Skip to content

Control other sites linking directly to your files

Configure Hotlink Protection without breaking your own images or trusted integrations.

Where Tools → Security → Hotlink Protection

Before you start

  • List every legitimate site origin that embeds the protected files, including www, HTTPS and any approved CDN.
  • Back up existing settings before enabling protection.

Steps

  1. 1

    Open Hotlink Protection and read whether it is enabled or disabled.

  2. 2

    Review URLs to allow access. Include the legitimate origins that must embed your files.

  3. 3

    Set the extensions to protect as a comma-separated list. Protecting image types is different from blocking all links to the website.

  4. 4

    Submit the configuration, then use Enable if protection is still disabled. Do not assume saving a list and enabling the feature are the same action.

  5. 5

    Choose whether to Allow direct requests, such as someone opening an image URL directly. Set an optional redirect only when you have a suitable destination.

    Review allowed origins, extensions and direct-request behaviour.

Check it worked

  • Load images on your own site, including www/non-www variants and approved integrations.
  • Check direct-file access behaves as intended. Restore the previous settings if legitimate assets fail.