Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An image that does not appear is a symptom, not a diagnosis. The cause may be your browser, one extension, a missing file, a server response, a CDN cache, a security policy, or code trying to read an image from another origin. Start with reversible visitor checks, then inspect the exact image request if you own the site.

Before changing settings, record the scope: is one image missing or every image, one browser or all browsers, one device or an entire network? Note the page URL, a direct image URL if available, and any visible or developer-console error.

Fast checks for visitors

Work through these steps in order and retest after each one. The sequence is designed to identify local browser problems without changing the website.

  1. Reload once. A transient connection or partially loaded page can leave an image element empty. Avoid repeatedly refreshing a page that may be submitting a form.
  2. Open the page in a private window. Google lists private browsing as an initial test for Google Images. If the image appears privately, your normal profile data, cache, cookies, or extensions is a likely factor; it does not prove that every website problem is browser-side.
  3. Clear cache and site cookies. Remove cached files and cookies for the affected site, then reopen the page. Sign-in sessions and preferences may be removed, so save any needed credentials first.
  4. Disable extensions temporarily. Ad blockers, privacy tools, script managers, download helpers, and toolbars can block image hosts or rewrite requests. Turn them off for the affected site, testing one change at a time, then re-enable them to identify the conflicting extension.
  5. Confirm JavaScript is enabled. Some galleries, lazy-loading scripts, and image viewers do not request the final file until JavaScript runs. Check the browser’s site settings and reload.
  6. Try another browser or network. This is an isolation test, not a guaranteed fix. If another browser works on the same device, compare extensions and stored site data. If every browser fails on one network but works on another, a proxy, DNS filter, firewall, or network policy may be involved.

If only one site is affected, send its owner the page URL, a failing image URL if you can copy it, your browser and device, and the exact error text. That information is more useful than saying simply that “images are broken.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identify the failure before changing a site

Site owners should reproduce the problem in a private window, then open developer tools (usually F12 or Ctrl/Cmd + Shift + I). In the Network panel, reload and filter by Img. Select the failed request and record its URL, status, response headers, initiator, and timing. In Console, copy policy, CORS, JavaScript, or certificate messages.

Observation Most useful next check
One file returns 404 or another error Verify the path, filename, capitalization, hostname, protocol, upload, and server route.
Many files fail with 403 or an authentication message Check access rules, hotlink protection, signed URLs, cookies, authorization headers, and firewall or bot controls.
Requests never leave the browser and Console reports CSP Inspect the page’s img-src policy and allow the actual image origin.
Request is pending, times out, or fails TLS/DNS Test the image host directly and investigate DNS, certificates, origin availability, proxy, or network filtering.
Direct URL works but the embedded page does not Compare the generated HTML, srcset, lazy-loading attributes, referrer rules, CSP, and JavaScript that replaces the URL.
Old content persists after a fix Clear browser, page, plugin, and CDN caches; inspect response cache headers.

A successful HTTP status alone is not enough. The response must contain image bytes with an appropriate content type, not an HTML error page, login screen, redirect loop, or truncated file.

Verify the image address, upload, and generated markup

Open the resource directly

Paste the exact request URL into a new tab. Check spelling, capitalization, path, hostname, protocol, query string, and redirects. Confirm that the file exists at the expected upload location and that the server returns the intended image. A template may still point to an old domain or directory after a redesign or migration.

Inspect responsive and lazy-loading attributes

Look at the rendered element, not only the CMS editor. A valid-looking src can be overridden by srcset, sizes, a lazy-loading placeholder, or JavaScript. Ensure the selected candidate URL is reachable and that an intersection-observer script actually runs when the image enters the viewport.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check permissions and content type

Web-server permissions must allow the process to read the file and the client to request it. The response should use a suitable image media type such as image/jpeg, image/png, image/webp, image/avif, image/gif, or another format supported by your complete browser and processing path. Do not assume that a format supported by one editor is supported by every browser, proxy, optimizer, or image library.

Cache layers that hide a fix

There can be several independent caches: the browser, a page or plugin cache, an image-optimization cache, a reverse proxy, and a CDN. A stale cached 404 can survive after the file is uploaded, while a stale successful response can keep serving an old image.

  1. Purge the affected page and image in the application or plugin cache.
  2. Clear the browser cache or use a private window.
  3. If a CDN is present, purge the individual image URL when possible, then retest privately.
  4. Inspect response headers such as Age, ETag, Last-Modified, and cache-control directives to see which layer answered.

Use a versioned filename or query string for intentional asset changes, but do not use cache-busting as a substitute for fixing an incorrect URL or failed origin.

Migration, rewrites, and WordPress-specific cases

If failures began during a domain move, HTTPS conversion, host change, or permalink change, compare old and new URLs in the generated HTML and database. A migration can leave absolute HTTP URLs, an old uploads directory, or incorrect hostname settings.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For WordPress on Apache, rewrite configuration involving mod_rewrite can be one cause of image 404s in some migration and shared-hosting situations; it is not a universal WordPress explanation. Check the server’s rewrite rules and error log. If appropriate, save the current permalink settings to regenerate rules. Avoid editing server files when you do not understand the hosting configuration; ask the host to verify Apache modules, document-root mapping, and permissions.

