SEO

403 Forbidden

Also called 403, 403 error

An HTTP status code meaning the server refuses to serve a page to that requester, which can silently lock search engines out.

Quick facts: 403 Forbidden

Category
SEO
Also called
403, 403 error
Level
Intermediate
Affects
Crawling, indexing, rendering, AI crawler access
Where to see it
Search Console Page indexing report and URL Inspection, server access logs, firewall and CDN dashboards, curl
In this article4
  1. How a 403 Forbidden error happens
  2. Why it matters
  3. Common mistakes
  4. How to act on it

403 Forbidden is an HTTP status code meaning the server understood the request but refuses to hand over the page to whoever asked. Unlike a 401, which asks for a login, a 403 says that trying again with credentials will not help: this requester is simply not allowed in.

How a 403 Forbidden error happens

The page usually exists. Something between the request and the content decides to block it. Common causes include:

  • File or folder permissions on the server set too tightly, often after a migration or a plugin update.
  • A folder with no index page where directory listing is switched off.
  • A security plugin or web application firewall blocking certain IP addresses, countries or user agents.
  • Bot protection at a CDN that challenges or blocks automated visitors.
  • Deny rules in an .htaccess file, or an IP allowlist left over from a staging site.

The awkward part is that many of these rules treat people and crawlers differently. You and your customers may see the site perfectly while Googlebot receives a 403 on every request. Google says Googlebot crawls mainly from IP addresses in the United States, so a UK business that blocks overseas traffic to cut spam can lock Google out without realising it.

Why it matters

Google treats a 403 like other client errors: as a sign the content is not available. Pages that keep returning it are dropped from the index over time, and new pages behind the block are never indexed at all. Because the site looks normal in a browser, the first sign is often a slow, unexplained fall in traffic.

Search Console reports these URLs in the Page indexing report under “Blocked due to access forbidden (403)”. Google also asks site owners not to use 403 to slow its crawling; if your server is under strain, a 503 or 429 is the right signal, because those tell Googlebot to come back later rather than to give up.

The same blocks affect AI search crawlers. Blocking some of them may be a deliberate decision, but it should be a decision, not a side effect of a firewall setting nobody has looked at.

Common mistakes

  • Geo-blocking everything outside the UK. It blocks search engine crawlers, as well as UK customers using a VPN or travelling abroad.
  • Aggressive bot settings switched on and forgotten. A rule meant for scrapers catches legitimate crawlers.
  • Using 403 to remove pages. If content is gone, a 404 or 410 says so clearly. A 403 suggests it exists but is hidden.
  • Launching with staging restrictions in place. An IP allowlist that protected the development site goes live with it.
  • Blocking CSS, JavaScript or image folders. Google cannot render the page properly if it cannot fetch the files that build it.

How to act on it

Check the Page indexing report first, then run a live test in URL Inspection on an affected page to see what Google receives. If it gets a 403 while your browser does not, look at your firewall, CDN and security plugin settings. Server logs show the answer directly: log file analysis reveals every request from Googlebot and the status code it got.

Allow verified search engine crawlers through by confirming them with a reverse DNS lookup rather than trusting the user agent, which anyone can fake. Then re-run the live test and request indexing for the pages that matter most. Diagnosing access problems like this is part of my technical SEO service.

Do and do not

Do

  • Test pages with URL Inspection's live test after any security change
  • Verify search crawlers by reverse DNS before allowing them
  • Use a 404 or 410 for content that is genuinely gone

Do not

  • Block all non-UK traffic at the firewall
  • Use 403 to slow down crawling
  • Launch with staging access rules still active

Questions people ask about this

Why can I see my site but Google gets a 403 error?

Because the block applies to the requester, not the page. Firewalls, CDNs and security plugins often filter by IP address, country or user agent, so a rule can catch Googlebot, which crawls largely from US addresses, while UK visitors pass. URL Inspection's live test in Search Console shows exactly what Google receives.

Will a 403 error remove my pages from Google?

If it persists, yes. Google treats a 403 as a sign the content is unavailable and drops those URLs from its index over time. A brief block usually does little lasting harm, and pages generally return once Google can crawl them again, though that can take days or weeks.

What is the difference between a 401 and a 403?

A 401 means the page needs authentication, such as a login, and the request did not provide it. A 403 Forbidden means the server will not serve the page to this requester even with credentials. For SEO both keep the content out of Google, which is correct for members' areas and a problem anywhere else.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.