Cloudflare error 520: web server is returning an unknown error

Cloudflare's catch-all error means your origin sent something empty or invalid. The usual causes and how to test your origin directly, bypassing Cloudflare.

· 3 min read · By the Spot Downtime team

Error 520: Web server is returning an unknown error is Cloudflare's catch-all. Cloudflare reached your server and got something back, but it was empty, malformed, or the connection dropped mid-answer. It isn't a Cloudflare outage: the problem is on your origin server, and Cloudflare is only reporting it.

What usually causes a 520

The application crashed mid-request

A PHP-FPM worker, Node process or app server dies while handling the request, so the connection closes with no response. Look for segfaults, out-of-memory kills and restarts at the same timestamps as the 520s.

Response headers too large

Cloudflare limits the total size of response headers. An app that sets dozens of cookies, or a huge Content-Security-Policy, crosses it, and Cloudflare reports a 520 even though the origin answered.

An empty or invalid response

The origin sent a response with no status line or headers, or something that isn't valid HTTP. Some security modules and broken proxies do this when they block a request.

The origin firewall resets the connection

A firewall, fail2ban or a security plugin that sees all traffic arriving from a handful of Cloudflare IPs may decide it's an attack and reset the connections.

How to diagnose it

Bypass Cloudflare and talk to your origin directly. Replace 203.0.113.10 with your server's real IP:

bash
curl -sv https://example.com/ --resolve example.com:443:203.0.113.10 -o /dev/null
  • If this also fails or returns nothing, the problem is your server: check its error logs.
  • If it works, compare the response headers' size, and check whether your firewall treats Cloudflare's IPs differently.
HTTP headers checkerSee the full response headers a URL returns, including how many cookies it sets.DNS lookupCheck the A records for your domain. Behind Cloudflare's proxy you'll see Cloudflare's IPs, which confirms traffic is proxied.

Allow Cloudflare's IP ranges

Every proxied request reaches your server from Cloudflare's published IP ranges. Make sure your firewall and any rate limiters allow them, and use the CF-Connecting-IP header to see the real visitor IP in your logs.

520 is the vaguest of the family. If you see a different code, the cause is narrower: 521 (connection refused), 522 (connection timed out), 524 (response took too long). Monitoring your site through Cloudflare records the exact code each time, which makes intermittent 520s much easier to match against your server logs.

Keep reading