Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare Error 1006 means the IP address making your request has been banned by the Cloudflare customer protecting the site. The reliable fix is not a magic header or proxy: use an authorized, stable client identity, collect the error evidence, and have the site owner correct the matching Cloudflare rule or allowlist your IP. Cloudflare says its support team cannot override a block imposed by the website owner; the owner must investigate the security settings or allow the client IP.

This guide separates what a scraper operator can diagnose from what only the site owner can change, with commands, owner-side checks, rate-limit guidance, and recovery steps for legitimate crawling.

What Error 1006 means

Cloudflare describes 1006 as access denied because your IP address has been banned. The decision belongs to the Cloudflare customer’s configuration, not to Cloudflare support. If you do not own the site, request that its operator investigate the security settings and allow your authorized client IP. If you own it, inspect the rules that produced the match before changing your crawler.

Do not confuse the numeric error with a general HTTP status. Cloudflare 1xxx errors are normally rendered in the response HTML body, so a scraper that checks only the status code can miss the explanation. Save the body, headers, URL, timestamp and any CF-RAY identifier.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

First response: capture evidence without increasing the block

  1. Stop aggressive retries. Repeated requests can reinforce a rate or bot-control decision. Preserve the original response instead.
  2. Record the request context. Note the public egress IP, exact URL, HTTP method, timestamp with time zone, User-Agent, response status, relevant headers and the complete HTML body.
  3. Look for Cloudflare details. Search the body for “Error 1006” and record the CF-RAY value if present.
  4. Test one authorized URL. Use a minimal request rather than a full crawl. Cloudflare recommends curl for inspecting HTTP responses and supports an origin comparison when the owner permits it.
curl -svo /dev/null https://example.com/

Replace the host with an authorized target. The verbose output helps show the connection, response status and headers; it does not bypass the ban.

Decide who can actually fix the problem

If you are a scraper operator

You cannot remove a Cloudflare IP ban from your side. Contact the site owner through its published technical or abuse address, identify your project and lawful purpose, provide the timestamp, URL, source IP and CF-RAY value, and ask whether the IP can be allowlisted. Include your intended request rate and User-Agent so the owner can create a narrow exception rather than disabling protection broadly.

If you own the protected site

Review the rules that evaluate the requesting IP and the request context. A mistaken IP Access rule, Zone Lockdown rule or custom security rule can create a 1006 response. Check recent rule changes and the security event details for the exact expression that matched. Remove only the unintended match or create a narrowly scoped allow rule for the verified crawler.

Site-owner checks in Cloudflare

IP Access and Zone Lockdown

Search IP Access rules and Zone Lockdown entries for the crawler’s public address, its network range, or an expression that resolves to that address. Confirm whether the address is shared by other jobs or users; allowlisting a shared egress IP can grant access to traffic you did not intend to trust.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Custom security rules and managed protections

Inspect the Security Events record for the request and identify the rule action. An expression matching a country, ASN, path, header or threat score may be responsible even when no explicit IP deny exists. Test a narrowly scoped exception on the required hostname and path, then remove it when the authorized job ends.

Origin anti-bot modules

Cloudflare’s crawler guidance warns site owners not to block legitimate crawlers through origin anti-bot modules, server configuration or robots.txt. Verify that your origin web server, CMS security plugin and hosting firewall are not rejecting the crawler before Cloudflare’s edge decision is reached. Review the guidance at Cloudflare’s crawler documentation and your own origin logs.

Robots.txt and verified crawlers

Check that the crawler’s User-Agent is not accidentally denied in robots.txt or server rules. If you intend to permit a verified crawler, validate its identity according to your documented policy instead of trusting a self-declared name.

User-Agent blocking: a separate failure mode

Cloudflare User Agent Blocking can deny requests containing a specified User-Agent. Cloudflare recommends custom rules for specific agents rather than relying on User-Agent rules. Changing your User-Agent alone does not solve Error 1006’s defined cause—an IP ban—but it can reveal a second, independent rule after the IP issue is corrected. Keep a truthful, contactable User-Agent and obtain permission before crawling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rate limits and request behavior

Cloudflare documents rate limiting for preventing scraping and controlling bot requests. Rules can use repeated 403 or 404 responses as signals, so a fast crawler that keeps requesting missing or denied URLs may trigger protection. For an authorized job:

  • Use conservative concurrency and a steady delay rather than bursts.
  • Cache successful responses and avoid requesting unchanged resources.
  • Stop or back off on 403, 429 and Cloudflare challenge pages.
  • Do not retry the same denied URL indefinitely.
  • Follow the site’s published robots and API terms.

