Cloudflare error 525: SSL handshake failed

Cloudflare couldn't set up HTTPS with your origin. What the SSL modes mean, the common causes, and the quick fix with an Origin CA certificate.

· 3 min read · By the Spot Downtime team

Error 525: SSL handshake failed means Cloudflare tried to open an encrypted connection to your origin server and the handshake failed before any HTTP was exchanged. It only happens when Cloudflare's SSL mode is Full or Full (strict), because those are the modes that encrypt the connection to your server.

Cloudflare's SSL modes, briefly

ModeVisitor → CloudflareCloudflare → your server
FlexibleHTTPSPlain HTTP (not recommended)
FullHTTPSHTTPS, any certificate
Full (strict)HTTPSHTTPS, valid trusted certificate (recommended)

Common causes

Nothing is serving HTTPS on the origin

Port 443 isn't open, or the web server has no HTTPS site configured, so Cloudflare's TLS handshake gets nowhere. This is common right after switching from Flexible to Full.

No certificate for this hostname (SNI)

Cloudflare sends the hostname during the handshake (SNI). If your server has HTTPS set up for other domains but not this one, it may abort the handshake.

No shared TLS version or cipher

An old server limited to outdated protocols, or a very locked-down config, may have nothing in common with what Cloudflare offers. TLS 1.2 and 1.3 with modern ciphers work.

A firewall interfering

Something between Cloudflare and the server resets connections on port 443 partway through the handshake.

How to diagnose it

Test the handshake directly against your origin IP, sending the right hostname:

bash
openssl s_client -connect 203.0.113.10:443 -servername example.com </dev/null

If that fails, the server isn't set up for HTTPS on this name. If it shows a certificate, check it covers the domain and has a full chain.

Open port checkerConfirm port 443 is open on your origin server.SSL certificate checkerCheck a certificate's names, expiry and chain.

The easy fix: a Cloudflare Origin CA certificate

In Cloudflare, create a free Origin CA certificate (valid for up to 15 years), install it on your server for your domain, and use Full (strict). It's trusted by Cloudflare only, which is all the origin needs.

If the handshake succeeds but the certificate is rejected, you'll see error 526 instead.

Keep reading