Hotlink protection prevents other websites from loading your images, videos, or downloads directly from your server. This consumes bandwidth and can slow down your site. In Plesk, you can enable this protection within minutes by setting up your own domain list in the webserver settings of your domain. This article shows step by step how this works and what to watch out for.
What is hotlinking and why protect against it
Hotlinking occurs when another website embeds an image or file from your server using the original URL, without hosting the file itself. The result: your server processes the requests and pays for the bandwidth, while someone else displays the content.
Plesk checks the HTTP Referer header for this purpose. This is the address from which a request for an image originates. If this does not match your own domains, the request is denied or replaced with an alternative image.
Setting up hotlink protection in Plesk
You set up the protection at domain level, via the webserver settings. Follow these steps:
Log in to Plesk
Open your Plesk panel and select the domain for which you want to block hotlinking.
Go to Apache & nginx Settings
Open the Apache & nginx Settings option in the domain menu. On servers with LiteSpeed, you’ll find the same setting under the webserver settings of the domain.
Find the hotlink setting
Scroll to the security options section and look for Hotlink Protection.
Enter your own domains
Enter your domain and variants, for example example.com and www.example.com. Only requests from these domains will be allowed.
Optionally choose an alternative image
You can upload an image that will be shown when hotlinking is detected, for example with a short message.
Save the settings
Click OK or Apply. The change is usually applied immediately.
Managing whitelist and exceptions
Don’t forget to also add subdomains that load images, such as a cdn subdomain, to the whitelist. Otherwise, these will be blocked just like external sites.
Do you want certain external parties, such as image search engines or a social network, to be allowed to display your content? Then explicitly add those domains to the list. This way you retain control over who may use your content, without blocking everything.
Testing and verifying
After saving, open several pages of your website in an incognito window and check that all images load correctly. Also test pages with content from subdomains or a CDN, as these are sometimes accidentally blocked as well.
Hotlink protection is one part of a broader security approach. Combine it where possible with an up-to-date SSL certificate and proper DNS settings for your domain names. If you’re unsure about the correct settings, consult the knowledge base for more background articles about Plesk.
Frequently asked questions
Does hotlink protection slow down my website?
No, the server only checks the Referer header, which creates barely noticeable overhead. It can even relieve your site by processing fewer unauthorized requests.
Can I allow an external partner to use my images?
Yes, add that partner’s domain to your whitelist in Plesk. You decide which domains get access.
Can I set up hotlink protection per folder?
In Plesk, this is set at domain level. For folder-specific rules, you can add additional .htaccess rules on Apache-based environments.
Does hotlink protection also work with email images?
Hotlink protection focuses on web content loaded via a browser. For the security of your business email, different settings apply, such as SPF and DKIM.
Do I need to set this up again if I switch to another provider?
Yes, the setting is at server level in Plesk. When switching to Tandata, your support team can help you reconfigure these settings if desired.
Conclusion
With hotlink protection in Plesk, you prevent others from using your images and files without permission. Set up your own domains correctly, don’t forget subdomains, and check after activation that everything still loads properly. This way you protect your bandwidth without your visitors noticing anything.