Cloudflare Error 521: Web Server Is Down

Cloudflare couldn’t connect to your origin — the connection was refused.

Seen on: Cloudflare

Meaning

The origin actively refused Cloudflare’s TCP connection: the web server is stopped, isn’t listening on 80/443, or a firewall is rejecting Cloudflare IPs.

Common causes

  • Web server process stopped
  • Not listening on port 443 while SSL mode is Full/Strict
  • Origin firewall/fail2ban blocking Cloudflare IP ranges
  • Wrong origin IP in DNS records

⚡ Quick fix

  1. Start/restart the web server
  2. Confirm it listens on 80/443 (ss -ltnp)
  3. Allow Cloudflare IP ranges in the firewall
  4. Verify the A/AAAA record points to the right origin

Detailed fix by platform

Cloudflare

  1. If SSL mode is Full or Strict, the origin must accept HTTPS on 443.
  2. Check fail2ban-client status for banned Cloudflare IPs.

How to diagnose

  1. Service — Is nginx/apache running?
  2. Ports — Listening on 80/443?
  3. Firewall — Cloudflare IPs allowed?
  4. DNS — Origin IP correct?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.