Hotlink protection prevents other websites from directly displaying files hosted on your server, such as images, without your permission.
When hotlinking occurs, external websites load your files directly from your hosting account. This can increase bandwidth usage and server load because the files are served from your infrastructure instead of theirs.
Table of Contents
How hotlinking works
A website can display an image or file by linking directly to its URL.
For example:
<img src="https://example.com/image.jpg">
If another website uses a direct link to a file stored on your hosting account, every visitor to that website generates traffic on your server.
The file remains physically stored on your hosting environment, but it is displayed elsewhere.
Configuring hotlink protection in .htaccess
Hotlink protection can be enabled using Apache rewrite rules in the .htaccess file.
Example configuration:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp)$ - [F,NC,L]
Replace:
yourdomain.com
with your actual domain name.
How this configuration works
The rules above:
- enable the rewrite engine
- check the referring website (
HTTP_REFERER) - allow requests originating from your own domain
- block image requests coming from external domains
If the request comes from another website, access to the file is denied.
Allowing multiple domains
If files should be accessible from additional domains, subdomains, or external services, extra exceptions can be added.
Example:
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?anotherdomain\.com [NC]
This allows requests from the specified domain.
Practical implications
Hotlink protection is most commonly applied to:
- images
- media files
- downloadable resources
It should be configured carefully because some legitimate services may also access files externally, including:
- CDN services
- website optimization tools
- external applications
- feed readers
Blocking these services unintentionally may cause images or files to stop loading in certain situations.
What is normal behavior?
After enabling hotlink protection:
- files continue working on your own website
- direct external embedding may stop working
- blocked requests typically return a 403 Forbidden response
Changes take effect as soon as the updated .htaccess file is processed by the web server.
Summary
Hotlink protection helps prevent external websites from using files hosted on your server without authorization. Using .htaccess rules, you can restrict direct access to images and other resources while continuing to allow access from your own domain.