# Please Unblock challenges.cloudflare.com to Proceed: Fixes

> Why a Cloudflare page says to unblock challenges.cloudflare.com, how to fix it in a browser or network, and what it means for automated clients.

- Source: https://zerocaptcha.io/blog/please-unblock-challenges-cloudflare-com
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

"Please unblock challenges.cloudflare.com to proceed" means the site you opened is protected by a
Cloudflare security check, and your browser could not load that check from
`challenges.cloudflare.com`, the domain Cloudflare serves it from. Something on your side blocked
it (an ad or script blocker, a privacy extension, a DNS filter, a firewall or a VPN), or, as on 18
November 2025, Cloudflare itself was having an outage. To fix it, allow `challenges.cloudflare.com`
and reload. For automated clients, the same message means the challenge script was blocked by the
automation's own setup.

## Where the message comes from

The sentence appeared on Cloudflare's interstitial challenge page, the "Just a moment..." screen a
site's Cloudflare rules show before the page itself. That page runs Cloudflare's challenge
platform, which Cloudflare's docs describe as "the same underlying technology powering Turnstile",
the widget some sites embed in their forms, and both load from `challenges.cloudflare.com`. When
that domain cannot be reached, the check cannot run, and the page asks you to unblock it.

The message is not documented on any developers.cloudflare.com page (searched 30 September
2026). It was widely reported during Cloudflare's outage of 18 November 2025, when challenge
screens on many large sites showed it at once. Cloudflare's post-mortem says Turnstile failed to
load during the outage, which began at 11:20 UTC and was fully resolved at 17:06 UTC.

Today's challenge page words the same problem differently. Its current script (checked 30
September 2026) shows "Incompatible browser extension or network configuration", then: "Your
browser extensions or network settings have blocked the security verification process", and
asks you to check whether your internet or firewall settings block your device from reaching
"challenges.cloudflare.com". The Cloudflare Turnstile widget reports the same situation as
error `200500`, "Iframe load error", whose documented fix is to "Check if `challenges.cloudflare.com`
is blocked".

## Fixes for people browsing

Try these in order, reloading the page after each:

1. **Check your blockers.** Cloudflare's docs say "Ad blockers and content blockers may prevent
   challenge scripts from loading properly", and that script blockers, fingerprinting protection
   and canvas blockers can interfere too. Allow `challenges.cloudflare.com` in the extension, or
   turn the extension off for the site.
2. **Turn on JavaScript and cookies.** The check needs both; with JavaScript off, the page says
   "Enable JavaScript and cookies to continue".
3. **Check DNS filtering.** Pi-hole, NextDNS, AdGuard DNS or a router's filter can block the domain
   for every device on the network. Allow `challenges.cloudflare.com` and its subdomains. Cloudflare
   added two hostnames in July 2026, `hagen.challenges.cloudflare.com` and
   `brunhild.challenges.cloudflare.com`, and asks for both to be allowed.
4. **Try without the VPN or proxy.** Cloudflare lists VPNs and proxies among the causes of failed
   challenges.
5. **Check a company or school firewall.** A network that filters domains needs
   `challenges.cloudflare.com` on its allowlist. Only its administrator can change that.
6. **Check the clock.** A wrong device time breaks the check; Cloudflare shows "Incorrect device
   time" for it.
7. **Use Cloudflare's own test page.** `debug.challenges.cloudflare.com` checks whether your
   browser and network can run the challenge.

If none of this helps and many sites fail at once, the problem may be Cloudflare's. Check
[Cloudflare's status page](https://www.cloudflarestatus.com/) before changing anything else.

## Fixes for site owners

If your visitors report the message on your own site:

- **Content Security Policy.** Allow `https://challenges.cloudflare.com` in `script-src` and
  `frame-src`, or use the nonce-based approach Cloudflare recommends; Turnstile works with
  `strict-dynamic`.
- **Load the script from Cloudflare.** Cloudflare says `api.js` "must be fetched from the exact URL"
  it documents: "Proxying or caching this file will cause Turnstile to fail when future updates
  are released."
- **WebViews.** In a mobile app's WebView, the documented causes are disabled JavaScript, missing
  DOM storage or cookie support, blocked access to `challenges.cloudflare.com`, and a user agent
  that changes during the session.

