Your site was fine yesterday. Today, visitors see a Cloudflare error page with a number on it: 520, 521, 522, 524 or 525. Sales stall and your phone starts ringing.
These errors look alarming, but they’re far more specific than a generic “site down” message. Each code tells you where the connection broke, and that makes them quick to fix once you know how to read them. This guide explains what each one means, how to find out whether the fault is yours or Cloudflare’s, and what to do next.
First: Where Is the Problem?
When you use Cloudflare, visitors don’t connect directly to your server. They connect to Cloudflare, and Cloudflare connects to your server, known as the origin. Errors in the 520 to 527 range almost always mean the link between Cloudflare and your origin has failed, not that Cloudflare itself is down.
The error page helps you confirm this. It usually shows three stages: your browser, Cloudflare and your host. The stage marked with an error tells you where the problem sits. If the host stage is flagged, the issue is on your origin server, and that’s the case for most of the errors in this guide.
Every error page also shows a Ray ID, a unique reference for that request. Write it down, because it’s what Cloudflare support will ask for.
A Quick Diagnostic Before You Dig In
Two checks save a lot of time.
Test the origin directly. Bypass Cloudflare by reaching your server by its IP address, or temporarily set the DNS record to “DNS only” (grey cloud). If the site fails here too, the problem is your server, not Cloudflare. If it loads fine, the problem is in how Cloudflare and your origin connect.
Check whether your server is actually running. Look at your hosting control panel, server status and recent resource usage. A crashed web server, a full disk or an overloaded CPU explains many of these errors on its own.
Error 520: Web Server Returned an Unknown Error
What it means: Your origin server accepted the connection but sent back something Cloudflare couldn’t understand, such as an empty response, a crash or a malformed reply.
Common causes:
- The web server or application crashed while handling the request
- A PHP or application error producing an empty or broken response
- Oversized response headers, such as too many cookies
- Your server resetting the connection, sometimes because a firewall or security module is interfering
How to fix it:
- Check your server error logs at the time of the failed request. They usually name the cause.
- Look for application crashes, memory exhaustion or PHP fatal errors.
- Test the origin directly (see above) to confirm the fault sits there.
- Review security modules or firewall rules that may be dropping Cloudflare’s requests.
- Check for unusually large cookies or headers if the error appears only for some visitors.
Error 521: Web Server Is Down
What it means: Cloudflare tried to connect to your origin and the connection was refused. In most cases, the server isn’t accepting connections at all.
Common causes:
- The web server (Apache, Nginx or LiteSpeed) is stopped or has crashed
- The server is offline
- A firewall or security tool is blocking Cloudflare’s IP addresses
- The origin isn’t listening on the port Cloudflare expects
How to fix it:
- Confirm your web server is running and restart it if it isn’t.
- Make sure your firewall, hosting security tools and rate limiters allow Cloudflare’s published IP ranges. This is one of the most common causes, and it often appears after a security tool is installed or updated.
- Check that your server listens on the expected ports, typically 80 and 443.
- Verify the DNS record points to the correct origin IP.
Error 522: Connection Timed Out
What it means: Cloudflare couldn’t complete a connection to your origin in time. The connection attempt itself stalled.
This is the one people search for most, and it has several possible causes.
Common causes:
- An overloaded server that can’t accept new connections
- A firewall silently dropping Cloudflare’s traffic, so connections hang
- The wrong origin IP address in your DNS records, for example after a server move
- Network problems between Cloudflare and your host
How to fix it:
- Check your server load. High CPU, memory or connection counts often explain it.
- Allow Cloudflare’s IP ranges through every firewall layer, including hosting-level and server-level ones.
- Confirm the DNS record points to the correct, current origin IP.
- Ask your host to check for network issues or connection limits.
- If it happens during traffic spikes, look at whether the server is sized for the load, and consider caching more content at the edge.
Error 524: A Timeout Occurred
What it means: Cloudflare connected to your origin successfully, but the origin took too long to send a response. By default, Cloudflare waits roughly 100 seconds before giving up on a proxied request.
The difference from 522 is important: in 522 the connection itself fails, while in 524 the connection works and the server is simply too slow.
Common causes:
- Slow, heavy scripts, such as large reports, imports, exports or backups run through the browser
- Unoptimised database queries
- An overloaded server processing requests slowly
- Long-running admin or plugin tasks
How to fix it:
- Find the slow request and optimise it, whether that means database queries, plugins or scripts.
- Move long-running jobs out of the browser request and into background tasks or scheduled jobs.
- Upgrade server resources if the load is consistently too high.
- For tasks that legitimately run long, check whether your Cloudflare plan allows a longer timeout. Extended timeouts are generally an Enterprise option, so confirm the current terms with Cloudflare.
Error 525: SSL Handshake Failed
What it means: Cloudflare and your origin couldn’t complete the secure handshake needed to establish an encrypted connection.
