Cloudflare errors

Cloudflare error 520: Web server returns an unknown error

Cloudflare reached the website server, but got an answer it could not use.

Quick answer

Cloudflare is a service that sits in front of many websites. A 520 means the real website server sent back something empty, broken or unexpected. The problem is on the website side, not your device.

When to wait: Often yes. Try again in a few minutes; if it stays, the owner must act.

If you are visiting the website

  1. Wait a minute and reload once A 520 is sometimes caused by a short crash or restart on the website's own server. Reload once after a minute. Reloading again and again does not help and only adds load.
  2. Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the problem sits on the website side and nothing on your device needs changing.
  3. Write down the Ray ID and the time At the bottom of the Cloudflare error page you see a 'Cloudflare Ray ID' (a code that identifies your exact request). Copy it together with the time and your time zone. The owner can look up exactly that request with it.
  4. Tell the website owner If the problem stays, contact the website through another channel (email or social media) and send the error code, the Ray ID, the page address and the time.

If you run the website

  1. Read the origin error log at the error time Look at your web server and application logs (for example the nginx or Apache error log and your PHP or app log) for crashes, fatal errors or killed worker processes at the time of the 520. If you have no log access, ask your host to check that exact time.
  2. Allow all Cloudflare IP ranges Security plugins, ban tools or firewalls sometimes treat Cloudflare as one very busy visitor and cut it off. Allow every range listed at https://www.cloudflare.com/ips/ in your firewall, iptables rules, .htaccess or hosting panel. Keep the list current, for example through the Cloudflare API, because ranges can change.
  3. Shrink oversized headers and cookies Cloudflare cannot pass on origin responses whose headers are larger than 128 KB. Too many or too large cookies are the usual reason. Remove cookies you no longer need and do not store large data in them.
  4. Test the origin directly, without Cloudflare Run curl -v --resolve example.com:443:ORIGIN_IP https://example.com/ (replace the domain and ORIGIN_IP with your server's real address). curl then talks straight to your server. Check whether you get a proper status line such as 'HTTP/1.1 200' with headers, or an empty or cut-off reply.
  5. Check HTTP/2 between Cloudflare and your server If your server speaks HTTP/2 to Cloudflare, a broken setup can produce answers Cloudflare cannot read. Fix the server configuration, or turn off 'HTTP/2 to Origin' in the Speed settings of the Cloudflare dashboard to test.
  6. Check Authenticated Origin Pulls With this feature, your server only accepts requests that carry Cloudflare's client certificate. If it is on in Cloudflare but your server is not set up for it, or the other way round, requests fail.
  7. Isolate briefly, then escalate Setting the DNS record to DNS-only (grey cloud) for a short test shows whether the error comes from your server. This exposes your server's real IP address and removes Cloudflare's protection, so switch back quickly. If you still need help, send Cloudflare support the Ray ID, full URL, time and your curl output.

Is it the website or me?

A 520 is almost never caused by your device. Cloudflare (a service that sits between visitors and many websites) received your request fine. The website's own server then answered with something empty or broken.

Changing browsers, clearing cookies or restarting your router normally does not help. The fix happens on the website's server.

What 'unknown error' really means

Cloudflare uses 520 as a catch-all when the origin server (the website's real computer behind Cloudflare) breaks the conversation without a valid HTTP answer. That can be a dropped connection, an empty reply or headers that cannot be read.

The other codes from 521 to 526 describe more specific failures. A 520 is what is left when none of them fit.

How 520 differs from 502 and 521

A 502 Bad Gateway is a general code that any proxy (a server that passes requests on) can return. A 521 means the origin refused the connection outright. A 520 means a connection happened, but the answer was unusable.

For developers: what happens technically

Cloudflare opens a connection to the origin, forwards the request and waits for a status line and headers. If the origin closes the socket early, sends nothing, sends headers above 128 KB or sends a broken HTTP/2 frame, the edge returns 520.

Compare what the origin sent with what Cloudflare showed the visitor, using Cloudflare's analytics or logs filtered by Ray ID. Matching the times with your own server log usually reveals the crash or the faulty response.

Common questions

Is Cloudflare down when I see error 520?

Usually not. The error page itself comes from Cloudflare, which shows that Cloudflare is working. The website's own server is the part that failed.

Can I fix a 520 myself as a visitor?

Not really. You can reload once, check again later and tell the owner the Ray ID and time. Everything else has to happen on the website's server.

Why does the 520 come and go?

On-and-off 520s often mean the server crashes under load, a worker process gets killed, or only some pages send oversized cookies. Logs from the exact error times usually show the pattern.

Should I just turn Cloudflare off to make the error go away?

Pausing Cloudflare can prove that the origin is at fault, but it exposes your server's real IP address and removes Cloudflare's caching and protection. Use it only as a short test, then fix the origin and turn Cloudflare back on.

Likely causes

  • Common The website server crashed or closed the connection. (Website side)
  • Sometimes Response headers or cookies are too large. (Website side)
  • Sometimes A firewall on the server blocks Cloudflare. (Website side)

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: