SecurityPlayerAccess control

Domain Locking and Geo-Restrictions for Embedded Video

How embed-domain lists, country and IP bans and signed links work in the UFOLOAD player, how matching rules behave and where each control stops.

Once a video is public, anybody who can read your page source can copy its address. Sometimes that is fine. Often it is not: another site embeds your player and spends your traffic, a licence covers only some countries, or a block of addresses keeps scraping your library. UFOLOAD gives you several controls for that, and they work at different layers. This article explains what each one does, how the matching rules work, and where each one stops, so you can combine them sensibly instead of trusting a single switch.

The controls at a glance

ControlWhat it limitsWhere you set it
Allowed embed domainsWhich sites may show your player in an iframePlayer studio, Access tab
Banned countriesViewers from the listed countriesPlayer studio, Access tab
Banned IP addressesSingle addresses and masksPlayer studio, Access tab
Allowed download domainsWhich sites may open the download pagePlayer studio, Access tab
Signed links with a lifetimeHow long a playback address stays valid, and for whomAPI, POST /files/{id}/links

Everything on this list is part of the player and delivery settings of your account and applies to all your videos. The rules are ready on every plan; only the download button itself is limited to the Pro and Max plans, as the pricing page shows.

Step 1: lock embedding to your domains

The embed player runs inside an iframe on somebody else's page, and the browser tells it which page that is through the referrer. The player passes that host to the server, which compares it with your list. If the host is not on the list, the server refuses with a 403 and the player shows an unavailable message instead of the video.

The matching rules are strict and worth knowing exactly:

  • example.com allows that exact host and nothing else. It does not allow www.example.com.
  • *.example.com allows every subdomain of example.com, but not the bare example.com. To cover a site and its subdomains, list both entries.
  • Case does not matter, and ports and a trailing dot are ignored, so Example.com:8080 matches example.com.
  • The list holds up to 100 entries. An empty list means the player may be embedded anywhere, which is the default.
  • Write plain host names. If you paste a full address by mistake, only its host is kept.
Heads up

Add every host you actually embed on, including staging and preview domains, before you turn the list on. A video that suddenly shows an unavailable message on your own staging site is the most common surprise.

What domain locking does not do

This control stops casual hotlinking: somebody pasting your iframe into their page. It is not a security boundary, and it is better to know why. The check relies on the referrer sent by the browser. If a page strips the referrer, the player cannot tell where it is embedded, and in that case it does not block, because privacy settings and referrer policies would otherwise break legitimate embeds. Equally, a determined visitor who copies the signed playlist address from the network panel can play it elsewhere until it expires, because segments are checked by the signature on the link, not by the page that asks for them. The public watch page of a video is not restricted by the domain list either: anyone with its link can open it.

So think of the list as a fence that keeps honest neighbours out. For stronger control over a stream you serve yourself, use signed links, described below. If you need the opposite, a video that only chosen people can reach, note that UFOLOAD has no private videos and no DRM; read self-hosting versus YouTube versus a video host before you rely on it for confidential content.

Step 2: block countries and IP addresses

Country and IP rules are enforced in two places: when a viewer opens the watch or embed page, and on every request for the playlist and segments at the delivery layer. Delivery checks are made for each request rather than cached, so a rule you add applies to the very next segment, and someone who already has a link cannot bypass the rule by keeping it.

  • Countries are two-letter ISO 3166-1 alpha-2 codes separated by commas, for example US, CN, RU. The viewer's country is looked up from the IP address in a geolocation database. Each list holds up to 100 entries.
  • IP addresses can be a single address such as 203.0.113.7 or a mask with a star in the last octet such as 203.0.113.*, which covers the whole range of 256 addresses. IPv6 addresses can be listed exactly.

Two practical cautions. Masks are blunt: a .* mask on a mobile or office network blocks every legitimate person behind it. And IP-based geography is only as accurate as the address data behind it. Visitors on a VPN or a proxy appear to be wherever the exit node is, so a country ban is a way to reduce unwanted traffic or honour a regional licence in good faith, not a guarantee.

Tip

You are not blocked by your own rules while you are logged in as a member of the organization that owns the video, and neither is our support staff. That is deliberate, so banning your own country does not lock you out of your library, but it also means you must test from a logged-out browser or another network.

If you play the stream in your own page with hls.js (see embedding an HLS video), the domain list is not involved, because the player never asks the UFOLOAD page for permission. Control comes from the link itself. POST /api/v1/files/{id}/links issues playback and download links with a lifetime of 60 seconds to 30 days. Add bind_ip to tie the link to one IPv4 address, or bind_cookie to tie it to a cookie value that your server sets for the visitor; the response then names the cookie that must accompany the request.

bash
curl -X POST "https://ufoload.com/api/v1/files/FILE_ID/links" \
  -H "Authorization: Bearer $UFOLOAD_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"ttl": 600, "bind_ip": "203.0.113.7"}'

A short lifetime combined with binding is the strongest tool available: a link copied from your page is useless within minutes and useless from any other address. The price is that you must issue links from your server on every page view, which is the pattern the upload and API guide and the API documentation describe.

Download domains

Players on the Pro and Max plans can show a Download button. A separate list, allowed download domains, works exactly like the embed list but controls which sites may open the download page in a frame. Leave it empty to allow every site. Visitors who open the download page directly on UFOLOAD are not restricted, the same as with the watch page.

Step 3: save and test

  1. Save the lists in the Access tab.
  2. Open a page on an allowed domain in a private window and confirm that the video plays. Check the subdomain variant too.
  3. Open the same embed from a domain that is not on the list, for example a local test page served from another host name, and confirm the player shows the unavailable message.
  4. For a country or IP rule, test while logged out, from a network that matches the rule if you have one.
  5. Keep your own page's referrer policy at a sensible value such as strict-origin-when-cross-origin. A policy of no-referrer hides the host from the player, which then cannot enforce the list.

Used together, an embed list plus short-lived signed links cover most real cases: casual hotlinking is blocked at the door, and anyone going further has to work for a link that expires. If you also run ads in the player, the monetization guide explains the ad formats and how breaks are scheduled. The list of everything available in the player is on the features page, and the video hosting checklist shows which access controls to demand from any provider.

Try it with a free account

Upload a video, get an HLS player and an API key in minutes. Plan limits are listed on the pricing page.