Cloudflare errors
Cloudflare error 525: SSL handshake failed
Cloudflare could not set up a secure connection with the website server.
Quick answer
A 525 means the secure (TLS) handshake between Cloudflare and the real server failed. The certificate or HTTPS settings on the server do not work with Cloudflare.
When to wait: Often yes. Try again in a few minutes; if it stays, the owner must act.
If you are visiting the website
- Wait a few minutes and reload once Sometimes a 525 appears for a short time while the owner changes certificates. Wait a few minutes, then reload once.
- Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the problem sits between Cloudflare and the website's server.
- Write down the Ray ID and the time The error page shows a 'Cloudflare Ray ID' (a code for your exact request) at the bottom. Note it with the time and time zone.
- Tell the website owner If the problem stays, contact the website through another channel (email or social media) and send the error code, Ray ID, page address and time.
If you run the website
- Check which SSL mode you use In the Cloudflare dashboard under SSL/TLS, Overview, see the encryption mode. In Full and Full (strict), Cloudflare speaks HTTPS to your server on port 443, so the server must accept secure connections there.
- Test the secure connection to your server Run openssl s_client -connect ORIGIN_IP:443 -servername example.com with your server's address and domain. A handshake error or 'connection refused' confirms the problem; a certificate printout means the basics work.
- Install a valid certificate Use a free Let's Encrypt certificate, for example with certbot, or create a Cloudflare Origin CA certificate under SSL/TLS, Origin Server, Create Certificate. Then reload the web server, for example with sudo nginx -t followed by sudo nginx -s reload.
- Make sure SNI serves the right certificate SNI (Server Name Indication) lets one server pick the right certificate for each domain. Your server needs an HTTPS block for this exact hostname on port 443, otherwise it may send no certificate or the wrong one.
- Allow modern protocols and ciphers Enable TLS 1.2 and TLS 1.3. In nginx, ssl_protocols TLSv1.2 TLSv1.3 is the current default; remove old custom cipher lists that Cloudflare cannot use.
- Read the TLS errors in your server log Look at the web server error log at the error times. Apache logs TLS details through mod_ssl, and nginx may need a more detailed log level to show handshake failures.
Is it the website or me?
It is the website. Your browser connected securely to Cloudflare (a service between visitors and many websites). The secure link from Cloudflare to the website's own server is the part that failed.
Your device's date, browser or antivirus are not involved here. Only the owner can fix it.
Which handshake failed?
A handshake is the short agreement on encryption at the start of a secure connection. A 525 is about the second link, between Cloudflare and the origin server (the website's real computer).
That server either has no working certificate, keeps port 443 closed, or cannot agree on encryption settings with Cloudflare.
How 525 differs from 526
With 525 the secure connection could not be set up at all. With 526 the connection worked, but Cloudflare rejected the server's certificate during its strict check.
For developers: what happens technically
In Full or Full (strict) mode, Cloudflare starts a TLS handshake with the origin and sends the hostname through SNI. If the origin resets the connection, offers no certificate or shares no cipher suite with Cloudflare, the edge returns 525.
A direct openssl s_client test with -servername reproduces the handshake. Watch for missing SNI support and outdated protocol settings.
Common questions
Is my connection to this website unsafe?
Your link to Cloudflare is still encrypted. The page simply cannot load because the hidden link behind Cloudflare is broken, so no data reaches the website.
Is Cloudflare down?
Usually not. Cloudflare served the error page. The website's server failed the secure handshake.
Does a Cloudflare Origin CA certificate work in browsers?
Only behind Cloudflare. Cloudflare warns that visitors see certificate errors if you pause Cloudflare or turn off proxying for a hostname that uses such a certificate.
Should I switch to Flexible mode to make the error go away?
Better not. Flexible sends traffic between Cloudflare and your server unencrypted, and it causes redirect loops when your server forces HTTPS. Install a certificate and use Full (strict) instead.
Likely causes
- Common No valid certificate is installed on the server. (Website side)
- Sometimes Port 443 is closed on the server. (Website side)
- Rare The server and Cloudflare share no common encryption settings. (Website side)
What to avoid
- Do not switch to Flexible mode as a fix; it removes encryption between Cloudflare and your server and can cause redirect loops.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Cloudflare Docs: Error 525 (SSL handshake failed)
- Cloudflare Docs: Origin CA certificates
- Cloudflare Docs: Full (strict) encryption mode
- nginx: Module ngx_http_ssl_module
- Cloudflare Docs: Flexible encryption mode
Last reviewed: