Hotlinking occurs when another website embeds your image or file URLs directly into their pages. Every time a visitor loads that page, your server delivers the file — consuming your bandwidth without bringing you any traffic. On shared hosting, this can quickly exhaust your bandwidth quota and even get your account suspended.
What is Hotlinking and Why is it a Problem?
Imagine you have an image at https://yourdomain.com/img/product.jpg, and another site uses <img src="https://yourdomain.com/img/product.jpg">. Every visitor to that external site causes your server to send that file — you pay the bandwidth cost while they benefit from your resources.
The consequences include:
- Bandwidth depleted faster than expected — potentially incurring overage charges
- Increased server load slowing down your own website
- Risk of account suspension if bandwidth exceeds quota on shared hosting
- Copyrighted files used without your permission
Method 1: Enable via DirectAdmin GUI
DirectAdmin includes a built-in Hotlink Protection feature you can enable without editing .htaccess manually:
- Log in to DirectAdmin → click Advanced Features
- Select Hotlink Protection
- Toggle Enable Hotlink Protection on
- Enter Allowed URLs — domains permitted to link your files (include your own domain)
- Enter Allowed Extensions — file types to protect, e.g.
jpg,jpeg,png,gif,webp,pdf,mp3,mp4 - Set a Redirect URL — a "No Hotlinking" image to show in place of blocked requests
- Click Save
DirectAdmin automatically writes the appropriate .htaccess rules for you.
Method 2: Configure .htaccess Manually
For finer control, or if your hosting lacks a GUI option, add the following to your .htaccess in public_html/:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|svg|pdf|mp3|mp4)$ - [F,NC,L]
How each condition works:
!^$— allows direct access (no referer), so typing the URL in a browser still works!^https?://(www\.)?yourdomain\.com/— allows requests from your own domain[F]— returns a 403 Forbidden response instead of serving the file
Replace yourdomain.com with your actual domain before saving. To allow multiple domains, add additional RewriteCond lines for each.
Understanding Bandwidth Loss from Hotlinking
Hotlinking may seem like a minor issue, but the bandwidth consumed can be substantial — especially on shared hosting plans with strict quotas. Here is a concrete breakdown of how fast bandwidth disappears:
| Scenario | Bandwidth/Day | Bandwidth/Month |
|---|---|---|
| 200 KB image × 10,000 external visitors/day | ~2 GB | ~60 GB |
| 500 KB image × 10,000 external visitors/day | ~5 GB | ~150 GB |
| 5 MB PDF × 1,000 downloads/day | ~5 GB | ~150 GB |
Most shared hosting plans include 10–30 GB of bandwidth per month. A single popular hotlink source can exhaust your entire quota within days. Enabling Hotlink Protection is the most direct way to stop this from happening.
Hotlink Protection for WordPress Sites
If you run WordPress, there are additional approaches beyond .htaccess to protect your media files:
Via functions.php
Add the following snippet to your theme's functions.php to intercept and block hotlinked requests at the PHP level:
// Block hotlinked images and files in WordPress
function block_hotlinks() {
$referer = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : '';
$allowed = 'yourdomain.com';
if ($referer && strpos($referer, $allowed) === false) {
$ext = pathinfo(parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH), PATHINFO_EXTENSION);
if (in_array(strtolower($ext), ['jpg','jpeg','png','gif','webp','pdf'])) {
header('HTTP/1.1 403 Forbidden');
exit;
}
}
}
add_action('init', 'block_hotlinks');
Note: .htaccess-level protection is always preferable because it stops the request before PHP or WordPress loads, using fewer server resources.
Recommended Plugins
- All In One WP Security — includes a built-in Hotlink Protection toggle under the Filesystem section
- WP Cerber Security — combines hotlink blocking with bot protection and malware scanning
Show a Warning Image Instead of Blocking
Instead of returning 403, you can redirect hotlinked requests to a "No Hotlinking Allowed" image — so the other site displays your warning instead:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp)$ /img/no-hotlink.jpg [R=302,NC,L]
Create a no-hotlink.jpg in your /img/ directory — for example, an image saying "Please visit yourdomain.com for this content."
Allowing Multiple Domains
If you have a CDN, staging server, or multiple domains that need access, add a RewriteCond for each:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain2\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://cdn\.yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|pdf)$ - [F,NC,L]
Verify Hotlink Protection is Working
- Open your browser's Developer Tools → Network tab
- Access the image URL directly — it should load normally (no referer = allowed)
- Create a temporary HTML page on a different domain (or use codepen.io) that embeds your image URL
- If configured correctly, the image will return 403 or display your warning image
Note: Google Bot and social media crawlers (Facebook, Twitter) send referers differently. If you need Open Graph preview images to work correctly, make sure to allow empty referers — which is already handled by the !^$ condition.
Things to Keep in Mind
- Private/Incognito browsers may not send a Referer — these requests will be treated as direct access and allowed through
- HTTPS to HTTP referer is suppressed — browsers don't send referer when navigating from HTTPS to HTTP, which can cause false positives
- No SEO impact — Google crawls images directly without sending hotlink-style referers, so your image indexing is unaffected
Hotlink Protection with Cloudflare and CDNs
If your site already uses Cloudflare or a CDN, you have more powerful options available at the network edge rather than at the server level.
Cloudflare Scrape Shield
Cloudflare offers built-in Hotlink Protection under the Security > Scrape Shield section in the dashboard. Enabling it takes a single click and requires no changes to your server files. The key advantage is that Cloudflare blocks the request at the edge — before it even reaches your origin server — so there is zero impact on your server load or bandwidth.
- Protects all file types automatically, no extension lists required
- Works even if your server is down or under maintenance
- Compatible with all hosting plans including shared hosting
Whitelisting a CDN Pull Zone
If you use a CDN like Bunny CDN or KeyCDN alongside your origin server, you must whitelist the CDN's pull domain. Otherwise the CDN cannot fetch assets from your origin:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://[^.]+\.b-cdn\.net/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|pdf)$ - [F,NC,L]
Replace b-cdn.net with the actual pull zone hostname shown in your CDN dashboard.
Comparison: Hotlink Protection Methods
| Method | Level | Difficulty | Best For |
|---|---|---|---|
| DirectAdmin GUI | Apache | Very easy | Beginners |
| .htaccess manual | Apache | Intermediate | Fine-grained control |
| Cloudflare Scrape Shield | Edge/CDN | Very easy | Already using Cloudflare |
| WordPress Plugin | PHP | Easy | WordPress sites |
Thai Hosting with Full .htaccess Support
AsiaGB Hosting supports mod_rewrite and Hotlink Protection on all plans — starting at 500 THB/year with 99% Uptime SLA.
View Hosting Plans