Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
5xx errors

How to Fix the “Cloudflare Protects This Website” Error

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The message “Cloudflare protects this website” does not identify one specific fault. It may appear with a numbered Cloudflare code, such as 1020 or a 5xx status, or with no code at all. Reload once after a short wait. If the page persists, save the exact message, code, Ray ID, URL, and time (including your time zone), then send those details—and a screenshot—to the website owner. A visitor normally cannot change the site’s Cloudflare rules or origin server.

What the message actually tells you

Cloudflare’s visitor-facing error page says that if the problem is not resolved in the next few minutes, it is most likely an issue with the web server you were trying to reach. “A few minutes” is guidance, not a guaranteed restoration time. The phrase itself is not an error code and does not prove that your browser, device, internet provider, or Cloudflare is the cause.

Look for a numbered code in the full page. Cloudflare treats the main cases differently:

What you see What it establishes Correct next step
“Something went wrong trying to reach it,” with no visible code The page gives no unique diagnosis; it suggests a problem reaching the web server. Retry briefly, then send the owner a screenshot, URL, and time.
1020 / Access denied A Cloudflare firewall rule denied the request. Send the screenshot to the site owner so they can inspect the event and rule.
5xx, such as 502 or 504 A server or connectivity failure. A 502/504 can originate at Cloudflare or at the site’s origin. Report the exact code, message, URL, and time to the owner; the owner may need the host.
Another 1xxx code A member of Cloudflare’s distinct 1xxx error family. These codes appear in the HTML body, unlike ordinary HTTP statuses such as 403 or 429. Use the documentation for that exact code and contact the site owner.

See Cloudflare’s Error 1020 documentation, 5xx guidance, and 1xxx overview for the code displayed on your page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if you are a site visitor

1. Wait briefly and reload once

Close nothing and change no settings yet. Wait a short time, then reload the same URL once. Repeated refreshes can create more requests without fixing a server-side problem. If the page still fails, move to evidence collection rather than guessing at a browser fix.

2. Capture the complete error

Take a screenshot that includes the whole message, any number, the Ray ID, and the Cloudflare timestamp. Copy the exact URL from the address bar and note your local time and time zone. Do not paraphrase the code: “1020,” “502,” and “504” lead to different investigations.

For a 1020 page, a screenshot is specifically what Cloudflare asks visitors to provide. You can also record the browser and network used, but the code, Ray ID, URL, and time are the essential identifiers.

3. Follow the path for Error 1020

Error 1020 means a firewall rule configured for that website denied access. It is not an instruction to bypass the rule with a VPN, a different device, or repeated cookie deletion. Contact the owner through an email address, support portal, or social account that does not depend on the blocked page. Include your screenshot and the details you recorded. The owner can search Cloudflare Security Events by Ray ID or client IP, convert the event’s UTC timestamp to the dashboard’s search time zone, review the triggering rule, and decide whether to adjust it or allow your request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Follow the path for a 5xx page

Cloudflare’s visitor instruction for a persistent 5xx response is to report the problem to the site owner. Send the exact status and message, URL, time and time zone, Ray ID if shown, and screenshot. Do not label a 502 or 504 as definitely “a Cloudflare outage” or definitely “the server is down”: either the origin or an intermediary in the path can produce it.

5. If no code is shown

Send the owner the screenshot and the exact visible wording, including “something went wrong trying to reach it.” The phrase does not establish that clearing browser data, replacing hardware, buying a VPN, or changing your ISP will solve the failure. The owner needs to determine whether the request reached the origin and whether the page was generated by Cloudflare or passed through from the origin.

What site owners and support staff should check

Investigating a 1020 denial

  1. Ask the visitor for the screenshot, Ray ID, client IP (if they can provide it), URL, and the page’s UTC time.
  2. In Cloudflare, open Security Events and search by Ray ID or IP. Convert the displayed timestamp correctly if your dashboard search uses UTC.
  3. Identify the firewall, rate-limit, bot, or custom rule that matched.
  4. Confirm that the rule’s expression and any country, ASN, IP, path, or user-agent condition is intentional.
  5. Adjust the rule or create an appropriate allow action only after verifying the request is legitimate. Ask the visitor to retry once the change is deployed.

Cloudflare’s 1020 guide describes this owner-side workflow. Do not tell visitors to circumvent an access control.

