HTTP 429 / 454 / 455 Blocked

HTTP errors 429, 454 and 455 mean that our WAF has blocked your request because of bots, an old browser or firewall blocks – try a new browser or contact the owner.

Simply.com uses an advanced protection system (Web Application Firewall) to prevent and block attacks, abuse and exploitation of vulnerabilities in our customers' websites.

HTTP 429

When you encounter this error code, the web server performs an automatic security check of your browser before it lets you continue. The check is intended to protect the website from bots and automated attacks that could overload the server or try to exploit vulnerabilities.

All normal browsers can complete this check without problems.
In most cases the check occurs in the background, and a regular browser with JavaScript and cookies enabled gets through in a few seconds without you even noticing. Once the check is passed, you can browse the website freely for a while before it may be renewed.

You may see the message "Checking your browser" for various reasons, e.g.:

  • The website is currently receiving an unusually high number of requests or is under a deliberate attack.
  • The visit originates from an IP‑address with a poor reputation and known for attacks. You can look up the IP address at www.simply.com/rbl/.
  • A known crawler that has made too many requests in a short period.

If you get stuck on the check, you can try reloading the page, refreshing your browser or visiting the site from another device or network connection.

The error code tells the visitor that they should/can try again later.

HTTP 454

  • You are using a very old browser that lacks the features modern web relies on.
  • You are masquerading as a very old browser that lacks the features modern web relies on.

If you own the website and notice that legitimate visitors, integrations or devices are being affected, first contact the owner of that integration and ask them to investigate the problem.

HTTP 455

  • The individual request is blocked due to a firewall rule.
  • An AI agent that does not use a custom user‑agent, or uses a user‑agent also employed by botnets.

You can see the exact reason for the block by reviewing the logs for your product. This is done under "Web server logs" → "Web server Application Firewall" in our Control Panel. Based on the reason you can probably resolve the block.

Services whitelisted

Known third‑party services such as Googlebot, Bing, LinkedIn, Jetpack, PayPal, Facebook, ManageWP etc. are whitelisted in our security filter.

We do not whitelist security services, as our security filter itself is a security component – and removing it to scan security therefore makes little sense.

Requirements for whitelist addition

In general our WAF behaves properly towards normal requests, i.e. requests that comply with common rules. If you want to whitelist a known third‑party service, we can offer this provided there is a public and maintained URL with a list of used IP addresses.

Article from the support category: PHP

Other relevant articles