ERR_CONNECTION_REFUSED: what it means and how to fix it

The server is reachable but nothing accepts connections on the port. Quick checks for visitors, and the causes site owners should check first.

· 4 min read · By the Spot Downtime team

ERR_CONNECTION_REFUSED (“This site can't be reached. example.com refused to connect”) is one of the clearest errors a browser shows. Your browser found the server, knocked on the door, and the server's operating system answered: nothing here is accepting connections on that port. Firefox says Unable to connect; curl says Connection refused.

Quick checks for visitors

  • Check whether the site is down for everyone or just you.
  • Check the address: http:// vs https://, and any port number such as :8080.
  • Turn off a VPN or proxy and try again; a broken proxy setting gives the same error on every site.
  • If only one site fails and the checker says it's up, your network or antivirus may be blocking it.
Is it down for everyone?Check any URL from our servers, so you know whether it's the site or your connection.

Causes for site owners

The web server isn't running

The most common cause. It crashed, failed to start after a reboot, or a config error stopped it from restarting.

bash
sudo systemctl status nginx
sudo journalctl -u nginx -n 50       # why it stopped
sudo nginx -t                        # a config error blocks the restart

It's listening on the wrong port or address

An app listening on 127.0.0.1 only accepts connections from the same machine. A container that publishes the wrong port, or an app that moved from 3000 to 8080, is refused from outside.

bash
sudo ss -tlnp      # what's listening, on which address and port
# 127.0.0.1:3000  → local only     0.0.0.0:443 / [::]:443 → reachable from outside

A firewall rejects the connection

A firewall rule that rejects (rather than silently drops) produces the same error. Check ufw status, your cloud provider's firewall, and security groups.

DNS points to the wrong server

If the domain points to an old server that no longer runs a web server, every visitor is refused. Check the A record against your server's IP.

Open port checkerTest whether port 443 or 80 on your server is open from the internet.DNS lookupConfirm the domain's A and AAAA records point to the right server.

On localhost?

If localhost:3000 is refused, your dev server isn't running, crashed on start, or is on another port. Check the terminal it runs in. Inside Docker, localhost means the container itself, not your machine.

Refused vs timed out

Refused is fast and definite: the machine is reachable, but nothing's listening. A timeout (ERR_CONNECTION_TIMED_OUT) means nothing answered at all. The difference tells you whether to look at the service or the network. Behind Cloudflare, this same problem shows up as error 521.

A crashed web server is a classic “nobody noticed for hours” outage. An uptime monitor that checks every minute catches it straight away, with the error recorded so you know it was a refusal, not a slow page.

Keep reading