Cloudflare Errors 520, 521, 522 and 525
Your site shows a Cloudflare error page — 520, 521, 522, or 525 — meaning Cloudflare is up but can't get a good answer from your actual hosting server.
Common signs of this issue
- Visitors see an orange-and-grey Cloudflare page instead of your site, with a three-digit code in the 520s.
- The page names three parties — browser (working), Cloudflare (working), and your host (error).
- Error 521 says "Web server is down"; 522 says "Connection timed out"; 525 mentions an SSL handshake.
- The site may come and go, working for a while and then failing again.
- Your host's own control panel might still log in fine even while the site shows the error.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Read the code on the error page — it tells you which side broke. 521: your hosting server is down or refusing Cloudflare. 522: the server is too slow or unreachable. 525: the SSL certificate setup between Cloudflare and your host failed. 520: the server sent back something Cloudflare couldn't understand.
- Check your host's status page (search "[your host] status") — if their server or data center is having problems, that's the whole story.
- Confirm your hosting account is active and paid. A suspended or expired hosting account is one of the most common causes of a sudden, permanent 521.
- Note when it started and whether anything changed — a hosting migration, an SSL certificate renewal, or new firewall rules at the host are classic triggers.
- If you can log into your hosting control panel, see whether the site loads from inside the host's own preview or file manager — if the host's side works internally, the problem is in the connection between Cloudflare and the host.
- Check your email (including spam) for messages from your host — suspensions, expired plans, and server maintenance are usually announced there.
What this usually means
Cloudflare sits in front of your website like a receptionist. These errors all mean the same basic thing: the receptionist is at the desk, but nobody in the back office is answering. Your visitors' browsers are fine, Cloudflare is fine — the hosting server behind it is down, overloaded, blocking Cloudflare, or misconfigured.
A constant 521 usually means the web server is genuinely down or the hosting account was suspended. Intermittent 522s usually mean an overloaded server or a host-side firewall dropping some of Cloudflare's connections. A 525 nearly always follows an SSL change on the hosting side — the certificate there expired or the SSL mode in Cloudflare doesn't match what the host supports.
Because Cloudflare keeps showing its own branded page, sites can sit broken like this for days without the owner noticing — Cloudflare being 'up' hides the fact that the real site is down. It's worth checking your own site from time to time, or using a free uptime monitor that emails you.
What not to do
- Don't delete or pause your Cloudflare account to 'get around' the error — the underlying server problem remains, and you lose the protection and settings you had.
- Don't change Cloudflare SSL settings at random; the wrong mode can take a working site down or expose traffic unencrypted.
- Don't assume it's temporary and wait a week — a suspended hosting account or expired certificate never fixes itself, and Google notices extended downtime.
- Don't buy a new hosting plan in a panic before finding out why the current server stopped answering — it's often a five-minute fix on the host's side.
When to get help
The fastest route is a support ticket to your hosting company (not Cloudflare) saying: "My site behind Cloudflare shows error 521/522/525 since [date]. Is the server up, is my account active, and are you blocking Cloudflare's IP ranges?" Those three questions cover nearly every cause. If the host says everything's fine and the error persists, a professional can compare both dashboards and find the mismatch quickly — it's a well-bounded problem.
Could your hosting be the problem?
If your host is slow, unreliable, or hard to deal with, moving to a better one can clear up issues like this for good. One we genuinely recommend is Instant Access Internet Services — a smaller, compassionate company with 30 years in the business, known for being one of the fastest, with great management and low pricing. (Just a recommendation — no affiliate link, no kickback.)
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
Is Cloudflare broken when I see error 521?
No — the error page itself proves Cloudflare is running. 521 means Cloudflare reached out to your hosting server and it was down or refused the connection. The problem is on the hosting side.
What causes error 525 (SSL handshake failed)?
The secure connection between Cloudflare and your host couldn't be established — usually an expired or missing certificate on the hosting server, or a Cloudflare SSL mode (like Full or Full Strict) that the host isn't set up for.
Why does my site work sometimes and show 522 other times?
Intermittent 522s point to an overloaded server or a host firewall dropping some of Cloudflare's connections. It typically worsens at busy times until the underlying resource or firewall issue is fixed.
Will visitors think my site is gone?
Many will — the Cloudflare page is a dead end for them. Extended downtime also tells Google the site is unreliable, which can cost rankings, so treat a persistent 52x as urgent.
Who should I contact first — Cloudflare or my host?
Your host. These errors nearly always originate on the hosting server. Cloudflare support is only the right call if your host confirms the server is up and accepting connections.