Web

Cloudflare Error 522 Connection Timed Out: Causes and Fixes

Talha Aslan 18 min read 3 views

What is Cloudflare Error 522 and what should you do first?

Cloudflare Error 522 is a timeout. It means Cloudflare tried to open a connection to your origin server and did not get a timely reply. The problem usually sits on the server or in the firewall in front of it, not with the visitor. Check that your server is up, then confirm it allows Cloudflare IP ranges.

Do not change everything at once. Instead, follow this order, so you can narrow down the layer quickly.

  1. Check that your origin server is running and not out of resources.
  2. Open your Cloudflare DNS records and confirm the A record points to the right server IP.
  3. Make sure your server firewall does not block Cloudflare IP ranges.
  4. Send your hosting provider the error code, the time, and the affected URL.
  5. Avoid random Cloudflare setting changes until you know the cause.

We explain each step below. We also show you how to tell whether the problem sits with you or with your host.

What does the Cloudflare Error 522 screen look like?

First, visitors see a Cloudflare error page instead of your website. The page shows the error code and a title similar to "connection timed out". The official documentation names it "Error 522: connection timed out". However, the wording and layout of that page can change over time.

The screen also carries a useful hint. The error does not come from the visitor browser or from Cloudflare itself. It comes from the server that Cloudflare tried to reach.

So read it as "Cloudflare cannot reach my site" instead of "my site crashed". That shift helps you look in the right place: the origin server and the network path to it.

Why does Cloudflare Error 522 happen?

Cloudflare sits between your visitors and your server as a reverse proxy. When a visitor requests a page, Cloudflare first tries to open a TCP connection to your origin. If the server does not answer in time, Cloudflare gives up and shows Error 522.

The official documentation describes two cases. In the first, Cloudflare starts a connection and never receives the acknowledgment from the server. In the second, the connection opens, but Cloudflare still gets no answer to its request for the resource.

Therefore a 522 does not mean your application threw an error. In most cases the server is unreachable at the network level before your code even runs. For that reason, checking PHP or WordPress logs often sends you in the wrong direction.

Cloudflare's own guide makes the same point. The cause is not always visible in the origin error logs. So check the logs of every layer between Cloudflare and your server: load balancers, caches, proxies, and firewalls. A request can get stuck in any of them before it reaches your application.

How does Cloudflare connect to your origin server?

Knowing how the connection works makes the error easier to read. For example, every web request goes through a handshake before data moves. First the client sends a request packet. Then the server answers with an acknowledgment. After that, the client confirms it.

Cloudflare plays the client role toward your server. In other words, to your server Cloudflare does not look like an ordinary visitor. All requests arrive from a known set of IP ranges and carry traffic for many visitors.

That has three practical effects:

  • Your firewall may treat many requests from one source as an attack.
  • Your server will see Cloudflare IPs instead of real visitor IPs, and that is normal.
  • If a network device on the path drops packets, the error shows up across the whole site.

In short, a 522 is a broken handshake. You then look for the cause on the server, in the firewall, or on the network path.

Is your server firewall blocking Cloudflare IP ranges?

The official documentation lists this as the most common cause. Because of that, Cloudflare IP addresses can hit a rate limit or a full block in an .htaccess file, in iptables rules, or in a firewall. Your hosting provider has to allow all Cloudflare IP ranges.

The block often happens automatically. For example, an intrusion prevention tool on your server sees many requests from one IP and bans it. Cloudflare carries many visitors through few IPs, so that rule triggers easily.

Check these points:

  • Does the firewall deny list contain Cloudflare ranges?
  • Did a brute force protection tool ban Cloudflare IPs automatically?
  • Do web application firewall rules cut these requests?
  • Do rate limit rules also apply to requests from Cloudflare?

Always take the current ranges from the official Cloudflare IP list. Do not memorize them, because they can change.

Is your server down, overloaded, or dropping packets?

The second common cause is a server that cannot answer. For example, it may have shut down, restarted, hit its CPU or RAM limit, or started dropping network packets. Cloudflare then gets no reply to its connection attempt.

Load problems appear often on shared hosting. When a neighbor account eats resources, the server may accept fewer connections. We covered shared hosting resource limits before. An error that comes and goes by the hour is one sign.

If you can reach the server over SSH, look at the load. We explain how to read load average in a separate guide. Also confirm that the web server service runs and listens on the right port.

If the server is fully down, the fix sits with your host. So your first job is to learn the server status from the panel and from support.

If the server is up but silent, think about memory exhaustion. For example, a plugin or a scheduled task that eats memory can stop the web server from accepting new connections. Cloudflare's attempts then fail and you see a 522. A restart gives short relief, but the problem returns until you find the trigger.

