Skip to content

Errors / HTTP errors

403 Forbidden (Cloudflare)

Cloudflare, in front of the site, decided this request should not reach it.

Whoever matches the rule cannot use the site at all.

Seeing it on someone else’s site?

  • The site's security settings blocked you: a VPN, a country, a browser extension or an unusual network can trigger them.
  • Error 1020: Access denied means a firewall rule the site set; only the site owner can change it. Send them the Ray ID at the bottom of the page.

Why it happens, if it is your site

  • A WAF custom rule, an IP access rule or a country block set in the Cloudflare dashboard.
  • Bot Fight Mode or Super Bot Fight Mode classing the visitor (or a legitimate service, like a payment webhook) as a bot.
  • A managed WAF rule matching something in the request, like a form post that looks like SQL.
  • A 403 with no Cloudflare branding came from the server behind Cloudflare, not from Cloudflare.

How to fix it

  1. In the dashboard, Security → Events, search the Ray ID from the error page: it names the rule that blocked it.
  2. Add a skip rule for legitimate traffic (your own monitoring, a payment provider's webhook IPs) rather than turning protection off.
  3. If the page is plain nginx or Apache text behind Cloudflare, read the 403 page for the origin server instead.

Whose problem it is

Usually the server that answers the request.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with