{"id":18714,"date":"2026-09-23T04:06:42","date_gmt":"2026-09-23T04:06:42","guid":{"rendered":"https:\/\/www.hostinger.com\/support\/?p=18714"},"modified":"2026-09-23T04:06:42","modified_gmt":"2026-09-23T04:06:42","slug":"hostinger-cdn-429-too-many-requests-errors","status":"publish","type":"post","link":"https:\/\/www.hostinger.com\/support\/hostinger-cdn-429-too-many-requests-errors\/","title":{"rendered":"Hostinger CDN: 429 Too Many Requests errors"},"content":{"rendered":"<p>A 429 Too Many Requests response on a website behind <a href=\"https:\/\/www.hostinger.com\/support\/7935917-hostinger-cdn-website-optimization\/\">Hostinger CDN<\/a> almost always comes from the hosting server or a plugin, not from the Content Delivery Network (CDN). Hostinger CDN itself returns <a href=\"https:\/\/www.hostinger.com\/support\/how-to-troubleshoot-http-error-429-at-hostinger\/\">429<\/a> only as a last-resort protection during a <a href=\"https:\/\/www.hostinger.com\/support\/5634639-what-is-a-ddos-attack-and-how-to-prevent-it-at-hostinger\/\">DDoS<\/a> (Distributed Denial of Service) attack, when a website or a single address receives request volumes far above anything regular traffic produces. Finding where the response comes from resolves most cases.<\/p><h2 id=\"h-when-hostinger-cdn-returns-a-429-error\">When Hostinger CDN returns a 429 error<\/h2><p>Hostinger CDN limits request rates per website and per visitor IP address as one of its <a href=\"https:\/\/www.hostinger.com\/support\/5634639-what-is-a-ddos-attack-and-how-to-prevent-it-at-hostinger\/\">DDoS protections<\/a>, and it applies the limits only at attack-level volumes. Regular traffic does not reach them: visitors sharing one address through an office network, a mobile carrier, or a VPN (Virtual Private Network), busy administrators working in wp-admin, page builders, uptime monitors, and normal crawling all stay far below the thresholds.<\/p><p>The website is receiving attack-level traffic if Hostinger CDN does return 429, and the CDN is keeping it away from your hosting server. Visitors who share an address range with the attack source can be affected as well during an attack. The browser verification page usually appears before rate limiting does, because automatic attack protection challenges suspicious traffic first (see <a href=\"https:\/\/www.hostinger.com\/support\/hostinger-cdn-the-browser-verification-page\/\">Hostinger CDN: The browser verification page<\/a>). Keep the CDN enabled during an attack, and enable Under Attack mode if the website is the target (see <a href=\"https:\/\/www.hostinger.com\/support\/8512979-hostinger-cdn-the-under-attack-mode\/\">Hostinger CDN: The Under Attack mode<\/a>).<\/p><h2 id=\"h-other-sources-of-429-responses-on-your-website\">Other sources of 429 responses on your website<\/h2><p>Most 429 responses that visitors report come from one of three places behind the CDN.<\/p><p>The hosting server applies its own per-visitor limits through LiteSpeed Web Server, answering with <a href=\"https:\/\/www.hostinger.com\/support\/how-to-troubleshoot-http-error-429-at-hostinger\/\">429<\/a> or <a href=\"https:\/\/www.hostinger.com\/support\/3417446-how-to-fix-the-503-error-at-hostinger\/\">503<\/a> when a single address sends too many requests. Hostinger CDN passes these responses through unchanged, so they also carry the <code>x-hcdn-request-id header<\/code> &mdash; the header shows that the response travelled through the CDN, not that the CDN generated it.<\/p><p>WordPress and application plugins return 429 by design when they detect repeated requests from one address, including security plugins, login limiters, form spam protection, and API (Application Programming Interface) rate limiters.<\/p><p>Another proxy in front of Hostinger CDN causes per-visitor limits on the hosting side to trigger for everyone at once. When Cloudflare or a similar service proxies the website before Hostinger CDN, your hosting server sees the whole audience arriving from a handful of proxy addresses. Keep only one service active, as described in <a href=\"https:\/\/www.hostinger.com\/support\/hostinger-cdn-vs-cloudflare\/\">Hostinger CDN vs Cloudflare<\/a>.