Cloudflare Error 521, 522 and 525: What They Mean and How to Fix Them
Cloudflare's 52x errors mean Cloudflare couldn't talk properly to your server. 521: your server refused the connection. 522: it timed out. 525: the HTTPS handshake failed. How to tell which part is broken and fix it — usually the web server, firewall, or SSL mode.
When your site is behind Cloudflare's proxy (the orange cloud), visitors connect to Cloudflare, and Cloudflare connects to your server (the "origin"). The 52x errors mean the second step failed. (What is Cloudflare?, Proxied vs DNS only)
Visitor ──✓── Cloudflare ──✗── Your server
Cloudflare itself is fine. The problem is between Cloudflare and your server.
Error 521: Web server is down
Cloudflare reached your server's IP, but the connection was refused — nothing was listening, or something actively rejected Cloudflare.
Causes and fixes:
Your web server or app isn't running. On the server:
sudo systemctl status nginx sudo ss -tlnp | grep -E ':80|:443'Start it, and read its logs if it won't start. (ERR_CONNECTION_REFUSED)
It's not listening on the port Cloudflare uses. With SSL mode "Full" or "Full (strict)", Cloudflare connects on 443; with "Flexible", on 80. Make sure the matching port is open and served.
A firewall or security tool is blocking Cloudflare's IPs. Tools like fail2ban can ban Cloudflare's addresses because all your traffic appears to come from them. Allow Cloudflare's published IP ranges. (fail2ban)
Error 522: Connection timed out
Cloudflare tried to connect and got no response at all.
Causes and fixes:
- Firewall dropping the traffic — the server's firewall (UFW, iptables) or the cloud provider's firewall doesn't allow inbound 80/443. (UFW firewall basics)
- Wrong IP address in DNS — the A record in Cloudflare points at an old or incorrect server. Check it matches your server's public IP.
- Server overloaded or offline — out of memory, CPU pinned, or the machine is off.
- IPv6 mismatch — an AAAA record pointing at an address the server doesn't actually serve on. (IPv4 vs IPv6)
Test the origin directly, bypassing Cloudflare:
curl -v --resolve yourdomain.com:443:YOUR_SERVER_IP https://yourdomain.com
If that also hangs, the problem is your server or its firewall. (What is curl?)
Error 525: SSL handshake failed
Cloudflare connected, but the HTTPS handshake with your server failed. You'll only see this with SSL/TLS mode Full or Full (strict).
Causes and fixes:
- No certificate on your server, or it isn't serving HTTPS on 443 at all. Install one — a Let's Encrypt certificate or a free Cloudflare Origin Certificate. (How automatic SSL works)
- The server doesn't support SNI or the certificate isn't configured for this hostname.
- Protocol or cipher mismatch — very old server software.
Closely related: 526 Invalid SSL certificate — with "Full (strict)", the origin's certificate is expired, self-signed, or for the wrong domain.
Getting the SSL mode right
In Cloudflare → SSL/TLS → Overview:
| Mode | Cloudflare → your server | Use? |
|---|---|---|
| Off | No HTTPS | No |
| Flexible | HTTP (port 80) | Avoid — traffic to your server is unencrypted, and causes redirect loops |
| Full | HTTPS, any certificate | OK |
| Full (strict) | HTTPS, valid certificate | Best |
"Flexible" plus a server that redirects HTTP to HTTPS is the classic cause of ERR_TOO_MANY_REDIRECTS.
Quick diagnosis
| Error | Cloudflare says | Look at |
|---|---|---|
| 521 | Refused | Is the web server running? Firewall rejecting Cloudflare? |
| 522 | Timed out | Firewall dropping, wrong IP, server overloaded |
| 525 | SSL handshake failed | Certificate on the origin, SSL mode |
| 526 | Invalid certificate | Expired / self-signed / wrong-domain cert with Full (strict) |
Temporarily bypass Cloudflare
To check whether the site works without Cloudflare, set the DNS record to DNS only (grey cloud). If it then works, the problem is in the Cloudflare ↔ server settings. Switch back once fixed.
EasySpawn gives your app valid HTTPS on the server automatically, so it works with Cloudflare's Full (strict) mode — and the web server and firewall are set up for you. See how it works or join the waitlist.
Related: What Is Cloudflare? · Cloudflare Proxied vs DNS Only · ERR_TOO_MANY_REDIRECTS · 502 Bad Gateway
Keep reading
ERR_TOO_MANY_REDIRECTS: What Causes It and How to Fix It (Including Cloudflare)
"This page isn't working — redirected you too many times." The usual causes of a redirect loop — Cloudflare's Flexible SSL mode, conflicting www rules, an app that doesn't know it's behind a proxy, and login loops — and how to find and fix each.
"Your Connection Is Not Private" on Your Own Site: Causes and Fixes
When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.