ERR_CONNECTION_REFUSED: what it means and how to fix it
The server is reachable but nothing accepts connections on the port. Quick checks for visitors, and the causes site owners should check first.
· 4 min read · By the Spot Downtime team
ERR_CONNECTION_REFUSED (“This site can't be reached. example.com refused to connect”) is one of the clearest errors a browser shows. Your browser found the server, knocked on the door, and the server's operating system answered: nothing here is accepting connections on that port. Firefox says Unable to connect; curl says Connection refused.
Quick checks for visitors
- Check whether the site is down for everyone or just you.
- Check the address:
http://vshttps://, and any port number such as:8080. - Turn off a VPN or proxy and try again; a broken proxy setting gives the same error on every site.
- If only one site fails and the checker says it's up, your network or antivirus may be blocking it.
Causes for site owners
The web server isn't running
The most common cause. It crashed, failed to start after a reboot, or a config error stopped it from restarting.
sudo systemctl status nginx
sudo journalctl -u nginx -n 50 # why it stopped
sudo nginx -t # a config error blocks the restartIt's listening on the wrong port or address
An app listening on 127.0.0.1 only accepts connections from the same machine. A container that publishes the wrong port, or an app that moved from 3000 to 8080, is refused from outside.
sudo ss -tlnp # what's listening, on which address and port
# 127.0.0.1:3000 → local only 0.0.0.0:443 / [::]:443 → reachable from outsideA firewall rejects the connection
A firewall rule that rejects (rather than silently drops) produces the same error. Check ufw status, your cloud provider's firewall, and security groups.
DNS points to the wrong server
If the domain points to an old server that no longer runs a web server, every visitor is refused. Check the A record against your server's IP.
Open port checkerTest whether port 443 or 80 on your server is open from the internet.DNS lookupConfirm the domain's A and AAAA records point to the right server.On localhost?
localhost:3000 is refused, your dev server isn't running, crashed on start, or is on another port. Check the terminal it runs in. Inside Docker, localhost means the container itself, not your machine.Refused vs timed out
Refused is fast and definite: the machine is reachable, but nothing's listening. A timeout (ERR_CONNECTION_TIMED_OUT) means nothing answered at all. The difference tells you whether to look at the service or the network. Behind Cloudflare, this same problem shows up as error 521.
A crashed web server is a classic “nobody noticed for hours” outage. An uptime monitor that checks every minute catches it straight away, with the error recorded so you know it was a refusal, not a slow page.
Keep reading
- Browser errors · TroubleshootingERR_CONNECTION_TIMED_OUT: why a site takes too long to respondNothing answered your browser at all. How to tell a firewall dropping traffic from a server that's down or a domain pointing to the wrong IP.October 5, 2026 · 4 min read
- Browser errors · TroubleshootingDNS_PROBE_FINISHED_NXDOMAIN: fix 'this site can't be reached'DNS says the domain doesn't exist. Fixes for visitors, and for owners: expired domains, missing records, moved name servers and domains on hold.October 5, 2026 · 4 min read