Cloudflare errors

Cloudflare error 523: Origin is unreachable

Cloudflare could not find a network route to the website server.

Quick answer

A 523 means Cloudflare could not reach the real server at all. Usually the server address is wrong or the network path to it is broken.

When to wait: Often yes. Try again in a few minutes; if it stays, the owner must act.

If you are visiting the website

  1. Wait a few minutes and reload once A 523 can come from a short network problem at the website's host. Wait a few minutes, then reload once.
  2. Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the path between Cloudflare and the website's server is broken, not your connection.
  3. Write down the Ray ID and the time The error page shows a 'Cloudflare Ray ID' (a code for your exact request) at the bottom. Note it with the time and time zone.
  4. Tell the website owner If the problem stays, contact the website through another channel (email or social media) and send the error code, Ray ID, page address and time.

If you run the website

  1. Confirm the A and AAAA records In the Cloudflare DNS app, check that the A record (IPv4 address) and AAAA record (IPv6 address) hold your server's current public addresses. An old address after a host move is the most frequent cause.
  2. Check that the IPv6 address really works If you publish an AAAA record, your server must actually answer on that IPv6 address. Remove the record if the server has no working IPv6.
  3. Test the server without Cloudflare Run curl -v --resolve example.com:443:ORIGIN_IP https://example.com/ from another network. If this also fails, the server or its network is unreachable for everyone, not just for Cloudflare.
  4. AWS users: check VPC route tables Cloudflare uses addresses in 172.64.0.0/13. A broad route such as 172.0.0.0/8 that points to a private destination can capture that traffic. Add a more specific route for 172.64.0.0/13 towards your Internet Gateway.
  5. Ask your host for an MTR or traceroute Ask your hosting provider to run an MTR or traceroute (tools that show each network hop) from your server to a Cloudflare address found in your logs. This shows where packets get lost.
  6. Check your host's network status A routing outage at the provider makes the server unreachable. Their status page or support can confirm it.

Is it the website or me?

It is the website side. Cloudflare (a service between visitors and many websites) found no working network path to the website's own server.

Your internet provider is not part of that path. Nothing on your device can fix it.

What 'origin is unreachable' means

The origin server (the website's real computer) is not just slow or refusing. Cloudflare's traffic cannot get to it at all.

This usually means a wrong address in the DNS records or a routing fault in the hosting network.

How 523 differs from 521 and 522

A 521 means the server answered with a refusal. A 522 means the server was reachable but too slow. A 523 means the packets never arrived.

For developers: what happens technically

Cloudflare looks up the origin address from your DNS records in its dashboard and tries to route traffic there. If routers report the address as unreachable, or traffic is sent into a private network, the edge returns 523.

Route tables in cloud networks deserve a close look. A route that is broader than needed can swallow Cloudflare's own address range.

Common questions

Is Cloudflare down?

Usually not. Cloudflare showed you the error page, so it works. It just cannot reach the website's server.

I just moved to a new host. Why do I see 523?

The DNS records in Cloudflare probably still point to the old server's address. Update the A and AAAA records to the new server.

Is my internet provider to blame?

No. Your provider only carries traffic between you and Cloudflare, and that part worked. The broken path is between Cloudflare and the website's server.

What does the host need from me to fix it?

The exact times of the errors, the Ray ID from the error page, the server's IP address and, if possible, an MTR or traceroute from the server towards Cloudflare.

Likely causes

  • Common The DNS record points to an old or wrong server address. (Website side)
  • Sometimes A routing problem at the hosting provider. (Website side)

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: