Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare may block or challenge a request when a security rule considers its traffic risky, a rate limit is exceeded, or browser and bot signals match a configured control. But a plain 403 Forbidden is not necessarily from Cloudflare: it may come from the website’s own server, and an ISP or network restriction can prevent a connection before the site responds. The page’s branding, error code, Ray ID and timing help identify which problem you have—and who can fix it.

First identify where the block is coming from

Look at the response page, not just the browser’s “403” label. A Cloudflare-branded error page or a specific Cloudflare error code points toward a Cloudflare-side security control. A 403 without Cloudflare branding may have been generated by the origin server—the website’s own hosting or application layer. A connection failure with no Cloudflare error page may instead reflect a network or ISP restriction.

Branding is a clue, not a complete diagnosis. Cloudflare documents several possible sources of branded 403 responses, including WAF rules, Security Level settings, DDoS Protection, Browser Integrity Check and Validation Checks. Conversely, origin permissions, ModSecurity or an origin-side IP deny rule can produce an unbranded 403. Don’t change a Cloudflare setting until you have evidence that Cloudflare generated the denial.

What to do as a visitor

  1. Save the evidence. Record the page URL, exact error text or code, approximate time and timezone, and any Ray ID shown. For Error 1020, take a screenshot. The site owner can use the Ray ID or your client IP to look for a matching Security Events entry; include the time and timezone so the event can be found.
  2. Follow the code-specific guidance. If the page says Error 1015, wait before trying again. Cloudflare advises: “Do not repeatedly try to access the website within a short period of time, as this may extend the block.” The website owner sets the rate limit, so contact the site if the block persists.
  3. If it is a challenge, complete it normally. Allow the browser to use ordinary web functionality needed for the offered check. Browser Integrity Check, for example, can react to a missing or non-standard user agent and common HTTP header patterns. Disabling browser protections or spoofing headers is not a reliable or guaranteed fix.
  4. Contact the right party. Send the evidence to the website’s support team or administrator for a Cloudflare-branded block or a persistent unbranded 403. If the browser cannot reach the site and there is no Cloudflare response, contact your network administrator or ISP as appropriate; a site owner cannot change a restriction imposed by your ISP.

A visitor cannot edit the website’s firewall rule or directly unblock an IP from a site. The owner must identify the rule and decide whether an adjustment is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
  • DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
  • AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
  • CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
  • EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
  • OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.

What common Cloudflare errors mean

What you see What it indicates Useful next step
Cloudflare-branded 403 A Cloudflare-side control may have denied the request; the branding alone does not identify which one. Save the page, code and Ray ID if present, then contact the site owner.
Error 1020: Access denied Cloudflare identifies this as a denial by a firewall rule. Give the owner a screenshot, Ray ID or client IP if appropriate, and the time with timezone.
Error 1015: You are being rate limited The request exceeded a rate limit configured for the site. Wait rather than repeatedly refreshing or retrying; contact the owner if it continues.
Unbranded 403 The origin server may have refused the request, for example because of permissions, ModSecurity or an IP deny rule. Ask the website’s support team or administrator to check its server and application.
Connection failure without a Cloudflare error page A network-level restriction, including an ISP block of Cloudflare network addresses, is one possibility. Escalate to the ISP or network administrator if the site owner cannot find a corresponding request.

Why a legitimate request may be challenged or denied

Security controls make decisions from signals and rules, not from a visitor’s intent. A legitimate user can therefore encounter a challenge or denial. Possible factors include request patterns, browser headers, bot-like behavior, IP reputation, a matching WAF rule, a Security Level setting, Browser Integrity Check, or a rate limit. These are possible explanations, not a diagnosis of any particular block; the error page and the owner’s event records are needed to establish what happened.

Firewall and WAF rules

A custom or managed firewall rule can match properties of a request and block it. Error 1020 specifically points to a firewall-rule denial, but it does not tell the visitor which condition matched or whether the rule was configured correctly. The owner needs to inspect the event and rule expression.

Rate limits

A rate-limit rule is shaped by its configured request count, time period, matching characteristics and mitigation duration. Automated polling, repeated refreshes or multiple requests in a short period may hit a threshold even when each individual request is valid. Cloudflare notes that detection and enforcement can differ by a few seconds, so an apparent delay does not by itself prove the rule failed.

Rank #2
Sale
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
  • Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
  • Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
  • Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
  • Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
  • Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks

Browser Integrity Check and browser signals

Browser Integrity Check examines common HTTP headers associated with spam and may deny or challenge requests with no user agent or a non-standard one. Cloudflare says the feature is enabled by default and documents global or selective configuration for zone owners. Treat it as one possible cause only: an event record is needed to connect it to a particular incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ISP or network restrictions

An ISP-level block of Cloudflare network IP addresses is separate from a website owner’s Cloudflare rules. Cloudflare explains that a zone uses an address from a shared Cloudflare pool and that it cannot restore connectivity when an ISP imposes the block. That is a reachability problem, not the same thing as a 1xxx error served by the site’s configured security controls.

