Cloudflare error 521: web server is down
Your origin refused Cloudflare's connection. How to tell whether the web server is stopped or a firewall is blocking Cloudflare, and how to fix both.
· 3 min read · By the Spot Downtime team
Error 521: Web server is down means Cloudflare tried to open a connection to your server and was actively refused. Cloudflare and the visitor are fine; your origin server said “no” at the network level, before any HTTP happened.
The two causes
1. The web server isn't running
nginx, Apache or your app server crashed, failed to start after a reboot, or was stopped. With nothing listening on port 80 or 443, the operating system refuses every connection.
sudo systemctl status nginx # running?
sudo ss -tlnp | grep -E ':(80|443) ' # anything listening on 80 / 443?
sudo nginx -t # config valid? (a bad config stops a restart)2. A firewall is refusing Cloudflare
The server is up, but a firewall rejects connections from Cloudflare's IPs. This often happens after a security plugin, fail2ban, or a host's DDoS protection sees thousands of requests from a few IPs and blocks them, not realising they're Cloudflare.
How to tell which one
From outside, check whether the port accepts connections at all:
Open port checkerCheck whether port 443 or 80 on your origin IP is open from the internet.If the port is closed, start the web server. If it's open from the checker but Cloudflare is still refused, your firewall is treating Cloudflare's IPs differently. Look for them in:
sudo iptables -L -n | grep -i drop
sudo fail2ban-client status
sudo ufw statusAllowlist Cloudflare, then lock down everyone else
Check the origin IP in Cloudflare
If you recently moved servers, make sure the A record in Cloudflare's DNS points to the new server. A refused connection from an old, decommissioned machine looks exactly like this.
Watching both sides helps: monitor the site through Cloudflare, and add a TCP port monitor on the origin's port 443, so you know whether it's your server or the path to it the moment it happens. Related: error 522 is the timeout version of this error, and ERR_CONNECTION_REFUSED is what visitors see without Cloudflare.
Keep reading
- Cloudflare errors · TroubleshootingCloudflare error 520: web server is returning an unknown errorCloudflare's catch-all error means your origin sent something empty or invalid. The usual causes and how to test your origin directly, bypassing Cloudflare.October 5, 2026 · 3 min read
- Cloudflare errors · TroubleshootingCloudflare error 522: connection timed outCloudflare couldn't complete a connection to your server. Firewalls that drop traffic, overloaded servers and wrong origin IPs, and how to check each.October 5, 2026 · 3 min read