1. Home
  2. Hosting
  3. cPanel
  4. Set Up Hotlink Protection in cPanel for Your 1-grid Website
  1. Home
  2. Web Security
  3. Set Up Hotlink Protection in cPanel for Your 1-grid Website
  1. Home
  2. Website
  3. Set Up Hotlink Protection in cPanel for Your 1-grid Website

Set Up Hotlink Protection in cPanel for Your 1-grid Website

Protect your hosting bandwidth and stop external sites from directly embedding your images and media assets.

Hotlink Protection helps protect your website’s resources, reduces unnecessary bandwidth usage, and gives you greater control over how your images and media files are accessed online. This guide will help you enable Hotlink Protection in cPanel to prevent other websites from directly linking to files hosted on your 1-grid website. By the end of this guide, you’ll know how to configure Hotlink Protection, choose which file types to protect, allow or restrict direct access, and redirect unauthorised requests on your 1-grid Customer Zone account.

How to Set Up Hotlink Protection in cPanel | 1-grid


Before You Begin

Before restricting asset linking via cPanel, make sure you meet the following baseline requirements:

  • Access to your 1-grid Customer Zone
  • An active web hosting package running a cPanel dashboard
  • The specific list of your domains and subdomains to whitelist so your own images continue to display correctly
  • Identification of the precise file extensions (e.g., .png, .jpg, .webp) you intend to protect

💡 Context: Hotlinking occurs when an external website embeds an image or file hosted on your server directly into their pages. This means your hosting account serves the file and burns your account bandwidth every time someone visits their external page, draining your server resources without bringing traffic to your site.


Follow These Steps

Log in to your 1-grid Customer Zone, locate the web hosting service associated with your domain, and select Login to cPanel. Scroll down to the Security cluster section and click Hotlink Protection.

2. Confirm Allowed URLs

Before turning the protection framework on, review the URLs to allow access text block area. Make sure your primary root domain, subdomains, and any secondary companion domains you own are explicitly listed. This ensures your own web pages do not get blocked from rendering your images.

3. Choose Which File Types to Protect

Locate the field input row labelled Block direct access for the following extensions. Input the exact file type extensions you wish to lock down, separated cleanly by commas. Standard variations include: jpg, jpeg, png, gif, webp, bmp.

4. Decide Whether to Allow Direct Access

Review the Allow direct requests checkbox option parameter.

  • Checked: Web visitors can still look up or view a protected asset file if they paste its exact absolute URL directly into a clean browser window address bar.
  • Unchecked: Direct address bar lookups are also actively blocked and subject to your custom server firewall rule limits.

5. Configure a Redirect (Optional)

If you want to track or redirect bad requests, type a valid destination web layout path URL into the Redirect the request to the following URL text field. You can point scrapers back to your homepage, an “Access Denied” page, or a low-resolution warning graphic file.

6. Save Your Settings

Review your configurations, then click the Submit action button. The interface will refresh with a green success message confirming that the updated access guidelines have deployed.

If you ever need to turn off the block rules to allow an external partner to embed an asset stream file, simply return to the Hotlink Protection control page in cPanel and click the Disable button. The firewall definitions drop instantly.


What Happens Next?

Once saved, the web server writes rules directly to your root site configurations to intercept hotlinking attempts instantly.

  • Audit Loop: Open an external tool or private window to verify that your live site templates continue loading graphics perfectly across all device interfaces.

Important Things to Know

  • The Whitelist Priority: Leaving out companion configurations or staging versions of your domain name can accidentally break structural theme graphics on your secondary subdomains.
  • Immediate System Rules: Changes rewrite your hidden system rules in real-time. If visual page blocks occur, they can be fixed instantly by editing your settings panel.

Common Mistakes to Avoid

  • Forgetting to add your own subdomains or alternative validation URLs to the allowed access list.
  • Mistakenly locking down broad application download files that your consumers need to fetch seamlessly.
  • Inputting an invalid or broken destination web address inside the optional redirect target field.
  • Leaving the control room without manually testing image visibility across your core product page collections.

If This Didn’t Work

Should image files continue rendering on unauthorised external platforms after setting up your blocks, check whether your site uses an aggressive edge caching service that needs a cache flush. If your public website layouts load broken text blocks or display asset connection loops instead of graphics, double-check that your exact domain name formatting inside the whitelist matches your live URL format.


You’re Ready!

Your hosting account bandwidth protection rules are now fully active. Taking a few minutes to configure Hotlink Protection helps ensure your hosted data assets are only served where you intend, keeping your server running efficiently.



Need Help?

If your media files continue to leak bandwidth on external web applications or your custom redirect link triggers server loading loops, contact us. Our Technical Team is ready to see how they can assist.

To ensure our Technical Team can inspect your security environment quickly, please provide:

  • Your primary domain name and active web hosting account selection
  • The explicit file URL or asset route that is being bypassed or blocked incorrectly
  • The target URL of the external website attempting to load your files (if known)

Updated on August 18, 2026

Was this article helpful?

Related Articles