🔶

Cloudflare Error

Cloudflare Error 521: Web Server Is Down

Cloudflare cannot establish a connection to your origin server at all — it's actively refusing connections.

What This Error Means

A 521 means Cloudflare's edge tried to open a TCP connection to your origin server on the port it expects (usually 80 or 443) and the origin actively refused it — not a timeout, an immediate refusal, which typically means nothing is listening on that port at all.

Why It Occurs

The web server process on the origin (Nginx, Apache, etc.) is not running, crashed, or was never started. It can also occur if a firewall on the origin is specifically blocking Cloudflare's IP ranges, or if the origin server itself is completely powered off or unreachable.

Symptoms

  • ⚠ Every request to the site shows Error 521, consistently, not intermittently
  • ⚠ The origin server is unreachable even directly (bypassing Cloudflare) if the server itself is down

Common Causes

  • • The web server process (nginx, apache2, httpd) has stopped or crashed on the origin
  • • The origin server itself is powered off, rebooting, or unreachable
  • • A firewall on the origin is blocking Cloudflare's IP ranges specifically
  • • The origin's web server is listening on the wrong port relative to what Cloudflare/DNS is configured to reach

How to Fix It

  1. SSH into the origin server and check whether the web server process is actually running: `systemctl status nginx` (or apache2/httpd)
  2. If it's stopped, check why it stopped before just restarting it — `journalctl -u nginx --since "1 hour ago"` for the actual crash reason
  3. If the process is running, confirm it's listening on the expected port: `ss -tulpn | grep :443`
  4. Check the origin's firewall rules allow Cloudflare's published IP ranges (Cloudflare publishes these at cloudflare.com/ips) on the relevant ports
  5. If the server itself is unreachable via SSH too, check with your hosting/cloud provider whether the instance itself is down
CommandPurpose
systemctl status nginxCheck whether the web server process is running
ss -tulpn | grep :443Confirm the server is actually listening on the expected port
Advertisement

Verification

  • ✓ Confirm the web server process shows "active (running)"
  • ✓ Test a direct connection to the origin (bypassing Cloudflare via a hosts-file override) to confirm it now responds

Prevention

  • → Set the web server to auto-restart on failure with systemd's Restart=on-failure
  • → Set up uptime monitoring that checks the origin directly, not just through Cloudflare, so an origin-only outage is caught immediately

Related