Hotlink Protection DirectAdmin

Hotlinking occurs when another website embeds your image or file URLs directly into their pages. Every time a visitor loads that page, your server delivers the file — consuming your bandwidth without bringing you any traffic. On shared hosting, this can quickly exhaust your bandwidth quota and even get your account suspended.

What is Hotlinking and Why is it a Problem?

Imagine you have an image at https://yourdomain.com/img/product.jpg, and another site uses <img src="https://yourdomain.com/img/product.jpg">. Every visitor to that external site causes your server to send that file — you pay the bandwidth cost while they benefit from your resources.

The consequences include:

Method 1: Enable via DirectAdmin GUI

DirectAdmin includes a built-in Hotlink Protection feature you can enable without editing .htaccess manually:

  1. Log in to DirectAdmin → click Advanced Features
  2. Select Hotlink Protection
  3. Toggle Enable Hotlink Protection on
  4. Enter Allowed URLs — domains permitted to link your files (include your own domain)
  5. Enter Allowed Extensions — file types to protect, e.g. jpg,jpeg,png,gif,webp,pdf,mp3,mp4
  6. Set a Redirect URL — a "No Hotlinking" image to show in place of blocked requests
  7. Click Save

DirectAdmin automatically writes the appropriate .htaccess rules for you.

Method 2: Configure .htaccess Manually

For finer control, or if your hosting lacks a GUI option, add the following to your .htaccess in public_html/:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|svg|pdf|mp3|mp4)$ - [F,NC,L]

How each condition works:

Replace yourdomain.com with your actual domain before saving. To allow multiple domains, add additional RewriteCond lines for each.

Understanding Bandwidth Loss from Hotlinking

Hotlinking may seem like a minor issue, but the bandwidth consumed can be substantial — especially on shared hosting plans with strict quotas. Here is a concrete breakdown of how fast bandwidth disappears:

Scenario Bandwidth/Day Bandwidth/Month
200 KB image × 10,000 external visitors/day ~2 GB ~60 GB
500 KB image × 10,000 external visitors/day ~5 GB ~150 GB
5 MB PDF × 1,000 downloads/day ~5 GB ~150 GB

Most shared hosting plans include 10–30 GB of bandwidth per month. A single popular hotlink source can exhaust your entire quota within days. Enabling Hotlink Protection is the most direct way to stop this from happening.

Hotlink Protection for WordPress Sites

If you run WordPress, there are additional approaches beyond .htaccess to protect your media files:

Via functions.php

Add the following snippet to your theme's functions.php to intercept and block hotlinked requests at the PHP level:

// Block hotlinked images and files in WordPress
function block_hotlinks() {
    $referer = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : '';
    $allowed = 'yourdomain.com';
    if ($referer && strpos($referer, $allowed) === false) {
        $ext = pathinfo(parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH), PATHINFO_EXTENSION);
        if (in_array(strtolower($ext), ['jpg','jpeg','png','gif','webp','pdf'])) {
            header('HTTP/1.1 403 Forbidden');
            exit;
        }
    }
}
add_action('init', 'block_hotlinks');

Note: .htaccess-level protection is always preferable because it stops the request before PHP or WordPress loads, using fewer server resources.

Recommended Plugins

Show a Warning Image Instead of Blocking

Instead of returning 403, you can redirect hotlinked requests to a "No Hotlinking Allowed" image — so the other site displays your warning instead:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp)$ /img/no-hotlink.jpg [R=302,NC,L]

Create a no-hotlink.jpg in your /img/ directory — for example, an image saying "Please visit yourdomain.com for this content."

Allowing Multiple Domains

If you have a CDN, staging server, or multiple domains that need access, add a RewriteCond for each:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain2\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://cdn\.yourdomain\.com/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|pdf)$ - [F,NC,L]

Verify Hotlink Protection is Working

  1. Open your browser's Developer Tools → Network tab
  2. Access the image URL directly — it should load normally (no referer = allowed)
  3. Create a temporary HTML page on a different domain (or use codepen.io) that embeds your image URL
  4. If configured correctly, the image will return 403 or display your warning image

Note: Google Bot and social media crawlers (Facebook, Twitter) send referers differently. If you need Open Graph preview images to work correctly, make sure to allow empty referers — which is already handled by the !^$ condition.

Things to Keep in Mind

Hotlink Protection with Cloudflare and CDNs

If your site already uses Cloudflare or a CDN, you have more powerful options available at the network edge rather than at the server level.

Cloudflare Scrape Shield

Cloudflare offers built-in Hotlink Protection under the Security > Scrape Shield section in the dashboard. Enabling it takes a single click and requires no changes to your server files. The key advantage is that Cloudflare blocks the request at the edge — before it even reaches your origin server — so there is zero impact on your server load or bandwidth.

Whitelisting a CDN Pull Zone

If you use a CDN like Bunny CDN or KeyCDN alongside your origin server, you must whitelist the CDN's pull domain. Otherwise the CDN cannot fetch assets from your origin:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?yourdomain\.com/ [NC]
RewriteCond %{HTTP_REFERER} !^https?://[^.]+\.b-cdn\.net/ [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp|pdf)$ - [F,NC,L]

Replace b-cdn.net with the actual pull zone hostname shown in your CDN dashboard.

Comparison: Hotlink Protection Methods

Method Level Difficulty Best For
DirectAdmin GUI Apache Very easy Beginners
.htaccess manual Apache Intermediate Fine-grained control
Cloudflare Scrape Shield Edge/CDN Very easy Already using Cloudflare
WordPress Plugin PHP Easy WordPress sites

Thai Hosting with Full .htaccess Support

AsiaGB Hosting supports mod_rewrite and Hotlink Protection on all plans — starting at 500 THB/year with 99% Uptime SLA.

View Hosting Plans