Cloudflare errors

Cloudflare error 521: Web server is down

Cloudflare could not connect to the website server.

Quick answer

A 521 means Cloudflare tried to open a connection to the real website server and was refused. The server is off, not listening, or blocking Cloudflare.

When to wait: Often yes. Try again in a few minutes; if it stays, the owner must act.

If you are visiting the website

  1. Wait a few minutes and reload once A 521 often appears while a server restarts or after it crashed. Wait a few minutes, then reload the page once.
  2. Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the website's server is off or blocking Cloudflare, and your device is fine.
  3. Write down the Ray ID and the time The Cloudflare error page shows a 'Cloudflare Ray ID' (a code for your exact request) at the bottom. Note it with the time and time zone so the owner can find your request.
  4. Tell the website owner If the problem stays, contact the website through another channel (email or social media) and send the error code, Ray ID, page address and time.

If you run the website

  1. Start or restart the web server Check whether your web server runs, for example with systemctl status nginx or systemctl status apache2 on Linux, and start it if it is stopped. Then read its error log to learn why it stopped, so it does not happen again.
  2. Test the configuration before restarting Run sudo nginx -t or apachectl configtest. A broken configuration after an update often keeps the server from starting at all.
  3. Check the port for your SSL mode In Full and Full (strict) mode (the SSL mode is how Cloudflare connects to your server), Cloudflare connects on port 443. In Flexible mode it uses port 80. Your server must listen on that port; on Linux, sudo ss -tlnp lists the ports in use.
  4. Allow all Cloudflare IP ranges Firewalls, ban tools and rate limits can block Cloudflare because all visitors arrive from its addresses. Allow every range from https://www.cloudflare.com/ips/, for example with iptables -I INPUT -p tcp -m multiport --dports http,https -s RANGE -j ACCEPT for each range. Keep the list current.
  5. Test the origin directly Run curl -v --resolve example.com:443:ORIGIN_IP https://example.com/ with your domain and server address. 'Connection refused' confirms the server or a firewall is rejecting connections on that port.
  6. Check your host's status and server resources A full disk, lack of memory or an outage at your hosting provider can stop the web server. Your host's status page or support can confirm a known problem.

Is it the website or me?

It is the website. Cloudflare (a service between visitors and many websites) tried to connect to the site's own server and was refused.

Nothing on your phone or computer causes this. Waiting, or telling the owner, is all you can do.

What 'web server is down' means

The website's real computer, called the origin server, either has its web server program stopped or rejects connections from Cloudflare. The computer itself may still be running.

A common surprise is a security tool on the server that bans Cloudflare's addresses. The site then looks down for everyone, even though the server is fine.

How 521 differs from 522 and 523

With a 521 the origin actively says 'no' to the connection. With a 522 it does not answer in time, and with a 523 Cloudflare cannot even find a network path to it.

For developers: what happens technically

Cloudflare opens a TCP connection (the basic network connection) to the origin on port 443 or 80, depending on the SSL mode. If the origin replies with a reset, meaning nothing listens on that port or a firewall rejects it, the edge returns 521.

Test from outside with curl and the --resolve option, and check firewall logs for Cloudflare addresses.

Common questions

Is the website gone for good?

Usually not. A 521 means the server is not accepting connections right now. Most sites come back once the owner restarts the server or removes the block.

Is Cloudflare down?

Rarely. The error page is served by Cloudflare, so Cloudflare itself is working. The website's server is the one refusing connections.

Why did the 521 start right after I installed a security plugin?

Because every visitor reaches you through Cloudflare's addresses, a security tool can mistake Cloudflare for an attacker and block it. Allow Cloudflare's IP ranges in that tool, or make it read the real visitor address that Cloudflare passes along.

How long does a 521 usually last?

There is no typical duration. It lasts until the web server is started again or the block is lifted, so a quick message to the owner can shorten it.

Likely causes

  • Common The web server software is stopped or crashed. (Website side)
  • Common A firewall blocks Cloudflare connections. (Website side)
  • Sometimes The server is not listening on the expected port. (Website side)

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: