Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallIf you’re visiting a website, you can’t change its Cloudflare settings: send the site owner the error, Ray ID, time, affected URL, and what you were doing when access was blocked. If you own the site, find the request in Cloudflare’s Security Events, identify the rule or security feature that acted, and make the narrowest change that fixes the legitimate request. The right fix depends on the error: 1020 is a firewall-rule denial, 1015 is a rate limit, and 1010 is a browser-signature block.
First determine whether you’re a visitor or the site owner
The person who can change the block is usually the owner or administrator of the website. Cloudflare provides security services to that site; a visitor cannot edit the site’s rules or ask Cloudflare Support to override its owner’s settings. Cloudflare’s support guidance directs visitors to contact the website owner.
- If you’re a visitor: collect the error details and send them to the website’s support team. The owner can use those details to find the request and decide whether a rule needs adjustment.
- If you administer the site: use Security Events to identify the request and the service or rule that handled it before changing anything.
“Why am I blocked by Cloudflare?” doesn’t have one universal answer. A firewall rule, a rate limit, a browser-signature check, a bot mitigation feature, or a block elsewhere in the network can look similar to an end user. Diagnose the specific event rather than assuming that changing browsers, networks, or devices will resolve it.
What the Cloudflare error code means
| Error | What it indicates | Next step |
|---|---|---|
| 1020 | A site firewall rule denied access. | A visitor should send the error details to the site owner. The owner should search Security Events using the Ray ID or client IP, then inspect the matching rule. |
| 1015 | The site’s rate limiting temporarily blocked the request volume. | A visitor should wait and avoid rapid retries. The owner should review the rule’s threshold and period against legitimate traffic. |
| 1010 | The site owner denied access based on the browser signature. | A visitor should contact the owner. The owner can review Browser Integrity Check and related security configuration. |
These codes point to different causes and different controls. In particular, a 1020 firewall denial is not the same problem as a 1015 rate limit, so changing a rate threshold is not the remedy for every Cloudflare block.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
If you’re visiting a site that blocked you
Record enough detail for the site owner to find the event
Save a screenshot of the complete error page. Note the page URL, the time and timezone, and the action immediately before the block—for example, submitting a form or opening a particular page. Include the Ray ID if the page displays one. The Ray ID and your client IP can help the owner locate a 1020 request in Security Events; do not post a client IP publicly when you can send it through the site’s private support channel.
Send the information through the website’s official support channel. Explain whether the block happened once or repeats, and whether it followed a particular action. Avoid sending passwords, payment details, or other secrets: they are not needed to locate a Cloudflare security event.
Respond according to the error
- For 1015: wait before trying again. Cloudflare specifically warns that repeated attempts within a short period can extend the block. If it continues after waiting, contact the site owner rather than repeatedly refreshing.
- For 1010: contact the site owner. The block is based on a browser signature and is controlled by the site’s configuration; Cloudflare cannot override that customer setting for you.
- For 1020: send the screenshot, Ray ID, timestamp, URL, and context. The owner needs to identify the particular firewall rule before deciding whether your request should be allowed.
Changing VPNs, buying software, or replacing hardware is not a reliable general fix. A different trusted network might affect some challenge situations, but whether you can access the site ultimately depends on the actual cause and the owner’s configuration. If the block is at your internet provider rather than in Cloudflare, the appropriate support contact may be your ISP instead.
If you own the site: find the rule before changing it
- Open Security Events. Search for the event using the Ray ID, client IP, affected URL or path, and timestamp. Time and URL help narrow the search if you have no Ray ID.
- Inspect the Service field. Cloudflare’s Security Events identifies which security feature acted. Use that information to distinguish a managed WAF rule, custom rule, rate limit, IP Access rule, bot mitigation, or challenge.
- Confirm the match. Compare the event’s request details with the rule or feature that triggered it. Verify that the request is legitimate and that the reported time, path, and source match the user’s account.
- Choose a feature-specific, narrow correction. An exception for one known path or source is not interchangeable with a broad Allow rule: the latter can bypass multiple security controls.
- Retest the legitimate flow and review new events. Check that the affected user can complete the intended action, then inspect subsequent events to make sure the change did not allow unwanted requests.
Do not begin by switching off a collection of protections. The event and matching rule determine which setting to adjust; if those details are unclear, gather them before changing production security.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Fix a managed WAF rule false positive
If Security Events points to a managed rule that is blocking a legitimate request, Cloudflare’s troubleshooting guidance recommends using an exception, adjusting the OWASP managed ruleset where applicable, or disabling only the specific rule responsible. Cloudflare states: “If one specific rule causes false positives, disable that specific rule and not the entire ruleset.” Turning off a whole ruleset because of one false positive removes more protection than addressing the matching rule.
Scope an exception to verified request attributes where possible—for example, the affected endpoint or path, or a known source IP range or ASN when that is appropriate to the situation. Make sure an exception intended to apply before a managed ruleset is evaluated before that ruleset executes. Check the ordering and match conditions rather than assuming an exception later in processing will take effect.
