How to Fix Cloudflare Error Code 520
What a visitor should send the site, a with-and-without-proxy test for scripts, and Cloudflare's fixes for owners.
Updated
TL;DR
Error code 520 means the website's server behind Cloudflare sent Cloudflare an empty or unreadable reply, so Cloudflare served its own error page. Reload once after a short wait; if it fails again, only the site's owner can fix it, so send them the Ray ID.
What a 520 looks like in each client
Cloudflare picks the format from your client's headers; a site with its own error page shows that page instead.
| Where | What you see |
|---|---|
| Browser tab title (Cloudflare's default page) | example.com | 520: Web server is returning an unknown error |
| Browser page, under What happened? | There is an unknown connection issue between Cloudflare and the origin web server. As a result, the web page can not be displayed. |
| Browser page, advice for visitors | If you are a visitor of this website: Please try again in a few minutes. |
| curl with default headers | error code: 520 |
| JSON reply (Cloudflare's documented curl test) | "error_code":520,"error_name":"unknown_origin_error","error_category":"origin" |
| Status line over HTTP/1.1 | HTTP/1.1 520 <none> |
| Python requests, raise_for_status() | 520 Server Error: <none> for url: https://example.com/ |
Why this happens
The website's server gave Cloudflare a reply it could not read, or none at all.
Cloudflare sits between you and the site's server and relays what the server sends back. Often the site's app crashed before it finished replying, which Cloudflare says is common with some PHP applications.
Diagnose your 520 first
Anyone can run the first check in a browser; the rest need the site's server or Cloudflare account.
Open the site's home page; if it loads while your URL shows 520, only that page's reply breaks, not the whole server.
In Speed > Origin Analytics, look up the 520s' origin status; 0 means the server closed the connection, 200 means a malformed reply.
Look through the firewall deny list and security plugin bans for Cloudflare's published ranges; a hit means the server refuses Cloudflare itself.
Check when the 520s began; if right after enabling HTTP/2 on the server or Authenticated Origin Pulls (AOP), that change is the likely cause.
Solutions ranked by effectiveness
Pick the card for your role; only the last one changes the server.
- Most common fix
Reload once, then report the Ray ID
Applies when you are visiting the site. Its error page says to try again in a few minutes, so wait, reload once and stop if the 520 remains.
Copy the Ray ID at the page's foot and the UTC time at its top.
Send both, with the full URL, through the site's contact page or support email.
Write to the site, not Cloudflare, whose support helps only domain owners.
- For developers
Compare cf-ray with and without the proxy
If your script uses a proxy, request the page with and without it. A 520 with a cf-ray header on both runs is Cloudflare reporting the site's server, so your proxy needs no change.
URL=https://example.com/ PROXY=http://USERNAME:PASSWORD@proxy.geonode.io:9000 for P in "" "$PROXY"; do [ -z "$P" ] && echo "direct:" || echo "via proxy:" curl -sS -o /dev/null -D - -x "$P" "$URL" \ | grep -aiE '^HTTP/|^server:|^cf-ray:' done - Site owners
Apply the fix Cloudflare documents
If you run the site, take the step that matches your checks, then reload the failing URL.
If origin status is 0, check the error log at that time for a crash.
If it is 200, keep response headers under 128 KB; cookies often push them over.
Allow every range on cloudflare.com/ips in the firewall and in WordPress security plugins.
For HTTP/2 faults, turn off HTTP/2 to Origin in Speed > Settings > Protocol Optimization.
Stop the 520 from coming back
Server habits that keep Cloudflare's connections healthy and make the next 520 quick to trace.
Leave HTTP keep-alive on at the server; Cloudflare expects to reuse idle connections for up to 900 seconds.
Before turning on HTTP/2 at the server, confirm it supports multiplexing; Cloudflare warns that servers without it can get 520s.
Set nginx or Apache to accept Cloudflare's origin pull certificate before switching on AOP; enforce it once requests pass.
Log the CF-Ray request header, $http_cf_ray in nginx or %{CF-Ray}i in Apache, so Ray IDs map to log lines.
Related errors
Learn more
FAQ
Real residential IPs for automation
Run scrapers and browser automation through residential IPs, billed per GB of traffic you send.


