Skip to content
Hosting Operations11 min read

How to Fix Cloudflare Error 520: Comparison and Best Practices

Compare proven methods to resolve Cloudflare error 520. Practical troubleshooting steps, origin server checks, and best practices for website owners.

Written by Abdul AbrorTechnical Hosting Support Engineer
a close up of a cell phone screen with a line graph on it
On this page

TL;DR — Key takeaways

  • Cloudflare error 520 occurs when your origin server returns an empty, unknown, or unexpected response to Cloudflare, typically due to server overload, firewall blocks, or application crashes.
  • Server-side diagnostics (checking logs, resource usage, and firewall rules) resolve 80% of error 520 cases faster than Cloudflare configuration changes alone.
  • Temporarily pausing Cloudflare proxy allows you to isolate whether the issue is origin-side or Cloudflare-side without changing DNS records.
  • Long-term prevention requires rate limiting, health monitoring, proper timeout configurations, and whitelisting Cloudflare IP ranges in your firewall.
  • If the origin server responds correctly when tested directly but fails through Cloudflare, verify SSL/TLS mode compatibility and origin certificate validity.

Cloudflare error 520 appears when Cloudflare successfully connects to your origin server but receives an empty, unknown, or protocol-violating response. Unlike timeout errors, the connection completes—your server just doesn't respond correctly. This error is always origin-side, meaning the fix lies with your web server, application, or hosting infrastructure rather than Cloudflare's network.

This guide compares the most effective troubleshooting approaches, evaluates trade-offs between quick fixes and long-term solutions, and provides a decision framework for different hosting environments. You'll learn how to diagnose root causes, choose the right fix for your situation, and prevent recurrence.

What Cloudflare Error 520 Means

Error 520 is Cloudflare's catch-all response when your origin server returns something unexpected. The error message typically reads: 'Web server is returning an unknown error.' This happens when the origin completes the TCP handshake but then sends an empty response, crashes mid-request, or violates HTTP protocol expectations.

Common underlying causes include web server crashes, application-level exceptions that bypass error handlers, resource exhaustion (CPU, memory, or connection limits), firewall rules that drop requests after the initial connection, and origin server misconfigurations that send malformed HTTP responses.

Error 520 differs from error 521 (server down), error 522 (connection timeout), and error 524 (timeout after connection). With 520, the connection succeeds—the problem is what happens after. This distinction guides troubleshooting: you're looking for runtime failures, not connectivity issues.

Comparison: Server-Side Diagnostics vs Cloudflare Configuration Changes

For most website owners and support engineers, the hybrid approach prevents wasted time. Checking logs takes 30 seconds and often reveals the exact problem. Pausing Cloudflare for 5 minutes confirms whether the origin works independently. Only then should you modify Cloudflare settings.

  • Server-side diagnostics approach: Check web server error logs, review resource usage (top, htop, or hosting panel metrics), verify firewall rules aren't blocking Cloudflare IPs, test the origin server directly via IP address or hosts file override, and check for application crashes or exceptions. This approach identifies the actual failure point and typically resolves 520 errors within minutes once the root cause is found.
  • Cloudflare configuration approach: Adjust SSL/TLS mode, modify timeout settings, disable specific Cloudflare features (WAF rules, bot fight mode, rate limiting), or pause Cloudflare proxy entirely. This approach helps when Cloudflare features interact poorly with origin behavior, but often delays resolution if used without server-side diagnosis first.
  • Hybrid approach (recommended): Start with server-side logs and resource checks to understand what's failing. Use Cloudflare's pause feature to isolate whether the issue persists without Cloudflare. Then apply targeted Cloudflare configuration changes if needed. This combines speed with accuracy.

Step-by-Step Troubleshooting Process

If none of these steps resolve the issue, the problem likely involves application-specific behavior. Check your CMS or application logs for unhandled exceptions. Review recent plugin, theme, or code changes that coincide with when 520 errors began.

