403 Forbidden is an HTTP status code meaning the server understood the request but refuses to hand over the page to whoever asked. Unlike a 401, which asks for a login, a 403 says that trying again with credentials will not help: this requester is simply not allowed in.
How a 403 Forbidden error happens
The page usually exists. Something between the request and the content decides to block it. Common causes include:
- File or folder permissions on the server set too tightly, often after a migration or a plugin update.
- A folder with no index page where directory listing is switched off.
- A security plugin or web application firewall blocking certain IP addresses, countries or user agents.
- Bot protection at a CDN that challenges or blocks automated visitors.
- Deny rules in an .htaccess file, or an IP allowlist left over from a staging site.
The awkward part is that many of these rules treat people and crawlers differently. You and your customers may see the site perfectly while Googlebot receives a 403 on every request. Google says Googlebot crawls mainly from IP addresses in the United States, so a UK business that blocks overseas traffic to cut spam can lock Google out without realising it.
Why it matters
Google treats a 403 like other client errors: as a sign the content is not available. Pages that keep returning it are dropped from the index over time, and new pages behind the block are never indexed at all. Because the site looks normal in a browser, the first sign is often a slow, unexplained fall in traffic.
Search Console reports these URLs in the Page indexing report under “Blocked due to access forbidden (403)”. Google also asks site owners not to use 403 to slow its crawling; if your server is under strain, a 503 or 429 is the right signal, because those tell Googlebot to come back later rather than to give up.
The same blocks affect AI search crawlers. Blocking some of them may be a deliberate decision, but it should be a decision, not a side effect of a firewall setting nobody has looked at.
Common mistakes
- Geo-blocking everything outside the UK. It blocks search engine crawlers, as well as UK customers using a VPN or travelling abroad.
- Aggressive bot settings switched on and forgotten. A rule meant for scrapers catches legitimate crawlers.
- Using 403 to remove pages. If content is gone, a 404 or 410 says so clearly. A 403 suggests it exists but is hidden.
- Launching with staging restrictions in place. An IP allowlist that protected the development site goes live with it.
- Blocking CSS, JavaScript or image folders. Google cannot render the page properly if it cannot fetch the files that build it.
How to act on it
Check the Page indexing report first, then run a live test in URL Inspection on an affected page to see what Google receives. If it gets a 403 while your browser does not, look at your firewall, CDN and security plugin settings. Server logs show the answer directly: log file analysis reveals every request from Googlebot and the status code it got.
Allow verified search engine crawlers through by confirming them with a reverse DNS lookup rather than trusting the user agent, which anyone can fake. Then re-run the live test and request indexing for the pages that matter most. Diagnosing access problems like this is part of my technical SEO service.
