Cloudflare sits between your visitors and your server. When it cannot reach your server or gets an invalid response, it shows an error page with a code. The code tells you where the problem is. This guide explains each error and how to fix it.
First: is it Cloudflare or your server? #
Most Cloudflare 5xx errors come from the origin server, not from Cloudflare. To check quickly, pause Cloudflare and open your site after a few minutes. If it still fails, the problem is on your server or hosting; if it works, the problem is in your Cloudflare settings.
Error 520: Web server is returning an unknown error #
Meaning: the server sent Cloudflare an empty or invalid response.
Common causes: PHP or the web server crashed while handling the request, a firewall cuts Cloudflare connections, or response headers are too large.
Fix: check the error log in cPanel (Errors), make sure Cloudflare IP addresses are not blocked by your firewall, and temporarily disable security or cache plugins in WordPress to find the cause.
Error 521: Web server is down #
Meaning: the server refused the connection from Cloudflare.
Common causes: the web service is stopped, or a firewall (such as CSF) or a security plugin blocks Cloudflare IP addresses.
Fix: make sure your website runs on the server and whitelist the Cloudflare IP ranges (published at cloudflare.com/ips) in your firewall. If you host with Hyyat Host, contact support and we will check it for you.
Error 522: Connection timed out #
Meaning: Cloudflare could not complete a connection to your server in time.
Common causes: the server is overloaded, the A record in Cloudflare points to a wrong or old IP address (for example after moving your site), or a firewall drops the requests.
Fix: in the Cloudflare dashboard open DNS and make sure the A record points to your hosting’s correct IP address, check resource usage in cPanel, and whitelist the Cloudflare IPs.
Error 523: Origin is unreachable #
Meaning: Cloudflare cannot reach your server at all.
Fix: usually the A record has a wrong IP or the server is offline. Correct the A record or contact your host.
Error 524: A timeout occurred #
Meaning: the connection was made, but the server took more than 100 seconds to respond.
Common causes: a heavy script or database query (imports, backups, large reports).
Fix: optimize or split long tasks, and run heavy jobs with Cron Jobs instead of the browser.
Errors 525 (SSL handshake failed) and 526 (Invalid SSL certificate) #
Meaning: Cloudflare’s SSL mode is Full or Full (strict), but your server has no valid SSL certificate (525: no certificate or the secure handshake failed; 526: the certificate is expired or invalid).
Fix: enable SSL on your server. In cPanel open SSL/TLS Status and click Run AutoSSL to issue a free certificate, or use a Cloudflare Origin Certificate. Do not “fix” it by switching to Flexible, because that leaves the connection between Cloudflare and your server unencrypted. See also how to enable HTTPS and SSL.
Too many redirects (ERR_TOO_MANY_REDIRECTS) #
Meaning: the site is stuck in an endless redirect loop.
Common cause: the Cloudflare SSL mode is Flexible (it connects to your server over HTTP) while your site or WordPress redirects every visitor to HTTPS.
Fix: in Cloudflare open SSL/TLS and choose Full (strict) after making sure your server has an SSL certificate, then purge the Cloudflare and browser cache.
After the fix: purge the cache #
In Cloudflare go to Caching, then Purge Everything, clear your browser cache and open the site again. To connect a site to Cloudflare from the start, see how to activate Cloudflare.
Frequently asked questions #
What is the difference between Cloudflare error 521 and 522? #
Error 521 means your server refused the connection from Cloudflare (the web server is down or a firewall blocks Cloudflare). Error 522 means the connection did not complete in time (the server is overloaded or the A record points to the wrong IP).
How do I know if the problem is Cloudflare or my server? #
Pause Cloudflare on your site and open the website. If it still fails, the problem is on your server or hosting; if it works, the problem is in your Cloudflare settings.
Why do I get “Too many redirects” after enabling Cloudflare? #
Usually because the Cloudflare SSL mode is Flexible while your site redirects visitors to HTTPS, which creates a redirect loop. Set SSL/TLS mode to Full (strict) with a valid SSL certificate on your server.