How to Troubleshoot Website Access Blocked by Cloudflare
Identify Cloudflare 1xxx errors, collect the right evidence, and fix visitor or owner-side blocks without guesswork.
Start by recording the exact Cloudflare error before changing anything. Copy the numeric code, message, HTTP status, Ray ID, requested URL and time. Error 1015 means a rate-limit block; 1020 means a firewall rule denied the request. Codes 1006, 1007, 1008 and 1106 indicate an IP ban, 1009 a country or region ban, and 1010 a browser-signature ban. Error 1000 points to DNS or origin configuration.
Most blocks are decisions made by the website owner. Visitors can preserve evidence, wait when appropriate and contact the owner. Owners must inspect Cloudflare Security Events and change the matching rule.
Identify the block
| Signal | Meaning | Best next action |
|---|---|---|
| 1015 / HTTP 429 | Rate-limit threshold reached. | Stop refreshing, wait, then contact the owner if it persists. |
| 1020 / usually HTTP 403 | A firewall rule denied the request. | Send the screenshot and Ray ID to the owner; owners should inspect Security Events. |
| 1006, 1007, 1008, 1106 | IP ban. | Ask the owner to review or allow the address. |
| 1009 | Country or region ban. | Ask the owner to review the geographic rule. |
| 1010 | Browser-signature ban. | Ask the owner to review Browser Integrity Check or signature conditions. |
| 1000 | DNS, proxy, forwarding-header or SaaS-hostname problem. | The owner must correct the DNS or origin setup. |
| 403 without a 1xxx code | May be a WAF rule, IP/country rule or managed challenge. | Save the complete response and escalate to the owner. |
See Cloudflare’s documentation for 1020, 1015, 1006, 1010, 1009 and 1000.
Visitor workflow
- Read the complete page. Record the code, message, status, Ray ID, URL and timestamp.
- Save a screenshot and response details. Note whether you were on home, office, mobile or a VPN network.
- Handle 1015 differently. Stop repeated attempts. Rapid retries can extend the block.
- Contact the website owner. Send the screenshot, Ray ID, UTC time, URL and public IP if requested.
- Do not assume a reinstall or VPN solves it. A new network changes the signal but does not remove an owner policy.
Capture the response with cURL
curl -sS -D headers.txt -o page.html -w "HTTP %{http_code}\n" https://example.com/
Search page.html for “Cloudflare”, “Ray ID” or the numeric code. Keep headers.txt with the timestamp.
Capture it with Python
import requests
from datetime import datetime, timezone
url = "https://example.com/"
r = requests.get(url, timeout=30, allow_redirects=True)
print("time_utc:", datetime.now(timezone.utc).isoformat())
print("status:", r.status_code)
print("final_url:", r.url)
print("ray_id:", r.headers.get("cf-ray"))
print("server:", r.headers.get("server"))
print(r.text[:1000])
Capture it with Node.js
const url = 'https://example.com/';
const res = await fetch(url, { redirect: 'manual' });
console.log({ time_utc: new Date().toISOString(), status: res.status, location: res.headers.get('location'), ray_id: res.headers.get('cf-ray'), server: res.headers.get('server') });
console.log((await res.text()).slice(0, 1000));
Owner workflow
Error 1020
- Request the visitor’s screenshot, Ray ID, client IP, URL and time.
- Open Security → Analytics → Events in Cloudflare.
- Search by Ray ID or client IP and convert the UTC event time when needed.
- Inspect the matched firewall or WAF expression. Narrow it or allow the IP when appropriate.
- Retest once and record the new Ray ID.
Error 1015
Review the rate-limit threshold and counting period. A window that is too short can block legitimate bursts; Cloudflare gives increasing a period from one second to ten seconds as an example.
Errors 1006, 1007, 1008 and 1106
Review IP-ban controls and allow a legitimate client IP. Cloudflare Support cannot override another customer’s settings.
Error 1009
Review IP Access rules and the country or region restriction. Remove or narrow the geography only when justified.
Error 1010
Review Browser Integrity Check and browser-signature conditions. Check whether automation, unusual headers or a legitimate browser family is classified too broadly.
Error 1000
Check for a prohibited Cloudflare IP in DNS, a reverse-proxy loop, malformed forwarding headers or a missing SaaS custom hostname.
Browser, network or owner problem?
- Browser: one browser profile fails or the page names a browser-signature check.
- Network/IP: several devices on one connection fail with 1006-family codes.
- Geography: 1009 identifies a country or region rule.
- Owner rule: 1020 can match a path, method, header or other request property.
- Origin: 1000 is a site configuration problem.
Common mistakes
| Mistake | Why it fails | Fix |
|---|---|---|
| Refreshing a 1015 page repeatedly | More requests can extend the block. | Stop, wait, then retry once. |
| Sending only “Cloudflare blocked me” | The owner cannot correlate an event. | Include code, Ray ID, URL, UTC time, status and network context. |
| Changing several variables at once | You lose the triggering signal. | Record the original response and make one controlled change. |
| Asking Cloudflare Support to unblock another site | Support cannot override that site’s settings. | Contact the website owner. |
| Treating every 403 as identical | 403 can come from several controls. | Read the body and correlate the event in Security Events. |
Automating diagnostics safely
Use one request with a reasonable timeout, preserve headers and body, and avoid retry loops. Log status, cf-ray, URL and timestamp. For 429 responses, wait as instructed and use backoff only afterward. Do not automate attempts to defeat an owner’s access control.
Or skip the browser setup
If you need to archive or inspect a page, ScreenshotNeo returns a clean image or PDF from one GET request. It accepts cookie banners and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each step can be disabled. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and X-Page-Verdict and X-Billed identify the result.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo API docs for full-page and element capture, waits, custom headers and cookies, request blocking, device presets, dark mode, PDFs, caching and async jobs. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Performance, reliability and cost
- Keep diagnostic requests sparse; rate limits are part of what you are measuring.
- Use a 30–90 second client timeout for slow or challenged pages.
- Separate visitor troubleshooting from owner changes; only owners can alter access rules.
- For screenshot workloads, ScreenshotNeo bills only clean shots; failed loads and cache hits cost nothing.
FAQ
Will clearing cookies fix a 1020?
Usually no. A 1020 is a firewall-rule decision; send the Ray ID and time to the owner.
Is 1015 permanent?
It is a rate-limit block. Waiting is the first step; persistent failures require owner review.
Can Cloudflare Support unblock me?
Not for another customer’s rule. The website owner controls these settings.
Why does one URL work while another gets 1020?
Firewall expressions can match a path, method, header or other request property.


