Off-Site Backups** tab, click **Configure Destination** (or **Edit Configuration**), pick **SFTP Server**, and fill in:

- **Host**: the server's hostname or IP address, without `sftp://`.
- **Port**: usually 22.
- **Username**.
- **Authentication**: a password, or a private key. For a key, paste the whole thing, including the `-----BEGIN …` and `-----END …` lines. If the key has a passphrase, enter it under **Passphrase**.
- **Remote Path**: the folder for the backups, for example `/backups/ghost`. If it doesn't exist yet, we create it.
- **Backup retention (days)**: how many copies of each backup to keep. 0 keeps all of them.

Then click **Test Connection**, and **Save** once it passes.

For key logins, make a key pair just for this, and add the public half to the user's `~/.ssh/authorized_keys` on your server.

## What the user needs to be allowed to do

The connection test logs in, creates the folder if needed, writes a small file called `.magic-pages-connection-test-…`, checks that it's there, and deletes it.

Every copy after that:

- uploads each file under a temporary name ending in `.partial`, and renames it when the upload is complete, so you never find a half-written backup under the real name,
- lists the folder and deletes your site's oldest backups, unless retention is 0.

So the user needs to be able to create folders, write, rename and delete files in the remote path. A chroot or a jailed user is fine, as long as the path you enter is the path the user sees after logging in.

## When the test fails

The message starts with **"Failed to connect to SFTP server host:port"**, followed by the reason the server gave. The common ones:

- **Timed out**, or **connection refused**: the host or port is wrong, or a firewall is blocking us. If your server only lets in specific IP addresses, email us and we'll tell you which ones to allow.
- **All configured authentication methods failed**: wrong password, or the server doesn't accept the key. Check that the public key is in `authorized_keys` for this user, and that the server allows password logins if you're using one.
- **Cannot parse privateKey**, or a message about the passphrase: the key wasn't pasted in full, or the passphrase is wrong.
- **Permission denied**: the login works, but the user can't create the folder or write to it.

**"SFTP connection rejected: host resolves to blocked address"** means the hostname points at a private network address. It has to be one we can reach over the internet.

If none of that fits, email [help@magicpages.co](mailto:help@magicpages.co) with the host and port. Never send the password or the private key.