Skip to content
Mesa Web Designers

403 Forbidden

Forbidden. On the site you own. Somebody changed the locks.

A 403 isn't breakage — it's refusal: the server found your page and declined to serve it. Something with authority — a security plugin, a firewall rule, file permissions, an IP blocklist — decided the request looked wrong. Including, apparently, yours.

Skip the reading — (480) 525-7582Describe it in writing

Same-day diagnosis. Flat quote before any fix.

What’s actually happening

403 means a rule fired. The page exists; a gatekeeper vetoed the request. The gatekeepers are a known cast: server-level rules in .htaccess, security plugins and their firewalls, host-level protections like ModSecurity, CDN firewall rules, and file permissions set so the server itself can't read what it's serving.

The useful question is scope: 403 for everyone, everywhere is usually permissions or a sitewide rule gone wrong. 403 on wp-admin only is a security lockdown doing its job on the wrong person. 403 for just you — while the world browses fine — is your IP on a blocklist, often courtesy of your own security plugin misreading your login attempts.

The usual causes, ranked

After twenty-seven years of these calls, the odds are well mapped. Start at the top.

01

A security plugin locked you out

Failed logins, a country rule, or a rate limit tripped by your own activity — the guard dog bit the owner. The leading cause of the 'just me' 403.

02

ModSecurity or host firewall rules

Server-level rules pattern-matching something innocent — a page builder's requests, a long form post — as an attack. Common after hosts tighten rulesets.

03

Broken file permissions

After a migration or a botched change, files owned by the wrong user or set unreadable — the server refusing what it can't read. The sitewide flavor.

04

Hotlink or directory protection overreach

Rules meant to protect images or directories written broadly enough to catch real pages. Small intention, wide blast radius.

What you can safely try first

Nothing below can make things worse — that’s the selection criterion. Anything riskier belongs in professional hands, on a backup.

  1. 1

    Test from another network

    Phone on cellular: loads fine? Then it's your IP on a list, not the site — and the fix is unblocking, not repairing. This one test halves the problem.

  2. 2

    Ask one other person to try

    403 for them too establishes sitewide-versus-just-you conclusively. Two data points beat an hour of guessing.

  3. 3

    Recall what changed

    New security plugin? Host 'security upgrade' email? Migration? The 403's birthday and the change log usually point at the same day.

Stop and call when…

  • It's sitewide — permissions and server rules deserve careful hands, not experiments
  • You're locked out of wp-admin and the security plugin can't be reached to be calmed
  • The host's ModSecurity is flagging legitimate traffic — that's an evidence-based conversation with them

From there it’s our job: same-day look, flat quote, and the $229 flat repair covers most cases of exactly this.

Single Error Fix — buy it now, skip the hunt.

One error, hunted down and fixed — 500s, white screens, redirect loops, broken pages.

Covers one specific error or broken behavior on one site. Diagnosis, the fix, and a plain-English note on what happened. If we can't fix it, you get a full refund.

Questions we hear a lot.

Only I get the 403 — everyone else is fine. What happened?

Your IP got blocklisted, most often by your own security plugin after failed logins, aggressive refreshing, or VPN oddities. The fix is removing the block and adjusting the trigger so protecting the site stops including you among the threats.

Google Search Console says my pages return 403. Bad?

Very — if the crawler is forbidden, your rankings starve. Usually a bot rule or firewall is treating Googlebot as an attacker. It needs fixing promptly and verifying via the URL inspection tool; crawl-blocking 403s are how healthy sites quietly fall out of the index.

What does the flat fix cover?

Identifying which gatekeeper fired (plugin, server rule, permissions, CDN), restoring access, and adjusting the rule so it keeps guarding without the friendly fire. $229, same-day, refunded if we can't get you back in.

Take back the keys to your own site.

Send the symptom, get a same-day look and a flat quote from the developer who's fixed this exact thing more times than either of us can count.