What "Access Denied" means and why it appears
Access Denied is an error message that means the server received your request but decided you don't have permission to view that resource. It's different from a connection failure — the server is responding, it's just refusing. The message usually appears as a 403 Forbidden error in your browser's address bar or error page.
This happens for several reasons. Your IP address might be blocked by a firewall rule. Your user account might not have the right permissions for that folder or file. The server's configuration might restrict access to certain file types or directories. Or you might be trying to access a resource that requires authentication — a password or login — that you haven't provided yet.
The fix depends on which of these is actually happening. A 403 error on someone else's server means contacting the site owner. A 403 on your own server means checking your file permissions, firewall rules, or authentication settings.
Key Takeaways
- A 403 Access Denied error means the server received your request but refuses to show you that resource, usually because of permissions, IP blocking, or missing authentication.
- On someone else's website, contact the site owner or administrator — you cannot fix this yourself.
- On your own server, check file and folder permissions first, then firewall rules, then whether the directory requires a password.
- Permissions are usually set through your hosting control panel (cPanel, Plesk) or by editing .htaccess files and folder properties directly.
- If you recently moved files or changed ownership, permissions often reset and need to be reapplied to the new location.
When you're visiting someone else's website
If you see 403 Access Denied on a website you don't own, the site owner has intentionally blocked access to that page or folder. This might be because the page is under construction, the resource has been removed, or access is restricted to certain users.
Your only option is to contact the website owner or administrator. Look for a contact form, email address, or support link on the main site. Describe which page you were trying to reach and when you got the error. They can tell you whether the page should be public, whether it's temporarily down, or whether you need special permission to view it.
Do not try to work around the restriction. If the site owner blocked it, they have a reason — usually security or privacy.
File and folder permissions on your own server
If this is your own website or server, the most common cause is incorrect file permissions. Every file and folder on a server has a set of permissions that control who can read, write, or execute it. If the permissions are too restrictive, the web server process cannot read the file to send it to visitors.
On a Linux or Unix server, permissions are shown as three-digit numbers like 644 or 755. The first digit controls the owner, the second controls the group, and the third controls everyone else. For web-accessible files, 644 is standard (owner can read and write, everyone else can only read). For folders that need to be browsed, 755 is standard (owner can do everything, everyone else can read and execute).
To change permissions, use your hosting control panel's file manager, or connect via SFTP or SSH and use the chmod command. If you're using cPanel, right-click the file, select Permissions, and set it to 644. If you're using Plesk, select the file and change the permissions in the Properties panel. If you're using SSH, type chmod 644 filename for files and chmod 755 foldername for folders.
Firewall and IP blocking rules
Your server might be blocking your own IP address, or blocking an entire range of addresses. This happens when firewall rules are misconfigured, or when you've set up IP-based access restrictions and then forgotten about them.
Check your hosting control panel for firewall settings. In cPanel, this is under Security > ModSecurity or IP Blocker. In Plesk, it's under Security > Firewall. Look for rules that might match your IP address or your ISP's address range. If you find a rule blocking you, remove it or add an exception for your IP.
If you don't know your current IP address, visit a site like whatismyipaddress.com to find it. Then search your firewall rules for that address or the first three octets of it (for example, if your IP is 203.45.67.89, search for 203.45.67).
Authentication and password-protected directories
Some folders on a server can be set to require a username and password before anyone can view them. If you're trying to access one of these folders and haven't logged in, you'll see a 403 error or a login prompt.
If you set up password protection and forgot the credentials, you can reset them through your hosting control panel. In cPanel, go to Security > Password Protected Directories, find the folder, and change the password. In Plesk, go to Security > Password Protected Resources and update the credentials there.
If someone else set up the protection, ask them for the username and password. If you're the site owner but don't remember setting this up, check whether a .htaccess file in that folder contains authentication rules — you can edit or delete it to remove the protection.
Permissions after uploading or moving files
When you upload files to a new server or move them to a new folder, permissions often reset to a default that's too restrictive. The web server process might not be able to read the files, or might not be able to write to them if they need to be modified.
After uploading, select all the files and folders you just added. In your file manager, change the permissions to 644 for files and 755 for folders. If you uploaded a lot of files, you can usually do this recursively — meaning the permission change applies to the folder and everything inside it. In cPanel's file manager, right-click the top-level folder, select Permissions, check the "Recursive" box, and set the permissions.
If you're moving files from one server to another, the ownership might also change. The web server process needs to own the files, or at least be able to read them. Your hosting provider can help you fix ownership if permissions alone don't solve it.
.htaccess rules blocking access
A .htaccess file is a configuration file that sits in a folder and controls how the web server treats files in that folder. It can block access based on IP address, user agent, file type, or other conditions. If you or someone else created a .htaccess rule that's too broad, it might be blocking legitimate traffic.
Connect to your server via SFTP or your file manager and look for a file named .htaccess in the folder where you're getting the error. (It might be hidden — in cPanel's file manager, click Settings and check "Show Hidden Files".) Open it and look for lines that contain Deny, Order, or Require. These are the rules that control access.
If you don't recognize the rules or they look wrong, you can rename the file to .htaccess.bak to disable it temporarily. Then reload the page in your browser. If the error goes away, the .htaccess file was the problem. You can then edit it to fix the specific rule, or delete it if you don't need it.
Frequently Asked Questions
What's the difference between 403 Forbidden and 404 Not Found?
A 404 means the server couldn't find the file at all — it doesn't exist or the path is wrong. A 403 means the file exists, but the server won't let you see it. With a 404, check your URL spelling. With a 403, check permissions and access rules.
I own the server but I'm still getting 403. Where do I start?
Start with file permissions. Set files to 644 and folders to 755, then reload the page. If that doesn't work, check your firewall rules to make sure your IP isn't blocked. Then check for .htaccess files with overly restrictive rules. Most 403 errors on your own server are one of these three.
Can I fix a 403 error on a website I don't own?
No. You cannot change permissions or firewall rules on someone else's server. Contact the site owner and ask them to investigate. Provide the exact URL and the time you tried to access it.
Why did my site start showing 403 after I changed my hosting provider?
When files move to a new server, permissions usually reset to a default that's too restrictive. Log into your new hosting account, find the files you uploaded, and change their permissions to 644 for files and 755 for folders. Do this recursively if possible to cover everything at once.
Is 403 a security problem I should worry about?
Not usually. A 403 error means the server is working correctly — it's refusing access as intended. If you're seeing it on your own site and you didn't set up those restrictions, ask your hosting provider whether they added security rules. If you're seeing it on someone else's site, it's their choice to block access.