This status in the Page indexing report means Googlebot requested the URL and your server — or something in front of it — answered 403 Forbidden. Google can’t index content it is not allowed to fetch, and if the 403 persists, already-indexed pages drop out.
Is the 403 intentional?
Sometimes yes: account pages, staging areas, paid content. If those URLs should not be indexed, remove them from your sitemap and internal links, or mark them noindex (served with a 200 to Googlebot so it can see the tag). If the pages should rank, keep reading.
Common causes
| Cause | Typical sign |
|---|---|
| CDN AI or bot setting (Cloudflare AI Crawl Control “Block”, Bot Fight Mode) | 403 to all crawlers at once, site works in a browser |
| WAF rule on user-agent or country | 403 only for bots or only from some regions |
| Security plugin (Wordfence, iThemes, All-In-One Security) | Block page mentions the plugin; started after an update |
| Hosting firewall / mod_security | Generic 403 page from the host |
| .htaccess or server rule | 403 on specific folders or file types |
| Login or geo wall | Redirect to a login or “not available in your region” page |
Step-by-step fix
- Run URL Inspection → Test live URL on an affected page to confirm the 403 is current.
- Fetch the URL with the Googlebot checker: it shows who answered (CDN, WAF, plugin) and whether other crawlers are blocked too.
- In your CDN’s security events, find the request and the rule that acted.
- Allow verified crawlers in that rule; do not allow the user-agent string alone — it is trivially spoofed.
- Validate the fix in Search Console (“Validate fix”) and request indexing for key URLs.
Watch out for intermittent 403s
Rate limits and bot scoring can let Googlebot through most of the time and block it during crawl spikes. A single successful live test does not prove the problem is gone — keep an eye on Crawl stats for a week, or let a monitor check daily.