Recommended Free Tools
If you’re a visitor, you usually can’t remove a Cloudflare block yourself: save the full error page, including its code and Ray ID, and send it to the website owner with a short description of what you were doing. If you own the site, use the error details to find the matching event in Cloudflare Security Events, identify the rule or control that acted, and make only a targeted change if the request was legitimate. The right fix depends on the exact error; a generic 403, Error 1020, and Error 1015 do not mean the same thing.
First identify who can fix the block
Cloudflare provides security and traffic services for websites, but the site owner controls many of the rules that deny visitors. That makes the first question practical: do you own or administer the blocked website?
- If you are a visitor: record the exact error code, Cloudflare Ray ID, time, and what you were trying to do. Contact the site through another available channel and ask the owner to review the event. Cloudflare’s Error 1020 guidance specifically recommends giving the site owner a screenshot; its WAF FAQ also asks visitors to share their actions and the displayed Ray ID. Cloudflare Error 1020 guidance and Cloudflare WAF troubleshooting FAQ.
- If you own or administer the site: investigate the event in the Cloudflare dashboard before changing a rule. The error page and event log help identify whether a firewall rule, access rule, rate limit, origin server, or another layer denied the request.
A visitor generally cannot override a zone owner’s security settings. Cloudflare’s Error 1010 documentation says the site owner performed that block and Cloudflare support cannot override the customer’s security settings: Error 1010: The owner of this website has banned your access based on your browser’s signature.
Read the error before choosing a fix
Error 1020: a firewall rule denied the request
Error 1020 means a Cloudflare firewall rule denied access. The owner should search Security Events using the Ray ID or the visitor’s IP address, then inspect the matching event and the rule that acted. Cloudflare’s Error 1020 page was last updated August 3, 2026: Error 1020 documentation.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
403 Forbidden: check branding and origin
A 403 status by itself does not show that Cloudflare caused the denial. Cloudflare says an unbranded 403 is returned by the origin web server. A Cloudflare-branded 403 may be associated with WAF rules or other Cloudflare security features. If the page has no Cloudflare branding, investigate the origin server’s permissions and access controls rather than assuming a Cloudflare rule is responsible. See Cloudflare’s 403 documentation, last updated September 28, 2026.
Other 1xxx codes: do not reuse the 1020 fix
Cloudflare’s 1xxx errors cover different conditions, including blocks based on IP address, ASN, country, or browser signature, as well as DNS and configuration problems. For example, Error 1005 concerns an ASN ban, while Error 1010 concerns a browser signature. Look up the exact code and follow its specific cause rather than treating every 1xxx error as a firewall-rule problem. Cloudflare’s error index is at Cloudflare 1xxx errors; see also Error 1005 and Error 1010.
Error 1015: a rate-limit response
Error 1015 is associated with rate limiting. A rate-limiting rule can match an expression, track selected traffic characteristics over a measurement period, apply a request threshold, and take action for a mitigation duration. Cloudflare directs blocked visitors to its Error 1015 documentation from its rate-limiting guidance. See Rate limiting rules and Error 1015.
Rank #2
Possible ISP-level block
If an ISP blocks a shared Cloudflare IP, that is a connectivity issue between the user and the ISP, not necessarily a site owner’s security rule. Cloudflare says it cannot restore connectivity for users affected by an ISP-level block; the user should contact the ISP. Details: Understanding Cloudflare IP addresses.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What a visitor should send the site owner
- Capture the full error page, including any code, Cloudflare branding, Ray ID, and displayed timestamp. Preserve the page rather than cropping out diagnostic details.
- Write down the page or action that triggered the block: for example, signing in, submitting a form, or opening a particular section. Include the approximate time and timezone if known.
- Send the information through the site’s support email, contact form, or another official channel. Ask the owner to check the corresponding Cloudflare event.
- If the page is a generic unbranded 403, mention that too; the owner may need to inspect the origin server rather than a Cloudflare rule.
Do not repeatedly retry a request that may have triggered a rate limit. If the block is temporary, waiting may help, but the site owner is the party who can identify the rule and confirm what action is appropriate.
How a site owner investigates Error 1020 or a Cloudflare-branded denial
- Collect the visitor’s evidence. Ask for the full error page or screenshot, Ray ID, approximate time, visitor IP if they can provide it, and the action they were taking.
- Open Cloudflare Security Events. In the dashboard, select the relevant website (zone) and open its security events/logs view. Dashboard labels can change; use the current Cloudflare dashboard navigation if the exact label differs.
- Search with the Ray ID or client IP. Use the identifier shown on the error page where available. If searching by time, account for the difference between the error timestamp in UTC and the timezone displayed by the log search.
- Inspect the matching event. Find the action and the rule or security control that matched. Check its expression and conditions against the request; do not infer the cause solely from a generic 403 or from the visitor’s IP reputation.
- Choose the narrowest safe correction. If the request is legitimate, adjust the matching rule or create a limited exception suitable for that condition. Avoid broad allow rules unless you understand what other protections they bypass.