  • Step 1: Check origin server logs immediately. Look in your web server error log (Apache error_log, Nginx error.log, or hosting panel error viewer) for entries timestamped when the 520 occurred. Common indicators: segmentation faults, PHP fatal errors, application exceptions, or 'Premature end of script headers' messages.
  • Step 2: Verify server resource availability. SSH into your server or use your hosting panel to check CPU, memory, and active connections. If CPU is maxed or memory is exhausted, your server may be crashing under load. Restart the web server service as a temporary fix, then investigate the traffic spike or resource leak.
  • Step 3: Test origin directly. Add an entry to your local hosts file pointing your domain to the origin IP, or access the site via the origin IP address directly. If the error disappears, the origin works—the issue involves Cloudflare interaction. If it persists, focus on origin-side fixes.
  • Step 4: Whitelist Cloudflare IP ranges. Many firewalls (CSF, Fail2Ban, server-level iptables) block or rate-limit Cloudflare IPs if they appear to generate high request volumes. Download Cloudflare's IP list from their documentation and whitelist these ranges in your firewall configuration. Restart the firewall service after applying changes.
  • Step 5: Verify SSL/TLS configuration. In Cloudflare's SSL/TLS settings, confirm your encryption mode matches your origin's capabilities. If your origin has a valid SSL certificate, use 'Full (strict)'. If it has a self-signed certificate or no certificate, use 'Full' or 'Flexible'. Mismatches cause protocol errors that can trigger 520 responses.

Comparing Quick Fixes vs Long-Term Solutions

For high-traffic sites or customer-facing applications, keeping a runbook with proven quick fixes reduces mean time to recovery. For smaller sites, focus on long-term prevention to avoid recurring fire drills.

  • Quick fixes: Restart the web server or application service to clear crashed processes. Temporarily pause Cloudflare proxy to bypass the error while diagnosing. Increase PHP memory_limit or max_execution_time if resource exhaustion is confirmed. Clear application caches that may contain corrupted state. These restore service within minutes but don't prevent recurrence.
  • Long-term solutions: Upgrade server resources if consistently hitting CPU or memory limits. Implement rate limiting at the application or server level to prevent overload. Set up health monitoring and alerting to catch failures before users report them. Configure proper error handling in your application to return valid HTTP responses even during failures. Optimize slow database queries or inefficient code causing timeouts. These take hours to days but prevent future 520 errors.
  • Risk-aware approach: Apply the quick fix first to restore service. Document the incident details (timestamps, logs, symptoms). Schedule the long-term fix during a maintenance window with proper testing. This balances business continuity with sustainable operations.

Cloudflare-Specific Configuration Adjustments

Before changing Cloudflare settings, use the 'Pause Cloudflare on Site' option as a diagnostic tool. If pausing Cloudflare resolves the error, you've confirmed a configuration issue rather than an origin problem. Resume Cloudflare and adjust settings incrementally, testing after each change.

  • SSL/TLS mode: If your origin uses HTTP only, set encryption to 'Flexible'. If it has any SSL certificate (including self-signed), use 'Full'. If it has a valid certificate from a trusted CA, use 'Full (strict)'. Mismatches cause Cloudflare to classify the response as invalid.
  • Origin connection timeout: In Cloudflare's Speed settings, check that 'Origin Max HTTP Version' and timeout settings align with your server's response times. If your application has legitimate long-running requests (large file processing, report generation), you may need enterprise-level custom timeout configurations.
  • WAF and bot protection rules: Navigate to Security → WAF and review recent firewall events. If legitimate requests are being challenged or blocked in ways that cause incomplete responses, adjust rule sensitivity or add bypass rules for specific paths. Check Bot Fight Mode under Security → Bots; it can cause unexpected behavior with certain legitimate bot traffic.
  • Rate limiting: If you have rate limiting rules in place, verify they're using 'Block' or 'Challenge' actions rather than misconfigured actions that might cause connection drops. Review the rule thresholds to ensure they match your actual traffic patterns.
  • Cloudflare caching: Incorrect cache rules can sometimes cause Cloudflare to cache incomplete responses from temporary origin failures. Purge everything in Cloudflare's cache after resolving an origin issue to ensure no broken responses are served.

Prevention and Monitoring Best Practices

For mission-critical sites, consider a canary deployment approach: test configuration changes on a staging environment with Cloudflare enabled before applying them to production. This catches integration issues before they affect users.

  • Implement origin health checks: Use an external uptime monitor (UptimeRobot, Pingdom, StatusCake, or your hosting provider's monitoring) to track both direct origin access and Cloudflare-proxied access. Alert on any discrepancy between the two.
  • Whitelist Cloudflare IPs permanently: Don't wait for a firewall block to cause an outage. Proactively whitelist Cloudflare's published IP ranges in your firewall, mod_security, and fail2ban configurations. Document this in your server setup checklist.
  • Set up log aggregation: Centralize logs from your web server, application, and system into a searchable location. When a 520 occurs, you need to correlate events across multiple log sources quickly. Even a simple grep-able directory is better than nothing.
  • Load test before traffic spikes: If you expect traffic surges (product launches, campaigns, seasonal events), load test your origin server directly to confirm it can handle the volume. Address bottlenecks before enabling Cloudflare caching.
  • Review Cloudflare Analytics: Check Security → Events and Analytics → Traffic regularly for patterns. A sudden increase in 520 errors often correlates with deployment changes, traffic pattern shifts, or new bot activity.
  • Maintain a rollback plan: Before enabling new Cloudflare features or changing origin server configurations, document the current working state and how to revert. Keep Cloudflare's 'Pause' option in mind as an emergency rollback for Cloudflare-side issues.

