Community Tip - Fixing Error 403 Forbidden

Error
Try the suggestions in this Community Tip to help you fix Error 403 Forbidden.

Background
A 403 Forbidden Error is a client side error that means that the client sent something the origin was unable to process. With the exception of requests that violate WAF rules or subdomains that are not covered by a certificate, Cloudflare does not generate any 4xx errors, so this would indicate something is not configured correctly with your hosting provider or your client is sending something incorrect. When this happens, in your browser you’ll see the message “Error 403: Forbidden”. If the Quick Fix Ideas here don’t help, the best next step would be to generate a HAR file and send this to your hosting provider to identify what potential misconfiguration could be in place.

Registrar, basically free

Quick Fix Ideas

  1. You recently upgraded from a Free account to a Pro subscription; the 403 error is a temporary error related to an issue while replacing the certificate from the Free account with a certificate for the Pro account.

  2. Try using a different browser, or use a private/incognito window. Your DNS cache may be pointing to the origin server.

  3. You’re only seeing the error from certain countries. Check the origin server configuration for a country block.

  4. Pause Cloudflare until the issue is resolved, see How do I temporarily pause Cloudflare?.

  5. Disable the Browser Integrity Check.

  6. If you’re seeing a black & white 403 Forbidden error page without Cloudflare branding, this is always returned directly from the origin web server, not Cloudflare, and is generally related to permission rules on your server, either a permission rule you have set or an error in the .htaccess rules, Mod_security rules, or IP Deny rules. Make sure that Cloudflare’s IPs aren’t blocked.

  7. Cloudflare will serve 403 responses if the request violated either a default WAF rule enabled for all orange-clouded Cloudflare domains or a WAF rule enabled for that particular zone.

  8. Cloudflare will also serve a 403 Forbidden response for SSL connections to subdomains that aren’t covered by any Cloudflare or uploaded SSL certificate.

Research The Issue
YouTube
Community
Google

If You Need More Help
This community of other Cloudflare users may be able to assist you, login to Cloudflare and post your question to the Community. When you post on the Community make sure to include as much of this information as possible: the specific error message you are seeing, the URLs this is happening on, screen shot of the error, and the steps to reproduce the error. Please indicate what troubleshooting steps you’ve tried in order to help us help you.

Expert Comments Appreciated
This Community Tip will remain open for input from Community experts and those familiar with this issue. We really appreciate comments like: “What are the three things to always try”, or “Do this first” or “In my experience”.

This is a Cloudflare Community Tip, to review other tips, click here.

