You need a video on your website—a lesson in an online course, a video in a client portal, membership content, a product demo—but you don't want it on a public platform where anyone can find, share, or reuse it.
This is one of the most frequently asked questions in video hosting. And one of the most misunderstood. "Unlisted" doesn't mean private. Hiding the MP4 file URL in the source code isn't protection. Embedding a restricted YouTube video doesn't restrict access for anyone who finds the direct link.
This guide explains the difference between these approaches, describes the layers of protection that actually work, and shows how to test embedding before relying on it.
Private, unlisted, and public: what's the difference?
Many people confuse these three statuses. Confusion leads to a false sense of security—you think the video is protected, but it's actually accessible to anyone with a link.
| Private (on private hosting) | Public | Unlisted (via link) | |
|---|---|---|---|
| Appears in search and recommendations | No | Yes | No |
| Anyone with a link can watch | Only if you allow | Yes | Yes |
| Password or expiration date | Yes | No | No |
| Embedding is limited to your website | Yes | No | No |
| Advertising or recommendations of other people's content | No | Frequently | Frequently |
Unlisted videos are hidden from search. But the link to them works for anyone, and the embed can be copied to any website. This is hiding, not privacy.
Private videos on private hosting allow you to add real control mechanisms: password, link expiration date, and domain restrictions for embedding.
Option 1: Upload the file to your server
Uploading the MP4 to your own server and using the <video> tag is technically the simplest option. However, it has three serious problems:
No adaptive streaming. One file, one quality. A phone on a mobile data plan will painfully download a 4K file instead of automatically switching to 720p. The result is buffering, interruptions, and an irritated viewer.
The URL is visible in the source code. Anyone who opens the developer tools in their browser (Ctrl+Shift+I) will see a direct link to the file. This link can be copied and downloaded, regardless of any visual restrictions you've set on the page.
Security is your responsibility. Expiring signed URLs, referrer checks, and IP restrictions—all of this must be implemented independently. Without it, the "private" file is accessible to anyone who knows its address.
Self-hosting makes sense for engineering teams with specific requirements. For everyone else, the next option is simpler and more secure.
Option 2: Use a video hosting player
The video hosting service converts the uploaded video into adaptive streams, distributes them via a CDN, and provides you with an embed code (iframe) that loads the player. Almost every professional website embeds videos this way.
The question is: which hosting service and what control mechanisms does it provide?
What does a good private hosting service offer for embedding?
- Adaptive streaming. Automatic quality switching from 480p to 4K depending on the viewer's connection.
- Player without ads or third-party logos. The viewer sees your video—no YouTube recommendations, Vimeo logos, or offers to subscribe to someone else's channel.
- Domain restrictions. The player only works on the websites you specify.
- Subtitles. Subtitle tracks are also available in embeds.
- Analytics. How many times a video has been viewed, from which embed, and for how long.
Embedding Domain Restriction: Key Protection
Domain restriction is the most useful protection for embedded videos. You tell the hosting service which sites can display the player—for example, yourschool.org and *.yourschool.org. The hosting service instructs browsers to refuse to display the player on any other site using the HTTP header Content-Security-Policy: frame-ancestors.
Someone copied your embed code to their site? They see an empty frame instead of the video.
How does domain restriction work technically?
When a browser loads an iframe, it checks the server response headers. If the frame-ancestors header (or the older X-Frame-Options) specifies specific domains, the browser only allows display on those domains. On all other domains, the iframe is blocked.
This isn't a JavaScript check that can be bypassed. It's a browser-level mechanism—all modern browsers support it.
What domain restrictions don't do
Domain restrictions don't control who sees the page on your site where the video is embedded. If the page is open, the video plays. To control who's watching, you need page-level protection:
- Your authorization system (LMS, membership portal, client account)
- Password on the video or page
- Time limit
Page-Level Protection vs. Player-Level Protection
Proper privacy for embedded videos works on two levels:
Level 1: Player (Domain Restriction)
The player doesn't work anywhere except on your own websites. This prevents the embed code from being copied to other resources.
Level 2: Page (Authorization or Password)
The video page is only accessible to authorized users. This keeps unauthorized visitors away from the page with the video.
| Threat | Which protection works |
|---|---|
| Someone copied the embed code to another website | Domain Restriction |
| Someone shared the page link with an unauthorized person | Authorization or Password on the page |
| Old link continues to work for years | Expiration Date or Revocation |
| Someone downloads the video file | Hosting with streaming and downloads disabled |
| Someone's recording their screen | Nothing but DRM—and even DRM isn't perfect |
For most business needs—education, customer portals, membership content—the first four protections are sufficient.
Password: Embed vs. Delivery Page
Passwords work better on a separate video page than within an embed. Reasons:
On the page: a clear password prompt, your branding, and a clear error message. The viewer sees who the delivery is from and trusts the prompt.
In an embed: a password within an iframe is limited by the frame's space, may conflict with your page's design, and the viewer doesn't understand why the site is asking for another password.
Practical pattern:
- Video on your website (courses, portal) → embed with domain restrictions + authorization for your website
- Video for external recipients (clients, partners) → separate delivery page with password and expiration date
How to make an embed responsive
A good embed scales with the page. On desktop, the player takes up the entire width of the container. On a phone, it does the same, but with the correct aspect ratio.
