---
title: "Cloudflare Error 520, 521, 522 and 524: What They Mean"
description: "Cloudflare error 520, 521, 522 or 524 means Cloudflare reached you but not the site's own server. What each code means, what to try and how owners fix it."
url: https://proxynet.io/blog/cloudflare-5xx-errors
date: 2026-10-06
author: "Acar Diveroli"
category: "Tutorial"
lang: en
---

# Cloudflare Error 520, 521, 522 and 524: What They Mean

You click a link and, instead of the site, a page says "Connection timed out" with "Error code 522" under it. Below the heading sit three icons: your browser, marked "Working", Cloudflare, also "Working", and the site's server, the "Host", marked "Error". On another site the heading reads "Web server is down" or "A timeout occurred", with 521 or 524 as the code.

These pages come from Cloudflare, a service that sits in front of a large share of the web's sites. Below: how to read the page, what each code from 520 to 526 means, the "Internal server error" page of a Cloudflare outage, how these codes differ from the 1000-series errors that can be about you, and what site owners and people running monitors should do.

> **Note: Short answer**
>
> A Cloudflare 52x page means Cloudflare received your request but could not get a proper answer from the site's own server, which Cloudflare calls the origin. Your connection, browser and IP address are not the cause. Wait a few minutes and reload; if many sites fail at the same moment, check Cloudflare's status page, cloudflarestatus.com. If the site is yours, the code names the failing step: 521 refused, 522 no answer, 524 too slow, 525 and 526 the certificate.

## What does a Cloudflare 5xx error mean?

Cloudflare works as a reverse proxy: a server that stands in front of a website and receives every visitor's request on its behalf. The address you type leads to a Cloudflare data center near you. Cloudflare then opens a second connection to the site's server, the origin, fetches the page and passes it back to you.

That makes two legs: you to Cloudflare, and Cloudflare to the origin. A Cloudflare-branded error page proves that the first leg worked, because Cloudflare had to receive your request to answer it. The second leg failed.

Codes starting with 5 are server errors: under [RFC 9110](https://www.rfc-editor.org/rfc/rfc9110.html#name-server-error-5xx), the HTTP standard, the server knows it has erred or cannot do what was asked. The standard defines 500 to 505. The numbers 520 to 526 are Cloudflare's own, created so that a site owner can see exactly where the trouble is.

## How do you read the Cloudflare error page?

- **The heading and the code.** The name of the error ("Connection timed out", "Web server is down") and a line such as "Error code 522".
- **Three icons.** Browser, Cloudflare and Host, each marked "Working" or "Error". On a 52x page the Host is marked "Error": the site's server is the problem.
- **"What happened?" and "What can I do?"** One sentence about the failure, and advice for visitors, usually to try again in a few minutes.
- **The Ray ID and the time.** A Ray ID is the identifier Cloudflare gives every request; the time is in UTC. With both, the site owner can find your request in the logs.

There is also a plainer page: a white screen with "502 Bad Gateway" and the word "cloudflare" under it. According to Cloudflare, Cloudflare's own servers made that one. A 502 or 504 with the three icons means the origin sent it and Cloudflare displayed it. A page that does not mention Cloudflare at all came straight from the site's server.

## How does a 52x error happen, step by step?

1. **The site's address points to Cloudflare.** DNS, the internet's address book, returns a Cloudflare address, and your browser connects to a nearby Cloudflare data center.
2. **Cloudflare accepts your request.** That is why you see a Cloudflare page, not your browser's own error screen.
3. **Cloudflare connects to the origin,** encrypted or not, depending on how the owner set it up.
4. **That connection fails.** The server refuses it, stays silent, cannot be reached, offers a bad certificate, or answers too late or with something unreadable.
5. **Cloudflare picks the matching code** and draws the error page itself.

## What does each Cloudflare error code mean?

The names in the second column are the headings of Cloudflare's [5xx error documentation](https://developers.cloudflare.com/support/troubleshooting/http-status-codes/cloudflare-5xx-errors/), which has one page per code.

| Code | Name on the page | What failed | Usual cause |
|---|---|---|---|
| 520 | Web server returns an unknown error | The origin's answer was empty or unreadable | Crash, headers over 128 KB, firewall |
| 521 | Web server is down | The origin refused the connection | Server stopped, Cloudflare blocked |
| 522 | Connection timed out | The origin never answered the connection | Firewall drops Cloudflare, overload, wrong IP |
| 523 | Origin is unreachable | No network route to the origin | Wrong IP in DNS, routing fault |
| 524 | A timeout occurred | Connected, but no reply within 125 seconds | Slow page, long export |
| 525 | SSL handshake failed | The encrypted connection failed | No certificate, port 443 closed |
| 526 | Invalid SSL certificate | The origin's certificate was not trusted | Expired, self-signed or wrong name |
| 1016 | Origin DNS error | The origin's address could not be looked up | Missing or broken DNS record |
| 500 | Internal server error | Cloudflare's own network, many sites at once | A Cloudflare incident |

Two timings separate 522 from 524. For a 522, Cloudflare waits 19 seconds for the origin to accept the connection, or 90 seconds for it to acknowledge the request. For a 524, the connection worked, but the page did not arrive within 125 seconds. So 522 means "nobody picked up", 524 "they picked up and never came back".

