Tambena Consulting

How to Fix Cloudflare Error 521: Web Server Is Down

If you’ve landed on this page, you’ve probably already seen the message: Cloudflare tried to reach your web server and got refused. That’s Error 521 in a nutshell.

What throws people off is that the server can be sitting there perfectly fine, powered on, humming along , and you’ll still get this error. Usually it’s something smaller. A web service that quietly crashed. A firewall rule written a little too aggressively. A DNS record pointing somewhere it shouldn’t. An SSL setting that doesn’t line up with what your origin actually supports.

The upside is that Error 521 almost always comes down to the origin server itself, not some mystery on Cloudflare’s end. So rather than poking around your Cloudflare dashboard hoping something fixes it, you can actually work through this one methodically.

What Is Cloudflare Error 521?

Error 521 is Cloudflare’s way of saying “your web server is down” , specifically, that your origin refused the connection Cloudflare tried to make.

Picture Cloudflare sitting in front of your actual server, acting as a middleman. A visitor’s request hits Cloudflare first, and Cloudflare forwards it to your server behind the scenes.

If your server says no to that request, there’s nothing for Cloudflare to hand back to the visitor. So it throws Error 521 instead.

What Does “Origin Server Connection Refused” Actually Mean?

This just means the web server isn’t accepting the connection Cloudflare sent over.

The underlying machine , physical or virtual, doesn’t matter , could be totally healthy. But whatever’s supposed to be listening for web traffic on it, Nginx, Apache, whatever you’re running, might have stopped doing its job.

Or a firewall somewhere in the chain is catching that traffic and dropping it before it ever gets to the web server.

How Cloudflare Works as a Reverse Proxy

Worth understanding this before you start troubleshooting.

Without Cloudflare, a visitor connects directly to your server. With it turned on, there’s an extra hop:

Visitor → Cloudflare → Origin Server → Cloudflare → Visitor

That hop is what buys you caching, security filtering, TLS termination, and general traffic protection.

The tradeoff is that your origin now has to trust and accept connections coming specifically from Cloudflare’s IP ranges. Block those, even by accident, and the whole thing falls apart.

What Causes Cloudflare Error 521?

A few things tend to be behind this one.

1. The Web Server Is Stopped

Sometimes it really is this simple , the web server crashed or just isn’t running anymore.

On a Linux box, check whether Nginx or Apache (or whatever you’re serving with) is actually active right now.

If it’s down, restart it and reload the page. That alone fixes it more often than you’d think.

While you’re in there, skim your server logs too. Cloudflare specifically points people toward checking origin logs when 521 shows up, and it’s usually worth the two minutes.

2. Your Firewall Is Blocking Cloudflare

Honestly, this is probably the number one cause.

Somewhere , server firewall, hosting-level firewall, third-party security software , a rule is rejecting connections coming from Cloudflare’s IPs.

Go through whatever firewall setup you’re running and look for anything that could be catching that traffic.

3. Cloudflare’s IP Addresses Aren’t Whitelisted

Related to the above: your origin firewall needs to explicitly allow Cloudflare’s published IP ranges through, IPv4 and IPv6 both if you’re running dual-stack.

One thing to watch out for , don’t grab an IP list from some three-year-old blog post. Cloudflare’s ranges shift over time, so pull the current list straight from them.

4. The Server Is Overloaded

Not every 521 is about blocking. Sometimes the server just doesn’t have the room to accept new connections.

Worth a quick check on CPU, RAM, disk space, and connection limits. A traffic spike, a bloated app, or too many background jobs eating resources can all cause this.

5. Your DNS Settings Are Wrong

If your DNS is pointing at the wrong place, Cloudflare is essentially knocking on the wrong door.

Pull up your Cloudflare DNS records and confirm the A (or AAAA, if you’re on IPv6) record actually matches your current origin server.

This one trips people up a lot after a hosting migration , the old DNS record just sits there quietly pointing at a server that doesn’t exist anymore.

Also make sure you’re editing DNS at the right place. If your domain’s authoritative nameservers aren’t Cloudflare’s, changing records in the Cloudflare dashboard won’t do a thing.