Disabling a particular rule can reduce protection for requests that rule was designed to catch. Keep the exception limited to the legitimate traffic you have identified, and check fresh events after the change. Avoid replacing a narrow managed-rule exception with an IP Access Allow rule unless you understand the broader bypass.
Check IP Access rules before adding an Allow
An IP Access Allow rule is not simply a more convenient version of a single-rule exception. Cloudflare documents that this action can bypass custom rules, rate limiting, and WAF managed rules. An overly broad Allow can therefore remove checks that are unrelated to the false positive you are trying to fix.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Before allowing a source, confirm that it is trusted and that the scope is no broader than necessary. Prefer a verified, limited source or a rule-specific exception when that resolves the incident. If you do use Allow, account for the other security features it bypasses and review the resulting events.
Fix a 1015 rate-limit block
Review the active rate-limit rule’s threshold and period against the pattern of legitimate requests. Determine whether normal visitors or a legitimate integration can reach the configured limit—for example, by making several requests as part of one user action—before increasing it. Keep the threshold tied to actual traffic needs rather than copying a generic setting.
Cloudflare’s error guidance gives an example of a very short, one-second period and says an owner could consider increasing it, such as to ten seconds. That is an example for review, not a universal recommended value. Choose a threshold and interval that fit your site and the behavior the rule is intended to control. Visitors seeing 1015 should wait instead of retrying rapidly.
Investigate bot-related blocks carefully
First establish which bot feature is active; Bot Fight Mode and Super Bot Fight Mode do not offer the same exception controls.
Recommended Free Tools
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
- Bot Fight Mode: a WAF custom-rule Skip action cannot skip Bot Fight Mode. Do not spend time adding a Skip rule on the assumption that it will exempt a legitimate request from this feature.
- Super Bot Fight Mode: scoped Skip rules are supported. Where the event and configuration confirm this is the source of a false positive, use a skip scoped to the matching legitimate traffic rather than exempting unrelated requests.
Disabling a bot mitigation feature is a possible fallback, but it changes the site’s protection. Identify the feature and the affected request first, and weigh the resulting loss of protection before making that change.
Common troubleshooting mistakes
- Changing settings without identifying the service: the wrong control may have no effect or may weaken unrelated protections. Start with the Security Events Service field and matching rule.
- Allowing a whole IP range to fix one endpoint: an IP Access Allow can bypass custom rules, rate limiting, and WAF managed rules. Limit the scope or use the exception that matches the actual cause.
- Disabling an entire managed ruleset: this removes protection beyond the false-positive rule. Cloudflare recommends targeting the specific rule instead.
- Using a Skip action for Bot Fight Mode: that mode cannot be skipped with a WAF custom-rule Skip action. Confirm whether Super Bot Fight Mode is active before using a scoped Skip.
- Retrying a 1015 error repeatedly: rapid attempts may extend the block. Wait, then contact the site owner if it persists.
- Assuming every block is Cloudflare’s: an ISP-level block is separate from a Cloudflare rule block. If the site owner cannot find a corresponding event, ask them to verify where the block occurs before changing Cloudflare settings.
Document the blocked page without treating a screenshot as a fix
A screenshot can preserve what the user saw, but it does not identify the rule or grant access. If you need a captured record of a publicly reachable error page, ScreenshotNeo is a website screenshot API and MCP server; it does not change Cloudflare’s rules or bypass a site’s access controls. Its API can return an image or PDF for a URL, which can be useful for documenting a page that the capture request can reach.
Or skip the browser setup
Make one API request to capture the affected URL. Replace the example URL with the page you need to document and supply your API key. See the ScreenshotNeo API documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/affected-page -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://example.com/affected-page"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com/affected-page' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
- Cookie and consent banners, newsletter popups, and chat widgets are removed before a shot; each step can be turned off.
- Bot checks, blank pages, and failed loads are never billed. The API response includes page-verdict and billing headers.
- An MCP server provides the
take_screenshot,get_page_info, andcapture_pdftools for Claude, Cursor, and other MCP clients. - The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Every feature is available on every plan.
A capture is evidence for support or debugging, not a way around a 1020, 1015, or 1010 decision. If the page presents a challenge or block to the capture request, the screenshot service cannot make the site owner’s access decision for you. Sign up for 1,000 free screenshots a month with no card.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Keep the change proportionate to the incident
For a site owner, the safest resolution is the smallest change that restores the verified legitimate request while leaving unrelated protections in place. The important distinctions are the feature that acted, the scope of the exception, and the security controls the selected action bypasses. Recheck the affected flow and recent events after making a change. Cloudflare’s dashboard and product behavior can change, so confirm the current controls in your account when applying these steps.
Frequently Asked Questions
Why might only one page or action on a site be blocked?
A rule or exception can match a particular path, request, or source rather than every page on the site. The site owner can compare the affected request with its Security Events entry and matching rule.
Can a screenshot of the error tell me which Cloudflare rule blocked me?
Usually not by itself. It preserves the displayed error and may include a Ray ID, but the site owner needs the corresponding Security Events entry and configuration to identify the rule.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

