{"id":9062,"date":"2026-05-31T02:50:18","date_gmt":"2026-05-31T00:50:18","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=9062"},"modified":"2026-05-31T02:50:19","modified_gmt":"2026-05-31T00:50:19","slug":"how-to-configure-hotlink-protection-in-htaccess","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/","title":{"rendered":"How to configure hotlink protection in .htaccess"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Hotlink protection prevents other websites from directly displaying files hosted on your server, such as images, without your permission.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When hotlinking occurs, external websites load your files directly from your hosting account. This can increase bandwidth usage and server load because the files are served from your infrastructure instead of theirs.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#How_hotlinking_works\" >How hotlinking works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#Configuring_hotlink_protection_in_htaccess\" >Configuring hotlink protection in .htaccess<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#How_this_configuration_works\" >How this configuration works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#Allowing_multiple_domains\" >Allowing multiple domains<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#Practical_implications\" >Practical implications<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#What_is_normal_behavior\" >What is normal behavior?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-configure-hotlink-protection-in-htaccess\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_hotlinking_works\"><\/span>How hotlinking works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-3496135813\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A website can display an image or file by linking directly to its URL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;img src=\"https:\/\/example.com\/image.jpg\"&gt;\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If another website uses a direct link to a file stored on your hosting account, every visitor to that website generates traffic on your server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The file remains physically stored on your hosting environment, but it is displayed elsewhere.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Configuring_hotlink_protection_in_htaccess\"><\/span>Configuring hotlink protection in .htaccess<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hotlink protection can be enabled using Apache rewrite rules in the <code>.htaccess<\/code> file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example configuration:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>RewriteEngine On\n\nRewriteCond %{HTTP_REFERER} !^$\nRewriteCond %{HTTP_REFERER} !^https?:\/\/(www\\.)?yourdomain\\.com &#91;NC]\nRewriteRule \\.(jpg|jpeg|png|gif|webp)$ - &#91;F,NC,L]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Replace:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>yourdomain.com\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">with your actual domain name.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_this_configuration_works\"><\/span>How this configuration works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The rules above:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>enable the rewrite engine<\/li>\n\n\n\n<li>check the referring website (<code>HTTP_REFERER<\/code>)<\/li>\n\n\n\n<li>allow requests originating from your own domain<\/li>\n\n\n\n<li>block image requests coming from external domains<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If the request comes from another website, access to the file is denied.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Allowing_multiple_domains\"><\/span>Allowing multiple domains<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If files should be accessible from additional domains, subdomains, or external services, extra exceptions can be added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>RewriteCond %{HTTP_REFERER} !^https?:\/\/(www\\.)?anotherdomain\\.com &#91;NC]\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This allows requests from the specified domain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_implications\"><\/span>Practical implications<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hotlink protection is most commonly applied to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>images<\/li>\n\n\n\n<li>media files<\/li>\n\n\n\n<li>downloadable resources<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">It should be configured carefully because some legitimate services may also access files externally, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CDN services<\/li>\n\n\n\n<li>website optimization tools<\/li>\n\n\n\n<li>external applications<\/li>\n\n\n\n<li>feed readers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Blocking these services unintentionally may cause images or files to stop loading in certain situations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_is_normal_behavior\"><\/span>What is normal behavior?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After enabling hotlink protection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>files continue working on your own website<\/li>\n\n\n\n<li>direct external embedding may stop working<\/li>\n\n\n\n<li>blocked requests typically return a 403 Forbidden response<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Changes take effect as soon as the updated <code>.htaccess<\/code> file is processed by the web server.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hotlink protection helps prevent external websites from using files hosted on your server without authorization. Using <code>.htaccess<\/code> rules, you can restrict direct access to images and other resources while continuing to allow access from your own domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[6060,6061,6062,6063,6064,6065,6066,6067,1321,3779],"class_list":["post-9062","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous","manual_kb_tag-hotlink-protection","manual_kb_tag-hotlinking","manual_kb_tag-prevent-hotlinking","manual_kb_tag-image-hotlinking","manual_kb_tag-apache-rewrite-rules","manual_kb_tag-referrer-header","manual_kb_tag-referrer-blocking","manual_kb_tag-allowed-domains","manual_kb_tag-rewrite-engine","manual_kb_tag-htaccess-configuration"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9062\/revisions"}],"predecessor-version":[{"id":9063,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9062\/revisions\/9063"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=9062"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=9062"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=9062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}