{"id":13535,"date":"2026-09-07T09:38:40","date_gmt":"2026-09-07T07:38:40","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=13535"},"modified":"2026-09-07T09:38:45","modified_gmt":"2026-09-07T07:38:45","slug":"429-de-erori-legate-de-limitarea-ratei-de-solicitari-care-provoaca-probleme-de-acces-la-site-ul-web","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/","title":{"rendered":"429 Prea multe solicit\u0103ri: gre\u0219eli legate de limitarea ratei care provoac\u0103 probleme de acces la site-ul web"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A <strong>429 Too Many Requests<\/strong> response means that a client has sent more requests than a rate limit allows during a period of time. The client may be a real visitor, a search crawler, an API integration, or an unwanted bot. Access problems occur when the limit is too low, applied at the wrong layer, or enforced without a safe retry response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rate limiting is used to control request bursts and reduce unwanted traffic. It can be configured in the website server, a bot-protection system, a reverse proxy, or a shared hosting environment. A useful first step is to identify which layer returned the 429 response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#How_rate-limiting_mistakes_cause_a_429_response\" >How rate-limiting mistakes cause a 429 response<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#Burst_limits_are_too_strict\" >Burst limits are too strict<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#Bot_protection_treats_useful_traffic_as_unwanted\" >Bot protection treats useful traffic as unwanted<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#Shared_hosting_applies_a_limit_outside_the_website_configuration\" >Shared hosting applies a limit outside the website configuration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#A_reverse_proxy_applies_a_different_rule_than_the_origin_server\" >A reverse proxy applies a different rule than the origin server<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#How_to_confirm_the_source_in_logs\" >How to confirm the source in logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#Safe_recovery_after_legitimate_traffic_is_throttled\" >Safe recovery after legitimate traffic is throttled<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#How_to_avoid_blocking_real_users_and_search_crawlers\" >How to avoid blocking real users and search crawlers<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#429_versus_403\" >429 versus 403<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/429-too-many-requests-rate-limiting-mistakes-that-cause-website-access-problems\/#When_to_contact_support\" >When to contact support<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_rate-limiting_mistakes_cause_a_429_response\"><\/span>How rate-limiting mistakes cause a 429 response<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Burst_limits_are_too_strict\"><\/span>Burst limits are too strict<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-829571335\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A burst limit controls how many requests a client may send in a short period. A visitor loading several page resources at once, a crawler fetching many pages, or an API client sending requests in parallel can exceed the limit even when the traffic is legitimate. A limit designed only for slow, one-at-a-time browsing can block normal bursts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review whether the limit is based on a short burst, a longer request window, or both. Adjust the rule only after checking which traffic is being affected. Raising a limit for every request can increase server load, so a safer change is to target the affected endpoint, client group, or trusted service where the configuration allows it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Bot_protection_treats_useful_traffic_as_unwanted\"><\/span>Bot protection treats useful traffic as unwanted<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Bot protection can restrict automated requests. Some automated traffic is useful, including search engine crawlers, while other bots can create spam, malicious activity, or excessive load. The distinction matters because a broad rule may throttle both unwanted bots and legitimate crawlers. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/5-metode-de-a-bloca-robotii-nedoriti-pe-site-ul-dvs\/\">Unwanted bots can overload a server, distort analytics data, and attempt spam or malicious activity.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check whether the rule matches all automated clients, a user-agent pattern, an IP address, or a request path. Keep protection on sensitive or expensive endpoints, but avoid applying the same strict rule to public pages and critical services without reviewing their traffic patterns.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Shared_hosting_applies_a_limit_outside_the_website_configuration\"><\/span>Shared hosting applies a limit outside the website configuration<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On shared hosting, rate limiting or resource protection may affect more than one website process. A site owner may change an application rule and still receive 429 responses because the request is being limited by the hosting environment or another service in front of the site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Compare the time and source of the 429 response with the logs available to the website. If the application does not record the request, or if the response has the format of an upstream service, the limit may be outside the application. This distinction prevents repeated changes to the wrong configuration.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_reverse_proxy_applies_a_different_rule_than_the_origin_server\"><\/span>A reverse proxy applies a different rule than the origin server<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A reverse proxy receives requests before forwarding them to the website server. It may apply its own request limit, bot rule, or burst policy. In that case, the origin server may not see every request that visitors report as blocked. A proxy can also identify clients differently from the origin, which can make several users appear to share one rate-limit key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check each layer in request order: the visitor or API client, the reverse proxy, the hosting environment, and the origin application. The first layer that records the rejected request is the likely source of the 429 response.