When a site behind Cloudflare shows a 5xx page with the Cloudflare branding, the edge could not complete a request to your cPanel server. The three codes in the title map to three distinct failure points, and knowing which one you have cuts the diagnosis time in half. Error 521 means the origin actively refused the TCP connection. Error 522 means the connection attempt timed out with no reply. Error 525 means TCP connected but the TLS handshake with the origin failed. All three are origin-side problems, not Cloudflare outages, although a Cloudflare status incident is worth ruling out first.
Table of Contents
Short answer: For 521 check that Apache is running and that the site’s IP and port 443 are open; for 522 check that CSF or another firewall is not blocking Cloudflare’s IP ranges and that the server is not overloaded; for 525 check the SSL mode in Cloudflare and make sure the domain has a valid certificate on the origin that matches the hostname. Run curl -Ik --resolve domain:443:ORIGIN_IP https://domain/ from outside to test the origin directly and bypass Cloudflare.
Confirm which side is failing
Test the origin without Cloudflare in the path from a machine outside the server’s own network:
curl -Ik --resolve example.com:443:203.0.113.10 https://example.com/
curl -I --resolve example.com:80:203.0.113.10 http://example.com/
A refused connection points to 521, a hang to 522, and a TLS error such as alert handshake failure or a certificate name mismatch to 525. Then check whether the problem is global or limited to Cloudflare’s addresses by running the same test from the server’s own shell with curl -Ik https://127.0.0.1/ -H "Host: example.com". If local works and remote fails, the network or firewall is involved.
Error 521: origin refused
On the cPanel server confirm Apache is running and listening:
systemctl status httpd
ss -ltnp | grep -E ':(80|443) '
/scripts/restartsrv_httpd
Common causes are Apache having crashed after a configuration change, a stale httpd.conf rebuild, or a site whose IP was changed in WHM » Change a Site’s IP Address without the DNS record in Cloudflare being updated. Compare the A record in the Cloudflare dashboard with the address in /etc/userdatadomains for the account. If Apache is fine and the port is open, check that CSF is not returning a TCP reset for Cloudflare: csf -g 173.245.48.1 shows whether an address is in the deny list or the temporary block list.
Error 522: connection timed out
Timeouts are nearly always a firewall dropping packets or a server too busy to answer. Start with CSF and LFD, because Cloudflare’s shared addresses trip login-failure and port-scan triggers easily when many sites share them. Add the current Cloudflare IPv4 and IPv6 ranges to /etc/csf/csf.allow and /etc/csf/csf.ignore, then restart:
csf -a 173.245.48.0/20 Cloudflare
csf -ra
grep -c "Cloudflare" /etc/csf/csf.allow
Repeat for each published range, and keep the list refreshed because ranges change occasionally. If you use Imunify360 instead of or alongside CSF, whitelist the ranges there as described in Whitelist IPs and countries in Imunify360 from the CLI. Next check load: uptime and top on a server that is swapping will show the reason at once, and Apache’s MaxRequestWorkers being exhausted produces intermittent 522s under traffic. Finally confirm the origin’s own upstream is not the problem: an ISP null route after a DDoS makes every Cloudflare request time out while local tests succeed.
Error 525: SSL handshake failed
A 525 means Cloudflare connected but could not agree on TLS. The typical cause is the Cloudflare SSL mode set to Full (strict) while the origin serves the cPanel default self-signed certificate for that hostname, or serves a certificate for a different name because the site was added to Apache without SNI working. Check what the origin presents:
openssl s_client -connect 203.0.113.10:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates
If the subject is the server hostname or the dates are expired, run AutoSSL for the account with /usr/local/cpanel/bin/autossl_check --user=account or install a Cloudflare Origin CA certificate through WHM » Install an SSL Certificate on a Domain. Alternatively drop the Cloudflare mode to Full while the origin certificate is sorted out; do not use Flexible, which sends plain HTTP to the origin and breaks anything that redirects to HTTPS. Note that AutoSSL’s HTTP validation can itself fail behind the proxy; the DNS proxy and real IP guide covers the DCV exceptions.
Verify and prevent recurrence
After the fix, load the site through Cloudflare with curl -I https://example.com/ and look for the cf-cache-status header, which proves the request went through the edge to the origin. Then add the Cloudflare ranges to the firewall’s allow lists permanently and install a real-IP module so the logs show visitor addresses rather than Cloudflare’s, otherwise the next LFD block will be a repeat. The common pitfall is whitelisting only IPv4 while the zone is also served over IPv6, so Cloudflare’s IPv6 connectors still get blocked and the error returns intermittently.
Cloudflare error 521 at a glance

Official documentation: Cloudflare developer docs, cPanel & WHM documentation, Linux man pages.
Related guides: Cloudflare Tunnel (cloudflared): expose an internal service without opening ports · Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right · AutoSSL failed: fixing DCV errors, CAA records, CDN proxies and blocked /.well-known/.
Frequently asked questions
Does Cloudflare error 522 also appear when the cPanel server is under a DDoS attack?
Yes. If the origin’s network is saturated or the provider has null-routed the IP, Cloudflare’s connection attempts time out and every visitor sees a 522 even though the server itself is up.
How long does it take for a Cloudflare 525 fix to take effect?
Changing the SSL mode or installing a new origin certificate takes effect within a minute or two, since Cloudflare does not cache the TLS failure for long; retry after clearing the browser cache.
Can I undo whitelisting Cloudflare ranges in CSF?
Yes. Remove the lines from /etc/csf/csf.allow and /etc/csf/csf.ignore, then run csf -ra; however, without them a busy Cloudflare-fronted server will block the edge again sooner or later.