Choosing the Right Approach for Your Environment

In all cases, document your troubleshooting steps and findings. Error 520 often recurs if the root cause isn't fully addressed, and having a history helps identify patterns over time.

  • Shared hosting with limited access: You likely can't SSH or access raw logs. Use your hosting panel's error log viewer and resource usage graphs. Contact support if you see consistent resource exhaustion. Focus on application-level fixes: disable problematic plugins, reduce cron job frequency, or optimize database queries. Cloudflare's pause feature is your best diagnostic tool.
  • VPS or dedicated server with root access: Start with SSH access and tail logs in real-time while reproducing the error. Use htop to monitor resource usage. Check systemctl status for service failures. Investigate firewall logs for Cloudflare IP blocks. You have full control, so address root causes rather than applying workarounds.
  • Managed hosting or agency environment: Coordinate with your hosting provider or server administrator for access to logs and server metrics. Use Cloudflare's Analytics and Logs to provide evidence when requesting support. Document the exact timestamps and URLs affected to help support staff diagnose quickly.
  • High-traffic or e-commerce sites: Prioritize rapid diagnosis and service restoration. Keep a tested quick-fix runbook. Use Cloudflare's Load Balancing and Health Checks (enterprise feature) for automatic failover. Schedule follow-up post-incident reviews to implement preventive measures.
  • Multi-origin or load-balanced setups: Check whether 520 errors correlate with specific origin servers. Use Cloudflare's Load Balancing logs to identify unhealthy origins. The issue may be isolated to one backend rather than systematic.

Quick troubleshooting checklist

  • Review origin server error logs for crashes or exceptions at the time of 520 errors
  • Check server resource usage (CPU, memory, connections) via SSH or hosting panel
  • Test origin server directly using hosts file or IP address to bypass Cloudflare
  • Verify Cloudflare IP ranges are whitelisted in firewall, fail2ban, and mod_security
  • Confirm SSL/TLS encryption mode in Cloudflare matches origin certificate setup
  • Pause Cloudflare proxy temporarily to isolate whether issue is origin or Cloudflare-side
  • Review recent Cloudflare WAF and firewall events for blocked or challenged requests
  • Clear Cloudflare cache completely after resolving origin issues
  • Restart web server service if resource exhaustion or crashes are confirmed
  • Set up external monitoring for both direct origin access and Cloudflare-proxied access
  • Document incident details and root cause for future reference
  • Implement long-term fixes (resource upgrades, rate limiting, error handling) in maintenance window

FAQ

What causes Cloudflare error 520?

Cloudflare error 520 occurs when your origin web server returns an empty, unknown, or protocol-violating response to Cloudflare. Common causes include web server or application crashes, resource exhaustion (CPU or memory limits), firewall rules blocking Cloudflare IPs after initial connection, SSL/TLS configuration mismatches, or application errors that bypass proper HTTP error responses. The error is always origin-side, meaning the fix requires changes to your server, application, or hosting configuration rather than Cloudflare's network.

How do I fix Cloudflare error 520 quickly?

Check your origin server error logs first to identify crashes or exceptions. Verify server resource usage isn't maxed out via SSH or hosting panel. Whitelist Cloudflare's IP ranges in your firewall to prevent blocks. Test your site by accessing the origin IP directly—if it works, the origin is healthy and the issue involves Cloudflare interaction. Restart your web server service if you find resource exhaustion. As a diagnostic step, temporarily pause Cloudflare proxy in the Overview tab to confirm whether the error persists without Cloudflare. Most 520 errors resolve within minutes once you identify the origin-side failure.

Should I change Cloudflare settings or fix my server first for error 520?

Fix your server first. Error 520 is caused by origin server issues in nearly all cases, so checking server logs, resource usage, and firewall rules resolves the problem faster than adjusting Cloudflare settings. Start by verifying your origin responds correctly when tested directly. Only modify Cloudflare settings (SSL/TLS mode, WAF rules, or timeout configurations) after confirming the origin server is healthy and the error only occurs through Cloudflare. This approach prevents wasted time adjusting configurations that aren't causing the problem.