<\/p><h2 id=\"h-how-to-find-the-source-of-a-429-error\">How to find the source of a 429 error<\/h2><ol>\n<li>Note the exact URL, the time, and the <code>x-hcdn-request-id<\/code> header of a failing response: open the browser developer tools (F12), select the <strong>Network<\/strong> tab, click the request marked 429, and check <strong>Response Headers<\/strong>.<\/li>\n<li>Check whether another proxy is active for the domain. Disable the Cloudflare proxy or switch to a single CDN if the domain uses Cloudflare nameservers with proxying enabled.<\/li>\n<li><a href=\"https:\/\/www.hostinger.com\/support\/6348502-how-to-manage-themes-and-plugins-via-wordpress-overview-in-hostinger\/\">Review plugins<\/a> that limit requests &mdash; security plugins, login limiters, and API rate limiters &mdash; and their logs for the failing address and time.<\/li>\n<li>Confirm where the response comes from. Go to <strong>Hostinger dashboard &rarr; Websites &rarr; Dashboard &rarr; Performance &rarr; CDN<\/strong>, click <strong>Disable<\/strong>, wait a few minutes, and repeat the failing request. A 429 response that persists with the CDN disabled comes from your hosting server or a plugin. Re-enable Hostinger CDN after the test.<\/li>\n<\/ol><p><strong>NOTES<\/strong><\/p><ul>\n<li>Traffic blocking rules in the CDN dashboard block addresses or countries; they do not raise or lower any request limits.<\/li>\n<li>Search engine and AI crawlers are subject to the same DDoS protection as other visitors and are never limited at normal crawl rates. Follow <a href=\"https:\/\/www.hostinger.com\/support\/hostinger-cdn-search-engine-crawlers-and-seo\/\">Hostinger CDN: Search engine crawlers and SEO<\/a> if a crawler reports 429 errors.<\/li>\n<\/ul><h2 id=\"h-when-to-contact-hostinger-support-about-429-errors\">When to contact Hostinger support about 429 errors<\/h2><p><a href=\"https:\/\/www.hostinger.com\/support\/1583780-how-to-contact-hostinger-support\/\">Contact Hostinger support<\/a> when regular visitors receive 429 responses with the CDN enabled and not with it disabled, or when a website is under attack and legitimate visitors are affected. Include the domain name, the failing URL, the time, the <code>x-hcdn-request-id<\/code> value, and &mdash; for a service that must call your website, such as a payment provider &mdash; the IP addresses the provider publishes. The team can see whether the CDN&rsquo;s protection triggered for the request and adjust the response to the attack.<\/p><p>With the source identified, most 429 errors are resolved in the plugin or hosting settings that produced them, while Hostinger CDN keeps protecting the website from attack-level traffic.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Find out where a 429 Too Many Requests error comes from on a website behind Hostinger CDN.<\/p>\n","protected":false},"author":594,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"include_on_kodee":true,"footnotes":""},"categories":[262],"tags":[],"class_list":["post-18714","post","type-post","status-publish","format-standard","hentry","category-cdn"],"hreflangs":[],"include_on_kodee":true,"_links":{"self":[{"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/posts\/18714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/users\/594"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/comments?post=18714"}],"version-history":[{"count":2,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/posts\/18714\/revisions"}],"predecessor-version":[{"id":18716,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/posts\/18714\/revisions\/18716"}],"wp:attachment":[{"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/media?parent=18714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/categories?post=18714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostinger.com\/support\/wp-json\/wp\/v2\/tags?post=18714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}