A 403 Forbidden error means the server understood the request but refused to show the page. Unlike a login prompt, entering a password won't help: something is set up to deny access. This guide explains what the 403 Forbidden error means on our hosting and how to fix it, starting with the most likely causes.
What the 403 error looks like
- A plain page headed 403 Forbidden, often with "Access to this resource on the server is denied!"
- "You don't have permission to access this resource" or "Access denied".
- Chrome and Edge: "Access to example.com was denied" with
HTTP ERROR 403. - In WordPress: a 403 when saving a page, uploading, or opening part of the admin area.
Common causes on our hosting
| Cause | Typical sign |
|---|---|
| Wrong file or folder permissions | One file or folder is forbidden after an upload or change of permissions |
| No index file in a folder | Visiting example.com/folder/ gives 403, but a named file inside it works |
A rule in .htaccess | Whole site or folder is forbidden after installing a plugin or editing .htaccess |
| Security hardening or a security plugin | PHP files inside wp-content/uploads or other folders are blocked |
| Our firewall blocked a suspicious request | Only certain actions or pages fail, or only for one person or network |
| Hotlink or leech protection | Images work on your site but not when linked from elsewhere |
How to fix a 403 Forbidden error
Step 1: Check the address and try a private window
Make sure you're asking for a real page, not a folder with nothing in it. Then open the page in a private/incognito window, or on your phone using mobile data. If it works there, the block is tied to your browser or your network (see Step 6).
Step 2: Fix file and folder permissions
- In cPanel, go to Files > File Manager and open
public_html. - Look at the Permissions column. Folders should be
755and files644. (wp-config.phpcan be600or640.) - To fix one, right-click it, choose Change Permissions, set the right numbers and click Change Permissions.
Permissions such as 000, 700 on a folder or 600 on an image or HTML file will cause a 403. Avoid 777: it isn't needed here and can itself cause errors.
Step 3: Make sure the folder has an index file
When someone visits a folder, the server looks for a file such as index.php or index.html. If there isn't one and directory listings are turned off, the result is a 403. Upload your home page as index.html (or index.php) in that folder. Check the spelling and case: Index.HTML is not the same file on Instant Access Internet Services servers.
Step 4: Check the .htaccess file
- In File Manager, click Settings (top right), tick Show Hidden Files (dotfiles) and save.
- Right-click
.htaccessin the folder that shows the error and rename it to.htaccess.off. - Reload the page. If it works, a rule in that file was the cause. Look for lines like
Deny from all,Require all deniedor IP blocks, and remove the one that's wrong. - For WordPress, rename the file back or go to Settings > Permalinks and click Save Changes to create a fresh one.
Step 5: WordPress security settings and plugins
WP Toolkit's security hardening can block PHP files from running in folders such as wp-content/uploads, and security plugins can block admin pages, the REST API or certain countries. If the 403 started after you changed security settings, open Domains > WordPress Management (WP Toolkit), click Security on the site's card, and switch off the measure that affects the blocked page (for example the one that blocks PHP in wp-content/uploads). Temporarily deactivating a security plugin is a quick test.
Step 6: Blocked by our firewall
Our firewall stops requests that look like attacks with a plain "403 Forbidden" page. Legitimate actions can occasionally trigger it, such as saving a page containing code snippets or submitting an unusual form. If the 403 only happens for one action, or only from one network, open a ticket and include your IP address (from whatismyipaddress.com), the page address and the time it happened so we can check the block.
Step 7: Images blocked on other sites
If your images show a 403 when used on another site, a newsletter or a marketplace listing, hotlink protection is doing its job. Add that site's address to the allowed list in Security > Hotlink Protection, or turn it off.
Common questions
What's the difference between 401 and 403?
A 401 asks you to log in, and the right password fixes it. A 403 means access is refused whoever you are, so the fix is on the site or server side.
My whole site shows 403 after a restore or upload
Check that public_html is 750 or 755 and that your files are directly inside it, not inside an extra folder such as public_html/mysite/.
When to open a ticket
Open a ticket if none of the steps help. Include the full page address, the exact error, the date and time, what changed before it started, and your IP address.
Related guides
- File and Folder Permissions Explained (644 and 755)
- How to Show Hidden Files (.htaccess) in cPanel File Manager
- How to Turn Directory Listings On or Off in cPanel (Indexes)
- How to Secure WordPress with WP Toolkit Security Hardening
- How to Stop Hotlinking with cPanel Hotlink Protection
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