Problem: White space or cropping
If you set fixed dimensions — width="640" height="360" — the player doesn't adapt to the screen width. On a phone, it either extends beyond the boundaries or scales disproportionately.
Solution: aspect-ratio container
Modern CSS allows you to set the aspect ratio of a container, and the iframe inside it takes up all the available space:
.video-container {
position: relative;
aspect-ratio: 16 / 9;
width: 100%;
}
.video-container iframe {
position: absolute;
top: 0;
left: 0;
width: 100%;
height: 100%;
border: none;
}
Most hosting services already provide responsive embed code. Check:
- The player maintains the correct aspect ratio on phones and desktops
- The page doesn't "jump" when the player loads (space is reserved)
- Fullscreen mode works on mobile devices
Embedding from public platforms: limitations
YouTube
Unlisted videos on YouTube can be embedded, but:
- The embed code can be copied to any website — there is no domain limitation
- The player shows recommendations for other videos at the end
- There is no password or expiration date
- If a viewer clicks the YouTube logo, they leave your site
Vimeo
Vimeo allows you to hide videos from vimeo.com and limit embedding by domain. But:
- Domain restriction is not available on all plans
- Player contains the Vimeo logo (can be removed on higher plans)
- Direct navigation by embed URL may work
Private video hosting (VodSpot)
- Domain restriction on all paid plans (up to 25 domains)
- Direct navigation by embed URL is blocked
- Player without third-party logos, ads, and recommendations
- Password and expiration date for delivery pages
- Subtitles in any language in the embed
Common errors when embedding private videos
Mistake 1: "Unlisted = private"
YouTube "unlisted" only means "not in search." The link works for everyone. Embed can be copied anywhere. This is not privacy.
Mistake 2: Hiding an MP4 URL with JavaScript
Any attempt to "hide" a video file's URL using JavaScript obfuscation is an illusion of security. Browser developer tools will show all network requests, including the video file's URL. This isn't security—it's an inconvenience for the developer who supports it.
Mistake 3: Relying solely on domain restrictions
Domain restrictions prevent embed code from being copied to someone else's site. But they don't control who sees the page on your site. If a course page is accessible without a login, any visitor will see the video.
Mistake 4: Autoplay with sound
Technically, this isn't a privacy issue, but it is a UX problem: autoplay with sound is off-putting to viewers, disruptive to screen reader users, and is blocked by most browsers by default. The only acceptable autoplay is silent background hero loops.
Mistake 5: Not testing embedding
You set up a restriction but never tested it. Here's how to test it.
How to Test Embeds
Five tests to pass before relying on private embeds:
Test 1: Private Window. Open the page with the embed in a private browser window, logged out. Do you see what someone else sees? If the page is protected by authentication, you should see a login prompt, not the video.
Test 2: Foreign Domain. Paste the embed code into a test page on a different domain. The video shouldn't play—a blank frame or a restriction message should be displayed.
Test 3: Direct Navigation. Open the embed URL (src iframe) directly in the address bar. On a reputable hosting service, the video won't play—it should be redirected or blocked.
Test 4: Mobile Device. Test the page on a phone over a mobile data connection. The video should start playing within a few seconds. Subtitles and controls should work.
Test 5: Subtitles in Embedded Content. Turn on subtitles and switch between languages. Make sure the subtitle button is accessible and working correctly.
Embedding patterns for different tasks
Online course or LMS
- Embedding restricted by your LMS domain
- Authorization via LMS (student logs in once)
- Video downloading disabled
- Subtitles required
- View analytics for progress tracking
Client portal
- Embedding restricted by the portal domain
- Authorization via the portal
- Download — up to you (some clients require download functionality)
- Analytics for delivery confirmation
Membership site or community
- Embedding restricted by domain
- Authorization via the membership system
- Expiry date — by content type (a course can be available for 12 months, a webinar for 30 days)
Video delivery to an external client
- Separate delivery page (not embedded on an external site)
- Password + expiration date
- Instant revocation if needed
- Original download — controlled
Embedding Checklist
- Uses a video hosting player with adaptive streaming, not raw MP4
- No ads, third-party logos, or recommendations
- Responsive embedding — doesn't disrupt the page layout
- Domain restriction configured and tested
- Membership content requires authorization or password
- Expiration date set for temporary content
- Subtitles available in embeds
- Tested from a different domain and while logged out
Frequently Asked Questions
How do I embed a private video on a website?
Upload the video to a private video hosting service, copy the embed code to your page, and restrict embedding to your website's domain. If only certain people should see the video, put the page behind your site's login or use a password-protected delivery page.
Can I privately embed an unlisted YouTube video?
You can embed it, but unlisted videos are accessible to anyone with a link, and the embed code can be copied to other websites. This is not a private setting.
How do I prevent other websites from embedding my videos?
Use a hosting service that supports domain restrictions. This instructs browsers to refuse to display the player on websites you haven't approved.
Can I set a password for an embedded video?
Passwords work best on a separate video page. For embedded videos, protect the page where it's located with your website's authentication, and restrict embedding to your domain.
Do subtitles work in embeds?
They should. Check that the subtitle button works in the embedded player on your website. In VodSpot, subtitles are displayed in all embeds.