Cloudflare Error 525 SSL Handshake Failed and 526 Invalid Certificate

Your site shows a Cloudflare page reading "Error 525: SSL handshake failed" or "Error 526: Invalid SSL certificate" — Cloudflare is working, but it cannot make a trusted secure connection to your hosting server.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

Cloudflare sits between your visitors and your hosting server, and there are two separate connections: visitor to Cloudflare, and Cloudflare to your server (the "origin"). The SSL/TLS mode controls the second one. Flexible encrypts only the visitor side and talks to your server over plain HTTP. Full encrypts both sides but accepts whatever certificate your server offers, even an expired or self-signed one. Full (strict) encrypts both sides and requires a valid, unexpired certificate that matches your domain — either a normal public certificate or a Cloudflare Origin Certificate. Full (strict) is the secure setting to aim for.

Error 525 means Cloudflare knocked on port 443 and could not complete the secure handshake: no certificate installed for your domain, HTTPS not enabled on the server, the server only supporting outdated settings, or a server firewall cutting the connection. Error 526 means the handshake happened but, in Full (strict) mode, the certificate was not acceptable — most often expired, self-signed, issued for a different hostname, or a free certificate that quietly failed to renew. The general 520, 521 and 522 errors, covered in Cloudflare errors 520, 521 and 522, point to a server that is down or slow rather than a certificate problem.

The tempting fix is to drop the mode to Flexible, and it often makes the error disappear. It also means traffic between Cloudflare and your server is no longer encrypted, and if your site or WordPress forces HTTPS it very often creates an endless too many redirects loop. The proper fix is on the server: get a valid certificate installed and renewing — a free host certificate or a Cloudflare Origin Certificate — then keep Cloudflare on Full (strict).

What not to do

When to get help

A 525 or 526 takes the whole site offline for every visitor, so every hour counts, especially for a shop or a lead-generating site. If you do not have access to both the Cloudflare account and the hosting control panel, or the certificate on the server keeps failing to renew, this is worth handing over. Someone experienced checks both sides at once — the origin certificate, the port 443 setup, the mode, and any firewall between them — and fixes it without downgrading your security or creating a redirect loop.

Glenn at WebsiteSelfHelp untangles Cloudflare and SSL problems for small businesses, from expired origin certificates to half-finished migrations. Send him a short description with the error number and what changed, and he will tell you honestly what the fix involves before anyone touches a login.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

What does Cloudflare error 525 SSL handshake failed mean?

It means Cloudflare tried to open a secure connection to your hosting server and the handshake failed before any page was sent. The usual causes are no certificate on the server, HTTPS not enabled for your domain, or a server firewall interfering.

What is the difference between Cloudflare error 525 and 526?

With 525 the secure handshake never completes. With 526 the handshake works, but Cloudflare's Full (strict) mode rejects the certificate your server presents, usually because it is expired, self-signed, or for the wrong hostname.

Which Cloudflare SSL mode should I use?

Full (strict) whenever your server has a valid certificate, which is free on most hosts or via a Cloudflare Origin Certificate. Flexible is the least secure and often causes redirect loops; Full is a stopgap that does not check the certificate.

Is a Cloudflare 525 or 526 error my host's fault or Cloudflare's?

Almost always the hosting side. Cloudflare is reporting that your server's secure setup is missing or invalid. Your host or developer usually needs to install, renew, or correct the certificate on the server.

Can I just switch to Flexible mode to fix error 526?

It may make the error go away, but it stops encryption between Cloudflare and your server and often causes an endless redirect loop on sites that force HTTPS. Treat it as an emergency measure for minutes, not a fix.

How long does it take to fix a Cloudflare 525 or 526 error?

Once the right person is looking at it, often under an hour. Issuing or installing a certificate on the server is quick; the delay is usually getting access to both the host and the Cloudflare account.

Will a Cloudflare 526 error hurt my SEO?

A few hours will not. If it lasts days, Google sees the site as unavailable and may slow crawling or temporarily drop pages. Fixing it quickly is what matters.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible