Emergency server help: get in touch

Cloudflare Error 521, 522 and 525 on cPanel: Fixes

Diagnose and resolve Cloudflare 521 (origin refused), 522 (connection timed out) and 525 (SSL handshake failed) on cPanel servers by checking CSF blocks, Apache status, origin certificates and the SSL mode, with commands to verify each fix.

Published Updated 6 min read

When a site behind Cloudflare shows a 5xx page with the Cloudflare branding, the edge could not complete a request to your cPanel server. The three codes in the title map to three distinct failure points, and knowing which one you have cuts the diagnosis time in half. Error 521 means the origin actively refused the TCP connection. Error 522 means the connection attempt timed out with no reply. Error 525 means TCP connected but the TLS handshake with the origin failed. All three are origin-side problems, not Cloudflare outages, although a Cloudflare status incident is worth ruling out first.

Short answer: For 521 check that Apache is running and that the site’s IP and port 443 are open; for 522 check that CSF or another firewall is not blocking Cloudflare’s IP ranges and that the server is not overloaded; for 525 check the SSL mode in Cloudflare and make sure the domain has a valid certificate on the origin that matches the hostname. Run curl -Ik --resolve domain:443:ORIGIN_IP https://domain/ from outside to test the origin directly and bypass Cloudflare.

Confirm which side is failing

Test the origin without Cloudflare in the path from a machine outside the server’s own network:

curl -Ik --resolve example.com:443:203.0.113.10 https://example.com/
curl -I --resolve example.com:80:203.0.113.10 http://example.com/

A refused connection points to 521, a hang to 522, and a TLS error such as alert handshake failure or a certificate name mismatch to 525. Then check whether the problem is global or limited to Cloudflare’s addresses by running the same test from the server’s own shell with curl -Ik https://127.0.0.1/ -H "Host: example.com". If local works and remote fails, the network or firewall is involved.

Error 521: origin refused

On the cPanel server confirm Apache is running and listening:

systemctl status httpd
ss -ltnp | grep -E ':(80|443) '
/scripts/restartsrv_httpd

Common causes are Apache having crashed after a configuration change, a stale httpd.conf rebuild, or a site whose IP was changed in WHM » Change a Site’s IP Address without the DNS record in Cloudflare being updated. Compare the A record in the Cloudflare dashboard with the address in /etc/userdatadomains for the account. If Apache is fine and the port is open, check that CSF is not returning a TCP reset for Cloudflare: csf -g 173.245.48.1 shows whether an address is in the deny list or the temporary block list.

Error 522: connection timed out

Timeouts are nearly always a firewall dropping packets or a server too busy to answer. Start with CSF and LFD, because Cloudflare’s shared addresses trip login-failure and port-scan triggers easily when many sites share them. Add the current Cloudflare IPv4 and IPv6 ranges to /etc/csf/csf.allow and /etc/csf/csf.ignore, then restart:

csf -a 173.245.48.0/20 Cloudflare
csf -ra
grep -c "Cloudflare" /etc/csf/csf.allow

Repeat for each published range, and keep the list refreshed because ranges change occasionally. If you use Imunify360 instead of or alongside CSF, whitelist the ranges there as described in Whitelist IPs and countries in Imunify360 from the CLI. Next check load: uptime and top on a server that is swapping will show the reason at once, and Apache’s MaxRequestWorkers being exhausted produces intermittent 522s under traffic. Finally confirm the origin’s own upstream is not the problem: an ISP null route after a DDoS makes every Cloudflare request time out while local tests succeed.

Error 525: SSL handshake failed

A 525 means Cloudflare connected but could not agree on TLS. The typical cause is the Cloudflare SSL mode set to Full (strict) while the origin serves the cPanel default self-signed certificate for that hostname, or serves a certificate for a different name because the site was added to Apache without SNI working. Check what the origin presents:

openssl s_client -connect 203.0.113.10:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

If the subject is the server hostname or the dates are expired, run AutoSSL for the account with /usr/local/cpanel/bin/autossl_check --user=account or install a Cloudflare Origin CA certificate through WHM » Install an SSL Certificate on a Domain. Alternatively drop the Cloudflare mode to Full while the origin certificate is sorted out; do not use Flexible, which sends plain HTTP to the origin and breaks anything that redirects to HTTPS. Note that AutoSSL’s HTTP validation can itself fail behind the proxy; the DNS proxy and real IP guide covers the DCV exceptions.

Verify and prevent recurrence

After the fix, load the site through Cloudflare with curl -I https://example.com/ and look for the cf-cache-status header, which proves the request went through the edge to the origin. Then add the Cloudflare ranges to the firewall’s allow lists permanently and install a real-IP module so the logs show visitor addresses rather than Cloudflare’s, otherwise the next LFD block will be a repeat. The common pitfall is whitelisting only IPv4 while the zone is also served over IPv6, so Cloudflare’s IPv6 connectors still get blocked and the error returns intermittently.

Cloudflare 521, 522 and 525 errors comparedError 521 means the origin refused the connection, 522 that it did not answer in time, and 525 that the SSL handshake with the origin failed.Which part of the path failed521Web server downOrigin refused the TCPconnection.Check: web service running,firewall allows CF IPs.522Timed outOrigin did not answerin time.Check: DNS points to theright IP, server load,dropped packets.525TLS failedTCP worked but TLS didnot.Check: valid cert on 443,SNI / vhost for the name,SSL mode Full (strict).
Diagram: 521 = origin refused, 522 = origin timed out, 525 = TLS handshake with the origin failed.

Cloudflare error 521 at a glance

Cloudflare Error 521, 522 and 525 on cPanel summary card: For 521 check that Apache is running and that the site's IP and port 443 are open; for 522 check that CSF or another…
In short: For 521 check that Apache is running and that the site’s IP and port 443 are open; for 522 check that CSF or another firewall is not blocking Cloudflare’s IP ranges and that the server is not overloaded; for 525 check the SSL mode in…

Official documentation: Cloudflare developer docs, cPanel & WHM documentation, Linux man pages.

Related guides: Cloudflare Tunnel (cloudflared): expose an internal service without opening ports · Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right · AutoSSL failed: fixing DCV errors, CAA records, CDN proxies and blocked /.well-known/.

Frequently asked questions

Does Cloudflare error 522 also appear when the cPanel server is under a DDoS attack?

Yes. If the origin’s network is saturated or the provider has null-routed the IP, Cloudflare’s connection attempts time out and every visitor sees a 522 even though the server itself is up.

How long does it take for a Cloudflare 525 fix to take effect?

Changing the SSL mode or installing a new origin certificate takes effect within a minute or two, since Cloudflare does not cache the TLS failure for long; retry after clearing the browser cache.

Can I undo whitelisting Cloudflare ranges in CSF?

Yes. Remove the lines from /etc/csf/csf.allow and /etc/csf/csf.ignore, then run csf -ra; however, without them a busy Cloudflare-fronted server will block the edge again sooner or later.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.