403 Forbidden: What It Means and How to Fix It

A 403 Forbidden means the server understood the request and refused it. Find out whether a permission, a firewall rule, or Cloudflare is blocking access.

A 403 Forbidden is a refusal, not a failure. The server received the request, understood exactly what was asked for, and decided not to hand it over. Nothing crashed. Something — a file permission, a server rule, a firewall, or a CDN — looked at the request and said no.

That makes a 403 different from most errors you will chase. A 500 or a 502 means something broke. A 403 means something is working as configured, and the configuration is wrong, too strict, or aimed at the wrong visitor. The fix is almost always to find the rule that fired, not to restart anything.

The page usually says 403 Forbidden, Access Denied, You don’t have permission to access this resource, or — behind Cloudflare — Sorry, you have been blocked with a Ray ID at the bottom.

Is it the site, or is it you?

Before touching the server, find out who is being refused.

  • Everyone gets a 403 on the whole site. A server-side rule, a missing index file, or broken permissions. This is the site owner’s problem.
  • Everyone gets a 403 on one folder or file. Permissions or an access rule on that path.
  • Only you, or only from one network. Your IP, country, VPN, or browser fingerprint is being blocked by a firewall or CDN. The site is fine for everyone else.
  • Only automated tools, not browsers. Bot protection is rejecting non-browser clients — common, and often intentional.

The quickest separator is a second opinion from outside your network. Load the page on a phone over mobile data, and run the domain through the website checker. If the independent check gets a 200 and you get a 403, the block is aimed at you, not the site.

Causes, and how to tell them apart

Where you see it Most likely cause Where to look
Whole site, right after a migration or upload File ownership or permissions wrong ls -l on the web root
Homepage only, folders still work No index.html / index.php, and directory listing is off Web root contents, DirectoryIndex
One folder or file type An .htaccess or nginx deny rule Config for that path
Only you, or one country IP block, geo-block, or WAF rule Firewall, security plugin, CDN dashboard
“Sorry, you have been blocked” Cloudflare WAF or bot rule Cloudflare → Security → Events
After logging in, on one action App-level authorization, CSRF, or a security plugin Application log
Only for crawlers or monitoring tools Bot protection rejecting non-browser clients CDN bot settings, robots rules

Wrong file permissions or ownership

The most common server-side cause. After an upload, a migration, or a git clone run as the wrong user, the web server process can no longer read the files it is supposed to serve. The error log says so plainly: Permission denied in Apache, open() "…" failed (13: Permission denied) in nginx.

Fix: directories should normally be 755 and files 644, owned by the user the web server or PHP runs as. On a typical Linux host:

find /var/www/site -type d -exec chmod 755 {} \;
find /var/www/site -type f -exec chmod 644 {} \;
chown -R www-data:www-data /var/www/site

Never “fix” a 403 with chmod 777. It hides the ownership mistake and makes every file writable by any process on the server.

No index file, and directory listing is disabled

Request a folder and the server looks for index.html or index.php. If there is none, and directory listing is turned off — as it should be — the answer is a 403. This is why a half-finished upload or a deploy that emptied the web root produces a 403 on the homepage while /images/logo.png still loads.

Fix: confirm the index file exists where the server expects it, and that the DirectoryIndex (Apache) or index (nginx) directive names it. Do not switch on directory listing to make the error go away.

An .htaccess or nginx rule

Access rules are easy to add and easy to forget: Deny from all, Require all denied, an <IfModule> block copied from a hardening guide, or an nginx location block with deny all;. Security plugins on WordPress write rules like these on your behalf.

Fix: rename .htaccess to .htaccess.bak and reload. If the 403 disappears, the rule is in that file — restore it and remove rules one at a time. On nginx, search the config for deny and return 403, and run nginx -t before reloading.

A security plugin or firewall blocked the request

Wordfence, Sucuri, iThemes, ModSecurity, and host-level firewalls all return 403s when they think a request is an attack. False positives cluster around form submissions with code-like content, admin actions from a new IP, and requests from VPNs or data-centre IP ranges.

Fix: check the plugin or firewall log for the blocked request, find the rule ID, and allow-list the specific rule or IP rather than disabling protection.

