Skip to main content

cPanel: Enable and manage hotlink protection

Use Hotlink Protection to prevent other websites from loading images or files directly from your hosting and using your bandwidth. You decide which websites may embed your files and which file types are protected.

Who is this guide for?

This guide applies exclusively to customers whose hosting is managed on the new

Webland platform (WHMCS) and whose hosting plan includes cPanel.

Essential Hosting without cPanel: This guide does not apply to your hosting.

Previous platform using System Configurator or Domain Manager: Sign in at classic.webland.ch. The steps below do not apply to that platform.


Important information

Hotlink protection restricts the embedding of your files on other websites. It does not fully prevent people from downloading or copying publicly accessible content.

To keep your own website working correctly, allow all required website addresses.

These include the versions you use with and without www, subdomains and, where applicable, HTTP and HTTPS addresses.

If you preview files through cPanel, you may also need to allow the address you use to access cPanel.


Requirements

Before you begin, make sure you:

  • Are signed in to the client area on the new Webland platform.

  • Have access to your cPanel hosting service and Hotlink Protection.

  • Know which websites should still be allowed to embed your files.


Step 1: Sign in to cPanel

  1. Find your hosting service in the active services overview in the client area.

  2. Click “Log in to cPanel”.

You will be signed in to cPanel automatically.


Step 2: Enable hotlink protection

  1. Open “Hotlink Protection” in the “Security” section of cPanel.

  2. Click “Enable”.

  3. cPanel displays a confirmation with the allowed website addresses and protected file extensions.

  4. Click “Go Back” to adjust the settings.


Step 3: Specify allowed websites

Under “URLs to allow access”, enter the website addresses that may embed your files. Use one address per line.

Examples:

  • https://example.com

  • https://www.example.com

  • https://shop.example.com

Replace these examples with your actual addresses. Add partner websites and other domain variations where needed. Check any entries that are already filled in.


Step 4: Specify protected file types

Under “Block direct access for the following extensions”, enter the file extensions you want to protect, separated by commas.

Example:

jpg,jpeg,png,gif,webp

The hotlink rules will apply to these image formats. Allowed websites can still embed these files. The extensions do not form a blanket block on all access.


Step 5: Allow or restrict direct requests

Select “Allow direct requests” if visitors should be able to open a file directly, for example by entering its address in their browser.

This option also allows requests without an originating page, known as a referrer. Privacy settings can cause requests to omit this information.

If you clear this option, these requests may also be blocked.


Step 6: Set an optional redirect and save

To redirect blocked file requests:

  1. Enter a complete destination address under “Redirect the request to the following URL”.

  2. Choose a destination that is not itself blocked by the hotlink rules.

Leave this field empty if you do not need a redirect.

Then click “Submit” to save your settings.

Note: The redirect applies to the file request. For an embedded image, this does not automatically navigate the visitor to the destination page.


Step 7: Check your settings

Open your website and check that images and other protected files still display correctly. Also test any subdomains and allowed partner websites.

If you allow direct requests, open a file using its full address as well.


Disable hotlink protection

Open “Hotlink Protection” and click “Disable”.

Important: Disabling the feature deletes the list of allowed URLs in cPanel. Save a copy first if you want to reuse it later.


Troubleshooting

Images are missing from my own website

Check that the website address you actually use is allowed. Pay particular attention to HTTPS, the www version and subdomains.

A partner website cannot display my files

Check its address in the allowed URLs list. If the request does not include a referrer, also check “Allow direct requests”.

A change is not visible

Check that you clicked “Submit”. Then clear your browser cache and, where applicable, your website or CDN cache before testing again.

Did this answer your question?