Is Cloudflare Blocking AdSense? How to Check and Fix It
Approvalens · Updated October 4, 2026 · 6 min read
Cloudflare can block the AdSense crawler when a security setting challenges or rejects requests that look automated: Bot Fight Mode, "I'm Under Attack" mode, custom WAF rules, country blocks or rate limits. Google's crawler cannot solve a JavaScript challenge, so it sees a "Just a moment..." page instead of your content, and the review ends with "Site down or unavailable". The fix is to let verified Google crawlers through while keeping protection on for everyone else, then confirm it in Cloudflare's Security Events.
How Cloudflare ends up blocking Google
Cloudflare sits between visitors and your server. Every request passes through its security features before reaching your site. A browser can pass a challenge by running JavaScript; a crawler like Mediapartners-Google cannot. Anything that challenges, rate-limits or blocks bots will therefore hit the AdSense crawler unless it is exempted.
Google's own checklist asks: "Can the AdSense crawler access your site?" (Connect your site). There is no Cloudflare-specific help page from Google, but the result is the same as any other blocked crawler: no ads, and during the application, a rejection that says nothing about your content. The site down or unavailable guide covers the non-Cloudflare causes.
Settings to check
| Setting | Where in the dashboard | Risk for AdSense |
|---|---|---|
| Bot Fight Mode (Free plan) | Security > Bots | Challenges automated traffic. Cloudflare says it cannot be bypassed with WAF custom rules or Page Rules |
| Super Bot Fight Mode (Pro and up) | Security > Bots | Has a separate action for verified bots. Set it to Allow |
| "I'm Under Attack" mode | Overview, or Security > Settings | Shows a JavaScript challenge to every visitor, including crawlers |
| Security level "High" or "I'm Under Attack" | Security > Settings | More visitors get challenged |
| Custom WAF rules | Security > WAF > Custom rules | Rules like "challenge if not from TR" or "block empty referrer" catch Google |
| Country or ASN blocks | Custom rules or IP Access rules | Google crawls mostly from US addresses |
| Rate limiting rules | Security > WAF > Rate limiting | A crawl burst can trip a low threshold |
| Browser Integrity Check | Security > Settings | Can challenge unusual request headers |
| AI crawler and robots.txt controls | Security > Bots / AI Crawl Control | Check that any managed robots.txt only adds AI-crawler groups |
Turkish and other non-US sites hit the country rule problem most often: a rule that challenges "everything outside my country" to reduce spam also challenges Google.
Confirm the problem
Look at Security Events. In Security > Events (Security Analytics on newer dashboards), filter by user agent containing Google or by the AS number of Google (AS15169). For each event you see the action (Block, Managed Challenge, JS Challenge) and which feature or rule caused it. If you see Mediapartners-Google, Googlebot or Google-Display-Ads-Bot there, you have found the cause.
Test from outside. From a terminal:
curl -sI -A "Mediapartners-Google" https://example.com/
curl -s -A "Mediapartners-Google" https://example.com/ | grep -i -E "just a moment|challenge-platform|cf-chl"
A 403 or 503 status, or any of those markers in the body, means Cloudflare is challenging that request. Your test comes from your IP, not Google's, so Cloudflare may treat it differently from the real crawler. A clean result here is good news but not proof; Security Events is the reliable source.
Check the special files. Also fetch /robots.txt and /ads.txt. They should return 200 and plain text. A challenge on those paths affects AdSense as much as one on your home page.
Let verified Google crawlers through
Prefer Cloudflare's verified bot signal
Cloudflare maintains a list of verified bots, including Google's crawlers, identified by their IP addresses and reverse DNS rather than by user agent. Use that signal in rules instead of matching user agent strings.
A typical exemption in a WAF custom rule:
- Expression:
(cf.client.bot)(shown in the rule builder as "Known Bots") - Action: Skip, and select the features to skip (remaining custom rules, rate limiting, managed rules as needed)
- Order: place it first
On plans with Bot Management, the more precise field is cf.bot_management.verified_bot.
Bot Fight Mode
Because Bot Fight Mode does not run in the rule engine, a Skip rule does not affect it. Cloudflare intends it to leave good bots alone, but if Security Events show Google crawlers being challenged by Bot Fight Mode, turn it off while the site is under review, or move to a plan with Super Bot Fight Mode, which supports exceptions and a verified bots setting.
Super Bot Fight Mode
Set "Verified bots" to Allow. Set "Definitely automated" to a challenge or block if you like, but check events afterwards for Google user agents.
Under Attack mode, security level and country rules
Switch off "I'm Under Attack" unless you are actually being attacked; it should be a temporary measure, not a default. Set the security level to Medium or lower. For country rules, add and not cf.client.bot to the expression so verified crawlers are excluded.
Rate limiting
Exclude verified bots from rate limiting rules, or raise thresholds for paths crawlers fetch heavily, such as /sitemap.xml and article URLs.
Do not allowlist by user agent alone
Anyone can send User-Agent: Mediapartners-Google. A rule that allows that string lets scrapers walk past your protection. If you cannot use Cloudflare's verified bot field, verify Google crawlers the way Google documents: by reverse DNS lookup to a googlebot.com or google.com host followed by a forward lookup, or against Google's published IP ranges (Verifying Googlebot and other crawlers). Special-case crawlers such as Mediapartners-Google have their own IP range file, separate from Googlebot's.
robots.txt and ads.txt through Cloudflare
- Caching. If Cloudflare caches
/ads.txtor/robots.txt, purge the cache after every edit, or you and Google will see different versions for hours. - Managed robots.txt. Cloudflare can add AI-crawler rules to your robots.txt. Read the final file at
https://example.com/robots.txtand confirm there is noDisallow: /that applies to Mediapartners-Google or Googlebot. The robots.txt guide explains how the groups are read. - Redirects. If you redirect the apex domain to www (or the reverse) with a Cloudflare rule, make sure
/ads.txton the root domain ends at a 200 response. See the ads.txt guide.
Once events are clean, request a new review in AdSense and leave the settings alone until it finishes. Our checklist lists the other access checks worth running at the same time.
Check for challenges for free
A free scan requests your pages with crawler and browser user agents, compares the responses and flags Cloudflare challenge markers, blocked robots.txt and unreachable ads.txt. Run a free scan.
FAQ
Should I turn Cloudflare off to get approved?
Usually not. Exempt verified bots and fix the specific rule or feature that challenges Google. Turning the proxy off also removes protection and caching, and you will need the same fix later anyway.
Does the free Cloudflare plan work with AdSense?
Yes. Many approved sites use the free plan. Watch Bot Fight Mode and any country rules, since those are the common blockers on that plan.
My site loads instantly for me. Why would Cloudflare block Google?
Your browser already passed a challenge or is never challenged because of your location and reputation. Google's crawler is automated, comes from US data centres and cannot run challenge scripts.
Is allowing "Known Bots" safe?
It allows bots that Cloudflare has verified, such as Google's and Bing's crawlers. It does not allow scrapers that only fake a Google user agent.
Check your own site
Free scan: readiness score and every issue, usually in a few minutes.