Web Hosting Backups — What to Verify Before You Buy
A host that promises "daily backups" is not the same as a host that can put yesterday's site back online in an afternoon. Backups are an insurance product. You only learn whether the policy pays out when something is already broken.
This guide is a practical way to verify backup and restore reality before you buy. Pair it with how to choose web hosting without top-10 lists, renewal pricing checks, and the support drill. For why affiliate roundups skip restore proofs, read The Truth About Hosting Review Sites.
Why "we back up nightly" is not a plan
Sales pages love the word backup. They rarely answer the questions that matter after a bad deploy, a ransomware hit, or a deleted database:
- What is included? Files only? Databases? Email? DNS records? Cron jobs? SSL certs?
- How far back can you go? One day? Seven? Thirty? Forever — until you read the fine print?
- Who can restore? Self-serve in the panel, or a ticket that waits for a systems queue?
- How long does a restore take? Minutes, hours, or "we will get back to you"?
- Where do copies live? Same disk as the site? Same datacenter? Offsite?
If those answers are fuzzy, the backup is marketing infrastructure, not disaster recovery.
A 20-minute pre-purchase backup drill
You do not need to break a production site. You need comparable answers from every shortlisted host.
1. Ask for the backup matrix in writing
Send the same chat/ticket question to each host:
On this plan, what exactly is backed up (files, databases, email, DNS), how often, how many restore points, how long are they retained, and can I restore a single file or database myself from the panel?
Save the reply. Vague "we take care of backups" answers fail the drill.
2. Confirm restore, not just snapshot
Ask one follow-up:
If I need yesterday's WordPress database only, what are the steps and typical turnaround? Is restore self-serve?
A host that can snapshot but cannot restore a single database without rebuilding the whole account is a different product than one with granular restores.
3. Check whether backups are included or upsold
Many "unlimited" shared plans include a thin backup add-on — or none — and push a paid JetBackup / CodeGuard / panel plugin after checkout. Put the real monthly cost on your two-year renewal sheet. A $3/mo plan that needs a $3/mo backup add-on is a $6/mo plan.
4. Ask where copies live and who owns the export
You want at least:
- Copies that survive a disk failure on the same machine (not "backup = the live disk")
- A way to download a full export yourself (files + DB), not only restore in place
- Clarity on whether canceled accounts still get a recovery window
If you cannot export, you do not have a portable backup — you have a leash.
What good backup hygiene looks like in practice
Strong setups share boring traits:
- Documented scope. A help article that lists included objects and retention, not a badge that says "secure."
- Retention that matches your risk. A brochure site may need a week. A store taking orders needs enough points to undo a bad plugin and a quiet corruption that sat for days.
- Granular restore options. Full account, single database, and single file/path are the useful trio.
- Self-serve where the plan claims it. If the sales page says "one-click restore," verify the button exists on a trial or demo — or get a screenshot of the UI from support.
- Offsite or at least off-node copies. Same-server "backups" die with the server.
Your own offsite copy still matters. Host backups fail, get throttled during outages, or exclude the one folder you needed. A weekly (or daily) export to object storage you control is the adult move — especially before a host transfer.
Red flags that should pause the purchase
Walk away — or pause — when:
- Backups are "included" but restore requires a paid emergency ticket with no published SLA
- Retention is "up to 30 days" with no statement of how many points or how often
- Email, DNS, or databases are quietly excluded
- The only backup is a plugin you install yourself, with no host-side copy
- Support cannot explain the last successful restore they performed for a customer like you
- Canceling hosting immediately deletes every recovery point with no grace window
Affiliate lists rarely stress-test restores. They screenshot uptime widgets and move on.
A short backup decision checklist
Use this before you pay:
- Backup scope written down: files, DB, email, DNS — yes/no for each.
- Frequency and retention written down (e.g. daily, 14 restore points, 14-day retention).
- Restore path confirmed: self-serve vs ticket, granular vs full-account only.
- Typical restore turnaround noted from support (not from the marketing site).
- Add-on cost included in the two-year total if backups are not free on the plan.
- Export/download path confirmed so you can leave with your data.
- Your own offsite copy scheduled — even if the host looks excellent.
- Only then follow a referral link — including ours.
How this fits HostInsight
We treat backups the same way we treat support and renewal math: claims without a restore path are incomplete. Our FAQ on how we rank hosts prefers evidence over splash ratings — and a host that cannot explain restores does not deserve trust, no matter how green the uptime badge looks.
What to do next
- Shortlist two or three hosts that fit the workload and renewal math.
- Run the backup drill above on each (same questions, saved answers).
- Keep those notes next to your support drill and two-year cost sheet.
- Buy the plan you could recover from at 2am — not the one with the prettiest "secure backups" icon.
Browse more web hosting guides, keep the homepage ranking list handy, and treat any review that never mentions restore steps as unfinished until you verify them yourself.