Common causes:
- No SSL certificate installed on the origin when Cloudflare is set to a mode that expects one
- The origin doesn’t support the TLS versions or cipher suites Cloudflare uses
- Port 443 isn’t open or isn’t serving SSL
- A misconfigured certificate or server SSL setup
How to fix it:
- Make sure a valid SSL certificate is installed on your origin server.
- Confirm port 443 is open and your server is serving HTTPS on it.
- Review your SSL/TLS mode in Cloudflare, which is covered below.
- Check that your server supports modern TLS versions.
A related error: 526
If you see 526 (Invalid SSL certificate) instead, the handshake worked but the certificate on your origin isn’t valid, for example because it’s expired, self-signed or issued for a different domain. This appears when Cloudflare is in Full (strict) mode. Install a valid certificate, or use a Cloudflare Origin CA certificate, to fix it.
The Cloudflare SSL Setting That Causes Most Headaches
Cloudflare offers several SSL/TLS encryption modes, and picking the wrong one is behind many 525, 526 and redirect-loop problems.
- Off sends everything unencrypted. It’s not recommended.
- Flexible encrypts traffic between visitors and Cloudflare, but not between Cloudflare and your origin. It’s easy to set up, but it leaves part of the journey unprotected and can cause redirect loops if your origin forces HTTPS.
- Full encrypts the whole path, and accepts any certificate on your origin, including self-signed ones.
- Full (strict) encrypts the whole path and requires a valid certificate on your origin. This is the recommended setting.
The safe approach is to install a valid certificate on your origin and use Full (strict). If you switch modes and errors appear, the cause is usually a missing or invalid origin certificate.
Other Errors You May Run Into
523 (Origin is unreachable): Cloudflare can’t reach your origin, often because of a routing problem or an incorrect IP address in DNS.
502 and 504: These can come from your origin or from Cloudflare, so check the error page to see which stage is flagged.
Too many redirects (ERR_TOO_MANY_REDIRECTS): Usually caused by Flexible SSL combined with an origin that forces HTTPS. Switch to Full (strict) with a valid origin certificate.
When It’s a Hack, Not a Misconfiguration
Occasionally these errors are a symptom of something worse. A compromised site can crash servers, exhaust resources or trigger security tools that start blocking traffic. If errors appeared suddenly alongside strange files, unknown admin users or spam in Google, check our guide on what to do in the first hour of a WordPress hack before you start changing settings.
How to Stop These Errors Coming Back
Most of these errors are preventable.
- Keep your origin server and applications updated and monitored.
- Allow Cloudflare’s IP ranges through every firewall, and keep that list current.
- Install a valid SSL certificate and use Full (strict).
- Size your server for your real traffic, and cache static content at the edge so the origin handles less.
- Move slow scripts into background jobs.
- Set up uptime monitoring so you find out before your customers do.
Don’t Want to Debug This Yourself?
Reading logs and chasing firewall rules is not how most business owners want to spend a Tuesday. That’s what a partner is for.
Tremhost is a Cloudflare partner, and Armor Guard gives you a properly configured firewall, DDoS protection and SSL for $9 per site per month, set up so these connection errors are far less likely to catch you out. For sites that take payments or hold client data, Armor Shield adds firewall rules written for your application, unmetered traffic, free malware cleanup and a named engineer, from $29 per site per month.
If your site is down because of an attack or infection, not a configuration slip, Armor SOS is our emergency cleanup service. Triage is free and usually starts the same day.
Frequently Asked Questions
What does Cloudflare error 522 mean?
It means Cloudflare couldn’t establish a connection to your origin server in time. Common causes include an overloaded server, a firewall blocking Cloudflare’s IPs or an incorrect origin IP in your DNS.
What’s the difference between 521 and 522?
With 521, your origin actively refuses the connection, which usually means the server is down or blocking Cloudflare. With 522, the connection attempt times out, which usually points to overload, dropped traffic or a wrong IP.
What causes Cloudflare error 520?
Your origin returned an empty, malformed or unexpected response. Common causes are an application crash, a PHP error, oversized headers or a firewall resetting the connection.
How do I fix Cloudflare error 524?
The origin connected but took too long to reply. Optimise slow queries and scripts, move long-running tasks to background jobs, add server resources or check whether your plan permits a longer timeout.
How do I fix Cloudflare error 525?
Install a valid SSL certificate on your origin, make sure port 443 is open and serving HTTPS, and review your Cloudflare SSL/TLS mode. Full (strict) with a valid origin certificate is the recommended setup.
Is a Cloudflare error my server’s fault or Cloudflare’s?
For errors in the 520 to 527 range, it’s almost always the origin or the connection to it. Test your server directly, bypassing Cloudflare, to confirm.
Should I pause Cloudflare to fix the problem?
Pausing or switching a record to DNS only is a useful test, because it shows whether the origin works on its own. It removes your Cloudflare protection while it’s off, though, so use it briefly and put it back.
Can Cloudflare errors be caused by a hack?
Yes, occasionally. Malware can exhaust server resources or trigger firewall blocks. If errors coincide with other warning signs, treat it as a possible compromise.



