Protect your hosting bandwidth and stop external sites from directly embedding your images and media assets.
Hotlink Protection helps protect your website’s resources, reduces unnecessary bandwidth usage, and gives you greater control over how your images and media files are accessed online. This guide will help you enable Hotlink Protection in cPanel to prevent other websites from directly linking to files hosted on your 1-grid website. By the end of this guide, you’ll know how to configure Hotlink Protection, choose which file types to protect, allow or restrict direct access, and redirect unauthorised requests on your 1-grid Customer Zone account.

Before You Begin
Before restricting asset linking via cPanel, make sure you meet the following baseline requirements:
- Access to your 1-grid Customer Zone
- An active web hosting package running a cPanel dashboard
- The specific list of your domains and subdomains to whitelist so your own images continue to display correctly
- Identification of the precise file extensions (e.g., .png, .jpg, .webp) you intend to protect
💡 Context: Hotlinking occurs when an external website embeds an image or file hosted on your server directly into their pages. This means your hosting account serves the file and burns your account bandwidth every time someone visits their external page, draining your server resources without bringing traffic to your site.
Follow These Steps
1. Open Hotlink Protection
Log in to your 1-grid Customer Zone, locate the web hosting service associated with your domain, and select Login to cPanel. Scroll down to the Security cluster section and click Hotlink Protection.
2. Confirm Allowed URLs
Before turning the protection framework on, review the URLs to allow access text block area. Make sure your primary root domain, subdomains, and any secondary companion domains you own are explicitly listed. This ensures your own web pages do not get blocked from rendering your images.
3. Choose Which File Types to Protect
Locate the field input row labelled Block direct access for the following extensions. Input the exact file type extensions you wish to lock down, separated cleanly by commas. Standard variations include: jpg, jpeg, png, gif, webp, bmp.
4. Decide Whether to Allow Direct Access
Review the Allow direct requests checkbox option parameter.
- Checked: Web visitors can still look up or view a protected asset file if they paste its exact absolute URL directly into a clean browser window address bar.
- Unchecked: Direct address bar lookups are also actively blocked and subject to your custom server firewall rule limits.
5. Configure a Redirect (Optional)
If you want to track or redirect bad requests, type a valid destination web layout path URL into the Redirect the request to the following URL text field. You can point scrapers back to your homepage, an “Access Denied” page, or a low-resolution warning graphic file.
6. Save Your Settings
Review your configurations, then click the Submit action button. The interface will refresh with a green success message confirming that the updated access guidelines have deployed.
7. Disable Hotlink Protection (Optional)
If you ever need to turn off the block rules to allow an external partner to embed an asset stream file, simply return to the Hotlink Protection control page in cPanel and click the Disable button. The firewall definitions drop instantly.
What Happens Next?
Once saved, the web server writes rules directly to your root site configurations to intercept hotlinking attempts instantly.
- Instant Blocks: Scraping websites attempting to scrape or display your raw assets will show broken image boxes or load your designated redirect link destination layout.
- Audit Loop: Open an external tool or private window to verify that your live site templates continue loading graphics perfectly across all device interfaces.
Important Things to Know
- Extension Specificity: Hotlink protection controls apply strictly to the specific text extensions typed inside your configuration fields; unlisted assets remain fully open to embedding.
- The Whitelist Priority: Leaving out companion configurations or staging versions of your domain name can accidentally break structural theme graphics on your secondary subdomains.
- CDN Interaction Dynamics: If you funnel your site traffic through an external Content Delivery Network (CDN) or third-party proxy, you may need to apply matching hotlink settings inside your CDN control dashboard.
Common Mistakes to Avoid
- Forgetting to add your own subdomains or alternative validation URLs to the allowed access list.
- Mistakenly locking down broad application download files that your consumers need to fetch seamlessly.
- Inputting an invalid or broken destination web address inside the optional redirect target field.
- Assuming hotlink rules protect your website text from being manually copied, or stop users from saving images locally.
- Leaving the control room without manually testing image visibility across your core product page collections.
If This Didn’t Work
Should image files continue rendering on unauthorised external platforms after setting up your blocks, check whether your site uses an aggressive edge caching service that needs a cache flush. If your public website layouts load broken text blocks or display asset connection loops instead of graphics, double-check that your exact domain name formatting inside the whitelist matches your live URL format.
You’re Ready!
Your hosting account bandwidth protection rules are now fully active. Taking a few minutes to configure Hotlink Protection helps ensure your hosted data assets are only served where you intend, keeping your server running efficiently.
Related Articles
- Password Protect Directories in cPanel
- What is an SSL/TLS Certificate and Why It Matters
- Use the File Manager in cPanel
- WordPress Security Tips
Need Help?
If your media files continue to leak bandwidth on external web applications or your custom redirect link triggers server loading loops, contact us. Our Technical Team is ready to see how they can assist.
To ensure our Technical Team can inspect your security environment quickly, please provide:
- Your primary domain name and active web hosting account selection
- A screenshot of your Hotlink Protection settings panel configuration
- The explicit file URL or asset route that is being bypassed or blocked incorrectly
- The target URL of the external website attempting to load your files (if known)