Skip to content
Troubleshooting

Cloudflare Error 1015 “You Are Being Rate Limited”: Causes and Fixes

Cloudflare error 1015 means you sent more requests than a site's rate limiting rule allows within its counting window, and Cloudflare is blocking you for a set period. The rule is written by the site owner, not by Cloudflare, and it expires on its own. Waiting works; so does sending fewer requests. Rotating IP addresses only helps if the rule counts by IP — and on many sites it counts by something else.

seamless Team9 min readSeptember 28, 2026
  • troubleshooting
  • cloudflare
  • rate limiting
  • 1015
An hourglass-shaped metering structure with cubes piled in front and only a few spaced cubes passing beyond its crimson waist

Cloudflare's 1xxx codes each name the component that acted. 1015 is the rate limiter; its sibling 1020 is a firewall rule that never expires on its own. Mixing them up is the most expensive mistake here — one needs patience and pacing, the other needs a different request.

How a Cloudflare rate limiting rule works

A site owner defines three things: which requests count (for example, anything under /api/ or every POST to /login), how they are grouped (per IP by default), and the threshold — a number of requests within a counting period. Cross it, and Cloudflare applies the action for the mitigation period the owner chose.

SettingWhat it controlsTypical values
Matching expressionWhich requests are countedA path, method, host or content type
Counting characteristicsWhat one ‘visitor’ isIP address; on higher plans also cookie, header, query, ASN, country or JA3/JA4 fingerprint
Threshold and periodHow many requests per windowe.g. 100 requests per 10 seconds
Mitigation timeoutHow long the block lastsFrom seconds up to hours, set by the owner
ActionWhat happens when exceededBlock (1015 page), managed challenge, or custom response

Because each site writes its own rule, there is no universal ‘1015 limit’. A threshold that is generous on one site can be aggressive on another behind the same Cloudflare network.

How long does error 1015 last?

As long as the owner's mitigation timeout — commonly between ten seconds and an hour. If the response carries a Retry-After header, that is the number to wait. If not, back off exponentially from about thirty seconds and stop once a single request succeeds. Hammering the endpoint while blocked does not shorten the timer, and some rules count blocked requests too, so persistent retries keep you over the threshold indefinitely.

Fixing it as a normal visitor

  1. 1Wait a few minutes, then reload once — not repeatedly.
  2. 2Close duplicate tabs of the same site. Auto-refreshing dashboards and open tabs all count toward one limit.
  3. 3Pause extensions that prefetch or poll, such as price trackers and link previewers.
  4. 4Leave shared networks — office, university or mobile carrier NAT — where hundreds of people share your public IP and its budget.
  5. 5If it persists, contact the site with the Ray ID. Only the owner can see which rule fired and whether it is set too tight.

Fixing it as a developer or scraper

For automated traffic, a 1015 is useful information: you now know roughly where the threshold is. The fix is to stay under it, which means pacing first and spreading load second.

python
import random
import time
import requests

def polite_get(session: requests.Session, url: str, max_tries: int = 5):
    delay = 30
    for _ in range(max_tries):
        r = session.get(url, timeout=30)
        if r.status_code != 429:
            return r
        wait = int(r.headers.get("Retry-After", delay))
        time.sleep(wait + random.uniform(0, 5))
        delay = min(delay * 2, 900)
    raise RuntimeError(f"still rate limited after {max_tries} tries: {url}")
Honour Retry-After when present, back off exponentially when not, and give up rather than loop forever.
  • Measure the threshold, then run at 60–70% of it. Slowly increase concurrency until the first 1015, note the rate, and back off well below it.
  • Add jitter. Perfectly regular intervals are easier to spot than the threshold itself.
  • Cache and deduplicate. The cheapest request is the one you do not send twice.
  • Prefer the site's API or sitemap. They are often under a looser rule than the HTML front end.

Does rotating proxies fix 1015?

Only when the rule counts by IP address. Then each exit has its own budget, and spreading requests across a rotating residential pool multiplies the rate you can sustain. When the rule counts by something else, a new IP inherits the same counter:

Rule counts byDoes a new IP help?What does
IP addressYesDistribute load across exits
Session cookieNoA fresh cookie jar per identity
API key or auth headerNoStay within the key's quota
JA3/JA4 TLS fingerprintNoVarying or realistic TLS clients
ASNOnly if the new IP is in another networkResidential or mobile instead of one hosting range

The test is simple: hit the limit, then send one request from a fresh exit with the same cookies and client. If it passes, the counter is per IP. If it fails instantly, the counter is attached to something you carried across.

Spread load across real residential exits

Rotating residential from €1.20/GB with per-request or sticky sessions set in the username. Purchased data never expires.

See residential proxies

If you own the site

  1. 1In Security → Events, filter to the rate limiting rule and check who it is catching.
  2. 2Raise the threshold or narrow the expression if real customers appear — shared corporate and carrier IPs are the usual collateral.
  3. 3Count by session cookie or API key rather than IP where users sit behind NAT.
  4. 4Use a managed challenge instead of a block for borderline traffic, so humans get through.
  5. 5Exclude your own uptime checks, webhooks and monitoring before they trip the rule.

Sources

Frequently asked questions

What does Cloudflare error 1015 mean?

You exceeded the request rate a website's Cloudflare rate limiting rule allows, and Cloudflare is temporarily blocking you. The rule and its limits are set by the site owner, not by Cloudflare.

How long does a Cloudflare 1015 ban last?

It lasts for the mitigation timeout the site owner configured, commonly from ten seconds to an hour. If the response includes a Retry-After header, wait that long. Continuing to send requests while blocked can keep you over the threshold.

Is error 1015 the same as HTTP 429?

Effectively yes. Cloudflare returns 1015 with an HTTP 429 Too Many Requests status by default, so clients should treat it as a rate limit and back off rather than as a permanent failure.

Will a VPN or proxy fix error 1015?

Only if the rule counts requests per IP address. If it counts by cookie, API key, TLS fingerprint or ASN, a new IP carries the same counter and the block continues.

What is the difference between Cloudflare 1015 and 1020?

1015 is a rate limit that expires by itself once you slow down. 1020 is a firewall rule that matched something about your request and will block it indefinitely until either the rule or the request changes.

SE
seamless Team
Proxy infrastructure

The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.

Ready to try seamless proxies?

Residential, ISP and datacenter proxies with no data expiry.

Browse Plans