521 means Cloudflare reached your origin and it actively refused the connection. That's a dead listener, not a slow one — check the web server process first.
nginx/apache crashed, failed config test after an edit, or the server rebooted and the service didn't come up.
After a config change the server listens on 8080 instead of 80, or binds to 127.0.0.1 only.
REJECT (not DROP) answers fast with a refusal — that maps to 521. A DROP would give you 522 instead.
ss -tlnp | grep -E ':80 |:443 '
systemctl status nginx; nginx -t
systemctl restart nginx && ss -tlnp | grep 443
curl -I https://yourdomain.com/ --max-time 10
Keep an uptime check on the origin itself (not through Cloudflare) so you can tell 'origin down' from 'Cloudflare can't reach origin' in seconds. The distinction chooses your whole fix path.
The origin actively refused the connection — nothing listening on that port. Server down, web server crashed, or the wrong port published. It's the origin-side equivalent of ECONNREFUSED.
The web server likely failed to restart after the cert change (nginx -t before reload catches it) — the old process died, the new one didn't come up. Check the service status: it's refusing because it's not running, not because of TLS.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.
One short email when new fixes and production templates drop. No spam, unsubscribe anytime.
Spin up a cloud server in 60 seconds and reproduce this fix yourself — pay by the hour.
Sentry — Free tier: see the exact line of code that broke, before users report it.
We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush