Geonode logo
Website blocks

How to Fix Cloudflare Error Code 1020 Access Denied

Four checks, then three ranked fixes for people who see 1020 and for site owners.

Updated

TL;DR

Error code 1020 means the site's owner set a firewall rule in Cloudflare, your request matched it, and Cloudflare refused the request with HTTP 403. Switch off any VPN or proxy and reload; if 1020 stays, only the owner can lift it.

What error 1020 looks like

Browsers get Cloudflare's page; curl and scripts may get a one-line text body. Here, example.com stands for the site you opened.

WhereWhat you see
Browser (Cloudflare page)Access denied / Error code 1020 / You do not have access to example.com. / The site owner may have set restrictions that prevent you from accessing the site.
Browser (Error details box)Provide the site owner this information. / I got an error when visiting example.com/page. / Error code: 1020 / Ray ID / Country / Data center / IP / Timestamp
curl -D - (response headers)HTTP/2 403 / server: cloudflare / cf-ray: 230b030023ae2822-SJC
curl or Python urllib, default headerserror code: 1020
Python requests, raise_for_status()403 Client Error: Forbidden for url: https://example.com/
API client (Accept: application/json)"title":"Error 1020: Access denied","status":403 / "error_code":1020,"error_name":"firewall_rule_blocked" / "retryable":false,"owner_action_required":true
AI agent (Accept: text/markdown)# Error 1020: Access denied / **Do not retry.** This block is intentional. Contact the site owner if you believe this is an error.

Why this happens

Someone running the site decided to turn away traffic like yours.

A rule can test your IP address, its country, its network (ASN), your User-Agent or the page path. A VPN or proxy replaces the first three with its own, and those may be what the rule matched.

Diagnose your 1020 first

Each check tells you what the owner's rule looked at, and so who can clear it.

  • In the Error details box, read Country; if it is not where you are, a VPN or proxy likely carried your request.

  • Open the site's home page; if it loads while your URL shows 1020, the rule covers only part of the site, such as /login.

  • Run the script on the machine where the page opens in a browser; if only the script gets 1020, the rule matched what it sends.

  • In a script, print the 403 body and headers; a 1020 in the body confirms the rule, while cf-mitigated: challenge marks a challenge page.

Solutions ranked by effectiveness

Visitors start at the top; the last card is for whoever manages the site's Cloudflare account.

  1. Most common fix

    Turn off the VPN, proxy or relay

    Applies when you browse through a VPN app, a proxy setting, an extension or iCloud Private Relay. Leave it off whenever you visit this site; changing servers or countries is not a fix.

    1. Disconnect the VPN, clear the browser's proxy, and disable proxy or user-agent switcher extensions.

    2. On a Mac with Private Relay, choose Safari's View > Reload and Show IP Address.

    3. On an iPhone or iPad with Private Relay, tap Page Menu, then Show IP Address.

  2. Check next

    Send the Ray ID to the owner

    Applies when the first fix changes nothing. The Ray ID and timestamp let the owner find your exact request.

    1. Copy everything in the Error details box before you close the tab.

    2. From a script, copy the cf-ray response header, which carries the Ray ID.

    3. Send it through the site's contact form, with what you were doing at that moment.

    4. If the site lists no contact, look its domain up at lookup.icann.org.

  3. Site owners

    Find the matching rule by Ray ID

    If you run the site, look the request up in Security Events and change the rule that blocked it if the block was a mistake.

    1. Under Security > Analytics, open the Events tab and add a Ray ID filter.

    2. Convert the visitor's UTC timestamp to your time zone before you search.

    3. Keep the time range short; sampled data can hide the event in a wide one.

    4. Edit the rule under Security rules, or allow the IP in IP Access rules.

Stop the 1020 from coming back

For people who visit the site every day and for scripts that collect from it on a schedule.

  1. If your VPN app supports split tunneling, exclude this site so the VPN stays on for everything else.

  2. Where the site offers an API or data export, use it for scheduled jobs instead of its pages.

  3. Name your tool and a contact URL in the User-Agent; owners see it beside the Ray ID in Security Events.

  4. Make scripts stop at the first 1020 and alert you, because Cloudflare marks the error as not retryable.

Residential IPs for permitted collectionSet the country you are in by adding it to the proxy username.
Try residential proxies

Related errors

Learn more

FAQ

It is Cloudflare's Access denied error for a firewall rule. The site's owner told Cloudflare to refuse requests with certain traits, and yours had one.

Start on your side by disconnecting VPNs and proxy tools, then reload. If 1020 remains, write to the site with the Ray ID and timestamp from the error page.

No. A 1015 rate limit returns HTTP 429 with a Retry-After time, but a 1020 has no timer: it lasts until the owner changes the rule or you turn off the VPN or tool it matched.

Write to the website itself. Cloudflare support takes requests only from site owners and cannot override a customer's security settings.

Not necessarily. A 1020 rule may match your IP or something else, while Cloudflare's 'Your IP address has been banned' errors are 1006, 1007, 1008 and 1106 and an ASN ban is 1005.

Turning it off can, for example on an Enterprise-plan site that blocks Cloudflare's list of known VPN servers. Turning one on to reach a site that refuses your own IP or country goes around the owner's decision.

One IP from start to finish

A sticky port keeps the same residential IP for up to 24 hours.