Hotlinking is another site embedding your images on your bandwidth. Refuse image requests whose Referer names a foreign host, but never an empty one: the header is optional (RFC 9110), so direct visits, privacy settings and crawlers that fetch images on their own often send none, and refusing them can drop you from image search.
# /var/www/example/images/.htaccess - Needs: mod_rewrite; AllowOverride FileInfo
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https?://([^/]+\.)?example\.com(:\d+)?(/|$) [NC]
RewriteCond %{HTTP_REFERER} !^https://([^/]+\.)?(google|bing|duckduckgo)(\.com?)?(\.\w\w)?(/|$)
RewriteRule \.(avif|gif|jpe?g|png|svg|webp)$ - [F,NC]Line 3 passes an empty Referer, and line 4 the site's own hosts; test the host only, since the default strict-origin-when-cross-origin policy sends other sites just the origin. Line 5 passes google.co.uk, bing.com and duckduckgo.com, not google.evil.net. Line 6 answers 403:
(none) 200 https://cdn.example.com/ 200 https://www.google.co.uk/ 200 https://duckduckgo.com/ 200 https://forum.example.net/t/42 403 https://google.evil.net/ 403
A CDN caches one answer for all referrers, so enforce the rule there. Cross-Origin-Resource- Policy: same-site (Security Headers and CORS) blocks every foreign embed, image search included. A Hotlink and Bad-Bot Blocker pairs this block with a bad-bot filter.