Page indexing report · Search Console

Blocked due to access forbidden (403)

Google requested the page and something on your side refused it. Googlebot never sends credentials, so Google says the server is returning this error incorrectly, and the page won’t be indexed.1 Here’s how to find which layer sent the 403 and let Google back in.

Updated · Based on Google’s documentation, statements from Google staff and published studies · 13 sources

Check the URL first

The checker shows whether the URL forbids an ordinary request. A pass doesn’t clear it: firewalls and CDNs often block by Google’s IP addresses, which no outside test can reproduce. URL Inspection and your logs can.

Free, no sign-up. Checks status, noindex, robots.txt, canonical, content and sitemap.

In 30 seconds

  • Google doesn’t index URLs that return 403, and removes ones that were indexed.2
  • The usual cause is a CDN, firewall or security rule that blocks Google’s IPs, often added automatically.3
  • Since September 2026, Cloudflare’s Block setting for AI training also blocks Googlebot.12
  • Never use 403 to slow crawling. Use 429 or 503, briefly.4

What the status means

HTTP 403 means the request was understood and refused. Google’s report points out that Googlebot never provides credentials, so a 403 can’t mean “wrong password”. It means a rule decided to turn Google away. The fix Google suggests is to admit visitors who aren’t signed in, or to allow Googlebot after verifying its identity.1

Google treats 403 like most other 4xx codes: content in the response is ignored, the URL isn’t indexed, and if it was indexed it’s removed. Crawling of the URL slows gradually.2

Where it happens

The 403 stops Google at the crawl stage. Select a stage to see what happens there.

Crawl

Googlebot checks robots.txt, then requests the URL. It spaces requests out so it doesn’t overload the server.

What goes wrong: The URL is blocked, returns an error, or the server is slow, so Google backs off and crawls less.

Report statuses at this stage

Is it a problem?

It’s a problem more often than a 401, because a 403 on a public page is rarely deliberate. Google notes that in general you can only fix issues whose Source column says Website, and this one comes from your site.1

Usually fine

  • Admin, login and account URLs
  • Directories you deliberately don’t list
  • Private files nobody links to

Worth fixing

  • Any public page or sitemap URL
  • A sudden jump after a CDN, security or plugin change
  • Many unrelated URLs at once, which points to a site-wide rule
  • robots.txt itself returning 403

The last one matters. Google treats a robots.txt served with a 4xx status as if it didn’t exist, so your disallow rules stop applying.4

Find the cause

Answer a few questions. Each cause is explained below.

Question 1Should Google be able to index this URL?

Your CDN or firewall is blocking Google

Google’s Martin Splitt and Gary Illyes wrote that flood protection can put wanted crawlers on a CDN’s blocklist, that it can happen automatically, and that it can be hard or impossible to control because it happens on the CDN’s side.3 They recommend checking blocklists every now and then. On Cloudflare, block and challenge rules both produce a 403.10

An AI-crawler setting

Cloudflare classes Googlebot as a mixed-use crawler, one whose crawl serves both search and AI training. It now applies its Block setting for AI training to these crawlers.12 If you turned on AI blocking and the 403s started then, this is the first thing to check.

Rate limiting with the wrong status

A 403 doesn’t tell Google to slow down. Google says 4xx codes other than 429 have no effect on crawl rate.2 If the server needs relief, Google recommends 500, 503 or 429, and only for a couple of hours to a day or two.9

Country blocking

Google says Googlebot’s default IP addresses appear to be in the US, and that it should be treated like any visitor from there.8 A rule that blocks US traffic, or traffic from “unknown” locations, blocks most of Google’s crawling.

The origin server forbids it

When browsers get the 403 too, the origin is the likely source: deny rules, mod_security, or IP blocklists.10 File permissions are the other common culprit, especially for uploads.

Where 403s come from

Pick a source to see how to check for it and what to change. The last tab shows how to prove what Google received.

