Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Error & Status Codes 2 min read

HTTP status code 403 Forbidden: causes and solutions

In short

A 403 Forbidden means: the server understood the request but refuses access. Unlike 401, logging in does not help here - the cause lies in permissions, rules or protection mechanisms.

What does status code 403 mean?

The requested page or file exists, but the server deliberately does not deliver it. This is often intended - for example for protected directories - but can also be caused by incorrect settings.

Typical causes

  • Wrong file permissions: the web server is not allowed to read the file or folder (file permissions with chmod).
  • No index file: you open a folder that contains no index.php or index.html, and directory listing is disabled for security reasons.
  • Rules in the .htaccess: entries such as Require all denied or IP blocks prevent access.
  • Protection mechanisms: the ModSecurity web application firewall classified a request as suspicious, or your IP address was blocked after several failed logins (IP block).
  • Security plugins of your CMS block certain areas, countries or addresses.
  • Hotlink protection: images may only be embedded on your own website.

Solution for visitors

  • Check the address - open the home page instead of a folder if necessary.
  • Reload the page and clear the browser cache.
  • If the error only occurs in your network, your IP address may be blocked. Try another network as a test, such as mobile data.
  • If the error persists, contact the operator of the website.

Solution for site operators

  1. Check the error log: it usually states the reason - such as "permission denied", "client denied by server configuration" or a ModSecurity rule (reading log files).
  2. Check file permissions: 644 for files and 755 for folders are common.
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;
  1. Check the .htaccess: rename the file as a test (e.g. to .htaccess_test). If the error disappears, the cause lies in one of its rules.
  2. Check the index file: is there an index.php or index.html in the requested folder?
  3. Check security plugins: deactivate them as a test to rule out a block by the plugin.
  4. Firewall block: if the error log contains a ModSecurity message for a legitimate action, send us the log line - we will check the rule and set up an exception if necessary.

Intended protection

A 403 is often exactly right: configuration files, backups or internal folders should not be publicly accessible. This is how you block a folder completely:

Require all denied

Would you like to stop attacks before they even reach your website? ShieldCache checks every request with a web application firewall based on OWASP and blocks suspicious access in a targeted way.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Bester Hoster Überhaupt

Ich bin mit allem zu 100% zufrieden. Ich nutze diesen Anbietern schon jahrelang! Nie Probleme gehabt.
Michael G.Recommends us · 08/07/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.