Domain-restricted video privacy you can actually enforce

You're in great company

Unlisted links and 'copy the embed' privacy aren't real controls

  • Unlisted links leak the moment they're shared

    An unlisted URL is one forward away from an open web page. Once the link is out, there is nothing stopping it from getting indexed, screenshotted, or reposted on a third-party site with your video embedded on their traffic.

  • Copied embed codes play anywhere

    A raw iframe pasted onto a competitor's site, a forum, or a scraper's blog plays the video with your bandwidth and none of your intent. Without domain restriction, an embed is portable in every direction.

  • Password-only protection is not enough for paid content

    For paid courses, premium tutorials, and gated partner content, a shared password gets forwarded once and the paywall stops mattering. Domain restriction plus password is what actually keeps paid content on the paid property.

Domain restriction is the piece most video hosts either don't offer or offer as a checkbox with no teeth. Vimeo enforces the domain whitelist at playback: the player asks the browser what page it is loading on, checks against the whitelist, and refuses to render if the answer isn't on the list. Combined with password protection and privacy modes, it is what makes video privacy on Vimeo genuinely enforceable.

Domain whitelisting that stops the player from loading off approved sites

Set a whitelist of approved domains, subdomains, or specific pages where the video is allowed to play. Vimeo enforces the whitelist at playback, so an embed code copied onto an unauthorized site loads a message instead of the player. Manage the whitelist per video or per folder, apply changes in bulk when a domain moves, and layer with password protection and privacy modes for defense in depth.
Get started now

Per-video or per-folder whitelist

Set the whitelist on a single video or set folder-level defaults so every upload inherits the same approved domains. New content is safe by default.

Subdomain and specific-path rules

Whitelist a full domain, a subdomain, or a specific path. The rule can be as broad or as narrow as the security posture requires.

Player refuses to load off list

The player checks the referrer at load and refuses to render on domains not on the whitelist. A copied embed on an unapproved site shows a not-authorized message instead of playing.

Bulk domain updates

When a marketing domain changes or a partner is added, update the whitelist in bulk across every affected video. One action, propagated across the library.

Layered privacy: domain restriction plus password plus privacy mode

For sensitive content such as paid courses, premium tutorials, or partner training, the combination of domain whitelisting and password protection significantly reduces the chance of a clean rip on another site. Enterprise plans layer SSO, SCIM, and folder-level access on top, so a paid course is behind identity, behind password, and locked to the approved domain, three layers instead of one.
Get started now

Pair with password protection

Domain restriction alone stops the embed from playing off list. Adding a password stops on-list playback by anyone who doesn't have the password. Two independent controls, not one.

Privacy modes as a base layer

Set the video to Hide from Vimeo so it doesn't have a Vimeo.com page. The only way in is through your approved embed on your approved domain.

SSO and identity on top

Enterprise SSO plus SCIM ties access to identity. Combined with domain restriction and password, sensitive content is behind three independent controls.

Analytics for embed sources

See which domains actually played the video, catch a copied embed attempt on a domain not authorized, and iterate the whitelist as legitimate placements shift.

Trusted by marketers, businesses, and video pros around the globe

  • 100+ billion

    video views (and counting)

  • 7+ million

    videos uploaded every month

  • 4+ billion

    minutes streamed each month

What domain restriction changes for content that needs to stay put

Video that used to leak the moment the URL got shared stays where you put it. Paid content stops walking off to third-party sites, partner content stays on the partner property, and internal training doesn't end up cached on someone's personal blog. Combined with password protection and privacy modes, domain restriction turns a nice-to-have into a control your legal team actually recognizes.
  • Paid content stays paid

    A paid course or premium tutorial only plays on the paying property. A copied embed on a scraper site shows a not-authorized message instead of playing your content on their traffic.
  • Partner content stays with the partner

    Co-branded video on a partner property doesn't accidentally play on their competitor's site. The embed enforces the partnership boundary.
  • Internal training stays internal

    Employee training locked to your internal domain doesn't end up on someone's personal blog or cached on a search engine. Confidentiality gets a real backstop.
  • Cleaner analytics

    Embed-source data shows only the domains you actually approved. Traffic reporting stops being polluted by unauthorized reuses of your content.
  • Bandwidth stays with your users

    You aren't paying to serve video to someone else's audience. Domain restriction keeps playback (and the bandwidth bill) tied to your audience.
  • Compliance answers get simpler

    SOC 2 and ISO 27001 audits ask about access controls. 'Domain restriction plus password plus SSO' is the answer that maps to how auditors think about layered security.
  • Combines with in-player CTAs

    Lead-capture forms and CTAs inside the player still work behind domain restriction, so gated content still captures leads without leaking to unauthorized surfaces.
  • Works with responsive iframe embed

    Domain restriction applies to the standard responsive iframe embed. No custom player, no special SDK, just the same embed code Vimeo already gives you.
  • Easy to audit

    See the whitelist per video, per folder, and per workspace. Ops answers 'what domains are approved for the finance training?' in seconds instead of digging through settings.

How to set up domain-restricted video privacy on Vimeo

Vimeo domain restriction is available on paid plans and set per video or per folder. Here's the flow from empty setting to enforced whitelist.
  1. Step 1

    Open the video in your Vimeo workspace and go to Privacy settings. Look for the 'Where can this be embedded?' option and switch to 'Specific domains'.
  2. Step 2

    Add the domains, subdomains, or specific paths where the video is allowed to play. Include your marketing site, your LMS, your paid course platform, and any approved partner properties.
  3. Step 3

    Layer with additional privacy controls: password protection if the content is gated or paid, Hide from Vimeo if the video shouldn't have a Vimeo.com page, and privacy modes as the base layer.
  4. Step 4

    Set folder-level defaults so new uploads inherit the approved domain list. Contributors don't have to remember to configure the whitelist, and new content is safe by default.
  5. Step 5

    Verify enforcement by attempting to embed the video on a non-approved domain. The player should refuse to load. Review embed-source analytics after the first week and adjust the whitelist based on legitimate placements.

Find the right plan for you

    Vimeo offers discounts to US-based non-profit organizations and educational institutions. Learn more.

    For more information on feature availability, please reference our pricing page.

    Frequently asked questions about domain-restricted video privacy