Hotlink Protection

Hotlink Protection That Does Not Block Search Engines

Hotlinking is another site embedding your images on your bandwidth. Refuse image requests whose Referer names a foreign host, but never an empty one: the header is optional (RFC 9110), so direct visits, privacy settings and crawlers that fetch images on their own often send none, and refusing them can drop you from image search.

A hotlink blocker that lets search engines and direct visits throughApache config
# /var/www/example/images/.htaccess - Needs: mod_rewrite; AllowOverride FileInfo
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://([^/]+\.)?example\.com(:\d+)?(/|$) [NC]
RewriteCond %{HTTP_REFERER} !^https://([^/]+\.)?(google|bing|duckduckgo)(\.com?)?(\.\w\w)?(/|$)
RewriteRule \.(avif|gif|jpe?g|png|svg|webp)$ - [F,NC]

Line 3 passes an empty Referer, and line 4 the site's own hosts; test the host only, since the default strict-origin-when-cross-origin policy sends other sites just the origin. Line 5 passes google.co.uk, bing.com and duckduckgo.com, not google.evil.net. Line 6 answers 403:

Output of 68
(none)                           200
https://cdn.example.com/         200
https://www.google.co.uk/        200
https://duckduckgo.com/          200
https://forum.example.net/t/42   403
https://google.evil.net/         403

A CDN caches one answer for all referrers, so enforce the rule there. Cross-Origin-Resource- Policy: same-site (Security Headers and CORS) blocks every foreign embed, image search included. A Hotlink and Bad-Bot Blocker pairs this block with a bad-bot filter.