CloudFront: 403 ERROR — The request could not be satisfied
CloudFront refused or couldn’t serve the request — wrong alternate domain/certificate, blocked by origin access settings, a WAF/geo rule, or a disallowed HTTP method.
Seen on:
AWS
Meaning
The page includes a Request ID and often a reason: “Bad request. We can't connect to the server for this app or website” (origin/cert issue) or 403 (no CNAME/alternate domain for the host, S3 origin denying OAC, WAF block, method not allowed).
Common causes
- Host not in the distribution’s Alternate domain names (CNAMEs)
- S3 origin bucket policy not allowing OAC/OAI
- WAF or geo restriction blocking
- POST/PUT not allowed by the behavior’s allowed methods
- Origin unreachable or TLS mismatch (502 variant)
⚡ Quick fix
- Add the domain to alternate domain names with a matching us-east-1 certificate
- Update the S3 bucket policy for the distribution’s OAC
- Check WAF logs and allowed methods
Detailed fix by platform
IAM
{ "Effect": "Allow", "Principal": { "Service": "cloudfront.amazonaws.com" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-site/*", "Condition": { "StringEquals": { "AWS:SourceArn": "arn:aws:cloudfront::123456789012:distribution/E123ABC" } } }
How to diagnose
- Host — In alternate domain names?
- Origin — Bucket policy/OAC
- WAF — Blocked requests?
- Method — Allowed methods
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026