How to Fix Cloudflare Error Code 522 (Connection Timed Out)
Checks that show who can clear the error, ranked fixes and a proxy tunnel test in cURL, Python and Node.js.
Updated
TL;DR
Error code 522 means Cloudflare could not get the website's server to accept its connection or acknowledge its request in time, so it showed a Connection timed out page. Your browser and proxy did not produce it: retry in a few minutes, and tell the site if it persists.
What error 522 looks like
Captured from Cloudflare's 522 preview; your client's request headers decide which one you get.
| Where | What you see |
|---|---|
| Browser tab title | example.com | 522: Connection timed out |
| Browser page (Cloudflare default) | Connection timed out / Error code 522 / You Browser Working / <city> Cloudflare Working / example.com Host Error |
| Browser page, under What happened? | The initial connection between Cloudflare's network and the origin web server timed out. As a result, the web page can not be displayed. |
| curl with default headers | error code: 522 |
| curl -D - (response headers, default request) | HTTP/2 522 / content-type: text/plain; charset=UTF-8 / server: cloudflare / cf-ray: a46a81872ddd1787-HKG |
| Python requests, raise_for_status() | requests.exceptions.HTTPError: 522 Server Error: <none> for url: https://example.com/ |
| API client (Accept: application/json) | "title":"Error 522: Connection timed out" / "error_name":"connection_timeout" / "retryable":true,"retry_after":120,"owner_action_required":true |
Why this happens
Cloudflare tried to reach the site's server, which did not answer in time.
Cloudflare says the most common cause is the server blocking or rate limiting Cloudflare's IPs. Every visit arrives from those IPs, so auto-ban tools can mistake them for a few busy sources.
Diagnose your 522 first
Three browser checks show whether the fault is the site's alone; two owner checks then find its cause.
Look at the diagram on the error page; if only Host shows Error, Cloudflare could not reach the site's server.
Turn off your proxy or VPN and reload; if the 522 stays, the site's server fails for direct visitors too.
Open cloudflarestatus.com; if it lists an incident for a location near you, the problem may reach beyond this one site.
Open Origin Analytics in Cloudflare; a high TCP failure rate on certain paths in Top endpoints suggests a path-specific fault rather than a dead server.
Curl the origin via --connect-to from a host your firewall admits; an answer means the server is up, silence means it is down or overloaded.
Solutions ranked by effectiveness
Visitors start with the first card, site owners the second, proxy users the third.
- Most common fix
Wait, reload once, then alert the owner
Applies when you visit a site you do not run. Its error page asks visitors to try again in a few minutes, so wait that long before one reload.
If it fails again, send the owner the Ray ID, URL, time and time zone.
Contact the site directly, because Cloudflare support takes cases only from domain owners.
- Site owners
Let Cloudflare reach your origin server
If you run the site, work down this list and reload the failing URL after each change.
Stop the firewall, .htaccess, plugins and ban tools from blocking or rate limiting cloudflare.com/ips ranges.
If the --connect-to test hangs, ask your host whether the server is overloaded or offline.
Make the A or AAAA record in Cloudflare's DNS app match the server's current IP.
If nothing helps, send Cloudflare support an MTR from the server to a Cloudflare IP.
- For developers
Confirm the proxy opened the tunnel
Applies when a 522 reaches you through a proxy. Tunnel 200 plus a cf-ray means Cloudflare sent the 522 through TLS the proxy cannot fake; a failed tunnel points to the proxy.
curl -sS -o /dev/null \ -x http://USERNAME:PASSWORD@proxy.geonode.io:9000 \ -w 'tunnel %{http_connect} site %{http_code} server %header{server} cf-ray %header{cf-ray}\n' \ https://example.com/
Stop the 522 from coming back
Two tasks for site owners, then one setting for scripts and monitors that check the site.
Refresh the firewall allowlist from cloudflare.com/ips or the Cloudflare API on a schedule; new ranges appear there first.
On AWS, route 172.64.0.0/13 to the Internet Gateway so a wide 172.x route cannot capture Cloudflare's traffic.
Set scraper and monitor read timeouts above 110 seconds, so a 522 arrives as a code, not a timeout.
Related errors
Learn more
FAQ
Recheck each fix from one IP
Sticky ports keep one residential IP for up to 24 hours while you retest.