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_confirm_the_source_in_logs\"><\/span>How to confirm the source in logs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use the same URL, client, and approximate time as the reported failure. Then compare records across the layers that handle the request.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Record the affected request.<\/strong> Note the URL, request method, client or crawler, time of the response, and whether the problem affects one endpoint or the whole site.<\/li>\n\n\n\n<li><strong>Check the application log.<\/strong> If the request reaches the application, look for the response and the rule or limit that rejected it.<\/li>\n\n\n\n<li><strong>Check the reverse-proxy or protection log.<\/strong> A 429 recorded there but not in the application indicates that the request was stopped before it reached the origin.<\/li>\n\n\n\n<li><strong>Compare several clients.<\/strong> If many visitors are blocked together, the limit may use a shared address, proxy identity, or broad rule. If only one client is affected, the limit may be tied to that client or its request pattern.<\/li>\n\n\n\n<li><strong>Check the response guidance.<\/strong> A <code>Retry-After<\/code> header tells a client when to try again. If it is absent, clients cannot use a server-provided retry time and may retry too soon.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Safe_recovery_after_legitimate_traffic_is_throttled\"><\/span>Safe recovery after legitimate traffic is throttled<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Pause repeated retries.<\/strong> A client that immediately repeats a rejected request can extend the burst and continue the rate limit.<\/li>\n\n\n\n<li><strong>Use the Retry-After value when it is present.<\/strong> Wait for the stated period before trying again.<\/li>\n\n\n\n<li><strong>Use controlled retries when it is absent.<\/strong> Add increasing delays between attempts instead of sending requests continuously. Keep the retry process bounded so one failure does not create a request loop.<\/li>\n\n\n\n<li><strong>Identify the affected traffic.<\/strong> Separate real users, known API clients, search crawlers, and unwanted bots before changing a rule.<\/li>\n\n\n\n<li><strong>Adjust the narrowest rule.<\/strong> Increase the burst or request allowance only for the endpoint, client group, or layer confirmed by the logs.<\/li>\n\n\n\n<li><strong>Protect critical endpoints separately.<\/strong> Login, payment, account, and API endpoints may need stricter limits than public content. Apply changes with care so that protection is not removed from sensitive paths.<\/li>\n\n\n\n<li><strong>Test after the change.<\/strong> Confirm that normal visitors and approved automated clients can access the required pages, while the intended protection remains active.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_avoid_blocking_real_users_and_search_crawlers\"><\/span>How to avoid blocking real users and search crawlers<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not treat every automated request as unwanted. Search crawlers can be useful, while unwanted bots can create spam, malicious activity, excessive server load, and inaccurate analytics. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/5-metode-de-a-bloca-robotii-nedoriti-pe-site-ul-dvs\/\">Bot controls should distinguish useful crawlers from traffic that should be restricted.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review rules by endpoint and traffic type. Public pages may need to tolerate normal visitor bursts. Expensive or sensitive endpoints can use tighter limits. API clients should use deliberate retry delays, and the service should provide <code>Retry-After<\/code> when a temporary limit is reached.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"429_versus_403\"><\/span>429 versus 403<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Response<\/th><th>Meaning<\/th><th>Typical focus<\/th><\/tr><\/thead><tbody><tr><td>429 Too Many Requests<\/td><td>The request rate has exceeded a configured limit.<\/td><td>Check bursts, retry handling, client grouping, and the layer applying the limit.<\/td><\/tr><tr><td>403 Forbidden<\/td><td>The server understood the request but refuses access to the resource.<\/td><td>Check access rules and permissions rather than retrying repeatedly.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A 403 is an access denial, while a 429 is a request-rate response. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/motive-pentru-mesajul-403\/\">A 403 error means that access to the requested resource has been denied.<\/a> Treating a 429 as a permanent access block can lead to the wrong configuration change.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_to_contact_support\"><\/span>When to contact support<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Contact support when logs show that the 429 is generated by a hosting or upstream layer that you cannot change, when shared hosting appears to group unrelated visitors, or when the response source remains unclear after comparing the available logs. Include the affected URL, response time, client type, and the relevant log entries so the rate-limiting layer can be identified efficiently.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[43],"manual_kb_tag":[],"class_list":["post-13535","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-website-errors"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13535\/revisions"}],"predecessor-version":[{"id":13536,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13535\/revisions\/13536"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=13535"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=13535"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=13535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}