Cloudflare Error 522: Connection Timed Out
By the Does This Really Work Or Not editorial team
Published: October 6, 2026 · Last reviewed: October 6, 2026
Quick answer: Error 522 means Cloudflare is working, but it couldn't connect to the website's own server (the "origin") in time. Visitors can't fix it. The website's server is offline, overloaded, blocking Cloudflare, or set up in Cloudflare with the wrong address.
Is it you or the website?
It's the website. The error page itself proves this: it's generated by Cloudflare after Cloudflare tried to reach the site's server on your behalf. The page shows three boxes, You, Cloudflare and Host. A 522 has the first two marked "Working" and Host marked "Error".
To confirm it's not limited to you, run the site through our website status checker, which requests the page from an outside service. If that also gets a 522, wait and try later, or contact the site owner.
What the timeout actually is
According to Cloudflare's documentation, a 522 happens in one of two situations:
- The connection never completes. Cloudflare sends a connection request to the origin and gets no reply within 19 seconds. It retries at intervals of 1, 1, 1, 1, 1, 2, 4 and 8 seconds before giving up.
- The connection opens but the request goes unanswered. The connection is established, but the origin doesn't acknowledge Cloudflare's request within 90 seconds.
How 522 compares with its neighbours:
| Error | What happened |
|---|---|
| 521 | The origin refused the connection, usually because the web server isn't running |
| 522 | The connection timed out: no reply, often a firewall silently dropping traffic or an overloaded server |
| 523 | Cloudflare couldn't find a route to the origin, often a wrong or private IP address |
| 524 | Connected fine, but the origin took longer than 125 seconds (the current default) to send a response |
| 502 | The origin, or a proxy in front of it, sent back an invalid response |
If you're visiting the site
There's nothing to fix on your device. Wait a few minutes and reload. If the site stays down, contact its owner. The Ray ID at the bottom of the error page helps them find your request in their logs.
If it's your website
- Check the origin IP in Cloudflare DNS. Go to Cloudflare dashboard → your domain → DNS → Records. The proxied A or AAAA records must point to your server's current public IP. A server move, a new cloud instance or a changed IP that wasn't updated is a very common cause.
- Allow Cloudflare's IP ranges through your firewall. Cloudflare publishes them at cloudflare.com/ips. A firewall, a security plugin or
fail2banthat rate-limits or bans those addresses produces exactly this timeout. Checkiptables/nftablesrules, your cloud provider's security groups, and any hosting-panel firewall. - Confirm the web server is running and listening on ports 80/443.
- Check the service with
systemctl status nginx(orapache2). - Check which ports are open with
ss -tlnp | grep -E ':80|:443'. - From another machine,
curl -I http://YOUR.ORIGIN.IP -H "Host: example.com"should get an answer.
- Check the service with
- Check server load. A server at 100% CPU or out of memory may stop accepting new connections. Check
top/htopand the error logs from the time the 522s appeared. - Make sure keep-alive isn't disabled on the origin. Cloudflare lists disabled keep-alives as one of the causes.
- Check the hosting provider's status page. Network problems on their side can also time out connections from Cloudflare.
Our guides How DNS Fails and Incident Response Playbooks cover how to diagnose wrong-IP and provider-side outages step by step.
FAQ
Can I fix a 522 by clearing my cache or changing DNS?
No. Your device reached Cloudflare successfully. The broken step is between Cloudflare and the site's server.
My site works when I visit the server IP directly but gives 522 through Cloudflare. Why?
The server is fine, but Cloudflare's addresses are being blocked or rate-limited, or Cloudflare's DNS points to a different IP than the one you tested. Check steps 1 and 2.
Will pausing Cloudflare fix it?
Pausing sends visitors straight to your server. If the server is reachable, the site comes back, which confirms a firewall or DNS mismatch with Cloudflare. If the server is down, it stays down.