Cloudflare error 523: origin is unreachable

Cloudflare can't find a route to your server, almost always because of the IP in your DNS. How to check the record, including IPv6, and fix it.

· 3 min read · By the Spot Downtime team

Error 523: Origin is unreachable means Cloudflare couldn't find a route to your server at all. It didn't get refused or time out on a connection; it couldn't get there. That almost always comes down to the address Cloudflare is trying to reach.

Common causes

The DNS record points to the wrong place

The A or AAAA record in Cloudflare has an IP that no longer belongs to you, after a server migration, a new load balancer, or an IP change from your host. Or it was mistyped.

A private or reserved IP

Records like 10.0.0.5, 192.168.1.20 or 127.0.0.1 only work inside a private network. Cloudflare can't reach them from the internet.

A broken IPv6 record

If there's an AAAA record, Cloudflare may use it. A server whose IPv6 address changed, or never actually worked, causes 523s while IPv4 is fine. Remove the AAAA record if you don't serve over IPv6.

A network problem at your host

The data center or your provider has a routing issue. Check their status page.

How to fix it

Find your server's real public IP, then compare it with what Cloudflare has:

bash
curl -4 https://ifconfig.me    # run on the server: its public IPv4
curl -6 https://ifconfig.me    # and IPv6, if it has one
DNS lookupLook up your domain's records. For DNS-only (grey cloud) records you'll see the real origin IP to compare.IP lookupCheck who an IP belongs to. If the origin IP in your DNS belongs to an unexpected network, it's the wrong address.

Moving servers? Do DNS last

Get the new server fully working first, test it directly with curl --resolve, then update the record in Cloudflare. Keep the old server running until traffic has moved.

To catch a wrong record before visitors do, a DNS monitor can alert you when a record stops matching the value you expect.

Keep reading