Cloudflare "Error 521: Web server is down" or "Error 522: Connection timed out"

Both errors mean Cloudflare is fine and your own server is not answering it. 521 means your server refused the connection. 522 means it never answered at all. Cloudflare cannot fix either one. The fault is on your host.

What to do, in order

  1. Check the server is on. Log in to your host's panel. A stopped server, an unpaid bill or a full disk all look like this.
  2. Test the server without Cloudflare. Run curl -I http://YOUR.SERVER.IP -H "Host: yourdomain.com". No answer means the web server (nginx, Apache) is down. Restart it: sudo systemctl restart nginx.
  3. Check the firewall. A firewall or security plugin that blocks Cloudflare's addresses gives 521. Allow the ranges listed at cloudflare.com/ips.
  4. Check the DNS record. In Cloudflare's DNS tab, the A record must point at your server's current address. Hosts change addresses after a migration or a rebuild.
  5. Check the SSL mode. If Cloudflare is set to "Full" and your server has no certificate on port 443, you get 521 or 525. Install a certificate on the server, or set the mode to "Flexible" while you do.

If the site still will not come back, send me the address and I will find which step fails.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.