Cloudflare Error 1015 means the website has temporarily rate-limited your requests. The site owner configured a rule that allows only a certain number of requests in a time window, and your traffic exceeded that threshold—or was classified as if it had. Wait, stop refreshing, and try again later. If the block continues, contact the website owner and include the Cloudflare Ray ID shown on the error page.
The owner, not the visitor, controls the rate-limit rule. Owners should inspect the matching expression, counting method, threshold, action and mitigation duration. Error 1015 can also appear in a separate Cloudflare cache-purge failure, which has a different remedy.
What Error 1015 says
Cloudflare’s official Error 1015 documentation describes the message as “You are being rate limited.” It explains that the website owner configured rate-limiting rules restricting how many requests a visitor can make during a given period.
Rate limiting protects sites and APIs from bursts such as repeated login attempts, scraping, abusive automation and excessive API calls. Cloudflare evaluates a rule’s expression and counting characteristics, tracks the request rate, and applies the configured action when the threshold is reached. A legitimate user can therefore see 1015 even without malicious intent—for example, after repeatedly reloading a page, opening many tabs or using an application that retries too aggressively.
#1 Best Overall
It is usually temporary
A 1015 page normally represents a temporary mitigation, not a permanent account ban. The length depends on the owner’s rule and mitigation timeout. Do not assume that every block lasts exactly the same amount of time.
A separate cache-purge case exists
Cloudflare also documents an “Unable to purge” situation that can use error code 1015. That case concerns a site owner trying to purge cache, not an ordinary visitor being rate limited. The owner should retry the purge and contact Cloudflare support if it continues to fail.
What to do if you are visiting the site
- Stop retrying for a while. Close duplicate tabs and pause automated refreshes or scripts.
- Honor a Retry-After value if the response provides one. Cloudflare’s March 12, 2026 changelog lists a default
Retry-Aftervalue of 30 seconds for Error 1015 responses, but a WAF rate-limiting rule can provide a dynamic value that takes precedence. Treat 30 seconds as the documented default, not a guarantee that every page will become available then. - Try once after the waiting period. Rapid repeated attempts can extend the block, according to Cloudflare’s guidance.
- Contact the website owner if the error remains. Explain what you were doing, provide the URL and approximate time, and copy the Cloudflare Ray ID printed on the page. The owner can identify the rule and decide whether legitimate traffic was caught.
Changing networks, buying a VPN, reinstalling your browser or purchasing networking equipment is not Cloudflare’s stated fix for 1015. Those steps can also look like attempts to evade a site’s controls. The supported path is to wait and ask the site owner to investigate.
How website owners fix a legitimate 1015 block
If your users report 1015, begin in Cloudflare’s security configuration rather than telling everyone to change IP addresses. The WAF rate-limiting rules documentation describes the settings that determine when a request is mitigated.
1. Identify the matching rule
- Find the rule whose expression matches the affected URL, method, hostname, user category or other request attributes.
- Check the counting characteristics. A rule might count by source IP, session or another configured dimension, so many users can be grouped together unexpectedly.
- Review the threshold and the time period. A very short window can produce abrupt blocks during normal bursts.
Cloudflare gives an example in which a rule blocking requests over one second might be changed to a ten-second period. That is an example to evaluate against your traffic and security objective, not a universal setting.
Rank #2
2. Review the action and duration
Confirm whether the rule blocks, challenges or applies another mitigation, and inspect its mitigation timeout. Cloudflare notes that actions apply for the configured duration by default. Rule order also matters: some actions, including Block, stop evaluation of later rules. A broad rule placed above a more specific exception can therefore cause false positives.
3. Adjust cautiously
Raise a threshold or lengthen a window only enough to accommodate legitimate bursts. Narrow the expression when possible instead of weakening protection for every endpoint. Login and payment routes generally need stricter controls than static assets. After a change, monitor whether reports decline without allowing the abusive pattern the rule was designed to stop.
4. Ask for useful visitor evidence
Request the Ray ID, URL, approximate time and the action immediately before the page appeared. Cloudflare’s WAF FAQ specifically recommends the visitor’s action and Ray ID; URL and time make it easier for an owner to correlate the event in logs.
Retry-After and machine-readable responses
Developers building clients should inspect both the status headers and the response body. Cloudflare’s March 12, 2026 changelog says retryable Cloudflare-generated 1xxx responses include a standard Retry-After header. For 1015, the listed default is 30 seconds; a dynamic value configured in a WAF rule overrides that default.
