cPanelOps · Hosting guides for site operators
cPanelOpsv2.2.0
Plain-English cPanel help from the team behind FirstResponderHost
26 guides live
CpanelOps / PageOps

Home › Guides

Troubleshooting

ads.txt returns 403 Forbidden on cPanel: causes and fixes

Your ads.txt file is uploaded but ad networks report it as missing. Here is how to find what is blocking it and put it right.

You upload ads.txt to your site, open https://yourdomain.com/ads.txt, and get 403 Forbidden instead of your publisher line. To an ad network that is the same as having no file at all: its crawler cannot read it, so the file is reported as not found. A 403 means the server found something at that address and refused to hand it over. The cause is nearly always one of the five below, and each takes a couple of minutes to check.

First, confirm what the server is really saying

Open the address in a private browser window so nothing is cached. If you have a terminal, this shows only the response headers:

curl -I https://yourdomain.com/ads.txt

The first line tells you where to look. 200 means the file is being served and the problem is in the contents. 404 means the file is not where the crawler looks. 403 means it is there and something is blocking it.

1. The file's permissions are too tight

This is the most common cause. A file uploaded over SFTP or created in a terminal can end up readable only by its owner. The web server then has no right to read it.

  1. In cPanel, open File Manager and go to public_html.
  2. Right-click ads.txt and choose Change Permissions.
  3. Set it to 644: the owner can read and write, everyone else can read.

If it was something like 600 or 640, that was the problem. Reload the address and it should show your text.

2. A rule in .htaccess blocks text files

Some security snippets copied from the web deny access to whole file types. Open .htaccess in public_html (turn on Show Hidden Files in File Manager's settings) and look for a block like this:

<FilesMatch "\.(txt|log|ini)$">
  Require all denied
</FilesMatch>

Either take txt out of the list, or add an exception underneath it:

<Files "ads.txt">
  Require all granted
</Files>

3. A security plugin or firewall is in the way

WordPress security plugins often have a setting that protects "system files" and blocks direct requests for .txt files. Switch that one setting off, or add ads.txt to the plugin's allow list. On the server side, a ModSecurity rule can do the same thing. cPanel's ModSecurity page lets you turn it off for one domain for a minute to test. If the file loads with it off, turn it back on and ask your host to exempt the rule that fired rather than leaving the firewall off.

4. A proxy is challenging the crawler

If the site sits behind Cloudflare or a similar service, a bot-protection or "under attack" mode can show a challenge page to anything that is not a normal browser. Your own browser passes the challenge, so the file looks fine to you while crawlers are turned away. Add a rule that skips the challenge for the path /ads.txt.

5. "ads.txt" is not actually a file

It happens: a folder named ads.txt was created by mistake, or the upload produced ads.txt.txt. In File Manager the icon tells you which it is. Delete the folder and upload a plain text file with exactly the name ads.txt.

Check the contents while you are there

The file must sit at the root of the domain, not in a subfolder, and contain plain text only. A Google AdSense line looks like this, with your own publisher number in place of the zeros:

google.com, pub-0000000000000000, DIRECT, f08c47fec0942fa0

Use one line per seller. Do not paste it from a word processor, which can add invisible formatting and curly quotes.

How long until the warning clears

Ad networks re-read the file on their own schedule. Expect a few days, and longer on a site that sends few ad requests. Nothing you do on the server speeds that up, so once the address returns 200 and shows the right line, the fix is done and the rest is waiting.

Common questions

Does ads.txt go on the www address or the bare domain?

Crawlers ask for it at the root of the domain your ads run on. If your site redirects the bare domain to www, or the other way round, they follow that one redirect and read the file at the end of it. What they will not do is look in a subfolder, so yourdomain.com/files/ads.txt is the same as no file.

I have a subdomain with ads on it. Does it need its own file?

By default the file at the root domain covers the subdomains. A subdomain can be given a separate file of its own, and the root file then needs a subdomain= line pointing at it. Most small sites are simpler with one file at the root.

The file shows fine in my browser but the ad network still says "not found".

Two usual reasons. The network has not re-crawled yet, in which case the only cure is time. Or something treats crawlers differently from you: a bot challenge at a proxy, a country block, or a firewall rule keyed on the visitor's software. Test with the curl -I command above from a different connection; if that gets 200 and plain text, the server side is done.

Can a wrong line in ads.txt hurt?

Yes. A line with the wrong publisher number tells ad buyers that your own account is not an authorized seller, and they can stop bidding on your pages. Copy the line from your ad network's account page; do not retype the number.

Spotted a mistake, or a step that has changed?

cPanel's screens differ a little between versions and hosts. Tell us at info@firstresponderhost.com and we will correct the guide.

More guides