Cloudflare 520 to 526 errors
Understand the 52x errors a visitor sees when Cloudflare cannot get a good answer from your site, and work through the checks that clear them.
Parts of this feature are still being built. The Not yet section lists them.
Errors 520 to 526 come from Cloudflare, not from WordPress. They mean Cloudflare reached your domain but could not get a usable answer from the origin, which is the Avaloi server behind it. The number says what went wrong. Most are fixed by checking the domain's DNS and certificate, and by checking that the site answers at its temporary address.
The errors
| Code | Meaning | Usual cause |
|---|---|---|
| 520 | Unknown error | The origin sent a reply Cloudflare could not read. Often a PHP fatal error or an oversized header. |
| 521 | Origin is down | The origin refused the connection. The environment may be stopped or restarting. |
| 522 | Connection timed out | The origin did not answer the TCP connection in time. |
| 523 | Origin is unreachable | The domain points at an address that is not the Avaloi server. |
| 524 | A timeout occurred | The origin connected but took too long to answer, usually a slow page or a stuck PHP worker. |
| 525 | SSL handshake failed | The origin's certificate did not match the domain, or the certificate is not ready yet. |
| 526 | Invalid SSL certificate | Cloudflare's SSL mode is Full (strict), and the origin certificate is not valid for the domain. |
Check these first
- Open the temporary address. Every environment has one. Open Site info and copy the temporary hostname. If the site loads there, the problem is between Cloudflare and the domain, not the site itself. If it does not load, read the steps in Site is slow and Troubleshooting: 502 after a deploy.
- Check the domain's DNS records. Open Domains, then the domain, and compare the records with the ones Avaloi listed. A record that points somewhere else causes 523. A record through a proxy you do not control causes 521 or 522 at times.
- Check the certificate. Open Domains and look at the SSL status of the domain. A certificate that is still being issued, or that failed to renew, causes 525 and 526. See SSL certificates.
- Check the Cloudflare SSL mode. If the domain is on Cloudflare, Full (strict) needs a valid certificate at the origin. Full works with any certificate. Set the mode that matches the certificate status.
- Read the logs. Open Logs, pick
error.log, and look for the time of the visitor's error. A PHP fatal error at that time explains a 520. A slow request inaccess.logexplains a 524.
Fix it
- Correct the DNS record at your DNS host, then wait for it to spread. Check the record with Domains before you retry.
- If a certificate failed, fix the DNS or the challenge path first, then ask for a new certificate from the domain.
- If PHP is slow or stuck, restart PHP from Tools, then find the slow page in the logs.
- If a deploy caused a 520, roll back in Code.
Not yet
- A custom domain that Cloudflare fronts for you through Cloudflare for SaaS is not live on every plan yet. Until it is, set the DNS record that Domains shows, and do not expect Avaloi to change Cloudflare settings for you.
- Avaloi does not yet send a status page message for a 52x that affects only one domain. Check the status page for platform incidents.
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.