Investigating a 5xx response

  1. Preserve the exact code, message, URL, Ray ID, time zone, and affected hostname.
  2. Check origin web-server and application logs for the same minute and request path.
  3. Check every intermediary between Cloudflare and the origin: load balancers, reverse proxies, caches, firewalls, service meshes, and health checks.
  4. Verify DNS, TLS, origin reachability, connection limits, upstream timeouts, and recent deployments.
  5. Use available error analytics or Log Explorer to correlate the request. Involve the hosting provider when the origin is unavailable or rejecting connections.

Cloudflare’s 5xx documentation covers this evidence-gathering approach. A custom error page can change the appearance of the default Cloudflare page, so the visual design alone is not proof of where the response originated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Determining whether Cloudflare generated the page

For technical support, inspect response headers when you can reproduce the failure. Cloudflare-generated error responses may include cf-error-type and cf-error-origin. Cloudflare lists a 52x type as an origin-connectivity category. These diagnostic headers are present on Cloudflare-generated pages, not on errors forwarded from the origin; absence therefore does not prove that Cloudflare was uninvolved. See Cloudflare error diagnostic headers.

Common mistakes and their limits

  • Calling every page Error 1020: the wording alone is not 1020. Use the number actually displayed.
  • Assuming the visitor caused the block: 1020 reflects a site rule, which may match an IP range, path, country, or other condition.
  • Promising a fixed recovery time: Cloudflare says “the next few minutes,” not a service-level commitment.
  • Changing many variables at once: switching browsers, networks, VPNs, and devices destroys useful diagnostic context and cannot repair an origin outage.
  • Reporting without identifiers: “the site is down” gives an owner little to search. Include code, Ray ID, URL, and timestamp.

How to report the problem effectively

Use an alternate contact route and send a compact report:

  • Exact URL (including path and query string, if relevant)
  • Exact displayed code and wording
  • Ray ID, if present
  • Date, local time, and time zone
  • Screenshot of the complete page
  • Whether a single page or the whole domain fails

Cloudflare’s site-troubleshooting information guide explains the details owners should collect. The owner, rather than the visitor, can escalate a Cloudflare configuration issue or origin failure to the hosting provider.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If you need a reproducible image of the failing URL for a support ticket or incident record, ScreenshotNeo can capture it through one request instead of configuring a headless browser. It accepts consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each cleanup step can be disabled. Only clean shots are billed: bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. This does not bypass a Cloudflare firewall rule; it records what a permitted request receives.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Get an API key, then run the same request in the language you use. Full parameter names and options are in the ScreenshotNeo documentation.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/failing-page -o shot.webp

Python

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://example.com/failing-page"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({
  access_key: 'YOUR_API_KEY',
  url: 'https://example.com/failing-page'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
const body = Buffer.from(await res.arrayBuffer());
await Bun.write('shot.webp', body);

ScreenshotNeo also supports full-page captures with lazy images loaded, CSS-selector element shots, dark mode, 12 device presets or custom viewports, retina scale, PDF output with paper size, margins, landscape and page ranges, HTML/CSS rendering, custom JavaScript and CSS, clicks before capture, hidden selectors, selector/delay/network-idle waits, request and resource blocking, custom headers, cookies, user agents and Authorization, timezone and geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. Its parameter names are compatible with those used by other screenshot APIs, which can simplify migration.

The Free plan includes 1,000 shots per month with no card. Paid plans start at $5 for 3,000 shots; Growth is $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000. Yearly billing gives two months free, and every feature is available on every plan. ScreenshotNeo also provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients, so an AI agent can collect the evidence.

Create a free ScreenshotNeo account to get 1,000 screenshots a month without a card.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to escalate

Escalate to the site owner immediately when a 1020 or persistent 5xx response continues after the brief retry. Owners should escalate to their host or Cloudflare support after checking the rule, origin, and intermediaries and assembling the identifiers above. A general error page cannot establish that the affected site is undergoing a broad outage; only the owner’s logs and provider status information can do that.

Frequently Asked Questions

Is “Cloudflare protects this website” always Error 1020?

No. It is descriptive wording, not a unique code. Read the page for the numbered status; 1020, 5xx, and other 1xxx codes require different owner investigations.

What is a Ray ID used for?

It is a request identifier shown on many Cloudflare pages. Give it to the site owner so they can correlate your request with Security Events or server-side diagnostics.

Can a website visitor remove a Cloudflare firewall block?

No. A 1020 denial comes from a rule configured for the site. The owner must review the matching event and decide whether to change the rule or allow the request.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why might the page look like Cloudflare even when Cloudflare did not generate it?

An origin or intermediary can forward a custom error page. Cloudflare’s diagnostic headers can help owners distinguish Cloudflare-generated responses from errors passed through from the origin.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.