Cloudflare Error 525 SSL Handshake Failed and 526 Invalid Certificate
Your site shows a Cloudflare page reading "Error 525: SSL handshake failed" or "Error 526: Invalid SSL certificate" — Cloudflare is working, but it cannot make a trusted secure connection to your hosting server.
Common signs of this issue
- A Cloudflare-branded page says "Error 525: SSL handshake failed" or "Error 526: Invalid SSL certificate" instead of your site.
- The diagram on the error page shows your browser and Cloudflare as working, with the problem on the "Host" side.
- It started suddenly after months of working fine — often around the time a certificate on your hosting server was due to renew.
- It started right after changing the Cloudflare SSL/TLS mode, moving hosts, or reinstalling the site.
- Every page fails the same way, including the WordPress login page.
- Your host insists the site is up, and it may even load if you bypass Cloudflare.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Read the code carefully. 525 means Cloudflare could not complete a secure handshake with your server at all. 526 means the handshake worked but the certificate your server presented failed Cloudflare's check. They point at related but different fixes.
- In Cloudflare, open SSL/TLS, then Overview, and write down the current encryption mode. Error 526 only happens in Full (strict) mode; error 525 happens in Full or Full (strict). If Cloudflare has an automatic mode enabled, note what it says it has chosen.
- Check whether your hosting server has a valid certificate of its own. In your host's control panel, look under SSL/TLS, AutoSSL, or Let's Encrypt for your domain and note the expiry date. An expired or failed renewal on the server is the single most common cause of a sudden 526.
- If you or a developer installed a Cloudflare Origin Certificate on the server, find out when and for which hostnames. These are free and can be valid for many years, but they only cover the names chosen when they were created — a missing
wwwor subdomain will fail. - Ask your host a specific question: "Is HTTPS on port 443 enabled for my domain on your server, and what certificate is it serving?" A 525 frequently means the server is not answering secure requests for your domain at all, for example after a migration.
- Check the Edge Certificates page too. The certificate there protects visitors-to-Cloudflare traffic and can be perfectly valid while the server-side one is broken. A healthy edge certificate does not rule out an origin problem.
- Look at recent changes: a new host, a new server IP in your DNS records, a firewall or security plugin update on the server, or someone switching the mode from Flexible to Full. The fault almost always lines up with one of these.
- Note the Ray ID at the bottom of the error page and the time you saw it. If you end up contacting Cloudflare or your host, that ID lets them find the exact failed request.
What this usually means
Cloudflare sits between your visitors and your hosting server, and there are two separate connections: visitor to Cloudflare, and Cloudflare to your server (the "origin"). The SSL/TLS mode controls the second one. Flexible encrypts only the visitor side and talks to your server over plain HTTP. Full encrypts both sides but accepts whatever certificate your server offers, even an expired or self-signed one. Full (strict) encrypts both sides and requires a valid, unexpired certificate that matches your domain — either a normal public certificate or a Cloudflare Origin Certificate. Full (strict) is the secure setting to aim for.
Error 525 means Cloudflare knocked on port 443 and could not complete the secure handshake: no certificate installed for your domain, HTTPS not enabled on the server, the server only supporting outdated settings, or a server firewall cutting the connection. Error 526 means the handshake happened but, in Full (strict) mode, the certificate was not acceptable — most often expired, self-signed, issued for a different hostname, or a free certificate that quietly failed to renew. The general 520, 521 and 522 errors, covered in Cloudflare errors 520, 521 and 522, point to a server that is down or slow rather than a certificate problem.
The tempting fix is to drop the mode to Flexible, and it often makes the error disappear. It also means traffic between Cloudflare and your server is no longer encrypted, and if your site or WordPress forces HTTPS it very often creates an endless too many redirects loop. The proper fix is on the server: get a valid certificate installed and renewing — a free host certificate or a Cloudflare Origin Certificate — then keep Cloudflare on Full (strict).
What not to do
- Don't switch Cloudflare to Flexible as a permanent fix. It hides the problem, removes encryption to your server, and commonly causes redirect loops.
- Don't pause Cloudflare or turn off the orange proxy cloud without checking first. If the server has no working certificate, visitors will then hit a browser security warning instead.
- Don't buy a paid certificate to fix this before checking the free options. A free host certificate or a Cloudflare Origin Certificate is enough for Full (strict).
- Don't create a Cloudflare Origin Certificate and then turn off Cloudflare's proxy. Origin certificates are only trusted by Cloudflare, so browsers connecting directly will reject them.
- Don't change DNS records or move hosts while diagnosing. A new server IP brings its own certificate questions and muddies the picture.
- Don't ignore a 526 that fixed itself after a change on the host side. Find out why the certificate lapsed so it does not happen again at the next renewal.
When to get help
A 525 or 526 takes the whole site offline for every visitor, so every hour counts, especially for a shop or a lead-generating site. If you do not have access to both the Cloudflare account and the hosting control panel, or the certificate on the server keeps failing to renew, this is worth handing over. Someone experienced checks both sides at once — the origin certificate, the port 443 setup, the mode, and any firewall between them — and fixes it without downgrading your security or creating a redirect loop.
Glenn at WebsiteSelfHelp untangles Cloudflare and SSL problems for small businesses, from expired origin certificates to half-finished migrations. Send him a short description with the error number and what changed, and he will tell you honestly what the fix involves before anyone touches a login.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does Cloudflare error 525 SSL handshake failed mean?
It means Cloudflare tried to open a secure connection to your hosting server and the handshake failed before any page was sent. The usual causes are no certificate on the server, HTTPS not enabled for your domain, or a server firewall interfering.
What is the difference between Cloudflare error 525 and 526?
With 525 the secure handshake never completes. With 526 the handshake works, but Cloudflare's Full (strict) mode rejects the certificate your server presents, usually because it is expired, self-signed, or for the wrong hostname.
Which Cloudflare SSL mode should I use?
Full (strict) whenever your server has a valid certificate, which is free on most hosts or via a Cloudflare Origin Certificate. Flexible is the least secure and often causes redirect loops; Full is a stopgap that does not check the certificate.
Is a Cloudflare 525 or 526 error my host's fault or Cloudflare's?
Almost always the hosting side. Cloudflare is reporting that your server's secure setup is missing or invalid. Your host or developer usually needs to install, renew, or correct the certificate on the server.
Can I just switch to Flexible mode to fix error 526?
It may make the error go away, but it stops encryption between Cloudflare and your server and often causes an endless redirect loop on sites that force HTTPS. Treat it as an emergency measure for minutes, not a fix.
How long does it take to fix a Cloudflare 525 or 526 error?
Once the right person is looking at it, often under an hour. Issuing or installing a certificate on the server is quick; the delay is usually getting access to both the host and the Cloudflare account.
Will a Cloudflare 526 error hurt my SEO?
A few hours will not. If it lasts days, Google sees the site as unavailable and may slow crawling or temporarily drop pages. Fixing it quickly is what matters.