How website owners should investigate a false positive

  1. Collect a reproducible report. Ask for the error screenshot, Ray ID, approximate time and timezone, affected URL, and client IP if appropriate for your support process. A Ray ID or IP can help locate the request; the time must be interpreted in the timezone used by your dashboard.
  2. Search Security Events. Find the event using the Ray ID or client IP and inspect its action and matched rule. Confirm whether Cloudflare produced the denial before changing a rule. If there is no corresponding event and the response is unbranded, investigate the origin server instead.
  3. Inspect the control that matched. Depending on the event, review the relevant WAF custom or managed rule, Security Level, Browser Integrity Check behavior, IP Access rule or rate-limit rule. Check the request properties that caused the match, not just the visitor’s description that they were blocked.
  4. Choose the narrowest safe change. Refine the matching expression, adjust a justified threshold, or scope an exception to the necessary path or visitor. Avoid using a broad allow rule merely to make one report disappear.
  5. Verify the result. Re-test the affected request and confirm the intended traffic works without removing protections from unrelated requests. Account for rate-limit enforcement timing: Cloudflare says enforcement can lag detection by a few seconds, and a Block action can stop evaluation of later rules.

Why a broad IP or ASN allow rule is risky

Cloudflare’s IP Access “Allow” action is not necessarily a narrow exception to one rule. It can bypass configured custom rules, rate limits, WAF Managed Rules and deprecated firewall rules. Before using it, understand which controls the action bypasses and whether the scope covers more traffic than the affected visitor or path. A precisely scoped rule adjustment is generally easier to justify and review.

Rank #3
NETGEAR Nighthawk WiFi 6 Router R6700AX, Up to 1,500 sq ft, 1.8 Gbps
  • NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
  • WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
  • SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
  • READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
  • COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.

How to distinguish a Cloudflare issue from an origin 403

Compare the response with the owner’s Cloudflare Security Events and origin logs for the same request and time. A matching Cloudflare event supports a Cloudflare-side explanation. An unbranded 403 with no matching Cloudflare denial points toward the origin, where the administrator should check server permissions, application access controls, ModSecurity and IP deny rules. Absence of a matching event is not, by itself, proof of the cause; correlate the request across the available logs.

If there is no server response at all, investigate reachability separately. An ISP block of shared Cloudflare network addresses cannot be corrected by changing a website’s WAF expression. The network provider or ISP is the appropriate escalation point for a restriction imposed on its side.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can a screenshot help document the problem?

A screenshot can preserve the visible error page for a support report, especially when it includes the error code or Ray ID. It does not reveal the matching rule, replace Security Events, or unblock the request. If a URL is reachable in a browser but you need a saved image of its visible state, ScreenshotNeo is a website screenshot API and MCP server for developers. It is not a way around a Cloudflare block: a CAPTCHA, bot check or failed load is not something to treat as a successful capture.

Rank #4
Sale
TP-Link BE6500 Dual-Band WiFi 7 Router (BE400)
  • 𝐅𝐮𝐭𝐮𝐫𝐞-𝐑𝐞𝐚𝐝𝐲 𝐖𝐢-𝐅𝐢 𝟕 - Designed with the latest Wi-Fi 7 technology, featuring Multi-Link Operation (MLO), Multi-RUs, and 4K-QAM. Achieve optimized performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, and Samsung Galaxy S24 Ultra.
  • 𝟔-𝐒𝐭𝐫𝐞𝐚𝐦, 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝐰𝐢𝐭𝐡 𝟔.𝟓 𝐆𝐛𝐩𝐬 𝐓𝐨𝐭𝐚𝐥 𝐁𝐚𝐧𝐝𝐰𝐢𝐝𝐭𝐡 - Achieve full speeds of up to 5764 Mbps on the 5GHz band and 688 Mbps on the 2.4 GHz band with 6 streams. Enjoy seamless 4K/8K streaming, AR/VR gaming, and incredibly fast downloads/uploads.
  • 𝐖𝐢𝐝𝐞 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐰𝐢𝐭𝐡 𝐒𝐭𝐫𝐨𝐧𝐠 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 - Get up to 2,400 sq. ft. max coverage for up to 90 devices at a time. 6x high performance antennas and Beamforming technology, ensures reliable connections for remote workers, gamers, students, and more.
  • 𝐔𝐥𝐭𝐫𝐚-𝐅𝐚𝐬𝐭 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐖𝐢𝐫𝐞𝐝 𝐏𝐞𝐫𝐟𝐨𝐫𝐦𝐚𝐧𝐜𝐞 - 1x 2.5 Gbps WAN/LAN port, 1x 2.5 Gbps LAN port and 3x 1 Gbps LAN ports offer high-speed data transmissions.³ Integrate with a multi-gig modem for gigplus internet.
  • 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.

Or skip the browser setup

For a page you are authorized to capture, one GET request can return an image. See the ScreenshotNeo API documentation for parameters and response details.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

  • Cookie and consent banners, newsletter popups and chat widgets are removed before capture; each cleanup step can be turned off.
  • Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed. Responses identify the page verdict and billing status in headers.
  • An MCP server provides take_screenshot, get_page_info and capture_pdf tools for AI agents and MCP clients.
  • The Free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000. Every feature is on every plan.

Sign up free for 1,000 screenshots a month, with no card required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
  • Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
  • Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
  • Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
  • MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
  • Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home

Frequently asked questions

Can I unblock my IP from a website myself?

No. If the website’s Cloudflare rule or rate limit is responsible, the site owner controls that configuration. Provide the error details and ask the owner to investigate; if an ISP or network is blocking connectivity, raise it with that provider instead.

Does every Cloudflare-branded challenge mean I was identified as a bot?

No. A challenge or denial can result from several security controls and request signals. The page alone usually cannot establish which one matched.

Quick Recap

SaleBestseller No. 1
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
VPN SERVER: Archer AX21 Supports both Open VPN Server and PPTP VPN Server
$59.98
SaleBestseller No. 2
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
$24.32
Bestseller No. 5
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
$44.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.