NinjaOps Fixes / Cloudflare
Cloudflare Fixes
11 troubleshooting guides — each with the error, why it happens, and copy-paste commands to fix it.
Cloudflare 522: Connection Timed Out to Your Origin — 522 means Cloudflare TCP-connected nowhere: your origin never answered the handshake.
Cloudflare 525: SSL Handshake Failed With Origin — You are using Full (strict) mode, and the origin's certificate failed validation.
Cloudflare 520: Your Origin Returned Something Broken — 520 is Cloudflare shrugging: the origin connected but responded with an invalid/empty reply or crashed the connection.
Cloudflare 521: Web Server Is Down (Connection Refused) — 521 means Cloudflare reached your origin and it actively refused the connection.
Cloudflare Error 523: Origin Is Unreachable — 523 means Cloudflare couldn't even open a TCP connection to your origin — DNS points somewhere dead, the origin is down, or a firewall is dropping Cloudflare's IPs.
Cloudflare Error 524: A Timeout Occurred (Your Origin Is Too Slow) — 524 means Cloudflare connected to your origin, but the response took over 100 seconds (free/pro plans).
Cloudflare Error 526: Invalid SSL Certificate (Full-Strict Finds a Problem) — 526 fires in Full (strict) mode when your origin's certificate is expired, self-signed, incomplete, or wrong-hostname.
Cloudflare Error 530 (1016): Origin DNS Error — 530 with code 1016 means Cloudflare tried to resolve your origin's hostname and DNS failed.
Cloudflare Error 1020: Access Denied (Your WAF Fired on a Real Visitor) — 1020 means a Cloudflare firewall rule matched the request and blocked it — sometimes correctly, sometimes blocking your own users, your monitoring, or your app's own callbacks.
Cloudflare Error 1101: "Worker Threw a JavaScript Exception" — Your Worker code threw an unhandled exception while handling the request.
Cloudflare Error 1000: "DNS Points to Prohibited IP" — A Cloudflare-zone DNS record points back at Cloudflare IPs — a loop Cloudflare refuses to proxy.