Content Security Policy (CSP) blocks

A Content Security Policy can prevent an otherwise valid image from loading. Read the exact Console violation and compare the image’s origin with the policy’s img-src directive (or its fallback policy). Add only the trusted image origins required by the site, using the correct scheme and hostname. Do not weaken the entire policy to make one request work.

Rank #3
The New Real Book
  • Used Book in Good Condition

The CSP Level 2 specification states: “Whenever the user agent fetches a URL in the course of one of the following activities, if the URL does not match the allowed image sources for the protected resource, the user agent MUST act as if there was a fatal network error and no resource was obtained, and report a violation.” A policy block therefore looks like a network failure to the page even when the image server itself is healthy.

CORS: display versus reading image bytes

Cross-origin rules are often blamed too broadly. A normal <img> can commonly display a publicly accessible image from another origin without JavaScript reading its pixels. CORS becomes important when browser code fetches the bytes, draws the image to a canvas, generates a thumbnail, performs OCR, or otherwise processes the response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For such workflows, configure the image server’s Access-Control-Allow-Origin response deliberately and match the request mode and credentials. If a browser plugin or editor cannot fetch a remote image because of CORS, a server-side import or sideload route avoids exposing the cross-origin fetch to the browser. Never solve CORS by allowing every origin when the content is private.

CDN, firewall, and bot controls

A CDN or security layer may return 403, a challenge page, or an empty response to image requests. Compare the direct origin response with the CDN response, inspect headers, and check firewall events. Confirm that image paths are not covered by a rule intended for HTML pages, API endpoints, or hotlink prevention. If a challenge or CAPTCHA is presented, an automated capture or optimization service may not be able to obtain the image; permit legitimate traffic according to the provider’s documented controls rather than disabling protection globally.

Format, decoding, and upload failures

When the network request succeeds but the browser reports a decoding error, download the response and inspect it with an image tool. The file may be truncated, mislabeled, corrupted, or an HTML error saved with an image extension. Re-export a known-good file, upload it again, and verify that the optimizer has not produced an invalid variant. WordPress’s current media workflow lists JPEG, PNG, WebP, AVIF, GIF, and HEIC among formats it can process in supported configurations; that list is not a blanket guarantee for every browser, server, or plugin combination.

Performance and reliability checks

  • Use appropriately sized responsive images and modern formats, but retain a fallback when your audience includes browsers that cannot decode the chosen format.
  • Set explicit width and height to prevent layout shifts; this does not fix a failed request but makes loading behavior easier to observe.
  • Lazy-load below-the-fold images only after confirming the script and placeholder logic work.
  • Set realistic timeouts and retries in image-processing jobs, while avoiding retry storms against an unavailable origin.
  • Monitor the complete chain: upload, origin, optimizer, CDN, policy headers, and browser decode. A green CMS upload message does not prove that a public URL works.

Or skip the browser setup

If your goal is to obtain a reliable page image while diagnosing a site, ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One GET request is enough:

API documentation

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also offers an MCP server so Claude, Cursor, and other MCP clients can use take_screenshot, get_page_info, and capture_pdf. It supports full-page and element captures, device and viewport settings, retina scale, custom CSS and JavaScript, waiting conditions, request blocking, headers and cookies, geolocation, transparent backgrounds, resizing, caching TTLs, signed links, asynchronous webhooks, bulk capture, usage reporting, and PDF output.

The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account to test it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting by symptom

Only one image is missing

Open its direct URL, verify the upload and filename, inspect the request status, and check whether that individual URL is cached or blocked. Do not begin by changing global CSS or security settings.

Every image on one site is missing

Test privately, inspect CSP and firewall responses, and check whether the image hostname or CDN has changed. A shared policy, DNS, certificate, or authorization problem is more likely than dozens of corrupted files.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Images work in one browser only

Compare extensions, cookies, cache, JavaScript settings, and privacy protections. Re-enable extensions individually to find the conflict.

Images fail after a migration

Compare old and new hostnames, HTTPS schemes, upload paths, rewrite rules, and database-generated URLs. Review server logs and ask the host to verify document-root and mod_rewrite configuration.

The console reports a policy violation

Use the reported origin to correct img-src; do not treat a CSP error as a missing-file diagnosis.

JavaScript processing fails but the image displays

Check CORS response headers and whether the code is fetching or drawing pixels. A server-side sideload or proxy under your control may be more appropriate than changing the display markup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to escalate

Contact your host, CDN, or security provider when the direct resource fails at the origin, DNS or TLS is inconsistent, server configuration is inaccessible, or firewall logs show a block you cannot change. Include the timestamp, URL, request status, response headers, browser, network, and a copied Console message. That evidence lets support investigate the failing layer instead of asking you to repeat generic cache-clearing steps.

Frequently Asked Questions

Why do broken images show a small icon instead of an error page?

The browser could not obtain or decode the resource for the image element. The specific cause still requires checking the request status, response, and Console message.

Can clearing cookies fix images for everyone on a website?

No. Clearing cookies only tests one browser profile. If the direct image URL, server response, CDN, or policy is wrong, every visitor can be affected.

Should I convert every image to WebP or AVIF?

Only when testing shows a format or processing problem. Conversion does not repair incorrect URLs, permissions, CSP, CORS, DNS, or server failures, and support depends on the complete delivery workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.