Cloudflare error 522: connection timed out

Cloudflare couldn't complete a connection to your server. Firewalls that drop traffic, overloaded servers and wrong origin IPs, and how to check each.

· 3 min read · By the Spot Downtime team

Error 522: Connection timed out means Cloudflare tried to connect to your origin server and got no answer at all. Not a refusal (that's 521), not a slow page (that's 524): the connection itself never completed.

What causes a 522

A firewall silently dropping Cloudflare

The most common cause. A firewall that drops packets (instead of rejecting them) makes connections hang until they time out. Cloud firewalls like AWS security groups, DigitalOcean firewalls or your host's DDoS filter often do this if Cloudflare's IP ranges aren't allowed.

The server is overloaded

A server out of CPU or with a full connection backlog can't accept new connections fast enough. Check load, and whether the web server has hit its connection or worker limit.

The wrong origin IP

The A record in Cloudflare points to an IP where nothing answers: an old server, a typo, or a private IP that isn't reachable from the internet.

The network path

Routing problems at your host or data center. Rarer, but your host's status page will usually mention it.

How to diagnose it

  • Confirm the origin IP in Cloudflare's DNS settings is the server you think it is.
  • Check from outside whether the origin's port 443 (or 80) accepts connections.
  • Connect to the origin directly, bypassing Cloudflare:
bash
curl -sv https://example.com/ --resolve example.com:443:203.0.113.10 --connect-timeout 10 -o /dev/null
Open port checkerCheck whether your origin's port 443 is reachable from the internet. A timeout here points to a firewall or the wrong IP.IP lookupConfirm the origin IP belongs to your hosting provider, and not to an old server or another network.

Drop vs reject

A firewall that rejects gives you a 521 in a second. One that drops gives you a 522 after a long wait. If 522s come and go, look at rules that kick in under load, such as connection rate limits.

Fixing it for good

Allow Cloudflare's IP ranges in every firewall layer (host firewall and cloud firewall), keep enough capacity for peak traffic, and monitor the origin directly with a TCP port check next to your normal website monitor. When both fail, it's your server; when only the Cloudflare one fails, it's the path or a firewall rule.

Keep reading