ERR_CONNECTION_TIMED_OUT: why a site takes too long to respond

Nothing answered your browser at all. How to tell a firewall dropping traffic from a server that's down or a domain pointing to the wrong IP.

· 4 min read · By the Spot Downtime team

ERR_CONNECTION_TIMED_OUT (“example.com took too long to respond”) means your browser tried to connect to the server and heard nothing back. Not a refusal, not an error page: silence, until the browser gave up. That silence is the clue. Something between you and the server is dropping packets, or the server isn't there.

Quick checks for visitors

  • See whether the site is down for everyone.
  • Try another network (mobile data instead of Wi-Fi). If it works there, your network or ISP is the issue.
  • Disable VPN, proxy and any firewall or antivirus web filter temporarily.
  • Flush your DNS cache, in case you're connecting to an old IP address.
Is it down for everyone?Check the site from outside your network, with the exact error it returns.

Causes for site owners

A firewall drops the traffic

The top cause. A cloud firewall or security group without a rule for port 443, a host firewall with a default drop policy, or an IP block that caught real visitors. Dropped packets never get an answer, so clients wait and time out.

bash
sudo ufw status verbose
sudo iptables -L -n -v | head -40
# plus your cloud provider's firewall / security group rules

The server is down or unreachable

The machine is off, crashed hard, or lost its network. If you can't SSH in either, it's the server or its network, not the web server software.

DNS points to the wrong IP

An A record pointing to an old server that was shut down, or an IP that was reassigned. Compare the DNS answer with your server's current address.

The server is overwhelmed

Under very heavy load (or an attack), the server can't accept new connections fast enough, and some time out while others succeed.

Narrowing it down

bash
dig +short example.com                    # which IP?
nc -vz -w 5 203.0.113.10 443              # does the port answer?
traceroute -T -p 443 203.0.113.10         # where does the path stop?
DNS lookupCheck which IP addresses the domain points to.Open port checkerTest whether port 443 answers from the internet. A timeout here means a firewall or an unreachable server.

Works for you, not for others?

If you allowlisted your own IP during setup, the site works perfectly for you and times out for everyone else. Always test from outside your own network.

The fast-failing cousin of this error is ERR_CONNECTION_REFUSED; behind Cloudflare, the same situation is error 522. A TCP port monitor on your server's port 443 tells you within a minute when it stops accepting connections.

Keep reading