Can a wrong IP in your Cloudflare DNS record cause Error 522?

Yes, and it is a common cause. According to the official source, a mismatch between the origin IP in Cloudflare DNS and the current IP of your server can trigger a 522. This happens easily after a server move or an IP change.

The old IP may now point to another machine or to a server that is switched off. Cloudflare keeps trying that address and gets no answer. Also check subdomains, because each one can have its own record.

To verify, do this:

  1. Note the current server IP from your hosting panel.
  2. Compare it with the A and AAAA records in Cloudflare DNS.
  3. Check the records of each subdomain one by one.
  4. Reload the site after each change.

You can see the records yourself with our DNS lookup tool. You can also check who owns an IP with the IP lookup tool.

Can disabled keepalive trigger Cloudflare Error 522?

The official documentation also lists disabled keepalive on the origin web server as a possible cause. Keepalive keeps a connection open after a request instead of closing it each time. So Cloudflare does not need to open a new connection for every request.

With keepalive off, every request needs a fresh connection. Under heavy traffic, that pushes the connection limit of your server. As a result, some attempts time out and visitors see a 522.

This setting lives in your web server configuration. However, menu and setting names differ by server type, so we do not give exact names. Ask your hosting support or server admin to check the keepalive setting.

Keep in mind that keepalive alone is not always the answer. A very long wait time holds idle connections open and can fill the connection pool. So pick a balanced value for your capacity, then watch the result after the change.

Note: on shared hosting you may not be able to change this yourself. In that case, open a clear support ticket.

Can a network routing problem cause Error 522?

Yes. However, sometimes the server runs and the firewall is fine, but something on the network path between Cloudflare and your server fails. A router may drop packets, or a link may clog at one point. In that case the error often comes and goes.

The official documentation suggests collecting MTR or traceroute output to diagnose this. These tools show where packets disappear. If you send the output to your host, they find the problem much faster. We explain the tool in our guide to traceroute and tracert.

Cloudflare also offers Origin Analytics, which can help you see TCP connection failures on specific paths. Because the dashboard changes over time, look for the relevant section in your Cloudflare account.

We covered latency basics in our post on ping and latency. In network path problems, the host or its upstream provider usually owns the fix.

How does Cloudflare Error 522 differ from 521 and 524?

Cloudflare 5xx errors look alike, but each points to a different spot. The official page names 521 "web server is down", 522 "connection timed out", 523 "origin is unreachable", and 524 "a timeout occurred".

ErrorShort meaningFirst place to look
522The connection did not open or the reply came too lateFirewall, server load, DNS IP, keepalive
521The web server looks downWeb server service, port, server status
523The origin cannot be reachedNetwork path and routing
524A timeout occurredLong running server tasks

In short, 522 points to the connection stage. A 524 suggests the connection worked, but the answer took too long. You can read the details of each code in the Cloudflare 5xx error guide.

What is the step by step checklist for site owners?

Let us turn all of this into one plan. First, the list starts with the cheapest and safest checks. No step asks you to make a permanent change that puts your site at risk.

  1. Note the error code, the timestamp, and the URL. Take a short screenshot.
  2. Open your site from another network, for example mobile data, to see whether the problem is wide.
  3. Confirm in your hosting panel that the server is up and below its resource limits.
  4. Check that the A record in Cloudflare DNS shows the right IP.
  5. Confirm that firewall rules and .htaccess do not block Cloudflare ranges.
  6. Review the keepalive setting together with your host.
  7. If the problem stays, collect MTR or traceroute output and send it to support.

After each step, reload the site and write down the result. That way you see which change helped. Also, you will have a ready diagnosis history if the same issue returns.

The order matters. If you change Cloudflare settings without knowing the cause, you move two variables at once and lose track of what worked.

What should you tell your hosting provider?

The official documentation advises you to share the error code, the time, and the affected URL with your host. Cloudflare support usually helps domain owners only. So when the server is the source, your host is your main contact.

Also, a clear ticket shortens the fix. For example, include this information:

  • The error code and roughly when it first appeared.
  • The affected URLs: the whole site or only some pages.
  • Recent changes: a move, an IP change, a plugin, or a security setting.
  • A question about whether Cloudflare IP ranges are allowed.
  • A request for server resource usage and connection logs.

We are not a hosting company. As a team we prepare such tickets often on web projects. A clear ticket often points you the right way in the first reply.

What changes if you use Cloudflare Pages or Workers?

The official documentation also gives separate notes here. With Cloudflare Pages, check your custom domain setup. A custom domain that is linked wrongly can lead to a 522.

