“Blocked due to access forbidden (403)”: why Google is refused and how to fix it

“Blocked due to access forbidden (403)” means Googlebot requested the page and the server answered 403 Forbidden. Google cannot index what it is not allowed to read. Unlike a robots.txt block, this is not a polite instruction; the server actively refused the request.

If the URLs are private (an account area, an admin panel), this is fine, though it is better not to link to them publicly. If they are public pages, something between Google and your content is turning it away.

Common causes

  • A security plugin or web application firewall that blocks unknown bots, too many requests, or requests without cookies.
  • CDN bot protection (bot fight modes, challenge pages) that treats Googlebot as a bot to stop. Some challenge pages answer 403.
  • Country or IP blocking. Googlebot crawls mostly from the United States; a rule that only allows your home country locks it out.
  • Login walls on pages that are linked publicly.
  • File permissions or server rules on a directory, often after a migration.
  • Hotlink or referrer protection that refuses requests without a referrer.

How to find what is blocking

  1. Run URL Inspection → Test live URL on an affected page. If the live test also gets 403, the block is active now.
  2. Check the logs of your firewall, CDN and security plugin for blocked requests with the Googlebot user agent around the reported dates.
  3. Request the page yourself with a Googlebot user agent: curl -I -A "Googlebot/2.1 (+http://www.google.com/bot.html)" https://example.com/page. A 403 here usually points to a user-agent rule; a 200 here but 403 for Google points to IP or rate rules.

How to fix it

  • Allow verified Googlebot in the firewall or CDN. Most providers have a setting for verified search engine bots. Verify by reverse DNS (googlebot.com or google.com) or Google's published IP ranges, not by the user agent alone, which anyone can fake.
  • Relax rate limits for verified search engine crawlers instead of blocking them.
  • Remove geo-blocks for pages you want indexed worldwide, or exempt verified crawlers.
  • Keep private pages private and unlinked: if they are not meant for Google, a 403 is fine, but remove the links that lead Google there.

Then click Validate fix in the Pages report.

How to check that it worked

  • The live test in URL Inspection fetches the page.
  • Firewall logs show Googlebot requests passing.
  • The reason's count falls during validation.

What SignalCrawler checks here

An audit that is refused with 403 tells you so right away and explains the next step, typically allowing the SignalCrawlerBot user agent in your firewall for the audit. Inside the audit, internal links that lead to 4xx pages, including 403, are reported with the pages that link to them.