6. The Web Server Isn’t Listening on the Right Port

Depending on your Cloudflare SSL/TLS mode, your server needs to be listening on a specific port. Flexible mode expects port 80. Full and Full (Strict) expect 443.

Even if your service is technically running, if nothing’s actually bound to the expected port, you’ll still hit Error 521.

Check your config and make sure that port is genuinely open and listening.

How to Fix Cloudflare Error 521

Go through these roughly in order , it’ll save you time compared to jumping around.

Step 1: Check Your Origin Server

First things first: is the server actually online?

Log into whatever hosting panel you use and look for outage notices, maintenance windows, or resource alerts.

Got SSH access? Check your web service status directly.

If it’s stopped, restart it, then test the site again.

Step 2: Test the Origin Server Directly

While you’re troubleshooting, try bypassing Cloudflare and connecting straight to the origin’s IP.

This tells you a lot fast. If the server fails even without Cloudflare in the picture, the problem’s on the server side , focus there before touching anything in Cloudflare.

If it loads fine directly but fails through Cloudflare, now you know to look at firewall rules, DNS, SSL, or Cloudflare’s own configuration.

Step 3: Check Your Firewall Rules

Work through your server firewall, hosting firewall, and any security software running on top.

You’re hunting for rules that block Cloudflare’s IPs or traffic on ports 80 and 443 specifically.

Be careful not to just disable everything to make the error go away , that fixes the symptom, not the problem, and opens you up to other issues.

Step 4: Whitelist Cloudflare’s IP Addresses

Add Cloudflare’s current IP ranges to your firewall’s allowlist. On Linux, that’s usually iptables or a similar tool.

Cloudflare has documentation with examples for allowing their ranges over HTTP and HTTPS.

Once that’s done, test the site through your normal (proxied) hostname, not the raw IP.

Step 5: Verify Ports 80 and 443

Confirm your server is listening where it needs to be. Port 80 is HTTP, port 443 is HTTPS , which one matters depends on your SSL/TLS mode.

Flexible mode → port 80. Full or Full (Strict) → port 443.

Running on a nonstandard port? Double-check that your Cloudflare setup actually accounts for that.

Step 6: Review Your SSL/TLS Encryption Mode

Pop open the Cloudflare dashboard and check what SSL/TLS mode you’re on.

Flexible talks to your origin over plain HTTP. Full and Full (Strict) both require HTTPS on that connection.

If you’re on Full or Full (Strict), your origin needs HTTPS set up properly , Full (Strict) specifically also needs a certificate that passes Cloudflare’s validation.

Don’t just switch modes and hope. Make sure whatever you pick actually matches what’s installed on your server.

Step 7: Check the Origin SSL Certificate

Running Full or Full (Strict)? Take a look at your certificate and confirm it’s:

  • Installed correctly
  • Valid for the hostname being requested
  • Not expired
  • Actually being served over HTTPS
  • Compatible with your chosen SSL/TLS mode

Cloudflare also offers its own Origin Certificates if you want an easier way to secure that connection.

And a general note: certificate problems can trigger other Cloudflare errors too, not just 521. Keep the exact error code and your origin logs handy when you’re troubleshooting anything TLS-related.

Step 8: Review Cloudflare DNS Settings

Head to the DNS tab in your dashboard.

Check your A record, confirm it points to your current server. If you’re using IPv6, check the AAAA record too , people forget this one constantly, and a wrong AAAA record can cause problems even when the A record is fine.

Recently switched hosts? Double-check both before moving on.

Step 9: Check Server Logs

Logs tell you why the connection actually got refused. You’re looking for things like:

  • Web server crashes
  • Connection limits maxed out
  • Firewall blocks
  • TLS errors
  • Resource exhaustion
  • Bad configuration
  • Application failures

Cloudflare recommends this step directly, and it’s especially useful when everything looks fine on the surface but the connection keeps getting refused anyway.