For Workers, one detail matters. A Worker that fetches its own hostname needs a special configuration. Otherwise the request loops back on itself and times out. Read the details of this behavior on the official page.

If you use Origin Rules, make sure the target hostname resolves. If the name the rule points to does not resolve, Cloudflare cannot connect to the server.

So, beyond classic hosting problems, review the setup inside Cloudflare too. Still, on most sites the cause sits on the origin server.

In practice, ask one more question: did our team write this rule, or did we copy a template? Templates often keep old hostnames and targets. So when you review a configuration, confirm that every rule points to today's server.

What can visitors do when they see Cloudflare Error 522?

As a visitor you cannot fix the problem, because it also sits on the server side of the site owner. Still, you can try a few simple things. That way you learn whether the problem is only on your side.

  1. Reload the page after a few minutes, because a short load spike may be the cause.
  2. Try the same address from another device or from mobile data.
  3. Open a different page of the same site.
  4. Tell the site owner through another channel: email, social media, or phone.

Clearing the browser cache or turning off a VPN rarely helps. The connection problem sits between Cloudflare and the server, not between you and the site. Also, if you do not own the site, do not expect a fix from Cloudflare support.

How do you diagnose an error that comes and goes?

Intermittent 522 errors are harder to catch than constant ones. The server works most of the time, so it fails only at certain moments. That pattern usually points to load, a rate limit, or partial network loss.

First, record when the error appears. If it rises at busy hours, the server may lack resources. If it appears at the same time every day, a scheduled task, a backup, or a scan may overload the server.

Also, if the error shows up only for visitors from some countries, your firewall may block some Cloudflare servers in that region. So search your firewall logs for denied requests from Cloudflare ranges.

For a broader speed and resource check, our guide on server side causes of a slow website helps too.

Does Cloudflare Error 522 hurt SEO?

A short 522 usually does not cause a big problem. However, if the error lasts, search engine bots cannot reach your site and crawling can slow down. Google says in its own documentation that it may reduce crawl rate on sites with server errors.

For that reason, speed matters. If the outage drags on, indexed pages can suffer. We cannot give an exact duration or loss, because it depends on your site size and how widespread the error is.

While the error lasts, watch the crawl stats in Search Console. Also, check your key pages by eye once the site works again. Seeing product or service pages load cleanly is a good sign that recrawling can restart. For technical visibility topics, see our SEO consulting service.

For similar server errors, read our posts on 502 Bad Gateway and 503 Service Unavailable.

Is turning Cloudflare off a real fix for Error 522?

Many people pause the Cloudflare proxy to get around the problem. This method helps you learn whether the problem sits between Cloudflare and the origin or in the server itself. However, it is not a lasting fix.

With the proxy off, visitors go straight to your server. If the server is still down or overloaded, the site still does not open. Moreover, your real server IP stays public, and you lose Cloudflare protection and caching.

So do this only for diagnosis, for a short time, and on purpose. Find where this setting sits in the current Cloudflare interface. After you find the cause, turn the proxy back on.

The real job is to allow Cloudflare IP ranges and keep the server healthy. Also, if you changed a temporary setting while diagnosing, write it down. Forgotten temporary settings create new and harder problems weeks later.

How does server security work together with Cloudflare?

If you tighten security without thinking about Cloudflare, you raise the risk of a 522. Brute force protection, automatic IP bans, and a web application firewall can all block Cloudflare IPs by mistake.

The fix is to add Cloudflare ranges to the allow list of these tools. We covered Fail2ban setup and ModSecurity and 403 errors earlier. Review their rules with this point in mind.

To see real visitor IPs in your logs, your server needs a setup that reads the headers Cloudflare passes along. That way security tools judge visitors one by one, and do not treat Cloudflare as suspect in bulk.

If you will not make this change yourself, ask your server admin for it in plain terms.

Example scenario: why does a 522 appear after a server move?

Example scenario: a team moves a site to a new server and copies every file. However, they forget to update the A record in Cloudflare DNS. Cloudflare keeps connecting to the IP of the old server.

If the old server is shut down or handed to someone else, the connection attempts get no answer. So visitors see a 522. Meanwhile the site may run fine on the new server.

The diagnosis here is simple. First check the DNS record. Then check the firewall on the new server, because it may not allow Cloudflare ranges yet.

You can find the steps before and after a move in our hosting change checklist. In other words, add a DNS check and a firewall check to your move plan from the start.

This is an example scenario and not a real client case. Still, a 522 after a move is a common pattern in the field.

Which other errors do people confuse with Cloudflare Error 522?

Some errors look similar at first glance but come from a different place. Telling them apart keeps you from searching in the wrong spot. We separate them briefly below.

