Cloudflare Error 521: Web Server Is Down
Cloudflare couldn’t connect to your origin — the connection was refused.
Seen on:
Cloudflare
Meaning
The origin actively refused Cloudflare’s TCP connection: the web server is stopped, isn’t listening on 80/443, or a firewall is rejecting Cloudflare IPs.
Common causes
- Web server process stopped
- Not listening on port 443 while SSL mode is Full/Strict
- Origin firewall/fail2ban blocking Cloudflare IP ranges
- Wrong origin IP in DNS records
⚡ Quick fix
- Start/restart the web server
- Confirm it listens on 80/443 (
ss -ltnp) - Allow Cloudflare IP ranges in the firewall
- Verify the A/AAAA record points to the right origin
Detailed fix by platform
Cloudflare
- If SSL mode is Full or Strict, the origin must accept HTTPS on 443.
- Check
fail2ban-client statusfor banned Cloudflare IPs.
How to diagnose
- Service — Is nginx/apache running?
- Ports — Listening on 80/443?
- Firewall — Cloudflare IPs allowed?
- DNS — Origin IP correct?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026