What hotlinking is and why it is a problem
Hotlinking happens when another site embeds an <img> tag with a direct link to an image on your server instead of copying the file to itself. The picture shows up on someone else's page, but the bandwidth and the disk I/O load land on your hosting account. When a popular image sits on a busy forum, the bill can run into gigabytes of traffic a day without a single visit to your own site.
Hotlink Protection in cPanel closes this hole: the server checks the request's Referer header and serves the image only to visitors coming from approved domains.
How to turn on protection in cPanel
Open cPanel → Security → Hotlink Protection. In the URLs to allow access field, list the domains that are allowed to show the images — your main domain, mirrors, and subdomains. In the Direct request field, set what happens for requests with no Referer header at all: browsers and some apps never send it.
The Redirect URL field can point to a placeholder — an image saying the original lives on your site. The default extension list is jpg jpeg png gif bmp, and it can be extended to webp svg mp4.
What happens to .htaccess after enabling it
The tool appends a RewriteCond and RewriteRule block to the .htaccess file in the root folder. You can check the result through the file manager:
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://(www\.)?example\.com [NC]
RewriteRule \.(jpg|jpeg|png|gif)$ - [NC,F,L]
The rule lets through requests with an empty Referer (the first line) and requests from the approved domains, and blocks everything else with a 403 Forbidden.
Risks: what can break
| Traffic source | Referer | Risk after enabling |
|---|---|---|
| Google search, clicking a link | Present, the search engine's domain | Not blocked |
| Facebook link preview | Often empty | Depends on the Direct request setting |
| RSS readers and email clients | Usually empty | Depends on the Direct request setting |
| A stranger's forum with a direct image link | The forum's domain | Blocked, which is the goal |
If Direct request is allowed with no Referer, some hotlinks will still get through — many bypass the check simply by not sending the header at all. Hotlink Protection does not give full protection, but it cuts off the bulk of automatic loading and protects the hosting limits for traffic and I/O.
How to check that the rule is working
Open an image from your site directly in a browser — it should show up, because typing an address in the bar sends an empty Referer, which is allowed by default. Then check it with curl using a fake header from an outside domain:
curl -I -e "https://stranger-site.example/" https://your-domain.example/images/photo.jpg
A 403 response confirms protection is working. A 200 response means the domain stranger-site.example is either on the allowed list or the rule has not been saved yet.
When Hotlink Protection does not fit
If images need to be embedded on partner sites on purpose — for example, a pricing widget or a logo for a referral program — add the partner's domain to the allowed list explicitly. For images published on social networks through Open Graph, add domains like facebook.com, t.me, and other platforms, or link previews will stop showing.
Summary: Hotlink Protection setup checklist
- Turn on protection through cPanel → Security → Hotlink Protection
- Add your site, mirrors, and social network platforms to the allowed domains
- Set Direct request based on whether traffic with no Referer matters to you
- Check the rule with a curl command using a fake Referer
- Review the extension list if not just images but also video get hotlinked