Çevirme…traduzir…翻译…traducir…Traduire…Übersetzen…:greyg: Translate this Tip

FXFBCT111919

4 Likes
403 forbidden only on cloudflare a couple days
403 intermittent issues
Please help to check 403 request
Delays on Authorizing Certificate
Community Tip - All Published Tips
403 Forbidden issues
Getting 403 error
Cloudflare blocking some feed readers from accessing Armenian RSS feeds
Cloudflare headers preventing SSL certificate from connecting after domain transfer
Googlebot is blocking by cf
Captcha on IPs
Does solving the challenge because of Tor allow a log4j attack?
Community Tip - Alle veröffentlichten Tipps
Community Tip - 公開されているすべてのヒント
Sub-domain to parent domain 403 issue
Unable to publish Wordpress post when adds a picture in post (Generatepress Theme)
Unable to publish Wordpress post when adds a picture in post (Generatepress Theme)
Sub-domain to parent domain 403 issue
Cloudflare activation on cloudways wordpress causing a 403 error
403 error after pass to cloudflare
403 error after pass to cloudflare
Dashboard having issues
Terraform Logpush to Azure Storage 403: creating a new job is not allowed: error getting jobs to check allowance (1004)
Can't stream my music anymore
Help! I lost all control over one site
Slow Website load 1st time
IIS Client-Certificate getting 403.16
403 ERROR The request could not be satisfied
UNSOLVED: 403 errors in google console
Speed Test - "example.com returned status 403. (Code: 1001)"
403 error after pass to cloudflare
Speed Test - "example.com returned status 403. (Code: 1001)"
Receiving Error 1020 when accessing Cloudflare Dashboard
UNSOLVED: 403 errors in google console
What percent of 400's and 500's errors do you have?
WordPress and Gutenberg issue with /wp-json/wp/v2 that gives 403
WordPress and Gutenberg issue with /wp-json/wp/v2 that gives 403
Cannot Add Payment Method in Registrar
Page Rules cache do not work but work in Workers
Unstable access to site wia CloudFlare
Edge IP Restricted - Error 1034
Png 403 error
Page Rules cache do not work but work in Workers
API calls originating from AWS NAT Gateway are being presented with Captcha thus failing
Remove Shopify Headers
Googlebot is unable to reach my site if Cloudflare Specials is enabled
Custom bot getting 403 from cloudflare
Need Cloudflare to whitelist some ASNs
Torified Mozilla Thunderbird cannot subscribe to RSS feed
Site cannot be reached
Some issue with dns records
Wordpress REST API error 403
Enabling APO is now preventing images from appearing on other websites
Enabling APO is now preventing images from appearing on other websites
Enabling APO is now preventing images from appearing on other websites
Certificate doesnt work
Certificate doesnt work
Cloudflare not updating A Record with proxy on
Firewall blocking payment gate messages
Images Upload Failure
Website working but 403 Forbidden?
Getting 403 forbidden in my good bot (link checker)
Getting 403 forbidden in my good bot (link checker)
Getting 403 forbidden in my good bot (link checker)
Hotlink Protection not working / favicon / other files / firewall rules
UNSOLVED: 403 errors in google console
Getting 403 forbidden in my good bot (link checker)
Http/2 403
Http/2 403
Unable to connect AWS S3 to CloudFlare
Hotlink Protection possible bug
403 Forbidden (Help Please)
403 Forbidden (Help Please)
403 Forbidden (Help Please)
Iframe 403 forbidden
Error 1016 for eastcoastcollective.com
Iframe 403 forbidden
UNSOLVED: 403 errors in google console
Bot Fighting Mode Suddenly Blocking New Relic Ping
403 CSRF verification failed. Request aborted
Returned status 403. (Code: 1001)
CF workers breaking with AWS S3 starting June 1st
Fonts HTTP 403 only when behind tunnel
Fonts HTTP 403 only when behind tunnel
FIREWALL RULES to return 404 error instead of 403 error
FIREWALL RULES to return 404 error instead of 403 error
Cloudflare Challenge on all the sites I visit
Cloudflare Challenge on all the sites I visit
Google Search Console Indexing issues were detected with the URL
Google Search 403 Error
Google Search 403 Error
Some issue with my network
Cloudflare blocks requests from CDN Server [403]
Cloudflare Challenge on all the sites I visit
Firewall managed challenge vs Facebook Scraper bot
Problem with GTmetrix
403 Error, Contact Page
WpEngine, Wordpress, and Cloudflare managed ruleset
WpEngine, Wordpress, and Cloudflare managed ruleset
Trimming images via URL
Baidu Indexing Issues
Bucket Policy for IP Restrictions Not Working
403 error, contact form
403 error when saving Wordpress pages edited with Elementor
CDN Token authentication and client side caches
403 Issue (sometimes it's a 200 other times it's a 403)
DDoS attack still stopping website from loading - Is there something else I can try?
Cloudflare + wp-admin = Error 403
403 error on ads.txt with custom user agent
The requested URL was not found on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request
403 error on ads.txt with custom user agent
How do I block automated SEO searches for "scraping footprints"?
Big mess in official IP but website working !?
WAF - Wordpress wp-json/
Big mess in official IP but website working !?
Cross-Origin Read Blocking for ads
Access Service Tokens inside Access Groups not inheriting Action
Firewall blocking payment gate messages
Allow All Google Bots Crawler
My IPs are blocked on some cloudflare websites
My IPs are blocked on some cloudflare websites
Cross-origin errors
Cross-origin errors
Torified Mozilla Thunderbird cannot subscribe to RSS feed
Setting Up Segment Analytics CDN Proxy (403 Error)
Error 403 - Mobile App
403 on Cloudflare Pages site with Page Rule
403 on Cloudflare Pages site with Page Rule
403 Error and Content lost
Site showing 403 error and content missing
Optimize SEO Data error via Yoast
Getting 403 On Images
Error 403 When Search Engine Bot Desktop are Trying to access my Site
Using Lambda Function URL with Cloudflare (error 522)
Using Lambda Function URL with Cloudflare (error 522)
Cloudflare Images: Single request of an image counts as two images served
Inadvertent leak of the server's origin IP
403 Error from website Trawler
Did my woocommerce REST API blocked bt firewall of cloudware?
Bot Fight Mode challenging ShipStation
Subdomain redirect issue?
RecordID for RouterOS
Bingbot Unable to access sitemap - 403 Error
Legacy SSL Certification Issue
Legacy SSL Certification Issue
Legacy SSL Certification Issue
Managed/JS Challenge blocks CORS
503+403 error
Need help traversing nginx proxy to reach my cloudflare protected site (TLS end-to-end)
Cloudfare https ports
Cloudfare https ports
Cloudfare https ports
Cloudfare https ports
Cloudfare https ports
Cloudfare https ports
403 Error - Name Server Issue?
Deploy from Gitlab to CF Pages fails on initialisation
R2 issue: uploading files (or chunks) to presigned urls
403 error when trying to save Wordpress pages with Elementor Editor
403 error when trying to save Wordpress pages with Elementor Editor
403 Error - Request could not be satisfied
How to set the default Edge Cache TTL
Does Cache Everything really cache everything?
Why is Cf-Cache-Status BYPASS in this specific case
Why is Cf-Cache-Status BYPASS in this specific case
Why is Cf-Cache-Status BYPASS in this specific case
Managed/JS Challenge blocks CORS
Managed/JS Challenge blocks CORS
Pagespeed stopped working randomly *AND CANT FIX IT*
I am getting 403 Forbidden when I try and edit my posts
SSL certificate for Spaces of Digitalocean not valid
SSL certificate for Spaces of Digitalocean not valid
SSL certificate for Spaces of Digitalocean not valid
waitUntil() + setTimeout() How long will waitUntil() wait for?
Cloudflare Flexible SSL Interferes with Let's Encrypt Renewal
403 cloudflare error
Why is Cloudflare blocking AIOSEO on my website?
Captcha on IPs
Just upgraded from free to pro and 403 error appeared on my website
Ever since i changed the server names
What is this error code and how can I work around it?
Nginx reverse proxy - 403 cloudflare error
What is this error code and how can I work around it?
Random 403 errors for sites using Cloudflare (orange cloud)
Subdomain's not working even though the DNS record exists
Problem with a cloudflare SSL certificate from old unaccesible hosting
403 Forbidden on front-end pages
Error 403 forbidden
Website working but 403 Forbidden?
Enabling APO is now preventing images from appearing on other websites
DEAR systems and Cloudflare CDN
Please disable cloudflare workers
Site is fine via browser but 403 accessed programmatically
Site is fine via browser but 403 accessed programmatically