## What it means for automated clients

On a site you are allowed to automate, the same failure shows up in scrapers and test suites, for
reasons of the automation's own making:

- **Request blocking.** A common optimization in Playwright or Puppeteer aborts every request to a
  third-party domain, or every script and image, to save bandwidth. That also aborts the challenge
  script. Let `challenges.cloudflare.com` and its subdomains through.
- **Filtered egress.** A crawler behind a DNS filter, a corporate proxy or a cloud firewall with a
  domain allowlist cannot reach `challenges.cloudflare.com` either. Add it to the allowlist.
- **No JavaScript at all.** An HTTP client such as curl, requests or Scrapy never runs the
  challenge, so it never sees this message: it gets the challenge page's HTML with HTTP 403 and a
  `cf-mitigated: challenge` header instead. Unblocking a domain does not change that; the page
  wants a browser that passes the check, or a `cf_clearance` cookie from one.

This snippet, for Playwright, blocks images and fonts while letting Cloudflare's challenge through:

```js
import { chromium } from "playwright";

const browser = await chromium.launch();
const page = await browser.newPage();
await page.route("**/*", (route) => {
  const request = route.request();
  const host = new URL(request.url()).hostname;
  const cloudflare = host === "challenges.cloudflare.com" || host.endsWith(".challenges.cloudflare.com");
  if (!cloudflare && ["image", "font", "media"].includes(request.resourceType())) return route.abort();
  return route.continue();
});
await page.goto("https://shop.example.com/");
console.log(await page.title());
await browser.close();
```

Unblocking lets the check run; it does not make an automated browser pass it. Cloudflare documents
that "Browser automation frameworks, such as Selenium, Puppeteer, Playwright, and Cypress, are not
supported for solving production challenges". When the challenge runs and still does not pass,
you are facing the check itself, not a blocked domain:

- For a **Cloudflare Turnstile widget in a form**, a solving API returns a token for the page's
  sitekey: see the [Cloudflare Turnstile solver](https://zerocaptcha.io/cloudflare-turnstile-solver) and
  [Cloudflare Turnstile in headless browsers](https://zerocaptcha.io/blog/cloudflare-turnstile-headless-browser).
- For a **full-page challenge** ("Just a moment..."), what the page wants is a `cf_clearance`
  cookie. ZeroCaptcha's challenge task passes the page through your own proxy and returns the cookie with the user agent it is bound to.
  See the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver) and
  [the cf_clearance cookie explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained).

If the page keeps coming back after it passes, see
[why Cloudflare's challenge loops](https://zerocaptcha.io/blog/cloudflare-challenge-loop). Automate only sites you are
allowed to: see [responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## Sources

- [Cloudflare challenges: troubleshooting](https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/),
  [challenge solve issues](https://developers.cloudflare.com/cloudflare-challenges/troubleshooting/challenge-solve-issues/)
  and [supported browsers](https://developers.cloudflare.com/cloudflare-challenges/reference/supported-browsers/)
  (checked 1 October 2026).
- [Cloudflare Turnstile: client-side error codes](https://developers.cloudflare.com/turnstile/troubleshooting/client-side-errors/error-codes/),
  for `200500` (checked 1 October 2026).
- [Cloudflare Turnstile changelog](https://developers.cloudflare.com/turnstile/changelog/), entry of
  22 July 2026 (checked 1 October 2026).
- [Cloudflare Turnstile: Content Security Policy](https://developers.cloudflare.com/turnstile/reference/content-security-policy/)
  and [client-side rendering](https://developers.cloudflare.com/turnstile/get-started/client-side-rendering/)
  (checked 1 October 2026).
- [Cloudflare challenges: detect a challenge response](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/detect-response/)
  (checked 1 October 2026).
- [Cloudflare's post-mortem of the 18 November 2025 outage](https://blog.cloudflare.com/18-november-2025-outage/)
  (checked 1 October 2026).
- The current wording of the challenge page was read from Cloudflare's live challenge script on 30
  September 2026. Reports of the older message during the outage come from the press, such as
  [Yahoo Finance UK, 18 November 2025](https://uk.finance.yahoo.com/news/chatgpt-down-asked-unblock-cloudflare-140852390.html).

## Questions

### What does "Please unblock challenges.cloudflare.com to proceed" mean?

The site uses a Cloudflare security check, and your browser could not load that check from challenges.cloudflare.com. Something between you and Cloudflare blocked it: an extension, a DNS filter, a firewall, a VPN, or an outage on Cloudflare's side.

### How do I unblock challenges.cloudflare.com?

Allow challenges.cloudflare.com and its subdomains in your ad blocker, privacy extension, DNS filter or firewall, make sure JavaScript and cookies are on, turn off any VPN for a moment, then reload the page.

### Why does my scraper or headless browser get this message?

Usually because the automation blocks third-party requests to save bandwidth, or runs behind a network that filters domains. The challenge script must load from challenges.cloudflare.com. An HTTP client that runs no JavaScript cannot pass the check at all.
