🛡️ Allowlist OTTO SEO in Cloudflare WAF and CSP

Camilo Aponte

Camilo Aponte

Last updated on Oct 8, 2026

🔍 Overview

OTTO SEO needs to crawl your site and load its scripts without being blocked by your server's firewall or Content Security Policy (CSP). This article explains the areas to review when troubleshooting access problems in Cloudflare or another security layer.

⚠️ Review Your WAF Configuration

Check your Cloudflare WAF and any other firewall, security plugin, or server-level protection that could block OTTO SEO's crawler. Review the security events and blocked requests associated with your site, then create an exception for the crawler according to the identifier and guidance provided for your account.

If you use a third-party WAF or firewall plugin, review its allowlisting documentation and apply the equivalent exception there as well.

🌐 Review Your Content Security Policy

If your site sends a Content-Security-Policy HTTP header, review the directives that control scripts, connections, and other resources required by OTTO SEO. Confirm that your policy permits the Search Atlas resources used by your site, based on the domains shown in your account or provided by Search Atlas support.

  • script-src — review whether required OTTO SEO scripts are permitted.
  • connect-src — review whether required connections are permitted.
  • img-src — review whether required image resources are permitted.

✅ Test After Updating Your Rules

After updating your WAF or CSP, retry the affected OTTO SEO action and check your browser console, server logs, and security events for blocked requests. If requests are still blocked, record the exact error, affected domain, and timestamp before escalating the issue.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be instantly connected with a member of our team.