Cloudflare error 521: web server is down

Your origin refused Cloudflare's connection. How to tell whether the web server is stopped or a firewall is blocking Cloudflare, and how to fix both.

· 3 min read · By the Spot Downtime team

Error 521: Web server is down means Cloudflare tried to open a connection to your server and was actively refused. Cloudflare and the visitor are fine; your origin server said “no” at the network level, before any HTTP happened.

The two causes

1. The web server isn't running

nginx, Apache or your app server crashed, failed to start after a reboot, or was stopped. With nothing listening on port 80 or 443, the operating system refuses every connection.

bash
sudo systemctl status nginx          # running?
sudo ss -tlnp | grep -E ':(80|443) '  # anything listening on 80 / 443?
sudo nginx -t                         # config valid? (a bad config stops a restart)

2. A firewall is refusing Cloudflare

The server is up, but a firewall rejects connections from Cloudflare's IPs. This often happens after a security plugin, fail2ban, or a host's DDoS protection sees thousands of requests from a few IPs and blocks them, not realising they're Cloudflare.

How to tell which one

From outside, check whether the port accepts connections at all:

Open port checkerCheck whether port 443 or 80 on your origin IP is open from the internet.

If the port is closed, start the web server. If it's open from the checker but Cloudflare is still refused, your firewall is treating Cloudflare's IPs differently. Look for them in:

bash
sudo iptables -L -n | grep -i drop
sudo fail2ban-client status
sudo ufw status

Allowlist Cloudflare, then lock down everyone else

The robust setup is the reverse of the problem: allow Cloudflare's published IP ranges on ports 80 and 443, and block everyone else. Your origin is then only reachable through Cloudflare, and its protection can't be bypassed by hitting the IP directly.

Check the origin IP in Cloudflare

If you recently moved servers, make sure the A record in Cloudflare's DNS points to the new server. A refused connection from an old, decommissioned machine looks exactly like this.

Watching both sides helps: monitor the site through Cloudflare, and add a TCP port monitor on the origin's port 443, so you know whether it's your server or the path to it the moment it happens. Related: error 522 is the timeout version of this error, and ERR_CONNECTION_REFUSED is what visitors see without Cloudflare.

Keep reading