Geonode logo
Website and server errors

How to Fix Cloudflare Error 521 (Web Server Is Down)

Four checks and three ranked fixes, with server commands for owners and code that reads Cloudflare's reply.

Updated

TL;DR

Error 521 means Cloudflare tried to connect to a website's own server and the server refused, so Cloudflare shows an error page instead of the site. Nothing on the visitor's side caused it: reload after a few minutes, and if it stays, only the site's owner can fix it.

How error 521 shows up

Captured from Cloudflare's 521 preview; a site with its own uploaded error page shows that instead.

WhereWhat you see
Browser tab title (Cloudflare's default page)example.com | 521: Web server is down
Browser page, status diagramYou Browser Working / <city> Cloudflare Working / example.com Host Error
Browser page, under What happened?The web server is not returning a connection. As a result, the web page is not displaying.
Browser page, advice for the site ownerIf you are the owner of this website: Contact your hosting provider letting them know your web server is not responding.
curl with default headerserror code: 521
JSON reply (Cloudflare's documented curl test: TestAgent/1.0, JSON Accept header, gzip)"title":"Error 521: Web server is down" / "error_name":"origin_down" / "cloudflare_error":true / "retry_after":120

Why this happens

The website's own server refused to let Cloudflare connect, so no page came through.

Cloudflare lists two common causes: the web server program, such as nginx or Apache, has stopped, or a firewall or security tool on the server blocks Cloudflare's addresses.

Diagnose your 521 first

Visitors need only the first check; owners use the rest to find what on the server refuses Cloudflare.

  • Reload with your VPN or proxy off, then on; if only the proxied route shows 521, the site likely refuses only some Cloudflare addresses.

  • On the server, run ss -ltn; if the port your SSL/TLS mode needs is missing or bound to 127.0.0.1, Cloudflare cannot connect.

  • Run sudo fail2ban-client banned; if it lists an address from a cloudflare.com/ips range, fail2ban is blocking Cloudflare.

  • If only some URLs fail, run one through the dashboard's Trace page; a matching Origin Rule port override means they reach a closed port.

Solutions ranked by effectiveness

One card per reader, most common first: a visitor, the site's owner, then a developer working through a proxy.

  1. Most common fix

    Wait it out and tell the owner

    Applies when a site you do not run shows the Web server is down page. A short wait and a clear report are all a visitor can do.

    1. Reload once after a few minutes, as the page itself suggests.

    2. Check the site's status page or social accounts for news of an outage.

    3. Then report the URL, time and Ray ID (at the page's foot) to the site.

  2. Site owners

    Start the server and let Cloudflare in

    If you run the site, get the web server accepting connections again, then stop the firewall and fail2ban from turning Cloudflare away.

    1. Start the server: sudo systemctl enable --now nginx (apache2 or httpd for Apache).

    2. In nginx, write listen *:443 ssl instead of listen 127.0.0.1:443 ssl, then reload.

    3. Allow every cloudflare.com/ips range in the firewall and in ignoreip for fail2ban's web jails.

    4. Lift the bans already on those addresses: sudo fail2ban-client unban <IP> for each.

  3. For developers

    Confirm Cloudflare sent the 521, not your proxy

    Applies when a script gets 521 through a proxy. In Cloudflare's JSON reply, cloudflare_error true with error_name origin_down means the site refused Cloudflare, so keep your proxy and retry that host after retry_after seconds.

    curl -sS --compressed -A "TestAgent/1.0" \
      -x http://USERNAME:PASSWORD@proxy.geonode.io:9000 \
      -H "Accept: application/json" -H "Accept-Encoding: gzip, deflate" \
      https://example.com/ | grep -oE '"(cloudflare_error|error_name|retry_after|ray_id)":[^,]*'

Stop the 521 from coming back

Owner settings that keep a crash, a ban, an SSL/TLS switch or a firewall rule from shutting Cloudflare out again.

  1. Run sudo systemctl edit nginx and add Restart=on-failure under [Service], so systemd restarts the server after a crash.

  2. Restore visitor IPs in logs with nginx's realip module or Apache's mod_remoteip; otherwise fail2ban sees Cloudflare's addresses, not visitors'.

  3. Keep Automatic SSL/TLS on where offered; it upgrades 1% of traffic first and rolls back if origin connections fail.

  4. Route the site through Cloudflare Tunnel; cloudflared connects out, so the firewall needs no inbound rule for Cloudflare.

A success-rate test for your proxiesGeonode's Python script sends requests through your proxies and reports success rate and error types.
Try residential proxies

Related errors

Learn more

FAQ

It means the server behind the site turned Cloudflare away before any page could load. That refusal comes from the site's side, so only its owner or hosting provider can end it.

Visitors can only wait a few minutes and send the site the Ray ID. Owners restart the web server, make it listen on the port their SSL/TLS mode uses and allow all Cloudflare IP ranges.

A 521 is a refusal from the server; a 522 is silence, with no reply in time. Curl aimed straight at the server's IP shows the split: exit code 7 at once for a refusal, 28 after a wait.

Full and Full (strict) send https:// visitors to the origin over HTTPS on port 443, while Flexible always uses port 80. A server with no HTTPS listener on 443 refuses those connections.

Yes. Its iptables and nftables actions reject banned addresses by default, so a banned Cloudflare IP gets a refusal, the 521 pattern. CSF drops blocked packets by default instead, which shows up as 522.

A site behind Cloudflare resolves to Cloudflare's anycast addresses, so ping and port scans on its name reach Cloudflare, not the website's server. Test the IP in the A record on Cloudflare's DNS Records page instead.

Proxy request counts in your dashboard

The Statistics section shows successful and failed requests, plus bandwidth used each day.