403 Forbidden on Cloudflare

Behind Cloudflare, a 403 can come from two very different places, and the page tells you which.

  • A Cloudflare-branded page (“Sorry, you have been blocked”, “Access denied”, with a Ray ID). Cloudflare’s own WAF, bot management, IP Access Rules, or a country block rejected the request before it reached the origin. Look up the Ray ID in Security → Events and you will see the exact rule.
  • Your own server’s 403 page, delivered through Cloudflare. The origin refused it; Cloudflare just passed the response along. Debug it as a normal server-side 403.

Visitors who hit a Cloudflare block usually share one of a few traits: a VPN or privacy relay, an ad blocker that breaks the browser check, an unusual user agent, or an IP with a poor reputation. If real customers are being blocked, lower the security level for that path or add a skip rule — do not turn the WAF off entirely.

A related Cloudflare response is error 1020 Access Denied, which is a firewall rule explicitly matching the visitor. Too many requests in a short window, on the other hand, is a 429 Too Many Requests, not a 403.

403 vs 401 vs 404

These three are often confused, and the difference tells you where to look.

  • 401 Unauthorized means “I don’t know who you are.” The request is missing valid credentials — log in, send a token, or supply the right API key, and it may succeed.
  • 403 Forbidden means “I know who you are, and the answer is still no.” Logging in again will not help; a rule or permission has to change.
  • 404 Not Found means “there is nothing here.” Some servers deliberately return 404 instead of 403 to avoid revealing that a private path exists. If you are chasing missing pages, see 404 vs soft 404.

If you are a visitor

You cannot change the site’s rules, but you can remove the most common reasons a firewall refuses you:

  1. Reload once, then try a private window with extensions disabled.
  2. Turn off your VPN or iCloud Private Relay and try again.
  3. Clear cookies for that site — a stale or corrupted session can fail authorization checks.
  4. Check the URL. A trailing slash or a typo in a folder name can hit a protected path.
  5. If it is a Cloudflare block page, send the site owner the Ray ID. That single value lets them find the rule in seconds.

How to confirm the fix

  1. Request the page from outside your network and confirm a 200: curl -sI https://example.com/path from another machine.
  2. Check the path as an anonymous visitor, not while logged in as an admin — admins are often exempt from the rules that block everyone else.
  3. Test from a data-centre IP as well as a home connection. Search engine crawlers and uptime monitors do not browse from residential IPs, and a rule that blocks them quietly removes the site from search.

Why a quiet 403 is dangerous

A 403 on a login page is fine. A 403 on your homepage for Googlebot is a disaster that nobody notices, because the site looks perfect to you in your browser. The same is true of a WAF rule that starts blocking a country your client sells to, or a permissions change after a deploy that takes down one section of the site.

That is the case for checking a site from an independent server on a schedule. SitesRadar’s free plan checks one site from outside your network and emails you when it starts returning 4xx or 5xx errors, alongside SSL expiry, broken links, and DNS changes. If you manage client sites, work through the client site down triage checklist when the alert arrives.

FAQ

What does 403 Forbidden mean? It means the server understood the request but refused to fulfil it. The resource exists, or the server is not saying whether it does, and something — a permission, a rule, or a firewall — has denied access.

How do I fix a 403 Forbidden error on my website? Check the server error log first; it usually names the cause. Then check file permissions (755 for directories, 644 for files), confirm an index file exists, and look for deny rules in .htaccess, nginx config, security plugins, and your CDN’s firewall.

Why do I get a 403 on one website but not others? The site’s firewall or CDN is blocking something about your connection — usually a VPN, your IP’s reputation, your country, or a browser extension that breaks a bot check. Try another network or a private window.

Is a 403 error my fault? As a visitor, rarely. As the site owner, it is almost always a configuration you control: permissions, access rules, or firewall settings.

Does a 403 hurt SEO? Yes, if crawlers receive it. Googlebot treats a 403 like a missing page and will drop the URL from the index if the refusal persists. Make sure bot-protection rules do not block legitimate search engine crawlers.

What is the difference between 403 and 401? A 401 asks you to authenticate; supplying valid credentials can fix it. A 403 means that even with credentials, access is not allowed.

← More from the SitesRadar blog