Errors / HTTP errors
403 Forbidden (Cloudflare)
Cloudflare, in front of the site, decided this request should not reach it.
Whoever matches the rule cannot use the site at all.
Seeing it on someone else’s site?
- The site's security settings blocked you: a VPN, a country, a browser extension or an unusual network can trigger them.
Error 1020: Access deniedmeans a firewall rule the site set; only the site owner can change it. Send them the Ray ID at the bottom of the page.
Why it happens, if it is your site
- A WAF custom rule, an IP access rule or a country block set in the Cloudflare dashboard.
- Bot Fight Mode or Super Bot Fight Mode classing the visitor (or a legitimate service, like a payment webhook) as a bot.
- A managed WAF rule matching something in the request, like a form post that looks like SQL.
- A 403 with no Cloudflare branding came from the server behind Cloudflare, not from Cloudflare.
How to fix it
- In the dashboard, Security → Events, search the Ray ID from the error page: it names the rule that blocked it.
- Add a skip rule for legitimate traffic (your own monitoring, a payment provider's webhook IPs) rather than turning protection off.
- If the page is plain nginx or Apache text behind Cloudflare, read the 403 page for the origin server instead.
Whose problem it is
Usually the server that answers the request.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.
Often seen with
- 403 ForbiddenThe server understood the request and refuses to let you see this.
- 403 Forbidden (nginx)nginx found the path but is not allowed to serve it.