Recommended Free Tools
Cloudflare Error 1006 means the site’s Cloudflare customer has banned the IP address making your request. The durable fix is for the site owner to review the security rule or allow the authorized client IP—not to disguise the scraper. If you do not control the site, ask its owner for access; if you do, identify which IP, anti-bot, User-Agent, or rate-limit rule is blocking the request.
What Cloudflare Error 1006 means
Error 1006 is an access-denied response indicating that the client IP address has been banned by the Cloudflare customer protecting the website. Cloudflare’s direction is to ask the website owner to investigate its security settings or allow the client IP. Cloudflare support cannot override a customer’s block. Cloudflare’s Error 1006 documentation describes the condition and remedy.
This distinction matters: the error is about the network identity Cloudflare sees, not simply the scraper’s code or browser settings. A changed User-Agent, cleared cookie jar, or different TLS fingerprint does not itself resolve an IP ban. Do not treat proxies or identity spoofing as permission to access a site that has denied your requests.
First determine whether you are the site owner or scraper operator
If you do not control the target website
Stop repeated requests and contact the site owner or its technical support. Provide the exact URL, timestamp and time zone, the response status, the HTML error body, any CF-RAY identifier, and the public IP address your authorized client used. Ask the owner to confirm whether access is permitted and, if appropriate, allow that IP or provide an approved collection method. Follow the site’s terms and published crawling instructions.
#1 Best Overall
If you administer the website
Review the Cloudflare rules and any origin-side security software that could deny the client. Confirm the block is unintended before changing policy. If the crawler is legitimate and authorized, narrow the rule or allow the verified client IP as appropriate; avoid broadly weakening protections for all traffic.
Capture useful evidence before changing anything
Cloudflare 1xxx errors are represented in the HTML response body, so an HTTP status alone may not identify the specific error. Save the body and response headers alongside the request details. Look for “1006” in the body and record a CF-RAY identifier if present; it can help the site administrator investigate the event.
For an authorized target, a minimal request with cURL can show the response status, headers, and body:
curl -svo /dev/null https://example.com/
Replace example.com with the authorized host. The verbose output goes to standard error while the response body is discarded by /dev/null. If you need to inspect the body for the 1xxx code, save it instead:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorscurl -sv https://example.com/ -o response.html
Do not run repeated probes against a site that has denied access. Share the evidence with the owner rather than increasing request volume.
How site owners should find the blocking rule
Check IP Access and zone restrictions
Inspect IP Access rules and Zone Lockdown settings for a block matching the client address, its range, or the requested path. Verify the address Cloudflare actually sees, especially if traffic passes through a NAT gateway or an approved outbound proxy. Compare the rule’s scope with the affected URL and confirm whether the same client is blocked on other paths.
Rank #3
Inspect custom security rules and origin controls
Review custom security rules and any anti-bot module running on the origin. Cloudflare’s crawler guidance advises site owners not to block legitimate verified crawlers, to check robots.txt, and to ensure origin protections and rate limits do not inadvertently affect legitimate crawling. See Cloudflare’s guidance for verified bots. A rule that is correct for anonymous or abusive traffic may still match an authorized crawler because of an overly broad condition.
Review User-Agent rules as a separate cause
A User-Agent blocking rule can deny requests based on the User-Agent header. Cloudflare recommends custom rules rather than User-Agent blocking rules for specific agents; see User Agent Blocking documentation. Check whether such a rule is involved, but do not confuse it with the defined cause of Error 1006: that error indicates an IP ban. Changing the scraper’s User-Agent alone is not a fix for an IP-based ban.
Check rate limits and request patterns
Cloudflare documents rate limiting as a way to control bot traffic and prevent scraping. Repeated requests, bursts, or a high share of error responses may encounter configured controls; response-status-based rules can target repeated 403 or 404 traffic. Review the matching rate-limit policy and the request pattern before tuning it. Cloudflare’s documentation is at Rate Limiting Rules.
For legitimate collection, use a consistent approved identity, conservative pacing, caching, and the site’s published access rules. A proxy is only a possible network choice for an authorized workflow; it does not grant permission or replace diagnosis and owner approval.
Distinguish Cloudflare-edge behavior from origin behavior
A Cloudflare response and an origin response can differ. Cloudflare recommends inspecting HTTP responses with cURL and, where you are authorized and able to do so, testing the origin directly to distinguish origin behavior from the proxy layer. An origin comparison should be performed only by the site owner or with explicit authorization; do not try to evade the site’s protections by connecting around Cloudflare.
If the owner conducts the comparison, they should use the correct origin address, hostname and TLS settings so the test reaches the intended site. Compare status, body, and headers, then correlate the request with Cloudflare’s event and rule logs. An origin that responds normally while the public route returns Error 1006 points the investigation toward the Cloudflare-side decision; an origin denial calls for checking origin controls as well.
Best Value
Which remedy fits the likely cause?
| Finding | Appropriate next step | Who can act |
|---|---|---|
| IP Access or Zone Lockdown rule matches an approved client | Verify the address and rule scope; narrowly allow the authorized IP if appropriate | Site owner or Cloudflare administrator |
| Custom security or origin anti-bot rule catches a legitimate crawler | Review the condition and exemption scope; test that other protections still work | Site owner or origin administrator |
| User-Agent-specific rule matches the request | Review the rule independently; use an appropriately scoped custom rule for specific agents | Site owner or Cloudflare administrator |
| Rate limit matches bursts or repeated error traffic | Review request frequency, caching, error handling, and the policy threshold | Site owner; operator can reduce authorized request volume |
| You are an external scraper operator without permission | Stop and request authorization or an approved data-access route | Site owner decides whether to grant access |
A proxy service does not override a block or change who has authority to allow access. Consider a network change only after the site owner has approved the workflow and the cause has been established.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting common cases
- The browser shows a block, but the script only reports a generic failure. Save and inspect the HTML body as well as status and headers; the 1xxx identifier may be in the body.
- The status is 403 but you cannot find “1006.” Do not assume every 403 is Error 1006. Capture the full response and ask the site administrator to correlate it with Cloudflare and origin logs.
- Changing User-Agent did not help. Error 1006 identifies an IP ban. Ask the owner to check the client IP and allow it if authorized; separately check for User-Agent rules.
- The error began after faster or more frequent crawling. Pause the job, use conservative pacing and caching for any approved collection, and ask the owner to review rate limits and request logs.
- The operator says the IP changed but access is still denied. Do not keep cycling identities. Have the owner confirm the IP Cloudflare sees and whether another rule or origin control is responsible.
- You own the site but cannot find a Cloudflare rule. Inspect origin anti-bot modules, application controls, and rate limits, and compare an authorized origin test with the public route.
Or skip the browser setup
If your goal is to capture a page you are authorized to access—not to get around a site’s denial—ScreenshotNeo offers a one-request screenshot API. A screenshot service cannot authorize access to a blocked website; first resolve the block with its owner. ScreenshotNeo accepts cookie and consent banners like a visitor and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture, with each step configurable. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. It also provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for AI agents. See ScreenshotNeo and the API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, with no card required.
Frequently asked questions
Can Cloudflare support remove an Error 1006 ban?
No. The site’s Cloudflare customer controls the security decision; contact the website owner to request review or an allowlist change.
Free tools Windows power users keep installed
One-click scans. No signup required.
Does deleting cookies fix Error 1006?
Not as a remedy for the IP ban that defines Error 1006. The owner should investigate the network address and relevant security configuration.
Is a proxy an approved fix?
Not by itself. Use a different network identity only as part of an access method the site owner has approved, not to bypass a denial.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

