Cloudflare is blocking your website.
“Cloudflare is blocking my website” means one of two things. If visitors see a Cloudflare page, “Sorry, you have been blocked” or “Error 1020: Access denied”, your own site's Cloudflare security settings stopped them, and you fix it in your Cloudflare dashboard. If the site simply won't load for some people, with no Cloudflare page, Cloudflare's DNS may have classified your domain as a security threat: 1.1.1.1 for Families then answers 0.0.0.0 instead of your address. That classification comes off through Cloudflare's categorization feedback form.
The first is a setting you control. The second is Cloudflare's verdict on your domain. A free scan tells you in a minute whether Cloudflare's DNS blocks the domain, and which other vendors list it too.
Free, no signup. Checks Cloudflare's 1.1.1.1 for Families, Quad9 and the other vendors we read.
A Cloudflare page: “Sorry, you have been blocked”, or “Error 1020: Access denied”, with a Ray ID at the bottom.
what it is · Your own site's Cloudflare security settings. A firewall rule, a managed rule, Bot Fight Mode or the security level stopped that visitor or request. No list has your domain on it.
the fix · In the Cloudflare dashboard, open Security → Analytics → Events, search for the Ray ID or the visitor's IP from the screenshot, see which rule fired, then change the rule or allow the visitor.
You fix this one in your own settings. You don't need us.
No Cloudflare page at all. For some people the site just won't load: “This site can't be reached”, as if it were down. For everyone else it works.
what it is · Cloudflare's DNS has classified your domain as a security threat. A device or router that uses 1.1.1.1 for Families (1.1.1.2) gets 0.0.0.0 instead of your server's address, so the browser has nowhere to go. Company networks filtered by Cloudflare Gateway use the same categories.
the fix · Correct the category in Cloudflare's categorization feedback form, after you've removed whatever triggered it.
Our free scan checks this, together with Quad9 and the other vendors we read.
If the scan shows Cloudflare and nothing else, you don't need us. The feedback form is free and takes a minute. Follow the steps below and keep your €39.
If antivirus engines, web filters or Quad9 list the domain too, they keep blocking it after Cloudflare changes the category: on visitors' computers, on company networks, on routers. Each has its own inbox or form and wants its own wording. That part is what we do.
- 01
Check that it's the DNS block.
Run the free scan, or open radar.cloudflare.com/domains/feedback/ followed by your domain. That page shows the categories Cloudflare has your domain in. A security-threat category such as Phishing, Malware, Scam or Spam is what 1.1.1.1 for Families blocks.
- 02
Remove the cause, or confirm there was none.
Hacked: remove the injected pages or code and close the way in, usually an outdated plugin or a stolen password. Never hacked: look at the site as a stranger would. A login page that resembles another brand's can read as phishing. We don't do this step and we don't verify it.
- 03
Correct the category.
On the same Cloudflare page, untick the security-threat category, tick the one that fits your site (Business, Education, News & Media and so on) and press Submit. It is anonymous, has no text field and takes a minute. Cloudflare doesn't publish how long a review takes.
- 04
Check the other lists.
Antivirus engines, web filters and other DNS services such as Quad9 keep their own lists and don't follow Cloudflare. Each has its own inbox or form and its own wording. That part is what we do for €39.
// step 2: cleaning a hacked website · step 4: Quad9 blocking the site too?
After you pay €39, once, for this domain: we re-scan it, cache ignored, and send a separately written plain-text removal request to every vendor that takes one by email, within 48 hours and in practice within the hour, with your address as Reply-To. Form-only vendors become dashboard cards. Cloudflare becomes one too, with the link and what to tick; we never submit it for you. Replies go to your inbox, not ours.
It does not clean malware. It guarantees the dispatch, not the outcome. If the scan we run right after payment finds no vendor flagging your domain, we refund the full €39 automatically. No subscription, no account.
// free scan · payment only if vendors flag you and there are requests to send
pricing · refund policy · the vendors and how each is contacted
| Day 0 | 12 vendors flagging. Payment, re-scan, 12 separately written requests sent over one hour. |
|---|---|
| Day 3 | 8 of 12 vendors no longer returned the domain. |
| Day 7 | Still 8 of 12. The same eight. |
| Day 15 | All 12 cleared. The verdicts we read were last updated on day 15, so that is the latest day by which every vendor had cleared. |
One dispatch is one dispatch: a case, not a rate. It was a false-positive flag on a site that had never been hacked, which is not the situation most people arrive here in. Vendors re-scan when they review, so a hacked site has to be clean before any of this moves. The customer's own account of that order, in his words:
“ESET flagged our client's website even though it had never been hacked. I wasn't sure whether I could trust an online service with this, but I decided to give it a try. Two weeks later, all 12 vendors that had flagged the site, including ESET, had cleared it.”
// full readings: the case study · in our September 2026 data the median flagged domain carried 11 listings, Google's among them: the report, vendor by vendor
Their phone, laptop, router or office network asks a filtering DNS service for your address, and that service answers with a block instead. Yours doesn't. 1.1.1.1 for Families and Quad9 are the common ones; the scan checks both.
No. That page comes from your own Cloudflare security settings and stops one visitor or request. Find its Ray ID under Security → Analytics → Events in your Cloudflare dashboard, see which rule fired and change it. No vendor list is involved.
It can. Cloudflare's feedback page says the categories serve Cloudflare Radar, Gateway and 1.1.1.1 for Families. Gateway is what companies use to filter their networks; whether a company blocks a category is its own policy.
Cloudflare doesn't publish a time, and we don't promise one. The category page shows the current state whenever you check it.
No. It is a form a person fills in, and it takes a minute. After payment your dashboard has a card with the link and what to tick. The €39 covers the vendors we can email and prepares the rest.
// related: Quad9 blocking your website · blocked by an antivirus or firewall · a red warning instead of the site