Skip to content

Troubleshooting

Cloudflare Error 1009: Country or Region Banned, Explained

Cloudflare error 1009 means the site owner banned the country or region of your IP address. Why it happens, who can lift it, and when a proxy region is fine.

By 4 min readPublished Updated

Cloudflare error 1009, “Access Denied: Country or region banned”, means the site’s owner has banned the country or region your IP address is in. Cloudflare’s documentation points owners to IP Access rules, which can allow, block or challenge traffic by IP address, IP range, ASN or country, and notes that blocking by country there is an Enterprise feature. Only the owner can lift the ban. From your side, the one change that helps is to reach the site from an address in a region it serves, and only where you are permitted to use it from there.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

What Cloudflare’s docs say

The error page (checked 1 October 2026) gives the cause as “The owner of the website (for example, example.com) has banned the country or region your IP address from accessing the website.” Its resolution has two halves:

  • Visitors contact the site owner and ask for their IP address to be allowed.
  • Owners “ensure that the reported IP address is allowed under the IP Access rules security feature”.

Cloudflare’s IP Access rules documentation describes them as a way to “allowlist, block, and challenge traffic based on the visitor’s IP address, Autonomous System Number (ASN), or country”, and states “Block by country is only available on Enterprise plans.” Owners on other plans can still write WAF custom rules on the ip.src.country field; Cloudflare’s 1009 page doesn’t say which error code a blocked request shows in that case. The page does not document an HTTP status for 1009 either; Cloudflare lists “Most 1xxx Cloudflare error codes” among its causes of a 403.

Your IP decides the country, not your location

Cloudflare’s rules language describes ip.src.country as “The 2-letter country code in ISO 3166-1 Alpha 2 format” for the client’s address. The country that counts is the one of the address your request arrives from, which may not be yours:

  • A VPN or corporate proxy exits wherever its server is.
  • A cloud server exits from its data center’s region. A scraper that works from a laptop can meet 1009 once it runs from a server in another country.
  • A proxy network exits from whichever address it hands out, which may be in a different country from one session to the next unless you choose one.

Before anything else, find out which address, and so which country, your client actually uses when it gets the error.

What an automated client can do

  1. Check that you are allowed to use the site from where you are. A country ban is a deliberate choice by the owner, for reasons you may not see. If it is meant to keep you out, respect it.
  2. If you are permitted, use an exit address in an allowed region. Examples: your company’s own site that serves one country and a test job that runs abroad, or a data source that licenses you to access it from a given country. A proxy that exits in that country solves the mismatch. Choosing proxies for Cloudflare Turnstile covers proxy types, sticky sessions and picking a region.
  3. Otherwise, ask the owner. Send the IP address from the error, the time in UTC, and what your client does. The owner can allow the address with an IP Access rule; Cloudflare notes that allowing an IP or ASN “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”
  4. Keep the region fixed for the session. If you solve a Cloudflare Turnstile widget through a proxy, submit the form through the same proxy session. Solve Cloudflare Turnstile with a proxy shows how to pass one.

What not to do: cycle through countries until one gets through, on a site whose owner didn’t want you in. That is evading a ban, not fixing an error.

What ZeroCaptcha does and doesn’t do here

ZeroCaptcha solves Cloudflare Turnstile and Cloudflare challenge pages. It does not change the country your own requests come from, and a token does not lift a country ban: a banned request never reaches the form that would use it. A TurnstileTask runs through the proxy you give it, so the proxy you choose decides the region the widget sees; ZeroCaptcha accepts HTTP and HTTPS proxies on public addresses.

IP Access rules can also challenge visitors from a country instead of banning them. Then you meet a “Just a moment…” page rather than error 1009. That case is covered by the Cloudflare challenge solver page and Cloudflare challenge types.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What does Cloudflare error 1009 mean?

The site's owner has banned the country or region your IP address is in. Cloudflare's documentation titles it 'Access Denied: Country or region banned'.

Can I use a VPN or proxy to get past Cloudflare error 1009?

Only where you are permitted to use the site from the region the proxy exits in. The ban is the owner's decision; if you aren't allowed, ask the owner to allow your address instead of routing around it.

Why do I get error 1009 when I'm in an allowed country?

The ban applies to the country of your IP address, not to where you sit. A VPN, a corporate proxy or a cloud server can put your requests in another country than your own.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key