Guide
Cloudflare error 520, 521, 522, 523, 524, 525 or 526
Cloudflare errors 520 to 526 mean Cloudflare is working, but the website's own server, at its web host, isn't answering properly.
Cloudflare sits between visitors and many websites, to make them faster and safer. Its error page shows three boxes in a row:
- You, Browser: Working
- Cloudflare: Working
- Host: Error
That last box is the website's own server, which Cloudflare calls the origin. It's the one that needs fixing, and the web host is who to call.
If you're visiting a site
Your phone, computer and Wi-Fi are fine; the page says so. Cloudflare's own advice to visitors is: "Please try again in a few minutes." Clearing your cache or switching browser won't help. If it lasts, contact the business another way: they may not know.
What each number means
The heading on each page is Cloudflare's own wording.
- 520: Web server is returning an unknown error
- The host's server answered, but with something empty or garbled. Cloudflare lists a crashed or misconfigured server, a firewall or security plugin blocking Cloudflare, and very large headers (often too many cookies).
- 521: Web server is down
- The host's server refused Cloudflare's connection. Either the website's server isn't running, or its firewall is blocking Cloudflare.
- 522: Connection timed out
- Cloudflare gave up waiting for the host's server. Cloudflare says the most common cause is the host blocking or limiting Cloudflare's addresses; an overloaded or offline server does it too.
- 523: Origin is unreachable
- Cloudflare can't find a way to the server at all. Cloudflare says the most common cause is wrong DNS settings: the server address saved in Cloudflare isn't the one the host uses. If you've moved hosts lately, check this first.
- 524: A timeout occurred
- Cloudflare got through, but the server took too long to finish the page (Cloudflare's usual limit is 125 seconds). Usually a slow task, database or an overloaded server.
- 525: SSL handshake failed
- Cloudflare and the host's server couldn't set up a secure (https) connection between them. Often there's no valid security certificate on the server, or its secure port is closed.
- 526: Invalid SSL certificate
- The security certificate on the host's server is out of date, home-made (self-signed), or doesn't cover the site's name, and Cloudflare is set to insist on a valid one.
Cloudflare shows 500, 502, 503 and 504 errors too; those are in 500, 502, 503 and 504 errors.
If it's your site
Act now: while it lasts, nobody can see your site. Cloudflare's page tells site owners to contact their hosting provider for every one of these errors, so start there, not with Cloudflare.
- Write down the error number, the time, and the Cloudflare Ray ID at the bottom of the page (a reference for that one visit). A screenshot catches all three.
- Check your web host's status page, or their support account, for an outage.
- Send your host the message below. For 520 to 524 they look at whether the server is running, overloaded, or blocking Cloudflare. For 525 and 526 they check the security certificate on the server.
- For 523, also check who looks after your Cloudflare account (often your web person). They compare the server address in Cloudflare's DNS settings with the one the host gives them.
- Once it's fixed, open your site in a private (incognito) window to check.
Send this to your web host
Not sure what to say? Copy this into an email, add your website's address, and send it.
Hi, Our website shows a Cloudflare error: [520 / 521 / 522 / 523 / 524 / 525 / 526] "[the words on the page]". Cloudflare's page says the browser and Cloudflare are working and the host has the error. It started on: [date and time] Cloudflare Ray ID: [from the bottom of the error page] Could you check whether our server is running and not overloaded, whether a firewall or security setting is blocking Cloudflare's IP addresses, and that the server's SSL certificate is valid and covers our domain? If the server's IP address changed, please tell us the new one so we can update it in Cloudflare. Please tell me what you found and what you changed. Thanks
Find out sooner next time
Site health asks for your home page the way a visitor does, through Cloudflare, so a 52x error shows up as "Your home page didn't load", with the number. Site Watch does that once a night and emails you when it changes. One limit: with Cloudflare in front, the certificate we see is Cloudflare's, not the one on your host's server, so we can't warn you before a 526.
Checked against official sources on Oct 8, 2026.
PageKiwi Tips
We email you a link to confirm first. Never sold or shared. What we keep · Past tips