Recommended Free Tools
The fix depends on who you are. If you are visiting someone else’s site, you normally cannot remove a Cloudflare block yourself: save the complete error page, including the code and Cloudflare Ray ID, and send it to the site owner with the time and action that triggered it. If you own the site, use that Ray ID or the visitor’s IP address to find the matching event in Cloudflare Security Events, identify the rule or control that acted, and make the narrowest safe change.
Do not treat every Cloudflare-looking error as Error 1020. A branded 403, an unbranded origin 403, Error 1015 rate limiting, an ASN ban, and an ISP-level block require different investigation.
First identify your role
If you are a visitor
You can collect evidence and ask the website owner to review the block, but you cannot edit that site’s Cloudflare zone. Take a screenshot or capture the full page. Include:
- The exact error number and wording.
- The Cloudflare Ray ID.
- The approximate UTC time (or your local time and timezone).
- The URL you opened and what you were doing, such as signing in, submitting a form or downloading a file.
- Your public IP address, if the owner asks for it.
Send those details through the site’s support address or another contact channel. Cloudflare’s Error 1020 guidance specifically tells visitors to provide the owner a screenshot; its WAF FAQ also asks for the action taken and displayed Ray ID. Retrying repeatedly, clearing cookies or changing browsers may not help when a server-side rule is deliberately denying your request.
#1 Best Overall
If you own the website
Do not begin by disabling the WAF or adding a global allow rule. Start with the evidence on the error page, locate the corresponding security event, and then change only the control that caused the match.
Recognize the error before changing anything
Error 1020: Access denied
Error 1020 means a Cloudflare firewall rule denied the request. The owner should search Security Events by the Ray ID or client IP, convert the displayed event time to the timezone used for the search, and inspect the exact rule expression and action.
403 Forbidden
The status code alone does not prove Cloudflare caused the denial. An unbranded 403 is returned directly by the origin web server. A Cloudflare-branded 403 can result from WAF rules or another Cloudflare security feature. Check the page branding and your origin logs before editing Cloudflare settings.
Error 1015: Rate limited
Error 1015 is a rate-limiting response, not the same diagnosis as Error 1020. A rate-limit rule has a matching expression, characteristics to count, a measurement period, a request threshold and a mitigation duration. Counters can take a few seconds to update, so the rule is not an exact guarantee of how many requests reach your origin.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Other 1xxx errors
The 1xxx family covers different conditions, including IP, ASN, country and browser-signature restrictions, plus DNS and configuration failures. Error 1005 indicates an ASN ban; Error 1010 concerns a browser signature. Apply the procedure for the displayed code rather than assuming every 1xxx error is a firewall-rule problem.
ISP-level blocking
Sometimes an internet provider blocks access to a shared Cloudflare IP. That is a connectivity issue outside the website’s zone configuration. Cloudflare cannot restore connectivity for users affected by an ISP-level block; the visitor must work with the ISP.
Owner procedure for an Error 1020 or related block
- Request the complete evidence. Ask the visitor for the exact page or screenshot, Ray ID, approximate time and the action they were taking. A cropped message without the code or ID is often insufficient.
- Open Security Events. In the Cloudflare dashboard for the affected zone, search using the Ray ID or visitor IP. Apply the correct time range after converting the error timestamp to the dashboard’s timezone.
- Match the event. Confirm hostname, path, method, country, ASN, bot status and user-agent details where shown. Make sure the event belongs to the reported request, not a similarly timed scan.
- Read the acting control. Record whether the action came from a custom rule, WAF Managed Rule, IP Access Rule, rate limiting, bot control or another security feature. Inspect the expression and the fields it uses.
- Test the cause. Compare the visitor’s request with the rule criteria. A rule based on geography, ASN, path, header, cookie, browser signature or request volume may be matching exactly as configured—or matching more broadly than intended.
- Make the smallest correction. Adjust the offending expression, action or threshold, or create a narrowly scoped exception for a verified trusted request. Preserve unrelated protections.
- Verify from the affected path. Have the visitor retry the same URL and action. Check Security Events again to confirm the request now receives the intended action and that normal suspicious traffic is still controlled.
Choosing a safe owner-side remedy
IP, ASN and country controls
Cloudflare IP Access Rules can allow, block or challenge traffic by IP, ASN or country. For IP- or geography-based policies, Cloudflare recommends custom rules. Be careful with a broad allow: allowing an IP or ASN through IP Access Rules bypasses configured custom rules, rate limiting rules and WAF Managed Rules. That is wider than exempting one request from one condition. Prefer a scoped custom-rule change when the visitor only needs access to one path or operation.
