Cloudflare errors

Cloudflare error 522: Connection timed out

Cloudflare could not finish connecting to the website server in time.

Quick answer

A 522 means the real website server did not answer Cloudflare quickly enough when opening a connection or after a request. The server may be overloaded, offline or blocking Cloudflare.

When to wait: Often yes. Try again in a few minutes; if it stays, the owner must act.

If you are visiting the website

  1. Wait a few minutes and reload once A 522 often happens when the website's server is overloaded for a short time. Wait a few minutes, then reload once instead of many times.
  2. Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the problem is between Cloudflare and the website's server, not on your device.
  3. Write down the Ray ID and the time The error page shows a 'Cloudflare Ray ID' (a code for your exact request) at the bottom. Note it with the time and time zone for the owner.
  4. Tell the website owner If the problem stays, contact the website through another channel (email or social media) and send the error code, Ray ID, page address and time.

If you run the website

  1. Check the origin address in Cloudflare DNS Open the DNS records in Cloudflare and confirm the A record (IPv4 address) and AAAA record (IPv6 address) point to your current server. After a move to a new host, an old address is a common cause.
  2. Allow Cloudflare and lift rate limits Make sure firewalls, .htaccess rules, iptables and security tools do not drop or throttle Cloudflare's addresses from https://www.cloudflare.com/ips/. A rate limit that only counts the connecting address sees all your visitors as Cloudflare.
  3. Check server load Look at CPU, memory and the number of open connections at the error times. An overloaded server cannot accept new connections quickly enough, and Cloudflare gives up.
  4. Make sure keepalive is enabled Cloudflare reuses connections to your server through HTTP keepalive. In Apache keep KeepAlive On. In nginx do not set keepalive_timeout to 0, because that turns keepalive off.
  5. Test the origin directly Run curl -v --resolve example.com:443:ORIGIN_IP https://example.com/ from another network. If the connection hangs, the server or its network is too slow or drops packets.
  6. Ask your host for a network trace If nothing obvious shows up, ask your hosting provider to check for packet loss and to run an MTR or traceroute (tools that show each network hop and where traffic gets lost) from your server towards Cloudflare.

Is it the website or me?

It is the website side. Cloudflare (a service between visitors and many websites) could not finish talking to the website's own server in time.

Your network is not involved in that part of the trip. Changing settings on your device will not fix it.

What the time limits mean

Cloudflare shows a 522 when the origin server (the website's real computer) does not accept the connection within 19 seconds. It also shows a 522 when the server does not confirm the request within 90 seconds.

In both cases the server is too busy, offline, or something throws away Cloudflare's traffic on the way.

How 522 differs from 521, 523 and 524

A 521 is a fast, clear 'no' from the server. A 523 means there is no route to the server at all. A 524 means the connection worked, but the finished page took too long.

For developers: what happens technically

Cloudflare sends a SYN (the first packet of a TCP connection) and expects a SYN+ACK back within 19 seconds. After sending the request it expects an ACK within 90 seconds.

Silent drops by a firewall look exactly like an overloaded server from Cloudflare's side. Firewall logs and a direct curl test help to tell them apart.

Common questions

Is Cloudflare down when I see 522?

Usually not. Cloudflare served the error page, so it is working. The website's server did not answer it in time.

Why does 522 appear only at busy times?

That pattern points to an overloaded server. It runs out of capacity for new connections during peaks, and Cloudflare's connection attempts time out.

Can the owner make Cloudflare wait longer?

Cloudflare's documentation describes the 19-second and 90-second limits as the conditions for a 522 and offers no setting for them. The real fix is a server that answers faster or has more capacity.

Will Cloudflare's cache hide a 522?

Only for pages Cloudflare already holds in its cache (a saved copy). Anything that must come fresh from the server still fails until the server answers again.

Likely causes

  • Common The server is overloaded or offline. (Website side)
  • Sometimes Cloudflare addresses are blocked or rate limited at the server. (Website side)
  • Sometimes The DNS record at Cloudflare points to the wrong server address. (Website side)

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: