Geonode logo
Website and server errors

How to Fix Cloudflare Error Code 520

What a visitor should send the site, a with-and-without-proxy test for scripts, and Cloudflare's fixes for owners.

Updated

TL;DR

Error code 520 means the website's server behind Cloudflare sent Cloudflare an empty or unreadable reply, so Cloudflare served its own error page. Reload once after a short wait; if it fails again, only the site's owner can fix it, so send them the Ray ID.

What a 520 looks like in each client

Cloudflare picks the format from your client's headers; a site with its own error page shows that page instead.

WhereWhat you see
Browser tab title (Cloudflare's default page)example.com | 520: Web server is returning an unknown error
Browser page, under What happened?There is an unknown connection issue between Cloudflare and the origin web server. As a result, the web page can not be displayed.
Browser page, advice for visitorsIf you are a visitor of this website: Please try again in a few minutes.
curl with default headerserror code: 520
JSON reply (Cloudflare's documented curl test)"error_code":520,"error_name":"unknown_origin_error","error_category":"origin"
Status line over HTTP/1.1HTTP/1.1 520 <none>
Python requests, raise_for_status()520 Server Error: <none> for url: https://example.com/

Why this happens

The website's server gave Cloudflare a reply it could not read, or none at all.

Cloudflare sits between you and the site's server and relays what the server sends back. Often the site's app crashed before it finished replying, which Cloudflare says is common with some PHP applications.

Diagnose your 520 first

Anyone can run the first check in a browser; the rest need the site's server or Cloudflare account.

  • Open the site's home page; if it loads while your URL shows 520, only that page's reply breaks, not the whole server.

  • In Speed > Origin Analytics, look up the 520s' origin status; 0 means the server closed the connection, 200 means a malformed reply.

  • Look through the firewall deny list and security plugin bans for Cloudflare's published ranges; a hit means the server refuses Cloudflare itself.

  • Check when the 520s began; if right after enabling HTTP/2 on the server or Authenticated Origin Pulls (AOP), that change is the likely cause.

Solutions ranked by effectiveness

Pick the card for your role; only the last one changes the server.

  1. Most common fix

    Reload once, then report the Ray ID

    Applies when you are visiting the site. Its error page says to try again in a few minutes, so wait, reload once and stop if the 520 remains.

    1. Copy the Ray ID at the page's foot and the UTC time at its top.

    2. Send both, with the full URL, through the site's contact page or support email.

    3. Write to the site, not Cloudflare, whose support helps only domain owners.

  2. For developers

    Compare cf-ray with and without the proxy

    If your script uses a proxy, request the page with and without it. A 520 with a cf-ray header on both runs is Cloudflare reporting the site's server, so your proxy needs no change.

    URL=https://example.com/
    PROXY=http://USERNAME:PASSWORD@proxy.geonode.io:9000
    for P in "" "$PROXY"; do
      [ -z "$P" ] && echo "direct:" || echo "via proxy:"
      curl -sS -o /dev/null -D - -x "$P" "$URL" \
        | grep -aiE '^HTTP/|^server:|^cf-ray:'
    done
  3. Site owners

    Apply the fix Cloudflare documents

    If you run the site, take the step that matches your checks, then reload the failing URL.

    1. If origin status is 0, check the error log at that time for a crash.

    2. If it is 200, keep response headers under 128 KB; cookies often push them over.

    3. Allow every range on cloudflare.com/ips in the firewall and in WordPress security plugins.

    4. For HTTP/2 faults, turn off HTTP/2 to Origin in Speed > Settings > Protocol Optimization.

Stop the 520 from coming back

Server habits that keep Cloudflare's connections healthy and make the next 520 quick to trace.

  1. Leave HTTP keep-alive on at the server; Cloudflare expects to reuse idle connections for up to 900 seconds.

  2. Before turning on HTTP/2 at the server, confirm it supports multiplexing; Cloudflare warns that servers without it can get 520s.

  3. Set nginx or Apache to accept Cloudflare's origin pull certificate before switching on AOP; enforce it once requests pass.

  4. Log the CF-Ray request header, $http_cf_ray in nginx or %{CF-Ray}i in Apache, so Ray IDs map to log lines.

Code generated for your proxy setupGeonode's dashboard turns your residential proxy configuration into code for Python, Node.js and more.
Try residential proxies

Related errors

Learn more

FAQ

Cloudflare asked the site's server for the page and got back something empty, unknown or unexpected. Cloudflare draws the error page itself, but the fault lies with that server, which only its owner can repair.

As a visitor, reload once after a few minutes and report the Ray ID to the site. As the owner, look for a crash, oversized headers, a firewall block or broken HTTP/2 on the server.

Not a standard one: IANA lists 512 to 599 as unassigned, so Cloudflare's docs define what 520 means. Under RFC 9110, a client that does not recognize 520 must handle it as a 500.

Your request reached Cloudflare, but the site's server gave it no usable answer. Cloudflare's JSON reply marks it retryable after 60 seconds with owner_action_required true, so cap your retries and log the cf-ray.

Not on its own, since it only carries your request to Cloudflare. A 520 only through the proxy likely means the site's server handles that IP differently, for example by closing the connection; the owner sets that rule.

Usually not, because Cloudflare's error reference files 520 under origin errors, where the site's server is responsible. To rule out a wider problem, check Active incidents on cloudflarestatus.com.

Real residential IPs for automation

Run scrapers and browser automation through residential IPs, billed per GB of traffic you send.