In short
A 403 Forbidden means: the server understood the request but refuses access. Unlike 401, logging in does not help here - the cause lies in permissions, rules or protection mechanisms.
What does status code 403 mean?
The requested page or file exists, but the server deliberately does not deliver it. This is often intended - for example for protected directories - but can also be caused by incorrect settings.
Typical causes
- Wrong file permissions: the web server is not allowed to read the file or folder (file permissions with chmod).
- No index file: you open a folder that contains no
index.phporindex.html, and directory listing is disabled for security reasons. - Rules in the .htaccess: entries such as
Require all deniedor IP blocks prevent access. - Protection mechanisms: the ModSecurity web application firewall classified a request as suspicious, or your IP address was blocked after several failed logins (IP block).
- Security plugins of your CMS block certain areas, countries or addresses.
- Hotlink protection: images may only be embedded on your own website.
Solution for visitors
- Check the address - open the home page instead of a folder if necessary.
- Reload the page and clear the browser cache.
- If the error only occurs in your network, your IP address may be blocked. Try another network as a test, such as mobile data.
- If the error persists, contact the operator of the website.
Solution for site operators
- Check the error log: it usually states the reason - such as "permission denied", "client denied by server configuration" or a ModSecurity rule (reading log files).
- Check file permissions:
644for files and755for folders are common.
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;- Check the .htaccess: rename the file as a test (e.g. to
.htaccess_test). If the error disappears, the cause lies in one of its rules. - Check the index file: is there an
index.phporindex.htmlin the requested folder? - Check security plugins: deactivate them as a test to rule out a block by the plugin.
- Firewall block: if the error log contains a ModSecurity message for a legitimate action, send us the log line - we will check the rule and set up an exception if necessary.
Intended protection
A 403 is often exactly right: configuration files, backups or internal folders should not be publicly accessible. This is how you block a folder completely:
Require all deniedWould you like to stop attacks before they even reach your website? ShieldCache checks every request with a web application firewall based on OWASP and blocks suspicious access in a targeted way.
Related status codes
- 401 Unauthorized - login required
- 404 Not Found - page not found
- All status codes at a glance