- Verify both access and protection. Have the visitor retry the specific legitimate action and confirm the event no longer blocks it. Check that unrelated security controls still apply.
Cloudflare’s Error 1020 documentation recommends using the Ray ID or visitor IP to locate the event and assessing the rule. It does not prescribe one universal rule change; the safe correction depends on the matching event. See Error 1020 troubleshooting.
Rank #3
- 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
- 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
- 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
- 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
- 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.
Choose the right owner-side change
IP, ASN, or country access controls
Cloudflare IP Access Rules can allow, block, or challenge traffic based on visitor IP, ASN, or country. The documentation recommends custom rules for IP-based or geography-based blocking. Be especially careful with an allow action: Cloudflare notes that allowing an IP or ASN through IP Access Rules bypasses configured custom rules, rate-limiting rules, and WAF Managed Rules. That can be broader than exempting one request from one matching condition. Review Cloudflare IP Access Rules before applying an exception.
Rate limits
When the event points to rate limiting, inspect the rule’s match expression, tracking characteristics, measurement period, threshold, and mitigation duration. Cloudflare cautions that rate-limiting rules are not designed to let an exact number of requests reach the origin: counters can take a few seconds to update. A small difference between the configured threshold and observed requests is not, by itself, proof that the rule is malfunctioning. Change the relevant rule only after reviewing the actual traffic pattern. Documentation: Rate limiting rules.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBot, crawler, and monitoring traffic
Custom rules using block or challenge actions can affect known bots, including search engines and website monitoring, depending on the fields and conditions used. If the blocked requester is a crawler or monitor, inspect the matching event and bot status before adding an exception. A broad exemption could also admit traffic the rule was intended to stop. Cloudflare discusses this risk in its WAF troubleshooting FAQ.
Rank #4
- Bookbound planner helps you keep track of passwords and favorite websites
- Room for over 200 entries; 3.5 x 6 inch page sizes
- User name and security questions field
- Tips for what makes a strong password; web resources; notes pages
- Printed on quality paper containing 30% post-consumer waste; black simulated leather cover; 3.63 x 6.13 x .21 inches
Origin server and ISP causes
If the 403 is unbranded, inspect the origin server’s own access policy and logs. If the user reports an ISP-level block of a shared Cloudflare IP, changing the site’s WAF rule may not resolve it; the connectivity issue belongs with the ISP. Keep the enforcement layer aligned with the evidence rather than disabling Cloudflare protections to test a theory.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
If you need to preserve the blocked page for diagnosis, a screenshot can capture its visible code and Ray ID. ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. Here is a one-request example; replace the URL with the error-page URL you need to capture. See the ScreenshotNeo documentation for request options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/blocked-page -o shot.webp
ScreenshotNeo accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each of those steps can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed as clean shots, and the response reports the page verdict and billing status in headers. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. These are ScreenshotNeo’s stated plan terms; see ScreenshotNeo for current details.
Sign up free for 1,000 screenshots a month, with no card.
Best Value
Common troubleshooting mistakes
- Changing rules before finding the event: a guess can weaken protections without fixing the cause. Search by Ray ID or IP and inspect the matching action first.
- Searching the wrong time window: the error timestamp may be UTC while the dashboard view uses another timezone. Convert the time before concluding that no event exists.
- Treating all 403s as Cloudflare blocks: an unbranded 403 comes directly from the origin according to Cloudflare’s documentation. Check the branding and origin logs.
- Allowing an IP to solve one narrow false positive: IP Access Rules allow actions can bypass custom rules, rate limiting, and WAF Managed Rules. Review the scope before using them.
- Disabling rate limiting because counts do not look exact: counters may take a few seconds to update, and the feature is not designed to enforce an exact number of origin requests. Check the rule and traffic pattern instead.
- Exempting a crawler without verifying it: confirm the event and bot status, since a broad allow can affect more than the intended monitor or search crawler.
- Asking Cloudflare to overrule the site owner: Error 1010 guidance says Cloudflare support cannot override the customer’s security settings. The owner must review a site-configured block.
- Using a VPN or changing networks as a universal fix: that does not correct a site rule, origin permission, or ISP-level issue, and may change the evidence available to the owner.
FAQ
Can I unblock my IP from a Cloudflare-protected website?
If you are only a visitor, you cannot change the site’s Cloudflare rules. Send the owner the error details and ask them to review the matching event.
Does a Cloudflare Ray ID reveal why I was blocked?
It is a useful identifier for the site owner to search in Security Events; the ID alone does not tell a visitor which rule matched.
Should I keep retrying after Error 1015?
Avoid repeated rapid requests. The error is associated with rate limiting, and continued requests may keep matching the configured limit.
Will contacting Cloudflare support remove a website’s block?
Not when the site owner configured the block: Cloudflare’s Error 1010 documentation says support cannot override a customer’s security settings.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