Error 1016 belongs to the 1000-series but is a site-owner problem; it arrives with the HTTP status 530, which Cloudflare uses when it cannot resolve the origin's name. A branded 502 or 504 follows the general gateway rules explained in [502 Bad Gateway: What It Means](/blog/502-bad-gateway).

## Is a Cloudflare 52x error caused by your IP?

No. Your request reached Cloudflare, and the connection from Cloudflare to the origin has nothing to do with your address, browser or internet provider. Cloudflare's documentation tells visitors to report the problem to the site owner, because only the owner can fix it. That is also why clearing cookies, restarting the router or changing DNS servers does nothing here: they act on the leg that already worked.

One nuance: visitors in different countries reach different Cloudflare data centers. If the site's firewall blocks only some of Cloudflare's addresses, or one route to the origin is broken, a 522 can appear in one region only. A page that loads with a VPN on is useful information for the owner, not a repair.

## What can you do as a visitor?

1. **Wait a few minutes, then reload once.** Many 52x errors last only as long as a restart or a short overload. Reloading every few seconds adds requests to a server that is already struggling.
2. **Check whether other sites fail too.** If unrelated sites show Cloudflare errors at the same moment, the problem is probably Cloudflare's. [Cloudflare System Status](https://www.cloudflarestatus.com/) lists active incidents and planned maintenance by city, and "Subscribe to updates" lets you follow an incident.
3. **Try another page of the site.** A 524 often hits only heavy pages, such as a search or an export.
4. **Report it to the site.** Send the time on the page, the address, the error code and the Ray ID. Writing to Cloudflare does not help: its support assists only the domain's owner.

## "Internal server error, Error code 500": when Cloudflare itself is down

Sometimes the failure is in Cloudflare's own network. Then a Cloudflare page reading "Internal server error", "Error code 500" and "Visit cloudflare.com for more information." appears on many unrelated sites at once.

This happened on 18 November 2025. According to [Cloudflare's report on the outage](https://blog.cloudflare.com/18-november-2025-outage/), failures began at 11:20 UTC and everything worked normally again at 17:06 UTC. A database permission change had doubled the size of a configuration file used by Cloudflare's bot management system, and sites returned 5xx errors although their own servers were fine.

One site with a 52x is that site's problem; many sites with the same 500 page is Cloudflare's. Cloudflare's own test for owners: a 500 page containing the word "cloudflare" goes to Cloudflare support, any other 500 to the host.

## 52x vs 10xx: when the error is about you

Cloudflare's errors numbered in the 1000s look similar but mostly report decisions about your request, made by rules the site owner set:

- **Error 1015, "You are being rate limited":** your connection sent too many requests in a short time.
- **Error 1020, "Access denied":** a firewall rule matched your request.
- **Error 1006, "Access Denied: Your IP address has been banned":** the owner blocked your address.

Here your behaviour or address really is the trigger, and the fix is to slow down or contact the owner; [What Is Error 1015?](/blog/cloudflare-error-1015) explains how a rate limit counts requests. A 52x is the opposite: the request was fine, the site could not deliver.

## If it is your site: how to fix 520 to 526

Note the code, the time with its time zone, the URL and any Ray ID a visitor sent. The cause is not always in the origin's log: load balancers, caches and firewalls between Cloudflare and the origin keep logs too. A quick test: set the DNS record to "DNS only" or pause Cloudflare for a few minutes. If the site then loads, the origin works and the Cloudflare-to-origin leg is at fault.

- **521 and 522: let Cloudflare in.** Cloudflare calls blocked or rate-limited Cloudflare addresses the most common cause of 522. Check the firewall, iptables, `.htaccess` and security plugins, and allow all ranges Cloudflare publishes at cloudflare.com/ips. For 521, also check that the web server runs and listens on port 80 (Flexible mode) or 443 (Full and Full (strict)).
- **522 after a move: compare the IP.** The A record in Cloudflare's DNS may still point to the old server.
- **523: check the route.** Confirm the A or AAAA record, then ask the host for a traceroute from the origin to a Cloudflare address.
- **524: shorten long requests.** Move exports and reports that run past 125 seconds to a background job whose progress the page checks, or to a "DNS only" subdomain. Enterprise plans can raise the limit to 6,000 seconds.
- **520: read the crash log.** Empty replies usually mean the application died mid-request; oversized headers, mostly from too many cookies, are the other common cause.
- **525 and 526: fix the certificate.** The origin needs a valid certificate on port 443, unexpired, with its full chain and issued for the hostname; Cloudflare's own Origin CA certificate is one option. Switching from Full (strict) to Full silences 526 only by turning the check off.
- **1016: fix the DNS record.** Add the missing A record or point the CNAME to a name that resolves.