A quick way to tell them apart: if you see a Cloudflare branded error page, the problem sits between Cloudflare and the origin. If you see the browser own error screen, the problem sits on the visitor side or at domain level.

So look at who produced the screen. It is the first and cheapest diagnostic step.

Which free tools help with diagnosis?

However, a few simple lookups can narrow the problem. Also, you do not need server access for them. The tools below are enough for a first check.

  • DNS lookup shows which records your domain resolves to. Our DNS lookup tool does this.
  • IP lookup tells you which network and company owns the IP in your record.
  • Certificate check shows whether the endpoint has a certificate problem. Use our SSL checker.
  • Access tests from different networks show how widespread the problem is.

Note these results and attach them to your ticket. Support then works with facts instead of guesses. Moreover, you can compare results if the same error returns later.

Tools only give hints. The exact cause shows up in server logs and firewall settings.

How do you keep visitors informed while the error lasts?

If the outage drags on, talk to your visitors. It limits the loss of trust. Post a short note on your social accounts and in your email signature. You do not need technical detail; saying that you know and you are working on it is enough.

Then, if you sell online, keep another order channel open, such as phone or messaging. That way you do not lose customers completely during the outage. Also, if you run ads, think about pausing campaigns while the site is down, so you do not waste budget.

You can review ad results with our ROAS calculator. Also, your ad account may show landing page errors during the outage. Fix the site first, then switch the campaigns back on.

After the outage, run a short check: do the home page, the checkout step, and the contact form work? That way you know the problem is really over.

How do you stop Cloudflare Error 522 from coming back?

A lasting fix takes more than a one time repair. The habits below lower the chance that the error returns. They also shorten your diagnosis time when a problem appears.

  • Keep the Cloudflare IP list as an allow list in your server security rules, and watch for changes.
  • Re-check DNS records after every server move and IP change.
  • Watch server resource use, and review your plan before you hit the limits.
  • Set up external uptime monitoring, so you notice the error before your visitors do.
  • Agree with your host on a contact channel for incidents ahead of time.

If capacity problems keep returning, consider an upgrade. Our hosting upgrade guide helps you plan the switch.

For a new website project, our web design service covers these infrastructure choices from the start.

What is the final takeaway on Cloudflare Error 522?

Cloudflare Error 522 is a fault of the connection path, not of your application. Most of the time it comes from a firewall that blocks Cloudflare IPs, a server that is down or busy, a wrong IP in DNS, or the keepalive setting.

Stay calm and go in order. First check the server, then the DNS record, then the firewall. If needed, send your host a clear ticket.

This article is general guidance based on the official Cloudflare documentation. Menu names and behavior can change, so verify current details on the official Cloudflare Error 522 page. We cannot promise a guaranteed result for any step, because every setup differs.

Frequently Asked Questions

What does Cloudflare Error 522 mean?
Cloudflare Error 522 means Cloudflare could not connect to your origin server in time. In other words, the link between the visitor and Cloudflare works, but the link between Cloudflare and your server did not open. Typical causes are a server that is down or busy, a firewall that blocks Cloudflare, or a wrong IP in DNS.
How do you fix Cloudflare Error 522?
First confirm that your server is up and not overloaded. Then check that the IP in your Cloudflare DNS record is correct and that your firewall does not block Cloudflare IP ranges. If the error stays, send the error code, the time, and the URL to your host. Most cases get solved on the server side, but we cannot guarantee a result.
What is the difference between Error 522 and 524?
A 522 is a timeout during the connection stage, so Cloudflare cannot reach your server. A 524 means the connection worked, but the server answered too slowly. So for a 522 you check firewall and network access, and for a 524 you look at long running server tasks.
Can a visitor fix Cloudflare Error 522?
No, because the problem sits on the server side of the site owner. As a visitor you can reload after a few minutes, try another network, and tell the site owner. Clearing the browser cache or turning off a VPN rarely helps, because the failing link runs between Cloudflare and the server.
Does Cloudflare Error 522 hurt my website?
A short error usually causes no lasting harm. However, a long outage costs you visitors, and search engine bots may crawl less when they cannot reach the site. So fix it quickly. We cannot give an exact impact, because the result depends on your site and on how long the error lasts.
Will turning off Cloudflare fix Error 522?
Usually not. With the proxy off, visitors connect straight to your server, and if the server is down or overloaded the site still fails. Use it only for a short diagnosis and turn it back on afterward. Also, your real server IP becomes public and you lose Cloudflare protection while it is off.
  • cloudflare error 522
  • connection timed out
  • cloudflare errors
  • origin server
  • firewall
  • hosting problems
  • website not loading
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.