Troubleshooting
Cloudflare Error 1006/1007/1008: Your IP Address Has Been Banned
Cloudflare errors 1006, 1007, 1008 and 1106 mean the site owner banned your IP address. What the docs say, who can lift it, and why not to rotate IPs.
By ZeroCaptcha Engineering4 min readPublished Updated
Cloudflare errors 1006, 1007 and 1008, and the related 1106, all mean the same thing in Cloudflare’s documentation: “Access Denied: Your IP address has been banned”. The cause Cloudflare gives is “A Cloudflare customer blocked traffic from your client or browser”, and the docs do not say how the four codes differ. Only the site owner can lift the ban: “Since the website owner blocked your request, Cloudflare support cannot override a customer’s security settings.”
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
What Cloudflare documents
Cloudflare has a single troubleshooting page for all four codes (checked 1 October 2026). Its heading reads “Errors 1006, 1007, 1008 or 1106 Access Denied: Your IP address has been banned”, and it gives:
- Cause: “A Cloudflare customer blocked traffic from your client or browser.”
- Resolution: “Request the website owner to investigate their Cloudflare security settings or allow your client IP address.”
The page does not explain what separates 1006 from 1007, 1008 or 1106, so treat any explanation elsewhere that does as unofficial. The one special case it mentions is for developers: 1006 can appear in the Preview tab of Cloudflare Workers when a customer uses Zone Lockdown or another security feature to block the Google Cloud Platform addresses the Preview tab depends on.
The HTTP status for each code isn’t documented either. Cloudflare’s docs say 1xxx errors “appear in
the HTML body of the response”, and list “Most 1xxx Cloudflare error codes” among the causes of a
403.
Why an address gets banned
The 1006 page doesn’t name the feature behind the ban. One Cloudflare feature that does this is IP Access rules, which let an owner block traffic by IP address, IP range, ASN or country (a country ban has its own code, error 1009). An owner who bans an address has decided about that address, and the reason isn’t shown to you. A few possibilities to check:
- Your own traffic. A client that sent too much, too fast, or to paths it shouldn’t have may have been banned for it. Look at your logs for that site before you ask anyone.
- Someone else’s traffic on a shared address. Cloud servers, VPN exits and proxy networks reuse addresses. A ban placed because of an earlier user of your address, or because of a whole range or network, lands on you too.
- A range or network ban. If other addresses from the same provider are refused as well, the owner may have banned the range or the ASN rather than your address alone.
So check your IP’s history as far as you can: which address your client exits from, how long it has been yours, and whether your provider has had complaints about it.
What to do
- Confirm the address. Find the address your client actually used for the refused request: the proxy’s or VPN’s exit, not your machine’s.
- Stop sending requests from it to that site. Retrying doesn’t change the owner’s setting; it only adds to the traffic that led to the ban.
- Contact the site owner. Give the address, the time in UTC, what your client does, how often it runs, and a contact for questions. If the ban came from a shared address, say so.
- Let the owner decide. The owner can remove the ban or allow your address with an IP Access rule. Cloudflare notes that allowing an IP or ASN “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”
- If the answer is no, stop. A site that has banned you and declined to lift it is not one you are allowed to automate.
Don’t rotate IP addresses to evade a ban
It is technically easy to send the same requests through a different proxy until one address isn’t banned. Don’t. An IP ban is an owner’s deliberate decision about who may reach the site, and rotating addresses to get around it is evading that decision.
The same holds when the ban wasn’t aimed at you, for example a fresh cloud address with a bad history. The honest route is still to tell the owner and ask for an exemption, not to cycle addresses until one works.
ZeroCaptcha is no help against a ban and isn’t meant to be. It solves Cloudflare Turnstile widgets and Cloudflare challenge pages,
and neither a Cloudflare Turnstile token nor a cf_clearance cookie lifts a block: a banned request
never gets as far as a challenge or a form. The Cloudflare challenge
solver page explains what applies to challenge pages, which are a
different response.
Cloudflare 1xxx access errors at a glance
| Error | Cloudflare’s title or cause | Who can end it |
|---|---|---|
| 1006, 1007, 1008, 1106 | “Access Denied: Your IP address has been banned” | The site owner |
| 1009 | “Access Denied: Country or region banned” | The site owner |
| 1010 | Banned “based on your browser’s signature” | The site owner; a normal user agent may avoid it |
| 1015 | “You are being rate limited” | Time: slow down and wait |
| 1020 | “Access denied” by a firewall rule | The site owner |
Sources
- Cloudflare: Errors 1006, 1007, 1008 or 1106 (checked 1 October 2026)
- Cloudflare: 1xxx errors (checked 1 October 2026)
- Cloudflare: Error 403 (checked 1 October 2026)
- Cloudflare: IP Access rules (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.