If customers in one country report errors you cannot reproduce, check from there. With [Residential Proxy](https://proxynet.io/residential-proxy) you can pick a country and city and load the site as a home visitor there would; the `colo` line of `/cdn-cgi/trace` on your domain shows which Cloudflare data center answered.

## If you run a monitor or a scraper

A 52x is the site's outage, not a block, and your code should treat it that way.

1. **Retry a few times with growing pauses,** for example after 30 seconds, 2 minutes and 10 minutes, then stop and log it.
2. **Alert a person when it lasts,** with the code and the Ray ID.
3. **Keep your IP address.** A new address reaches the same broken origin and only adds load.
4. **Do not store the error page as content.** A change monitor that saves Cloudflare's page as a new version sends a false alert; [How to Monitor a Website for Changes](/blog/website-change-monitoring) shows how to filter such noise.
5. **Treat 1015 or 1020 as a request to slow down or ask permission,** never as something to work around.

For uptime checks of your own sites, fixed addresses are easier: you can allowlist them and compare results over time. [ISP Proxy](https://proxynet.io/static-isp-residential-proxy) exits in several countries give each check a stable address, so a 522 from one region stands out at once.

## Who runs into these errors?

- Visitors of small sites whose security plugin starts blocking Cloudflare's addresses.
- Shoppers during a sale, when an overloaded origin returns 522 or 524.
- Site owners right after a move, before the A record in Cloudflare is updated.
- Anyone using Cloudflare-protected sites during a Cloudflare incident.

## Common mistakes

- **Visitors: restarting the router or clearing the cache.** The failure is between Cloudflare and the site.
- **Visitors: writing to Cloudflare.** Only the site owner can act on a 52x.
- **Owners: blocking Cloudflare with a security plugin.** Every visitor arrives from Cloudflare's addresses.
- **Owners: lowering the SSL mode to silence 526.** The certificate check goes with it.
- **Monitors: rotating IPs on a 52x.** The origin is down for every address.

## Decision guide

| Your situation | What to do |
|---|---|
| One site shows 520, 521, 522 or 524 | Wait a few minutes, reload once |
| Many sites show "Error code 500" | Check cloudflarestatus.com, wait |
| The error lasts more than an hour | Send time, URL, code and Ray ID to the site |
| You see 1015, 1020 or 1006 | Slow down or contact the owner |
| Your site, 521 or 522 | Allow Cloudflare's IP ranges, check the A record |
| Your site, 524 | Move long requests to a background job |
| Your site, 525 or 526 | Install a valid or Origin CA certificate |
| Your monitor gets a 52x | Retry with pauses, alert, keep the IP |

## Frequently asked questions

### How long does Cloudflare error 522 last?

There is no fixed time. A restart or a short overload clears within minutes; a firewall blocking Cloudflare or a wrong IP in DNS keeps the error until the owner fixes it.

### Is error 522 a problem with my internet?

No. Cloudflare received your request, so your connection worked. The timeout happened between Cloudflare and the site's server.

### Can a VPN cause or fix a Cloudflare 52x error?

It does not cause one, and it is not a fix. With a VPN you reach a different Cloudflare data center, so a regional fault may vanish for you while the site stays broken for others.

### What is the difference between error 521 and 522?

With 521 the server refused the connection, usually because the web server is stopped or a firewall rejects Cloudflare. With 522 it did not answer at all in time, typically because a firewall silently drops the traffic or the server is overloaded.

### How do I know if Cloudflare is down?

When many unrelated sites show the same Cloudflare page, usually "Internal server error" with "Error code 500", open cloudflarestatus.com; active incidents are listed at the top.

### Why does error 524 appear only on some pages?

Because only some pages are slow. A search or an export can need more than 125 seconds on a busy server, while light pages still answer in time.

## Summary

A Cloudflare 52x page means the site's own server failed Cloudflare; nothing is wrong on your side. As a visitor, wait, reload once, check the status page when many sites fail together, and send the Ray ID to the site if it lasts. As an owner, follow the code: firewall and IP ranges for 521 and 522, routing for 523, slow requests for 524, certificates for 525 and 526. Monitors should retry with pauses and keep their address. You can compare proxy types for monitoring on [our proxy page](/proxy).
