Skip to main content

Cloudflare 520-525 errors: what they mean and how to fix

Cloudflare · 29.09.2026

What Cloudflare's 52x errors mean

Codes 520-526 are not errors from Cloudflare itself; they signal that the edge server could not get a proper response from the site's origin server. The difference between the codes is exactly which step the connection broke at: establishing the connection, the SSL handshake, or while waiting for a response from the application.

Such an error should be diagnosed on the origin server's side, not Cloudflare's: the Cloudflare network is working fine at that moment, and the problem lies in the connection to a specific VDS or in the web server running on it.

Error code table: what each one means

A brief look at the typical cause behind each code in this group:

CodeMeaningTypical cause
520Empty or malformed response from originThe web server crashed or returned corrupted headers
521Origin refused the connectionThe web server is stopped or the port is blocked by a firewall
522Connection not established in timeOrigin is unreachable over the network or overloaded
523Origin not found in routingAn incorrect IP address in the DNS A record
524Response timeout exceededThe application responds slower than 100 seconds
525SSL handshake error with originAn expired or invalid certificate on the server

Error 520: an empty response from the server

Code 520 means the origin accepted the connection but did not return a valid HTTP response. The first step is to check the web server log and see whether the process crashed at the moment of the request:

curl -v -H "Host: example.com" http://203.0.113.10/
tail -n 50 /var/log/nginx/error.log

A common cause is a PHP-FPM or Apache memory limit being exceeded, which makes the worker drop the connection mid-response. Check the limits in php.ini and the PHP-FPM logs for the same time window.

Errors 521 and 522: origin not responding to the connection

521 means an explicit refusal — the server accepted the TCP packet and immediately closed the connection. 522 means the packet never arrived within the allotted time. The check starts with the port:

nc -zv 203.0.113.10 443
systemctl status nginx

If the port is closed, check the firewall rules on the server and make sure connections from Cloudflare's IP ranges are allowed. If the service itself isn't running, restarting it and checking the systemd log for the crash reason resolves the error.

Error 524: response timeout exceeded

524 occurs when the origin accepted the connection and started responding but didn't finish within the edge server's timeout — 100 seconds by default. This is typical for heavy reports, data imports, or slow SQL queries.

  • check slow queries in the MySQL log through the slow query log
  • move a long operation into a background job instead of waiting inside the HTTP request
  • add indexes for the tables involved in the heavy query
  • for long-running operations, return an intermediate response and status via a separate endpoint

Errors 525 and 526: SSL handshake problems with origin

525 means the origin failed to complete the SSL handshake with Cloudflare — usually because of an expired, unexempted self-signed, or invalid certificate. 526 is a more specific case where the certificate fails chain validation under Full Strict mode.

The right fix is not to disable certificate validation, but to put a correct certificate on the origin, for example a Cloudflare Origin Certificate valid for 15 years, and keep Full Strict encryption mode, as described in the article on SSL/TLS modes.

Summary: diagnosing 52x errors in order

All errors in this group point to a break between edge and origin, so the check always starts on the server side, not in the Cloudflare dashboard.

  1. check that the web server is running and listening on the right port
  2. look at the web server and PHP-FPM logs at the time of the error
  3. check the firewall rules and access from Cloudflare's IP ranges
  4. for 524, find and speed up the slow query or operation
  5. for 525 and 526, replace the certificate on the origin and check the SSL mode, or hide the server behind Cloudflare Tunnel
← Back to Knowledge Base Ask Support