HTTP 429 / 454 / 455 Blocked
Simply.com's WAF can block requests with HTTP codes 429, 454 and 455 if bots, an outdated browser or a security rule – check logs and contact support.
Simply.com uses an advanced protection system (Web Application Firewall) to prevent and block attacks, abuse and exploitation of vulnerabilities in our customers' websites.
HTTP 429
When you encounter this error code, the web server performs an automatic security check of your browser before it lets you continue. The check is to protect the website from bots and automated attacks that could overload the server or attempt to exploit vulnerabilities.
All normal browsers can complete this check without issues and will subsequently receive an HTTP 200 response code.
In most cases the check occurs in the background, and a standard browser with JavaScript and cookies enabled gets through in a few seconds without you even noticing. Once the check has passed, you can freely browse the website for a while before it may be refreshed.
You may see the message “Checking your browser” for various reasons, e.g.:
- The website is currently receiving an unusually high number of requests or is outright under attack.
- The visit originates from an IP address with a poor “reputation” known for attacks. You can look up the IP address at www.simply.com/rbl/.
- A known crawler that has made too many requests in a short period.
- The error code may also originate from the website’s own code and protection (outside our control).
If you get stuck in the check, you can try reloading the page, updating your browser or visiting the site from another device or network connection.
The error code tells the visitor that they should/can try again later.
HTTP 454
This response code can occur if:
- You are using a very old browser that lacks the features modern web relies on.
- You are pretending to be a very old browser that lacks the features modern web relies on.
All normal browsers can complete this check without issues and will subsequently receive an HTTP 200 response code.
If you own the website and notice that legitimate visitors, integrations or devices are being affected, first contact the owner of that integration and ask them to investigate the issue.
HTTP 455
This response code can occur if:
- The individual request is blocked due to a firewall rule.
- An AI agent that does not use a custom user-agent, or uses a user-agent also employed by botnets.
You can see the exact reason for the block by reviewing the logs for your product. This is done under “Webserver logs” in our Control Panel.
Based on the reason you can probably resolve the block.
Services whitelisted
Known third‑party services such as Googlebot, OpenAI, Anthropic, Bing, LinkedIn, Jetpack, PayPal, Facebook, ManageWP etc. are whitelisted in our security filter.
We do not whitelist security services, as our security filter itself is a security component – and removing it to scan security therefore makes little sense.
Bots impersonating approved services
If you investigate blocks, note that many bots impersonate these known services in an attempt to get through the security filter. Therefore always verify whether it is actually an approved service that is being blocked (based on IP address).
Requirements for whitelist addition
In general our WAF behaves properly towards legitimate requests, i.e. requests that comply with common rules. If you wish to whitelist a known third‑party service, we can offer this provided there is a public and maintained URL with a list of used IP addresses.
Article from the support category: PHP