Can't access brave search through ProtonVPN

I use ProtonVPN, and when I try to access brave search I get a 403 error:

403 ERROR

The request could not be satisfied.

Request blocked. We can’t connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner.
If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation.

I have to turn off my VPN in order to access brave search, which goes against my privacy instincts, so I’ve been inclined to just use duckduckgo instead. Is there a workaround?

Try some different sites, which sites are causing the issue?

Same here, I use personal ovpn configs by the way, through my own vps… I think it’s blocking access to any vpn connections

Using secure DNS in brave://settings/security?search=dns?

@fanboynz In my case, turning it on/off is no different. Still the same error persist

This is a pretty surprising problem as Brave also has a builtin VPN. Is it working with theirs? Maybe there was an oversight somewhere?

Everything is working for me on desktop and mobile. On iOS I changed from the custom Brave Search I setup during the closed beta to the builtin one and now everything is working.

I love Brave Search and was constantly telling everyone about it, but after I signed up for ProtonVPN, I often can’t access Brave Search anymore, so I switched search engines again.

(Brave VPN doesn’t work for me, because the interface is controlled through Brave Browser and I need a VPN with clear separation from the browser. If Brave VPN had a separate VPN app I would have used it.)

Please fix the problem.

@b49320

With ProtonVPN Plus, you can choose to use different VPN servers.

Brave Search is using Cloudflare service that challenges Brave Search users. And one of the Cloudflare inspection nits to pick, is apparently/possibly a user’s IP address on the Internet / user’s WAN IP address.

Choose another ProtonVPN server … and test.


At the Cloudflare Bureau of Investigation, the long corridor wall of various “Browser Mugshot” suspects, are known for trying to conceal their identities.

Under the ‘Guess What?’ header of today’s news, on a nearby bulletin board > some Brave Browser user’s Brarve Browser setup appears as a suspect that matches or is “close enough” to some of the “Browser Mugshot” suspects - because Brave Browser also attempts to conceal by various means.


Cloudflare heavily weighs:

  • VPN exits
  • shared IPs
  • datacenter IPs
  • Tor
  • residential proxy networks
  • CGNAT abuse history

Cloudflare looks for:

  • browser fingerprint consistency
  • JavaScript behavior
  • cookie persistence
  • TLS fingerprint
  • IP reputation
  • automation indicators
  • anti-fingerprinting anomalies
  • extension interference
  • blocked scripts/resources

Brave’s fingerprinting defenses can:

  • randomize APIs
  • reduce entropy
  • alter canvas/audio/WebGL outputs
  • suppress client hints
  • partition storage
  • modify timing precision

To privacy tools this is good.

To bot-detection systems, it can look “non-standard.”

(That is sort of a synopsis of ChatGPT speak.)

Brave Search would be usable if it were just an occasional CAPTCHA, but the site often doesn’t load at all.

I change the servers regularly, but this is a constant problem. It takes many clicks now to change the server in Proton, so the problem still makes Brave Search unusable.

You might create a new Brave Browser user profile for the purpose of adjusting Brave Shields (and some other settings), in order to get a PASS by Cloudflare more often than not.

It doesn’t look like I’m getting blocked by Cloudflare. Nothing loads at all.

@b49320

You will not necessarily see an apparent response.

Have you tested using Brave Seach via another browser?

Can you change your (test another) connection to the Internet?

Following is a screenshot of the Brave Browser > Developer Tools > Network [tab] window when visiting ‘https://x.com’ - notice the “cloudflare” over in the right-most column. You could visit ‘https://search.brave.com’ and use DevTools to see what is happening - notice the column titles in the DevTools window:


Also notice how the DevTools window changes when Brave Site-Specific Shields Disabled vs Enabled - example:

Legitimate parent domain has been blacklisted and is breaking our application - #3 by manuel.hyros