403 Forbidden means the server understood the request and found the location, but refuses to serve it. Common causes are file permissions, a folder with no index file, or a security rule blocking you.
If you are visiting the site
- Check the address. Some sites forbid browsing folders directly.
- If you are on a VPN or a shared network, try without it; your address may be blocked.
- Clear the site’s cookies, or log in again if the page needs an account.
If you run the site
1. File permissions and ownership
The web server must be able to read files and enter folders.
ls -la /var/www/example.com/public
Usual settings: folders 755, files 644, owned by the site’s user. Fix a whole site with:
sudo find /var/www/example.com/public -type d -exec chmod 755 {} \;
sudo find /var/www/example.com/public -type f -exec chmod 644 {} \;
Every parent folder must also be enterable: a home folder at 700 blocks the web server from everything inside it.
2. Missing index file
Visiting a folder with no index.html or index.php returns 403 when folder listings are off (as they should be). Check the file exists, and that the index line in your Nginx config, or DirectoryIndex on Apache, includes it.
3. Server rules
Look for deliberate blocks:
- Nginx:
deny all;lines, orlocationblocks covering the path. - Apache:
Require all deniedorDeny fromin the site config or.htaccess. - Security plugins or a web application firewall blocking an address or pattern.
The error log usually names the rule:
sudo tail -n 30 /var/log/nginx/error.log
4. SELinux labels on RHEL-based systems
On AlmaLinux, Rocky and RHEL, files copied in from elsewhere can carry the wrong security label, giving 403 even with correct permissions:
ls -Z /var/www/example.com/public
sudo restorecon -Rv /var/www/example.com
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



