Troubleshooting
Please Unblock challenges.cloudflare.com to Proceed: Fixes
Why a Cloudflare page says to unblock challenges.cloudflare.com, how to fix it in a browser or network, and what it means for automated clients.
By ZeroCaptcha Engineering5 min readPublished Updated
“Please unblock challenges.cloudflare.com to proceed” means the site you opened is protected by a
Cloudflare security check, and your browser could not load that check from
challenges.cloudflare.com, the domain Cloudflare serves it from. Something on your side blocked
it (an ad or script blocker, a privacy extension, a DNS filter, a firewall or a VPN), or, as on 18
November 2025, Cloudflare itself was having an outage. To fix it, allow challenges.cloudflare.com
and reload. For automated clients, the same message means the challenge script was blocked by the
automation’s own setup.
Where the message comes from
The sentence appeared on Cloudflare’s interstitial challenge page, the “Just a moment…” screen a
site’s Cloudflare rules show before the page itself. That page runs Cloudflare’s challenge
platform, which Cloudflare’s docs describe as “the same underlying technology powering Turnstile”,
the widget some sites embed in their forms, and both load from challenges.cloudflare.com. When
that domain cannot be reached, the check cannot run, and the page asks you to unblock it.
The message is not documented on any developers.cloudflare.com page (searched 30 September 2026). It was widely reported during Cloudflare’s outage of 18 November 2025, when challenge screens on many large sites showed it at once. Cloudflare’s post-mortem says Turnstile failed to load during the outage, which began at 11:20 UTC and was fully resolved at 17:06 UTC.
Today’s challenge page words the same problem differently. Its current script (checked 30
September 2026) shows “Incompatible browser extension or network configuration”, then: “Your
browser extensions or network settings have blocked the security verification process”, and
asks you to check whether your internet or firewall settings block your device from reaching
“challenges.cloudflare.com”. The Cloudflare Turnstile widget reports the same situation as
error 200500, “Iframe load error”, whose documented fix is to “Check if challenges.cloudflare.com
is blocked”.
Fixes for people browsing
Try these in order, reloading the page after each:
- Check your blockers. Cloudflare’s docs say “Ad blockers and content blockers may prevent
challenge scripts from loading properly”, and that script blockers, fingerprinting protection
and canvas blockers can interfere too. Allow
challenges.cloudflare.comin the extension, or turn the extension off for the site. - Turn on JavaScript and cookies. The check needs both; with JavaScript off, the page says “Enable JavaScript and cookies to continue”.
- Check DNS filtering. Pi-hole, NextDNS, AdGuard DNS or a router’s filter can block the domain
for every device on the network. Allow
challenges.cloudflare.comand its subdomains. Cloudflare added two hostnames in July 2026,hagen.challenges.cloudflare.comandbrunhild.challenges.cloudflare.com, and asks for both to be allowed. - Try without the VPN or proxy. Cloudflare lists VPNs and proxies among the causes of failed challenges.
- Check a company or school firewall. A network that filters domains needs
challenges.cloudflare.comon its allowlist. Only its administrator can change that. - Check the clock. A wrong device time breaks the check; Cloudflare shows “Incorrect device time” for it.
- Use Cloudflare’s own test page.
debug.challenges.cloudflare.comchecks whether your browser and network can run the challenge.
If none of this helps and many sites fail at once, the problem may be Cloudflare’s. Check Cloudflare’s status page before changing anything else.
Fixes for site owners
If your visitors report the message on your own site:
- Content Security Policy. Allow
https://challenges.cloudflare.cominscript-srcandframe-src, or use the nonce-based approach Cloudflare recommends; Turnstile works withstrict-dynamic. - Load the script from Cloudflare. Cloudflare says
api.js“must be fetched from the exact URL” it documents: “Proxying or caching this file will cause Turnstile to fail when future updates are released.” - WebViews. In a mobile app’s WebView, the documented causes are disabled JavaScript, missing
DOM storage or cookie support, blocked access to
challenges.cloudflare.com, and a user agent that changes during the session.
What it means for automated clients
On a site you are allowed to automate, the same failure shows up in scrapers and test suites, for reasons of the automation’s own making:
- Request blocking. A common optimization in Playwright or Puppeteer aborts every request to a
third-party domain, or every script and image, to save bandwidth. That also aborts the challenge
script. Let
challenges.cloudflare.comand its subdomains through. - Filtered egress. A crawler behind a DNS filter, a corporate proxy or a cloud firewall with a
domain allowlist cannot reach
challenges.cloudflare.comeither. Add it to the allowlist. - No JavaScript at all. An HTTP client such as curl, requests or Scrapy never runs the
challenge, so it never sees this message: it gets the challenge page’s HTML with HTTP 403 and a
cf-mitigated: challengeheader instead. Unblocking a domain does not change that; the page wants a browser that passes the check, or acf_clearancecookie from one.
This snippet, for Playwright, blocks images and fonts while letting Cloudflare’s challenge through:
import { chromium } from "playwright";
const browser = await chromium.launch();const page = await browser.newPage();await page.route("**/*", (route) => { const request = route.request(); const host = new URL(request.url()).hostname; const cloudflare = host === "challenges.cloudflare.com" || host.endsWith(".challenges.cloudflare.com"); if (!cloudflare && ["image", "font", "media"].includes(request.resourceType())) return route.abort(); return route.continue();});await page.goto("https://shop.example.com/");console.log(await page.title());await browser.close();Unblocking lets the check run; it does not make an automated browser pass it. Cloudflare documents that “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not supported for solving production challenges”. When the challenge runs and still does not pass, you are facing the check itself, not a blocked domain:
- For a Cloudflare Turnstile widget in a form, a solving API returns a token for the page’s sitekey: see the Cloudflare Turnstile solver and Cloudflare Turnstile in headless browsers.
- For a full-page challenge (“Just a moment…”), what the page wants is a
cf_clearancecookie. ZeroCaptcha’s challenge task passes the page through your own proxy and returns the cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained.
If the page keeps coming back after it passes, see why Cloudflare’s challenge loops. Automate only sites you are allowed to: see responsible captcha automation.
Sources
- Cloudflare challenges: troubleshooting, challenge solve issues and supported browsers (checked 1 October 2026).
- Cloudflare Turnstile: client-side error codes,
for
200500(checked 1 October 2026). - Cloudflare Turnstile changelog, entry of 22 July 2026 (checked 1 October 2026).
- Cloudflare Turnstile: Content Security Policy and client-side rendering (checked 1 October 2026).
- Cloudflare challenges: detect a challenge response (checked 1 October 2026).
- Cloudflare’s post-mortem of the 18 November 2025 outage (checked 1 October 2026).
- The current wording of the challenge page was read from Cloudflare’s live challenge script on 30 September 2026. Reports of the older message during the outage come from the press, such as Yahoo Finance UK, 18 November 2025.
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.