What Cloudflare's 52x errors mean
Codes 520-526 are not errors from Cloudflare itself; they signal that the edge server could not get a proper response from the site's origin server. The difference between the codes is exactly which step the connection broke at: establishing the connection, the SSL handshake, or while waiting for a response from the application.
Such an error should be diagnosed on the origin server's side, not Cloudflare's: the Cloudflare network is working fine at that moment, and the problem lies in the connection to a specific VDS or in the web server running on it.
Error code table: what each one means
A brief look at the typical cause behind each code in this group:
| Code | Meaning | Typical cause |
|---|---|---|
| 520 | Empty or malformed response from origin | The web server crashed or returned corrupted headers |
| 521 | Origin refused the connection | The web server is stopped or the port is blocked by a firewall |
| 522 | Connection not established in time | Origin is unreachable over the network or overloaded |
| 523 | Origin not found in routing | An incorrect IP address in the DNS A record |
| 524 | Response timeout exceeded | The application responds slower than 100 seconds |
| 525 | SSL handshake error with origin | An expired or invalid certificate on the server |
Error 520: an empty response from the server
Code 520 means the origin accepted the connection but did not return a valid HTTP response. The first step is to check the web server log and see whether the process crashed at the moment of the request:
curl -v -H "Host: example.com" http://203.0.113.10/
tail -n 50 /var/log/nginx/error.log
A common cause is a PHP-FPM or Apache memory limit being exceeded, which makes the worker drop the connection mid-response. Check the limits in php.ini and the PHP-FPM logs for the same time window.
Errors 521 and 522: origin not responding to the connection
521 means an explicit refusal — the server accepted the TCP packet and immediately closed the connection. 522 means the packet never arrived within the allotted time. The check starts with the port:
nc -zv 203.0.113.10 443
systemctl status nginx
If the port is closed, check the firewall rules on the server and make sure connections from Cloudflare's IP ranges are allowed. If the service itself isn't running, restarting it and checking the systemd log for the crash reason resolves the error.
Error 524: response timeout exceeded
524 occurs when the origin accepted the connection and started responding but didn't finish within the edge server's timeout — 100 seconds by default. This is typical for heavy reports, data imports, or slow SQL queries.
- check slow queries in the MySQL log through the slow query log
- move a long operation into a background job instead of waiting inside the HTTP request
- add indexes for the tables involved in the heavy query
- for long-running operations, return an intermediate response and status via a separate endpoint
Errors 525 and 526: SSL handshake problems with origin
525 means the origin failed to complete the SSL handshake with Cloudflare — usually because of an expired, unexempted self-signed, or invalid certificate. 526 is a more specific case where the certificate fails chain validation under Full Strict mode.
The right fix is not to disable certificate validation, but to put a correct certificate on the origin, for example a Cloudflare Origin Certificate valid for 15 years, and keep Full Strict encryption mode, as described in the article on SSL/TLS modes.
Summary: diagnosing 52x errors in order
All errors in this group point to a break between edge and origin, so the check always starts on the server side, not in the Cloudflare dashboard.
- check that the web server is running and listening on the right port
- look at the web server and PHP-FPM logs at the time of the error
- check the firewall rules and access from Cloudflare's IP ranges
- for 524, find and speed up the slow query or operation
- for 525 and 526, replace the certificate on the origin and check the SSL mode, or hide the server behind Cloudflare Tunnel