Hotlink protection prevents other websites from directly linking to and displaying your images, videos, or files on their pages using your server's bandwidth. When you enable hotlink protection, unauthorized sites cannot embed your content, which saves bandwidth and reduces server costs while maintaining control over how your media appears online.
What is Hotlinking and Why Should You Block It
Hotlinking occurs when another website displays images or files from your server by embedding direct links to your content in their web pages. This practice steals your bandwidth because every time someone views the other site, your server delivers the content. For high-traffic sites, hotlinking can significantly increase bandwidth usage and hosting costs.
Common examples of hotlinked content include images, videos, audio files, PDFs, and downloadable documents. When websites hotlink your media, you pay for the bandwidth while they benefit from displaying your content. Hotlink protection blocks these unauthorized requests while still allowing legitimate access to your content.
How to Enable Hotlink Protection in cPanel
Setting up hotlink protection through your OBHost cPanel account takes just a few minutes. Follow these steps to protect your bandwidth:
- Log into your cPanel account and navigate to the Hotlink Protection tool in the Security section
- Click the Enable button to activate hotlink protection
- Review the automatically populated list of allowed referrers, which includes your domain and subdomains
- Click Go back to return to the configuration screen
Configure Allowed URLs and Protected File Types
After enabling hotlink protection, you need to specify which sites can access your content and which file types to protect:
Add trusted URLs: In the URLs to allow access field, enter any domains that should be allowed to display your content. Always include your own domain, subdomains, and the URL you use to access cPanel. This prevents blocking legitimate requests from your own website.
Specify file extensions: In the Block direct access for the following extensions text box, add file types you want to protect. Common extensions include .jpg, .jpeg, .png, .gif, .bmp, .mp4, .pdf, and .zip. Separate multiple extensions with spaces or commas.
Allow direct requests: If you want visitors to access files by typing the URL directly in their browser (for example, accessing an image at example.com/images/photo.jpg), select the Allow direct requests checkbox. Leave this unchecked for stricter protection.
Set up redirects: Instead of showing an error when hotlinking is detected, you can redirect requests to a different URL. Enter a redirect destination in the Redirect the request to the following URL field. Many site owners redirect to a warning image or their homepage.
Click Submit to save your hotlink protection settings.
Important Considerations When Using Hotlink Protection
Before enabling hotlink protection, understand these important points to avoid breaking functionality on your own site:
Always whitelist your cPanel URL: The URL you use to access your cPanel account should appear in the allowed referrers list. If it doesn't, you may not see embedded images when using the File Manager's HTML Editor.
Include all your subdomains: Make sure to add any subdomains where you display content from your main domain. For example, if blog.yourdomain.com displays images hosted on yourdomain.com, add the subdomain to the allowed list.
Whitelist necessary third-party services: If you use content delivery networks, email marketing platforms, or social media sharing tools that need to access your files, add their domains to the allowed URLs list.
Test after enabling: After activating hotlink protection, check your website thoroughly to ensure all images and media files display correctly on all pages.
How to Disable Hotlink Protection
If you need to turn off hotlink protection, click the Disable button in the Hotlink Protection interface. However, be aware that disabling hotlink protection deletes all entries in your allowed URLs list. We strongly recommend saving a copy of your allowed URLs locally before disabling the feature, so you can easily restore your settings if needed later.
Frequently Asked Questions
Will hotlink protection slow down my website for legitimate visitors?
No, hotlink protection does not affect loading speeds for visitors accessing your site normally. The protection only checks the referrer header when external sites try to load your content, which adds negligible processing time. Your regular visitors will not experience any performance differences.
Can I protect some file types but not others?
Yes, you have complete control over which file extensions to protect. You can protect only images (.jpg, .png, .gif) while allowing hotlinking of other file types, or vice versa. Simply add only the extensions you want to protect in the configuration settings.
What happens when someone tries to hotlink my protected content?
When hotlink protection blocks a request, the behavior depends on your configuration. If you set up a redirect URL, the request gets sent to that destination (often a warning image or your homepage). If no redirect is configured, the browser typically displays a broken image icon or error message instead of your content.
Does hotlink protection work with content delivery networks?
Hotlink protection can work alongside CDNs, but you must add your CDN's domain to the allowed URLs list. This ensures the CDN can pull and serve your content while still blocking unauthorized hotlinking from other sources. Consult your CDN documentation for specific domain information to whitelist.
Our support team is available 24/7 to help you configure hotlink protection or troubleshoot any issues with bandwidth theft. Contact us at https://www.obhost.net/contact or email support@obhost.org for assistance.