Skip to content
Back to Blog
DNS & Networking8 min read

520 Cloudflare Error [Solved]: 7 Fixes That Work

A 520 error means Cloudflare connected to your origin server but received an invalid or empty response. Here's how to diagnose and fix it fast.

Written by Abdul AbrorTechnical Hosting Support Engineer
520 Cloudflare Error [Solved]: 7 Fixes That Work
On this page

A 520 error means Cloudflare successfully connected to your origin web server but received an invalid, empty, or unexpected response. The origin didn't return valid HTTP headers or timed out after establishing the TCP connection. Cloudflare logs show the connection opened but no proper response came back.

This is different from a 521 (server is down) or 522 (connection timeout). With a 520, the server answered the door but said something Cloudflare couldn't parse.

I've seen this most often after a server configuration change, a PHP crash, or a firewall that blocks Cloudflare IPs mid-request. Let's walk through the fixes.

Check your origin web server logs first

Start at the origin. Cloudflare's error page won't tell you what your server said—or tried to say.

For Apache, check:

tail -f /var/log/apache2/error_log
tail -f /var/log/httpd/error_log

For Nginx:

tail -f /var/log/nginx/error.log

Look for segmentation faults, PHP-FPM timeouts, or "premature end of script headers." Those tell you the application crashed before sending a valid HTTP response. A restart might clear it temporarily, but you need to fix the root cause—usually a PHP memory limit, a bad module, or a database deadlock.

If you see nothing in the error logs, your firewall or rate-limiter may be silently dropping the connection.

Verify Cloudflare IPs are allowed

Many 520 errors happen because the origin firewall blocks Cloudflare's IP ranges mid-request. The TCP handshake completes, then the firewall drops packets during the HTTP exchange.

If you run CSF, ConfigServer Firewall, or iptables rules, make sure all Cloudflare IPv4 and IPv6 ranges are whitelisted. Cloudflare publishes the current list at their IP ranges page.

For CSF, add each range to /etc/csf/csf.allow:

173.245.48.0/20
103.21.244.0/22
103.22.200.0/22
# ... and so on for all ranges

Then restart:

csf -r

Some security plugins—ModSecurity, Imunify360, Wordfence—will also rate-limit or challenge requests from Cloudflare if they see many connections from the same IP. Whitelist the Cloudflare ranges in those tools too.

Restart your web server and PHP-FPM

Sometimes the worker processes hang or run out of memory. A quick restart can resolve transient 520s.

For Apache:

systemctl restart httpd
# or
systemctl restart apache2

For Nginx with PHP-FPM:

systemctl restart nginx
systemctl restart php-fpm
# or php7.4-fpm, php8.1-fpm, etc.

If the 520 returns immediately after restart, the problem is in your application code or configuration, not a stuck process.

Increase PHP memory and timeouts

PHP scripts that hit the memory limit or max execution time will die before sending headers. The web server then returns an incomplete response.

Edit php.ini or your site's .htaccess (if using Apache) or the pool config for PHP-FPM:

memory_limit = 256M
max_execution_time = 300

For PHP-FPM, also raise request_terminate_timeout in the pool config, usually /etc/php-fpm.d/www.conf:

request_terminate_timeout = 300

Restart PHP-FPM after changes. Watch the error logs during the next request to see if the timeout messages stop.

Check SSL/TLS settings on the origin

If you use Cloudflare in Full or Full (Strict) SSL mode, the origin must present a valid certificate. An expired cert, a mismatch, or a missing intermediate can cause Cloudflare to abort the connection and return a 520.

Verify your origin certificate from the command line:

openssl s_client -connect yourdomain.com:443 -servername yourdomain.com

Look at the certificate chain and the "Verify return code." If you see "unable to verify" or "certificate has expired," install or renew the cert.

In Cloudflare's SSL/TLS settings, double-check the mode matches your setup:

  • Flexible: Cloudflare to visitor is HTTPS, Cloudflare to origin is HTTP. No origin cert needed.
  • Full: Cloudflare to origin is HTTPS, but the cert can be self-signed.
  • Full (Strict): Cloudflare to origin is HTTPS, and the cert must be valid and trusted.

A self-signed cert will work in Full mode but fail in Full (Strict). If you just switched modes, that's your 520.

Look for rate limiting or DDoS rules

Cloudflare itself won't cause a 520 through its own rate limiting—it returns 429 or 1015 codes for that. But your origin might have a rate-limit module that sees Cloudflare's IP as the source of all requests and starts blocking.

Check for:

  • mod_evasive or mod_qos in Apache
  • limit_req_zone in Nginx
  • Firewall rules that track connection counts per IP

Because all traffic now comes from Cloudflare's IPs, these tools think a single IP is hammering the server. Whitelist Cloudflare's ranges or disable the rate limiter temporarily to test.

In Nginx, your limit_req_zone should key on a header like $http_cf_connecting_ip instead of $binary_remote_addr if you want to rate-limit real visitors behind Cloudflare.

Disable keep-alive or HTTP/2 temporarily

Some older Apache or Nginx builds mishandle persistent connections when Cloudflare sends pipelined requests. I've seen 520s disappear after disabling KeepAlive in Apache:

KeepAlive Off

Or in Nginx, reduce the timeout:

keepalive_timeout 10;

This is a test step, not a permanent fix—keep-alive improves performance. But if the 520 stops, you know the HTTP handling is buggy and you need to update the web server or investigate why the connection is closing mid-stream.

What if none of these work?

Pause Cloudflare temporarily to confirm the origin serves traffic directly. In the Cloudflare dashboard, click the orange cloud icon next to your DNS A record to turn it gray. Wait a minute for DNS to propagate, then visit your site by IP or by the non-proxied domain.

If the site loads, the origin is fine and the 520 is a Cloudflare-origin communication issue—usually SSL mode, firewall rules, or empty responses. If the site still fails, the problem is on the origin and has nothing to do with Cloudflare.

Another trick: temporarily switch to Cloudflare's Flexible SSL mode to rule out certificate issues. If the 520 disappears, your origin cert is misconfigured or expired.

Does a 520 mean my server is down?

No. A 520 means the server is up and accepting connections, but it returned something invalid or incomplete. A 521 means the server refused the connection. A 522 means the connection timed out before the server answered.

Can Cloudflare's edge cause a 520?

Rarely. Cloudflare logs 520s as origin errors, not edge errors. If Cloudflare itself had a problem, you'd see a 500-series error with a different code or a branded error page saying "Cloudflare is having issues." A 520 almost always points back to the origin.

Will increasing Cloudflare's timeout help?

Cloudflare's default timeout is 100 seconds for HTTP and 600 seconds for websockets on paid plans. If your origin takes longer than that to respond, you'll see a 524 (timeout) instead of a 520. A 520 means the origin responded quickly but sent garbage.

Can plugins or themes cause a 520 in WordPress?

Yes. A poorly coded plugin can crash PHP before headers are sent. Deactivate all plugins by renaming the wp-content/plugins folder via FTP or SSH, then re-enable them one by one to find the culprit.

What to check in order

Start with the origin logs—they tell you if PHP crashed, the application timed out, or the request never arrived. Then confirm Cloudflare's IPs are whitelisted in your firewall. Restart the web server and PHP-FPM to clear stuck processes. Check SSL mode and certificate validity if you use HTTPS to the origin. Finally, test with Cloudflare paused to isolate the problem.

Most 520 errors resolve with a firewall whitelist or a PHP memory bump. The rest usually trace to a bad SSL handshake or an application crash. Work through the list methodically and the origin will tell you what went wrong.