HTTP 429 / 454 / 455 Blocked
The HTTP 429, 454 and 455 error codes are due to Simply.com's firewall (WAF), which blocks bots and attacks – here we explain why and how to resolve the block.
Simply.com uses an advanced protection system (Web Application Firewall) to prevent and block attacks, abuse, and exploitation of vulnerabilities in our customers' websites.
HTTP 429
When you encounter this error code, the web server performs an automatic security check of your browser before letting you continue. The check is there to protect the website against bots and automated attacks that can overload the server or attempt to exploit vulnerabilities.
All normal browsers can complete this check without problems and will subsequently receive an HTTP 200 response code.
In most cases, the check takes place in the background, and a normal browser with JavaScript and cookies enabled gets through in a few seconds without you noticing it. Once the check has been passed, you can freely navigate the website for a while before it is possibly renewed.
You may see the message "Checking your browser" for various reasons, e.g.:
- The website is currently receiving an unusually high number of requests or is actively under attack.
- The visit comes from an IP address with a poor "reputation" that is known for attacks. You can look up the IP address at www.simply.com/rbl/.
- A known crawler that has made too many requests within a short time.
- The error code can also come from the website's own code and protection (outside our control).
If you get stuck in the check, you can try reloading the page, updating your browser, or visiting the page from another device or network connection.
The error code tells the visitor that they should/can try again later.
HTTP 454
This response code can occur if:
- You are using a very old browser that lacks the features a modern web is built on.
- You are presenting yourself as a very old browser that lacks the features a modern web is built on.
All normal browsers can complete this check without problems and will subsequently receive an HTTP 200 response code.
If you are the owner of the website and experience that legitimate visitors, integrations, or devices are affected, first contact the owner of this integration and ask them to investigate the problem. Check which user-agent is being sent.
HTTP 455
This response code can occur if:
- The individual request is blocked due to a firewall rule.
- An AI agent that does not use a custom user-agent, or uses a user-agent that is also used by botnets.
You can see the precise reason for the block by reviewing the logs for your product. This is done under "Webserver logs" in our Control Panel.
Based on the reason, you can most likely resolve the block.
Services whitelisted
Known third-party services such as Googlebot, OpenAI, Anthropic, Bing, LinkedIn, Jetpack, PayPal, Facebook, ManageWP, etc. are whitelisted in our security filter.
We do not whitelist security services, as our security filter is precisely a security element – and removing it in order to scan for security therefore does not make much sense.
Bots that pose as approved services
If you are investigating blocks, note that many bots pose as these known services in an attempt to get through the security filter. Therefore, always check whether it is in fact an approved service that has been blocked (based on IP address).
Requirements for adding to the whitelist
In general, our WAF behaves properly towards proper requests, i.e. requests that comply with common rules. If you wish to whitelist a known third-party service, we can offer this if a public and maintained URL exists with a list of the IP addresses used.
Article from the support category: PHP