Skip to content

Troubleshooting

Please Unblock challenges.cloudflare.com to Proceed: Fixes

Why a Cloudflare page says to unblock challenges.cloudflare.com, how to fix it in a browser or network, and what it means for automated clients.

By 5 min readPublished Updated

Also in:简体中文日本語한국어

“Please unblock challenges.cloudflare.com to proceed” means the site you opened is protected by a Cloudflare security check, and your browser could not load that check from challenges.cloudflare.com, the domain Cloudflare serves it from. Something on your side blocked it (an ad or script blocker, a privacy extension, a DNS filter, a firewall or a VPN), or, as on 18 November 2025, Cloudflare itself was having an outage. To fix it, allow challenges.cloudflare.com and reload. For automated clients, the same message means the challenge script was blocked by the automation’s own setup.

Where the message comes from

The sentence appeared on Cloudflare’s interstitial challenge page, the “Just a moment…” screen a site’s Cloudflare rules show before the page itself. That page runs Cloudflare’s challenge platform, which Cloudflare’s docs describe as “the same underlying technology powering Turnstile”, the widget some sites embed in their forms, and both load from challenges.cloudflare.com. When that domain cannot be reached, the check cannot run, and the page asks you to unblock it.

The message is not documented on any developers.cloudflare.com page (searched 30 September 2026). It was widely reported during Cloudflare’s outage of 18 November 2025, when challenge screens on many large sites showed it at once. Cloudflare’s post-mortem says Turnstile failed to load during the outage, which began at 11:20 UTC and was fully resolved at 17:06 UTC.

Today’s challenge page words the same problem differently. Its current script (checked 30 September 2026) shows “Incompatible browser extension or network configuration”, then: “Your browser extensions or network settings have blocked the security verification process”, and asks you to check whether your internet or firewall settings block your device from reaching “challenges.cloudflare.com”. The Cloudflare Turnstile widget reports the same situation as error 200500, “Iframe load error”, whose documented fix is to “Check if challenges.cloudflare.com is blocked”.

Fixes for people browsing

Try these in order, reloading the page after each:

  1. Check your blockers. Cloudflare’s docs say “Ad blockers and content blockers may prevent challenge scripts from loading properly”, and that script blockers, fingerprinting protection and canvas blockers can interfere too. Allow challenges.cloudflare.com in the extension, or turn the extension off for the site.
  2. Turn on JavaScript and cookies. The check needs both; with JavaScript off, the page says “Enable JavaScript and cookies to continue”.
  3. Check DNS filtering. Pi-hole, NextDNS, AdGuard DNS or a router’s filter can block the domain for every device on the network. Allow challenges.cloudflare.com and its subdomains. Cloudflare added two hostnames in July 2026, hagen.challenges.cloudflare.com and brunhild.challenges.cloudflare.com, and asks for both to be allowed.
  4. Try without the VPN or proxy. Cloudflare lists VPNs and proxies among the causes of failed challenges.
  5. Check a company or school firewall. A network that filters domains needs challenges.cloudflare.com on its allowlist. Only its administrator can change that.
  6. Check the clock. A wrong device time breaks the check; Cloudflare shows “Incorrect device time” for it.
  7. Use Cloudflare’s own test page. debug.challenges.cloudflare.com checks whether your browser and network can run the challenge.

If none of this helps and many sites fail at once, the problem may be Cloudflare’s. Check Cloudflare’s status page before changing anything else.

Fixes for site owners

If your visitors report the message on your own site:

  • Content Security Policy. Allow https://challenges.cloudflare.com in script-src and frame-src, or use the nonce-based approach Cloudflare recommends; Turnstile works with strict-dynamic.
  • Load the script from Cloudflare. Cloudflare says api.js “must be fetched from the exact URL” it documents: “Proxying or caching this file will cause Turnstile to fail when future updates are released.”
  • WebViews. In a mobile app’s WebView, the documented causes are disabled JavaScript, missing DOM storage or cookie support, blocked access to challenges.cloudflare.com, and a user agent that changes during the session.

What it means for automated clients

On a site you are allowed to automate, the same failure shows up in scrapers and test suites, for reasons of the automation’s own making:

  • Request blocking. A common optimization in Playwright or Puppeteer aborts every request to a third-party domain, or every script and image, to save bandwidth. That also aborts the challenge script. Let challenges.cloudflare.com and its subdomains through.
  • Filtered egress. A crawler behind a DNS filter, a corporate proxy or a cloud firewall with a domain allowlist cannot reach challenges.cloudflare.com either. Add it to the allowlist.
  • No JavaScript at all. An HTTP client such as curl, requests or Scrapy never runs the challenge, so it never sees this message: it gets the challenge page’s HTML with HTTP 403 and a cf-mitigated: challenge header instead. Unblocking a domain does not change that; the page wants a browser that passes the check, or a cf_clearance cookie from one.

This snippet, for Playwright, blocks images and fonts while letting Cloudflare’s challenge through:

import { chromium } from "playwright";
const browser = await chromium.launch();
const page = await browser.newPage();
await page.route("**/*", (route) => {
const request = route.request();
const host = new URL(request.url()).hostname;
const cloudflare = host === "challenges.cloudflare.com" || host.endsWith(".challenges.cloudflare.com");
if (!cloudflare && ["image", "font", "media"].includes(request.resourceType())) return route.abort();
return route.continue();
});
await page.goto("https://shop.example.com/");
console.log(await page.title());
await browser.close();

Unblocking lets the check run; it does not make an automated browser pass it. Cloudflare documents that “Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not supported for solving production challenges”. When the challenge runs and still does not pass, you are facing the check itself, not a blocked domain:

If the page keeps coming back after it passes, see why Cloudflare’s challenge loops. Automate only sites you are allowed to: see responsible captcha automation.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What does "Please unblock challenges.cloudflare.com to proceed" mean?

The site uses a Cloudflare security check, and your browser could not load that check from challenges.cloudflare.com. Something between you and Cloudflare blocked it: an extension, a DNS filter, a firewall, a VPN, or an outage on Cloudflare's side.

How do I unblock challenges.cloudflare.com?

Allow challenges.cloudflare.com and its subdomains in your ad blocker, privacy extension, DNS filter or firewall, make sure JavaScript and cookies are on, turn off any VPN for a moment, then reload the page.

Why does my scraper or headless browser get this message?

Usually because the automation blocks third-party requests to save bandwidth, or runs behind a network that filters domains. The challenge script must load from challenges.cloudflare.com. An HTTP client that runs no JavaScript cannot pass the check at all.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key