Cloudflare’s error-response documentation describes structured fields such as retryable, retry_after, owner_action_required and what_you_should_do. Depending on the request’s Accept header and the site’s custom error configuration, the response can be HTML or a machine-readable format.
Rank #3
Safe client behavior
- Read and parse
Retry-Afterwhen present. - Do not retry in a tight loop when the response says the error is retryable.
- Use exponential backoff with jitter for clients that must retry after the advised interval.
- Surface the Ray ID and owner-action guidance to an operator instead of silently discarding the failure.
Is Error 1015 the same as HTTP 429?
Not always. Cloudflare’s 1xxx overview explains that a 1xxx error is identified in the response body, while an HTTP error such as 429 appears in the status line. Cloudflare’s custom-error guidance also allows a blocked rate-limit request to return a 429 status while displaying a Cloudflare 1015 page.
Therefore, a client may observe both “HTTP 429” and “Cloudflare 1015” in one response. They describe related layers of the same event, but they are not interchangeable in every implementation. Log the status code, headers and body separately.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCommon symptoms and fixes
| What you see | Likely explanation | Correct next step |
|---|---|---|
| 1015 after several refreshes | The visitor exceeded the site’s configured request rate. | Wait, stop refreshing, then try once. |
| 1015 keeps appearing for normal use | The owner’s threshold, counting key or expression may be too broad. | Send the Ray ID and context to the owner; the owner reviews the rule. |
| HTTP 429 plus a 1015 page | The transport status and displayed Cloudflare error are being presented together. | Honor Retry-After and inspect both status and body. |
| Owner sees “Unable to purge” with 1015 | A Cloudflare cache-purge failure, not a visitor rate-limit page. | Retry the purge; contact Cloudflare support if it still fails. |
How to troubleshoot an API or automation client
- Capture the complete response. Save status, headers, body, timestamp, URL and Ray ID.
- Check request frequency. Look for loops, parallel workers, browser prefetching or retries that multiply a single user action.
- Apply server instructions. Parse
Retry-Afterand pause at least that long before another attempt. - Reduce concurrency. Queue requests and add jitter so many workers do not resume simultaneously.
- Contact the owner for an allow-list or policy change. Do not attempt to evade the limit by rotating addresses.
Testing a page after a rate-limit change
Once an owner adjusts a rule, test the exact URL and workflow that produced the report. Verify normal navigation, login or API calls, and any legitimate burst pattern separately. A screenshot can confirm what an end user sees, but it does not replace checking response headers and Cloudflare logs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
ScreenshotNeo can capture a page with one request when you need a visual check after changing Cloudflare settings. Before capture it accepts consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and each response reports the result in X-Page-Verdict and X-Billed headers. Its MCP server lets Claude, Cursor and other MCP clients call take_screenshot, get_page_info and capture_pdf.
Use the ScreenshotNeo documentation for all options. A basic cURL request is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
The same request in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
And in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
When to contact Cloudflare
For an ordinary visitor’s 1015 page, Cloudflare directs you to the website owner. Cloudflare states that only the website owner can contact its technical support about 1xxx errors; the available support channels depend on the owner’s current Cloudflare plan. If you own the zone and the problem is a cache-purge failure or a rule that behaves incorrectly after review, use the support options available in your account.
Practical checklist
- Pause and stop rapid retries.
- Honor a visible
Retry-Aftervalue; 30 seconds is Cloudflare’s documented 1015 default, not a universal guarantee. - Record the Ray ID, URL, time and preceding action.
- Send those details to the website owner.
- Owners: inspect expression, counting characteristics, threshold, action, duration and rule order.
- Keep cache-purge 1015 failures separate from visitor rate limiting.
Frequently Asked Questions
Does Error 1015 mean my account is permanently banned?
No. It normally indicates a temporary rate-limit mitigation. The duration is controlled by the website’s rule, so only the owner can confirm why your traffic was blocked.
Should I clear cookies to remove Error 1015?
Cloudflare’s official guidance does not identify clearing cookies as the remedy. Waiting without repeated retries and contacting the site owner are the supported steps.
Why can one office affect several users at once?
A rule may count requests by a shared characteristic such as source IP. If many people use the same network, their traffic can contribute to one threshold; the owner must decide whether the counting method is too broad.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