Step 10: Check What Changed Recently

Think back , what changed right before this started happening? Common candidates:

  • Firewall configuration
  • SSL certificates
  • DNS records
  • Web server configuration
  • A hosting migration
  • Security software updates
  • WordPress plugins
  • Server upgrades
  • Cloudflare settings themselves

More often than not, a recent change is the actual root cause, so don’t skip this even if nothing jumps out immediately.

Cloudflare Error 521 vs 522 vs 523

These three look similar on the surface, but they’re describing different failure points.

ErrorMeaningWhere to look
521Origin refuses Cloudflare’s connectionServer, firewall, ports, SSL, Cloudflare IPs
522Connection to origin times outServer responsiveness, network path, firewall, resource limits
523Cloudflare can’t reach the origin at allDNS, routing, origin availability, network config

Short version: 521 is an active refusal, 522 is a timeout, 523 is unreachable entirely. Each one points you somewhere different , for 521, start with whether the web service will accept a connection at all; for 522, look at what’s slowing things down or filtering traffic; for 523, it’s usually DNS or routing.

Quick Cloudflare Error 521 Checklist

If you just want the short version:

  1. Confirm the origin server is online.
  2. Confirm your web server (Nginx, Apache, etc.) is actually running.
  3. Test the origin directly, bypassing Cloudflare.
  4. Check your Cloudflare DNS records.
  5. Verify A and AAAA records.
  6. Review origin firewall rules.
  7. Whitelist Cloudflare’s current IP ranges.
  8. Confirm ports 80 and 443 are open.
  9. Check your SSL/TLS encryption mode.
  10. Verify the origin SSL certificate.
  11. Go through server and firewall logs.
  12. Check for recent infrastructure changes.
  13. If nothing works, contact your hosting provider.

When Should You Contact Your Hosting Provider?

If you’ve hit a wall , can’t access the origin, can’t pin down a server-side issue , it’s time to bring your hosting provider in.

They can look into things you can’t from the outside: infrastructure outages, resource constraints, network problems, service failures on their end.

When you reach out, give them the error code, a timestamp, the hostname affected, and whatever logs you’ve pulled. It’ll speed things up considerably compared to a vague “my site’s down” ticket.

How Tambena Consulting Can Help With Cloudflare and Infrastructure Issues

If this error keeps coming back after you’ve fixed it once, that’s usually a sign of something bigger going on underneath , not bad luck.

Tambena Consulting works on software, DevOps, cloud, web development, and infrastructure for businesses running modern digital systems.

On the DevOps side, that covers cloud workloads, CI/CD pipelines, infrastructure as code, and general operational cleanup. They also run cloud managed services , infrastructure management, monitoring, security, maintenance, backups, and ongoing support.

If Cloudflare errors, server connectivity issues, or infrastructure problems keep showing up on your end, it’s often faster to get someone to look at the whole picture rather than chasing one error at a time.

Need help with your website infrastructure, cloud environment, or DevOps setup? Contact Tambena Consulting to talk through your project and infrastructure needs.

Final Thoughts

At the end of the day, Error 521 is a connectivity problem between Cloudflare and your origin server.

Start with the server itself, then work outward: firewall, Cloudflare IPs, DNS, ports, SSL/TLS. Change one thing at a time so you actually know what fixed it , changing five settings at once just means you won’t know which one mattered.

Once your origin is accepting legitimate connections from Cloudflare again, everything should pass through normally.

FAQs

Can Error 521 fix itself? 

Sometimes, if it was a temporary hiccup on the server. If it keeps recurring, though, that’s your cue to actually dig into the configuration.

Can a firewall really cause this? 

Yes, and it’s one of the more common causes, especially when Cloudflare’s IPs simply aren’t on the allowlist.

Why does the site work when I disable the Cloudflare proxy? 

That’s usually a strong hint that something is blocking or misconfiguring Cloudflare’s traffic specifically, since bypassing it removes that layer entirely.

How do I stop this from happening again? 

Keep your server patched, keep an eye on resource usage, maintain your firewall rules, keep Cloudflare’s IPs whitelisted, and check your DNS and SSL settings every so often instead of only when something breaks.

tambena

tambena

Get A Free Qoute