Rate-limit false positives
Inspect the request characteristics and traffic pattern that caused the threshold. Check whether several people share one NAT address, whether a legitimate API client is bursty, and whether the measurement period fits the operation. Change the matching expression, threshold or mitigation duration only after confirming the event. Do not disable unrelated WAF protections as a shortcut.
Known bots, search engines and monitors
Custom block or challenge rules can unintentionally affect search crawlers and monitoring services, depending on the fields used. If the blocked actor is a crawler or uptime monitor, check its bot status and the matched rule before adding an open-ended allow. A narrowly defined exception for the verified traffic is safer than trusting an entire ASN without understanding the bypass.
Rank #4
Origin-side 403
For an unbranded 403, inspect origin web-server logs, application authorization, web-server access rules and upstream identity controls. Cloudflare rule edits cannot fix a denial generated after the request reaches your server.
Common symptoms and fixes
| What you see | Most likely layer | Next action |
|---|---|---|
| Cloudflare-branded “Error 1020: Access denied” with Ray ID | Firewall or security rule | Search Security Events by Ray ID or IP and inspect the matching rule. |
| 403 page with no Cloudflare branding | Origin server or application | Check origin logs and authorization settings. |
| Error 1015 | Rate limiting | Review expression, counted characteristics, period, threshold and mitigation duration. |
| Error 1005 | ASN ban | Review the ASN-based control; do not apply an Error 1020 fix automatically. |
| Error 1010 | Browser-signature restriction | Inspect the browser-signature rule and its matching fields. |
| Only users on one ISP fail | ISP-level connectivity block | Have affected users contact the ISP; changing the zone may not help. |
Troubleshooting branches
The event cannot be found
- Recheck the Ray ID character-for-character.
- Expand the time range and convert UTC correctly.
- Search by the visitor’s public IP as a second method.
- Confirm you are viewing the correct account and zone.
- Ask whether the visitor reached a redirect or a different hostname.
The visitor is still blocked after an edit
- Confirm the request now matches a different rule or managed protection.
- Check for an IP Access Rule that bypasses or overrides custom logic.
- Look for rate limiting, bot controls or origin authorization acting separately.
- Have the visitor repeat the exact action while you watch a fresh event.
A broad allow appears to work but creates risk
That result may be expected: an IP or ASN allow can bypass custom rules, rate limiting and WAF Managed Rules. Replace it with a narrower condition tied to the required hostname, path, method or verified property, then test both the legitimate request and a clearly suspicious one.
Automated monitoring is blocked
Identify the monitor’s verified bot status, source characteristics and requested path. Review the matching rule for user-agent, ASN, country, headers and request rate. Avoid an exception that trusts every client sharing the same network unless that scope is intentional.
Best Value
- Used Book in Good Condition
Performance, reliability and operational notes
- Preserve evidence: save the Ray ID, event details, rule version and change time in your incident record.
- Change one variable: editing several controls at once makes it difficult to identify the real cause.
- Expect timing effects: rate-limit counters can take seconds to update, so immediate repeated tests may not represent a stable result.
- Check both edges: test from the affected network and from a known-good network, while also checking origin logs for unbranded errors.
- Review after deployment: monitor Security Events for legitimate traffic and unwanted traffic after a rule change.
Or skip the browser setup
If you need a clean diagnostic image of the error page for the owner, ScreenshotNeo can capture a URL through one API request. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.
Use the ScreenshotNeo documentation for all options. A direct capture looks like this:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Replace the URL with the page showing the Cloudflare error. ScreenshotNeo includes full-page and selector capture, device presets and custom viewports, retina scale, PDF output, custom CSS or JavaScript, waits, request blocking, headers, cookies, user agents, authorization, timezone and geolocation controls, resizing, chosen cache TTLs, signed image links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Parameter names used by other screenshot APIs also work, which can simplify migration.
The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Frequently Asked Questions
Can Cloudflare support remove a block placed by a website owner?
No. For an Error 1010-style owner decision, Cloudflare documentation says support cannot override the customer’s security settings. Contact the site owner with the error evidence instead.
Should I use a VPN to bypass Error 1020?
A VPN changes your network identity and may trigger another IP, ASN or bot rule. It does not repair the website’s configuration. The reliable path for a visitor is to send the owner the code, Ray ID, time and action.
Why does the same page work on one network but not another?
The networks may differ by IP, ASN, country, browser signals or ISP routing. Compare the affected request’s Security Event with a successful request; if the issue is an ISP-level block, the ISP—not the Cloudflare zone owner—must address connectivity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




