DNS, Security & Integrations
Fix Cloudflare 522/520/521 Proxy Errors
Diagnose and fix Cloudflare 522/520/521 connection errors between Cloudflare and your origin server.
The Problem
These errors mean Cloudflare can't properly reach your actual server — a firewall blocking Cloudflare's IPs, a crashed web server, or a timeout are the usual suspects, and the error page itself gives you almost no detail.
About this problem
Error 520, 521 and 522 are Cloudflare's way of saying it reached out to your origin server and did not get a valid answer. 521 means the connection was refused, 522 means it timed out, and 520 means the origin returned something unexpected or closed the connection. The causes are on the origin side: a firewall dropping Cloudflare's IP ranges, a stopped web server, or a TLS handshake that fails.
People usually look for help when the site was working a moment ago and now shows a Cloudflare error page with no explanation. The page itself gives no detail, so the fix depends on testing the origin directly and comparing what happens with and without Cloudflare in the path.
What's Included
- Checking origin server firewall rules against Cloudflare's published IP ranges
- Verifying the web server is up and responding directly (bypassing Cloudflare)
- Checking for timeout or SSL handshake issues between Cloudflare and origin
- Confirming the site loads normally through Cloudflare afterwards
What's NOT Included
- Fixing an origin server that's down for unrelated reasons (that's diagnosed and flagged separately)
- Cloudflare account-level billing or plan issues
- DDoS mitigation configuration (separate, larger scope)
How It Works
- I identify which error code is occurring and on which hostnames, since each code points to a different failure.
- I test the origin server directly by IP, bypassing Cloudflare, to confirm the web server is running and answering on ports 80 and 443.
- I review the server firewall and any security tool such as fail2ban or a host firewall to confirm Cloudflare's published IP ranges are allowed.
- I check the SSL/TLS mode in Cloudflare against the origin certificate and look for handshake or protocol mismatches.
- I look for timeouts caused by slow responses or overloaded services and review the web server logs for the relevant requests.
- I apply the fix and confirm the site loads normally through Cloudflare.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What does Cloudflare error 522 mean?
- It means Cloudflare connected to your server but the connection timed out. The server may be down, overloaded or blocking Cloudflare's IPs.
- What is the difference between 520 and 521?
- 521 means your server actively refused the connection, usually because the web server is stopped or a firewall blocks it. 520 means the server responded with something Cloudflare could not interpret, or closed the connection abruptly.
- Is my site down because of Cloudflare or my host?
- These errors are about the path between Cloudflare and the origin, so the cause is almost always on the origin side or in how the two are configured. I test both to be sure.
- What if the server is simply down?
- I will identify and flag that, but repairing a server that is down for unrelated reasons is treated separately.
- Do you set up DDoS protection as part of this?
- No. DDoS mitigation configuration is a different and larger piece of work.
- Can you fix billing or plan problems on my Cloudflare account?
- No. Account-level billing and plan issues are not covered.