Rate-limit configuration examples are policy illustrations, not industry prevalence statistics. Review Cloudflare rate limiting rules and Cloudflare’s crawler and policy guidance for current controls.

Origin comparison: useful only with permission

If you administer the site and can reach the origin safely, compare an edge request with a direct-origin request from an approved network. A Cloudflare 1006 page at the edge but a normal origin response indicates a proxy-layer rule; the same denial at the origin points to a web-server, firewall or application control. Never probe an origin address that the owner has not authorized, and do not expose an origin by weakening its access controls.

Will a proxy or User-Agent change fix 1006?

Change What it can diagnose What it cannot promise
Ask owner to allowlist your fixed IP Addresses the documented IP-ban condition with owner approval Does not override other bot, path or rate rules
Change User-Agent May reveal a separate User-Agent rule Does not remove an IP ban
Use a proxy or new egress IP Can show whether the decision is tied to one authorized network Does not grant permission; another IP may also be blocked
Delete cookies or alter TLS fingerprints Little diagnostic value for a defined IP ban Not an authoritative remedy and may violate site rules
Slow the crawler and cache Reduces the chance of rate-limit matches after access is approved Cannot undo an existing owner-side deny rule

A proxy is therefore a conditional network option for an authorized team, not a bypass technique. Do not rotate addresses to evade a block or misrepresent your identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recovery procedure for an authorized crawler

  1. Pause the job and save one complete 1006 response.
  2. Confirm the egress IP and ensure it is stable and owned or contracted by your team.
  3. Send the owner the URL, time, source IP, CF-RAY, User-Agent, request rate and purpose.
  4. Wait for a documented allowlist or rule change; do not infer permission from a temporary successful response.
  5. Run one low-rate test request and verify that the HTML is the target page, not a challenge or block page.
  6. Resume with caching, backoff, bounded concurrency and monitoring for 403/429 responses.

Common symptoms and fixes

The program reports only “403 Forbidden”

Read and store the response body. The 1006 explanation may be there even when your library exposes only the status. Log headers, including CF-RAY, while removing credentials and personal data from shared logs.

The browser works but the scraper is blocked

A browser session and a server job may use different IPs, cookies, headers and request rates. Ask the owner to authorize the crawler’s actual egress IP and identify its truthful User-Agent; do not copy a browser identity deceptively.

A new IP works briefly, then fails

This indicates no durable authorization and possibly a reputation or rate-control match. Stop rotating, disclose the network you need to use, and request a stable allowlist with an agreed rate.

The owner says no Cloudflare rule matches

Have the owner check origin firewalls, CMS security modules, Zone Lockdown, inherited account rules, recent deployments and the security event timestamp. Compare an approved origin request only if the owner controls that test.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Only certain paths fail

Record the path, method and query string. A path-specific custom rule, origin restriction or rate limit may be responsible even when the home page is reachable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture an authorized page image or PDF rather than operate a general scraper, ScreenshotNeo provides a one-request website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks/CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, with the result explained by X-Page-Verdict and X-Billed headers. This does not bypass a site owner’s IP ban—you still need authorization.

See the complete parameter reference in the ScreenshotNeo documentation.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also supports full-page and selector captures, device and viewport settings, retina scale, PDF paper and page options, custom CSS/JavaScript, clicks, waits, request blocking, headers, cookies, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage data and an OpenAPI specification. Its MCP tools—take_screenshot, get_page_info and capture_pdf—work with Claude, Cursor and other MCP clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account.

Cost, reliability and operational choices

The lowest-risk design is a permitted, consistent identity with bounded concurrency and caching. It costs engineering time to coordinate an allowlist but avoids repeated failures and questionable access practices. A proxy adds a network cost and may change reputation without solving the owner’s rule. ScreenshotNeo’s cache-hit policy can reduce billed captures for repeated screenshot requests, while its verdict headers make failed loads visible to your pipeline.

FAQ

Can Cloudflare support remove Error 1006?

No. The protected website’s Cloudflare customer controls the block and must investigate or allow your IP.

Is Error 1006 the same as Error 1020?

Not necessarily. Treat the displayed code and body as the evidence for the specific rule; do not substitute a different Cloudflare error’s remedy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I keep retrying until it works?

No. Pause, preserve the response and obtain authorization before testing again.

Frequently Asked Questions

Can Cloudflare support remove Error 1006?

No. The protected website’s Cloudflare customer controls the block and must investigate or allow your IP.

Is Error 1006 the same as Error 1020?

Not necessarily. Use the displayed code and response body to identify the specific Cloudflare condition.

Should I keep retrying until it works?

No. Pause the job, save evidence and obtain authorization before testing again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.