Geonode logo
Website and server errors

How to Fix Cloudflare Error Code 522 (Connection Timed Out)

Checks that show who can clear the error, ranked fixes and a proxy tunnel test in cURL, Python and Node.js.

Updated

TL;DR

Error code 522 means Cloudflare could not get the website's server to accept its connection or acknowledge its request in time, so it showed a Connection timed out page. Your browser and proxy did not produce it: retry in a few minutes, and tell the site if it persists.

What error 522 looks like

Captured from Cloudflare's 522 preview; your client's request headers decide which one you get.

WhereWhat you see
Browser tab titleexample.com | 522: Connection timed out
Browser page (Cloudflare default)Connection timed out / Error code 522 / You Browser Working / <city> Cloudflare Working / example.com Host Error
Browser page, under What happened?The initial connection between Cloudflare's network and the origin web server timed out. As a result, the web page can not be displayed.
curl with default headerserror code: 522
curl -D - (response headers, default request)HTTP/2 522 / content-type: text/plain; charset=UTF-8 / server: cloudflare / cf-ray: a46a81872ddd1787-HKG
Python requests, raise_for_status()requests.exceptions.HTTPError: 522 Server Error: <none> for url: https://example.com/
API client (Accept: application/json)"title":"Error 522: Connection timed out" / "error_name":"connection_timeout" / "retryable":true,"retry_after":120,"owner_action_required":true

Why this happens

Cloudflare tried to reach the site's server, which did not answer in time.

Cloudflare says the most common cause is the server blocking or rate limiting Cloudflare's IPs. Every visit arrives from those IPs, so auto-ban tools can mistake them for a few busy sources.

Diagnose your 522 first

Three browser checks show whether the fault is the site's alone; two owner checks then find its cause.

  • Look at the diagram on the error page; if only Host shows Error, Cloudflare could not reach the site's server.

  • Turn off your proxy or VPN and reload; if the 522 stays, the site's server fails for direct visitors too.

  • Open cloudflarestatus.com; if it lists an incident for a location near you, the problem may reach beyond this one site.

  • Open Origin Analytics in Cloudflare; a high TCP failure rate on certain paths in Top endpoints suggests a path-specific fault rather than a dead server.

  • Curl the origin via --connect-to from a host your firewall admits; an answer means the server is up, silence means it is down or overloaded.

Solutions ranked by effectiveness

Visitors start with the first card, site owners the second, proxy users the third.

  1. Most common fix

    Wait, reload once, then alert the owner

    Applies when you visit a site you do not run. Its error page asks visitors to try again in a few minutes, so wait that long before one reload.

    1. If it fails again, send the owner the Ray ID, URL, time and time zone.

    2. Contact the site directly, because Cloudflare support takes cases only from domain owners.

  2. Site owners

    Let Cloudflare reach your origin server

    If you run the site, work down this list and reload the failing URL after each change.

    1. Stop the firewall, .htaccess, plugins and ban tools from blocking or rate limiting cloudflare.com/ips ranges.

    2. If the --connect-to test hangs, ask your host whether the server is overloaded or offline.

    3. Make the A or AAAA record in Cloudflare's DNS app match the server's current IP.

    4. If nothing helps, send Cloudflare support an MTR from the server to a Cloudflare IP.

  3. For developers

    Confirm the proxy opened the tunnel

    Applies when a 522 reaches you through a proxy. Tunnel 200 plus a cf-ray means Cloudflare sent the 522 through TLS the proxy cannot fake; a failed tunnel points to the proxy.

    curl -sS -o /dev/null \
      -x http://USERNAME:PASSWORD@proxy.geonode.io:9000 \
      -w 'tunnel %{http_connect}  site %{http_code}  server %header{server}  cf-ray %header{cf-ray}\n' \
      https://example.com/

Stop the 522 from coming back

Two tasks for site owners, then one setting for scripts and monitors that check the site.

  1. Refresh the firewall allowlist from cloudflare.com/ips or the Cloudflare API on a schedule; new ranges appear there first.

  2. On AWS, route 172.64.0.0/13 to the Internet Gateway so a wide 172.x route cannot capture Cloudflare's traffic.

  3. Set scraper and monitor read timeouts above 110 seconds, so a 522 arrives as a code, not a timeout.

Check your site from other countriesAdd a country code to the proxy username and load your own site from there.
Try residential proxies

Related errors

Learn more

FAQ

It is Cloudflare's Connection timed out error: the site's origin server, the machine behind Cloudflare, did not respond to Cloudflare within its time limit. Only the site's owner or host can repair it.

Visitors can only wait a few minutes, reload once and pass the Ray ID to the owner. Owners let Cloudflare's IP ranges through, get the server responding and fix a DNS record that points elsewhere.

Until the problem on the site's server is fixed or passes. Cloudflare's 522 page sends Retry-After: 120 and its JSON version flags owner_action_required, so scripts should wait two minutes between capped tries.

A 522 means the origin never completed the connection or never acknowledged the request. A 524 means it acknowledged the request but sent no HTTP response within the default 125 seconds.

Cloudflare waits 19 seconds for the server to accept its connection, with SYN retry intervals of 1, 1, 1, 1, 1, 2, 4 and 8 seconds, then 90 seconds for an acknowledgment. Its limits table marks neither as configurable.

Not directly: Cloudflare writes it when the site's server fails to answer. If it appears only through the proxy, the Cloudflare data center near the exit may lack a working path to that server, which only the owner can fix.

Recheck each fix from one IP

Sticky ports keep one residential IP for up to 24 hours while you retest.