# Cloudflare Error 521, 522 and 525 on cPanel: Fixes

Source: https://srvscripts.com/guides/cloudflare-error-521-522-525-cpanel/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

When a site behind Cloudflare shows a 5xx page with the Cloudflare branding, the edge could not complete a request to your cPanel server. The three codes in the title map to three distinct failure points, and knowing which one you have cuts the diagnosis time in half. Error 521 means the origin actively refused the TCP connection. Error 522 means the connection attempt timed out with no reply. Error 525 means TCP connected but the TLS handshake with the origin failed. All three are origin-side problems, not Cloudflare outages, although a Cloudflare status incident is worth ruling out first.

In short: For 521 check that Apache is running and that the site’s IP and port 443 are open; for 522 check that CSF or another firewall is not blocking Cloudflare’s IP ranges and that the server is not overloaded; for 525 check the SSL mode in…

**Short answer:** For 521 check that Apache is running and that the site’s IP and port 443 are open; for 522 check that CSF or another firewall is not blocking Cloudflare’s IP ranges and that the server is not overloaded; for 525 check the SSL mode in Cloudflare and make sure the domain has a valid certificate on the origin that matches the hostname. Run `curl -Ik --resolve domain:443:ORIGIN_IP https://domain/` from outside to test the origin directly and bypass Cloudflare.

## Confirm which side is failing

Test the origin without Cloudflare in the path from a machine outside the server’s own network:

```
curl -Ik --resolve example.com:443:203.0.113.10 https://example.com/
curl -I --resolve example.com:80:203.0.113.10 http://example.com/
```

A refused connection points to 521, a hang to 522, and a TLS error such as `alert handshake failure` or a certificate name mismatch to 525. Then check whether the problem is global or limited to Cloudflare’s addresses by running the same test from the server’s own shell with `curl -Ik https://127.0.0.1/ -H "Host: example.com"`. If local works and remote fails, the network or firewall is involved.

## Error 521: origin refused

On the cPanel server confirm Apache is running and listening:

```
systemctl status httpd
ss -ltnp | grep -E ':(80|443) '
/scripts/restartsrv_httpd
```

Common causes are Apache having crashed after a configuration change, a stale `httpd.conf` rebuild, or a site whose IP was changed in WHM » Change a Site’s IP Address without the DNS record in Cloudflare being updated. Compare the A record in the Cloudflare dashboard with the address in `/etc/userdatadomains` for the account. If Apache is fine and the port is open, check that CSF is not returning a TCP reset for Cloudflare: `csf -g 173.245.48.1` shows whether an address is in the deny list or the temporary block list.

## Error 522: connection timed out

Timeouts are nearly always a firewall dropping packets or a server too busy to answer. Start with CSF and LFD, because Cloudflare’s shared addresses trip login-failure and port-scan triggers easily when many sites share them. Add the current Cloudflare IPv4 and IPv6 ranges to `/etc/csf/csf.allow` and `/etc/csf/csf.ignore`, then restart:

```
csf -a 173.245.48.0/20 Cloudflare
csf -ra
grep -c "Cloudflare" /etc/csf/csf.allow
```

Repeat for each published range, and keep the list refreshed because ranges change occasionally. If you use Imunify360 instead of or alongside CSF, whitelist the ranges there as described in [Whitelist IPs and countries in Imunify360 from the CLI](/guides/imunify360-whitelist-ip-cli/). Next check load: `uptime` and `top` on a server that is swapping will show the reason at once, and Apache’s `MaxRequestWorkers` being exhausted produces intermittent 522s under traffic. Finally confirm the origin’s own upstream is not the problem: an ISP null route after a DDoS makes every Cloudflare request time out while local tests succeed.

## Error 525: SSL handshake failed

A 525 means Cloudflare connected but could not agree on TLS. The typical cause is the Cloudflare SSL mode set to Full (strict) while the origin serves the cPanel default self-signed certificate for that hostname, or serves a certificate for a different name because the site was added to Apache without SNI working. Check what the origin presents:

```
openssl s_client -connect 203.0.113.10:443 -servername example.com /dev/null | openssl x509 -noout -subject -issuer -dates
```

If the subject is the server hostname or the dates are expired, run AutoSSL for the account with `/usr/local/cpanel/bin/autossl_check --user=account` or install a Cloudflare Origin CA certificate through WHM » Install an SSL Certificate on a Domain. Alternatively drop the Cloudflare mode to Full while the origin certificate is sorted out; do not use Flexible, which sends plain HTTP to the origin and breaks anything that redirects to HTTPS. Note that AutoSSL’s HTTP validation can itself fail behind the proxy; the [DNS proxy and real IP guide](/guides/cloudflare-cpanel-dns-proxy-real-ip/) covers the DCV exceptions.

## Verify and prevent recurrence

After the fix, load the site through Cloudflare with `curl -I https://example.com/` and look for the `cf-cache-status` header, which proves the request went through the edge to the origin. Then add the Cloudflare ranges to the firewall’s allow lists permanently and install a real-IP module so the logs show visitor addresses rather than Cloudflare’s, otherwise the next LFD block will be a repeat. The common pitfall is whitelisting only IPv4 while the zone is also served over IPv6, so Cloudflare’s IPv6 connectors still get blocked and the error returns intermittently.

Diagram: 521 = origin refused, 522 = origin timed out, 525 = TLS handshake with the origin failed.

## Cloudflare error 521 at a glance

**Official documentation:** [Cloudflare developer docs](https://developers.cloudflare.com/), [cPanel & WHM documentation](https://docs.cpanel.net/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Cloudflare Tunnel (cloudflared): expose an internal service without opening ports](https://srvscripts.com/guides/cloudflare-tunnel-cloudflared/) · [Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right](https://srvscripts.com/guides/cloudflare-cpanel-dns-proxy-real-ip/) · [AutoSSL failed: fixing DCV errors, CAA records, CDN proxies and blocked /.well-known/](https://srvscripts.com/guides/autossl-failed-cpanel-dcv-caa-cdn/).

## Frequently asked questions

### Does Cloudflare error 522 also appear when the cPanel server is under a DDoS attack?

Yes. If the origin’s network is saturated or the provider has null-routed the IP, Cloudflare’s connection attempts time out and every visitor sees a 522 even though the server itself is up.

### How long does it take for a Cloudflare 525 fix to take effect?

Changing the SSL mode or installing a new origin certificate takes effect within a minute or two, since Cloudflare does not cache the TLS failure for long; retry after clearing the browser cache.

### Can I undo whitelisting Cloudflare ranges in CSF?

Yes. Remove the lines from `/etc/csf/csf.allow` and `/etc/csf/csf.ignore`, then run `csf -ra`; however, without them a busy Cloudflare-fronted server will block the edge again sooner or later.
