Cloudflare error 520: web server is returning an unknown error
Cloudflare's catch-all error means your origin sent something empty or invalid. The usual causes and how to test your origin directly, bypassing Cloudflare.
· 3 min read · By the Spot Downtime team
Error 520: Web server is returning an unknown error is Cloudflare's catch-all. Cloudflare reached your server and got something back, but it was empty, malformed, or the connection dropped mid-answer. It isn't a Cloudflare outage: the problem is on your origin server, and Cloudflare is only reporting it.
What usually causes a 520
The application crashed mid-request
A PHP-FPM worker, Node process or app server dies while handling the request, so the connection closes with no response. Look for segfaults, out-of-memory kills and restarts at the same timestamps as the 520s.
Response headers too large
Cloudflare limits the total size of response headers. An app that sets dozens of cookies, or a huge Content-Security-Policy, crosses it, and Cloudflare reports a 520 even though the origin answered.
An empty or invalid response
The origin sent a response with no status line or headers, or something that isn't valid HTTP. Some security modules and broken proxies do this when they block a request.
The origin firewall resets the connection
A firewall, fail2ban or a security plugin that sees all traffic arriving from a handful of Cloudflare IPs may decide it's an attack and reset the connections.
How to diagnose it
Bypass Cloudflare and talk to your origin directly. Replace 203.0.113.10 with your server's real IP:
curl -sv https://example.com/ --resolve example.com:443:203.0.113.10 -o /dev/null- If this also fails or returns nothing, the problem is your server: check its error logs.
- If it works, compare the response headers' size, and check whether your firewall treats Cloudflare's IPs differently.
Allow Cloudflare's IP ranges
CF-Connecting-IP header to see the real visitor IP in your logs.Related Cloudflare errors
520 is the vaguest of the family. If you see a different code, the cause is narrower: 521 (connection refused), 522 (connection timed out), 524 (response took too long). Monitoring your site through Cloudflare records the exact code each time, which makes intermittent 520s much easier to match against your server logs.
Keep reading
- Cloudflare errors · TroubleshootingCloudflare error 521: web server is downYour origin refused Cloudflare's connection. How to tell whether the web server is stopped or a firewall is blocking Cloudflare, and how to fix both.October 5, 2026 · 3 min read
- Cloudflare errors · TroubleshootingCloudflare error 522: connection timed outCloudflare couldn't complete a connection to your server. Firewalls that drop traffic, overloaded servers and wrong origin IPs, and how to check each.October 5, 2026 · 3 min read