CDN or firewall bot rules

Google says crawlers you want can “end up in your CDN’s blocklist”, usually in the web application firewall, and that the block may happen automatically.3 Cloudflare lists WAF rules with a block or challenge action, the Security Level setting, DDoS protection and Browser Integrity Check among the features that produce a 403.10

Check: the CDN’s security event log, filtered to Google’s IP ranges.6 Fix: allow verified Google crawlers. Google lists where Cloudflare, Akamai, Fastly, F5 and Google Cloud document this.3

How to fix it

  1. Open the row and note the “First detected” date. Compare it with recent CDN, security and plugin changes.
  2. Inspect one URL and run the live test. A 403 shows as a failed Page fetch.5
  3. Find the layer that answered: CDN security events first, then server and plugin logs, filtered to verified Google IPs.6
  4. Allow verified Google crawlers there, by IP range or verified-bot setting. Don’t allow by user agent alone.
  5. Replace any 403 used for rate limiting or bot checks with 429 or 503.3
  6. Run the live test again. When it passes, request indexing for key URLs and click Validate fix.5
  7. Check the CDN blocklist again in a few weeks. Google warns that IPs can end up there automatically.3

How long it takes

Google gives no figure for how quickly a 403 removes pages that were indexed. Treat it as urgent.

403 vs 503 or 429

If you have to turn Google away for a while, the status code decides what happens to your pages.

403 Forbidden503 or 429
Google reads it asThe content doesn’t exist2A server problem; 429 counts as one2
Indexed pagesRemoved2Kept for now, dropped if it persists2
Crawl rateNo effect2Google slows down temporarily2
Use it forContent that should never be publicOverload and bot checks, briefly3

Questions

What does “Blocked due to access forbidden (403)” mean?

Google requested the URL and your server, CDN or firewall answered 403 Forbidden. Google doesn’t index URLs that return 403 and removes ones that were indexed. Googlebot never sends credentials, so the 403 is a rule on your side.

Why does my page load in a browser but Google gets a 403?

Most likely a firewall, CDN or security plugin rule matches Google’s IP addresses or user agent. Bot protection can add Google’s IPs to a blocklist automatically. Check your CDN security events and access logs for verified Google requests.

Is Cloudflare blocking Googlebot?

It can. Firewall rules, bot challenges and security settings can all return 403 to crawlers, and since September 15, 2026 Cloudflare’s Block option for AI training also applies to Googlebot. Check Cloudflare’s security events and your AI crawler settings.

How do I allow Googlebot through my firewall?

Allow Google’s published IP ranges or your provider’s verified-bot category. Don’t allow by user agent alone, because anyone can fake it. Google documents a reverse and forward DNS check for single IPs.

Can I use 403 to slow Google down?

No. Google says 403 has no effect on crawl rate and gets URLs removed from search. Return 429 or 503 for a short time instead, or fix the server load.

How long until pages come back after fixing a 403?

Google says a requested URL is typically indexed in a day or so, though it can take longer. Validating the fix in the report typically takes up to about two weeks.

Sources

  1. Google, “Page indexing report”, Search Console Help
  2. Google, “How HTTP status codes affect Google’s crawlers”, Google Crawling Infrastructure, updated February 2026
  3. Martin Splitt and Gary Illyes (Google), “Crawling December: CDNs and crawling”, Search Central Blog, December 2024
  4. Gary Illyes (Google), “Don’t use 403s or 404s for rate limiting”, Search Central Blog, February 2023
  5. Google, “URL Inspection tool”, Search Console Help
  6. Google, “Verify requests from Google crawlers and fetchers”, Google Crawling Infrastructure, updated March 2026
  7. Google, “Google’s common crawlers”, Google Crawling Infrastructure, updated July 2026
  8. Google, “How Google crawls locale-adaptive pages”, Search Central, updated December 2025
  9. Google, “Reduce Google crawl rate”, Google Crawling Infrastructure, updated October 2026
  10. Cloudflare, “Error 403”, Cloudflare Support docs
  11. Cloudflare, “Actions reference”, Cloudflare Ruleset Engine docs
  12. Cloudflare, “Have it both ways: stay discoverable in search while disallowing AI training”, Cloudflare blog, September 2026
  13. Report on r/TechSEO, with a reply from John Mueller (Google), reported by Search Engine Journal, August 2026