Where Does Roundcube Store Config and Data?
Roundcube keeps local config in config.inc.php, with attachments in temp/, errors in logs/, and data in SQL.
Last updated
Roundcube is a thin client over IMAP with a small local footprint. One PHP file, config/config.inc.php, holds every setting that differs from defaults.inc.php. Attachments stage in temp, errors land in logs, and address books plus user prefs live in MySQL, Postgres, or SQLite.
Mail itself never rests here: the IMAP server owns messages. That makes Roundcube moves cheap but permission sensitive. The web user must write temp and logs, while the web server must refuse to serve config, temp, and logs to visitors.
Where Roundcube stores this, by platform
./config/config.inc.php
Only differences from defaults.inc.php belong here. Database DSN, IMAP hosts, and plugin lists are the usual entries. PHP syntax errors blank the page.
./temp
Attachments stage here for 48 hours by default, errors log beside it. Both must be web user writable and blocked from direct web access.
Frequently asked questions
How do I migrate Roundcube to a new server?
Copy config.inc.php, dump the database, and note any custom temp and log paths. Skins and plugins travel with the install tree, not the database.
A setting I expected has no effect. Why?
Copy the missing option from defaults.inc.php into config.inc.php. The local file only holds differences, so absent keys silently mean defaults.
Attachments fail and logs stay empty. What is wrong?
Make temp and logs writable by the PHP user and deny web access to config, temp, and logs. Blank pages usually mean a PHP syntax slip in config.inc.php.
Notice an outdated path? Let us know.