How to stop other sites from re-streaming your live video
Once a live stream's URL is public, anyone can embed it on their own site, or run a scraper in a data center that re-streams it, and you pay for the traffic. No single setting stops every case; the answer is layers, each cheap to apply and each closing a different gap.
1. Signed playback URLs
Your backend signs the playback URL with an expiry. A copied link stops working once it expires, so a URL pasted into a forum or another site is only good for a short time. Signed URLs only control who can start playback; a viewer who is already watching is not cut off.
2. Referer and Origin allowlists
List the pages allowed to embed the player. Requests from any other site's page are refused, which stops the most common case: someone embedding your player or stream on their own page.
3. Request-source policies
Real viewers come from home and mobile networks; most re-streaming scrapers run in data centers. A request-source policy classifies each request by the network it comes from and lets you log or refuse data-center sources per playback domain. Start in log mode, look at what it would have refused, then turn on refusal.
4. Address blocking
When a specific source keeps pulling your stream, block its addresses. Request logs record every playback and publish, and can be exported as CSV to find the source.
5. Protect ingest too
Protection is not only for viewers. Require a Stream Key on each ingest domain, and allowlist the publishers' public IP addresses where they are fixed, so nobody can publish into your channel.
What not to do
Do not cap how many times or how long legitimate viewers may watch to fight abuse: that turns away the audience you are paying to reach. Use the layers above, which target the abusers, not the viewers.
On Streaming CDN
Every customer sets these on its own playback and ingest domains in the console: signed URLs, Referer/Origin allowlists, request-source policies, address blocking, Stream Keys and publisher IP allowlists.