In some situations, accessing a directory directly through a web browser may display a list of all files stored inside it.
For example, visiting:
https://yourdomain.com/downloads/ might display all files located in the downloads directory if directory listing is enabled.
This behavior can expose files that were not intended to be publicly visible and may create security or privacy concerns.
Table of Contents
Disable Directory Listing with .htaccess
To prevent the contents of a directory from being displayed, create or edit a file named:
.htaccess Note: The filename begins with a dot (
.).
Add the following rule:
Options -Indexes Where Should the File Be Placed?
Place the .htaccess file inside the directory you want to protect.
For example:
public_html/downloads/.htaccess The rule will apply to that directory and, by default, to its subdirectories as well.
What Happens After Adding the Rule?
When a visitor attempts to access a directory without an index file (such as index.php or index.html), the server will no longer display the file listing.
Instead, the visitor will typically see:
- A 403 Forbidden error
- A custom error page, if configured
Applying the Rule to an Entire Website
If you want to disable directory listing across the entire website, add the rule to the main .htaccess file located in the website’s root directory, for example:
public_html/.htaccess Example:
Options -Indexes This will prevent directory listings throughout the website unless overridden by another .htaccess file.
Testing the Configuration
After saving the .htaccess file:
- Open a browser.
- Visit a directory that previously displayed a file listing.
- Confirm that the list is no longer visible.
If the directory now returns a 403 error, the configuration is working correctly.
Summary
To prevent visitors from viewing the contents of a directory, create or edit a .htaccess file and add the following directive:
Options -Indexes This disables directory browsing and helps protect files from being exposed through automatic directory listings.