How to Fix Cloudflare Error Code 1003 (Direct IP Access Not Allowed)
Four checks, then the fix for your case, with cURL, Python and Node.js code for scripts.
Updated
TL;DR
Error code 1003 means Cloudflare refused a request sent straight to one of its IP addresses, with no website named in it. Use the domain name instead of the IP, in the browser and in any script.
What error 1003 looks like
Every http:// request we sent to a Cloudflare IP got plain text.
| Where | What you see |
|---|---|
| Browser, http:// plus a Cloudflare IP | error code: 1003 |
| curl http:// to the IP, default headers | HTTP/1.1 403 Forbidden / Server: cloudflare / error code: 1003 |
| macOS curl, https:// to some Cloudflare IPs | curl: (60) SSL: no alternative certificate subject name matches target ipv4 address '104.16.2.189' |
| macOS curl, https:// to other Cloudflare IPs | curl: (35) / sslv3 alert handshake failure |
| curl -k https:// to an IP that sends a certificate | HTTP/2 403 / 403 Forbidden / cloudflare |
Why this happens
Many websites share each Cloudflare IP, so your request must name the one you want.
Browsers and scripts copy the URL's host into the Host header, so a URL with an IP names no site. A DNS lookup of a site Cloudflare proxies returns a Cloudflare IP, so pasting that result gives 1003.
Diagnose your 1003 first
Each check shows where the IP entered your request, so you know which fix below applies.
Look at the address bar; if it shows digits such as 104.16.2.189 where the site's name should be, you opened an IP.
Compare the IP with the ranges at cloudflare.com/ips; if it falls inside one, the IP belongs to Cloudflare, not to the site's own server.
Run curl -v with your URL and headers; if the > Host: line shows digits, an IP is going out as the site name.
Search code and nginx config for proxy_pass, Host headers and URLs built from DNS lookups; an IP in any can go out as the host.
Solutions ranked by effectiveness
In a browser, the first card is enough; the second is for scripts and nginx, the third for site owners.
- Most common fix
Open the site by its domain name
Applies when you typed, pasted, bookmarked or followed a link to an IP address. Put the site's name in its place.
In the address bar, replace the IP with the domain name, such as shop.example.com.
If you need the name, check the email, link or app that gave the IP.
Update the bookmark, start page or shortcut that still opens the IP.
- For developers
Send the hostname, not a Cloudflare IP
Applies to scripts and nginx. Put the hostname in the URL or in proxy_pass; if your code resolves DNS itself, connect to that IP but keep the name in Host and SNI.
# The fix: put the site's name in the URL, not its IP curl -sS -o /dev/null -w "%{http_code} by name\n" https://example.com/ # Resolving DNS yourself: connect to the IP, keep the name in Host and SNI IP=$(dig +short example.com | grep -m1 -E '^[0-9.]+$') curl -sS -o /dev/null -w "%{http_code} from %{remote_ip}\n" \ --resolve "example.com:443:$IP" https://example.com/ - Site owners
Check your zone status and DNS records
Applies when people report 1003 while trying to reach your site. Their request named a Cloudflare IP, so confirm your domain works by name and keep IPs out of what you publish.
In the Cloudflare dashboard, check that the domain's status is Active, not Pending or Moved.
Point each A record at your origin server's IP, never at a Cloudflare IP.
Swap IPs for the hostname in your links, monitors and webhooks.
Do not offer your origin server's IP as a workaround; requests to it skip Cloudflare.
Stop the 1003 from coming back
For scripts, monitors and servers that call Cloudflare sites every day.
Store sites by name and resolve at run time, since Cloudflare can change the IP behind a proxied record.
Validate target lists before a run, and refuse entries whose host part is an IP address.
Log each 1003 as a config bug and skip retries; it is not among Cloudflare's six retryable 1xxx codes.
Behind nginx, turn proxy_ssl_server_name on for HTTPS upstreams; it is off by default, so no SNI is sent.
Related errors
Learn more
FAQ
Keep proxy credentials out of scripts
Whitelist the IP your scripts run from, and they skip the username and password.


