Quick answer
Your monitoring bot got blocked by a firewall, but the site is fine. How Layer-7 heuristics stop fake alerts.
The Security Paradox
You pay for Cloudflare or Akamai to block bots. Your monitoring tool uses a bot to check your site. Inevitably, the Web Application Firewall (WAF) blocks your monitor, returning a 403 Forbidden error. Legacy tools see the 403 and immediately wake you up, screaming that the site is down.
Parsing the Headers
The reality is, the origin server is perfectly fine; the security layer is just doing its job. Advanced engines use Layer-7 Heuristics to read the HTTP headers. If a 403 is accompanied by a 'Server: cloudflare' header, the system recognizes a security handshake, not a crash.
Browser Masking
By injecting modern Chrome/Safari User-Agents and understanding WAF block patterns, intelligent monitoring systems bypass the noise. If the origin server was actually down, Cloudflare would return a 521 or 522. Distinguishing between a block and a crash is what separates enterprise tools from basic pingers.
Related PingStag guides
Stop Pinging Your Frontend: Monitoring Databases at Layer 4
Why HTTP monitoring is blind to internal infrastructure failures, and how raw TCP sockets fix the gap.
How to Monitor PostgreSQL Availability on Port 5432
Learn how TCP port monitoring can detect PostgreSQL availability problems even when your website still appears to be working.
How to Monitor MySQL Availability on Port 3306
A practical guide to MySQL TCP monitoring, what port 3306 can tell you, and why database monitoring should complement website uptime checks.
How to Monitor Redis on Port 6379
Learn why Redis availability matters, how TCP port 6379 monitoring works, and where a cache availability check fits in a production monitoring strategy.
