Skip to main content
Troubleshooting

Domain Protection Blocking

Your script is blocked by domain protection rules.

Symptom

A deployed script returns a 403 (Forbidden) response when loaded from your site, but works when accessed directly in a browser tab or from localhost. The browser console may show Failed to load resource: the server responded with a status of 403.

Likely Causes

  1. Domain not in allowlist: The domain serving the page is not in the project's domain protection list. Only domains explicitly added to the list (plus localhost) are permitted.
  2. Wildcard mismatch: You added *.example.com but the page loads from example.com (no subdomain). Wildcard patterns match subdomains, not the root domain itself.
  3. Propagation delay: You added the domain less than 60 seconds ago. Domain rules are stored in Cloudflare KV and take approximately 60 seconds to propagate globally.
  4. Referer header missing: The browser does not send a Referer or Origin header (e.g., due to Referrer-Policy: no-referrer on the page). Without a referrer, the Worker cannot determine the requesting domain and may block the request.
  5. Wrong domain format: The domain was entered with a protocol (https://example.com) or a trailing slash instead of just the domain name (example.com).

Checks

  1. Open the Protection panel in the Odyn editor (Protection icon in the left activity bar).
  2. Verify the domain serving your page is in the list. Check for exact matches and wildcard coverage.
  3. Check the page's Referrer-Policy header. Open the Network tab, find the HTML document request, and check the Referrer-Policy response header. If set to no-referrer, the browser suppresses the Referer header on script requests.
  4. Check the time since you last modified the domain list. If it was within the last 60 seconds, wait for propagation.
  5. Open the CDN URL directly in a browser tab (not embedded on a page). If it loads successfully, the block is domain-protection-specific.

Fixes

Add the correct domain

  1. Open the Protection panel.
  2. Add the exact domain: example.com (no protocol, no trailing slash).
  3. If you use subdomains, add both example.com and *.example.com to cover the root and all subdomains.
  4. Wait approximately 60 seconds for propagation.
  5. Reload the page.

Fix wildcard patterns

PatternMatchesDoes not match
example.comexample.comwww.example.com, staging.example.com
*.example.comwww.example.com, staging.example.comexample.com
Both entriesAll of the aboveOther domains

To cover all cases, add both the root domain and the wildcard.

Fix referrer policy

If your page uses Referrer-Policy: no-referrer, the CDN Worker receives no domain information and cannot validate the request. Options:

  1. Change the referrer policy to origin or strict-origin-when-cross-origin (both send the domain without the path).
  2. If you cannot change the referrer policy, consider whether domain protection is necessary for this deployment.

Verify on localhost

localhost is always allowed. If the script loads on localhost but not on your domain, the issue is in the domain list, not in the script itself.

What to Capture for Escalation

  1. The CDN URL being blocked.
  2. The domain serving the page (from the browser's address bar).
  3. The domain protection list from the Protection panel.
  4. The Referrer-Policy header from the page's HTML response.
  5. The HTTP status code and response body from the blocked CDN request.
  6. Whether the CDN URL loads when opened directly in a browser tab.