Cloudflare Error 523: Origin Is Unreachable

523 means Cloudflare couldn't even open a TCP connection to your origin — DNS points somewhere dead, the origin is down, or a firewall is dropping Cloudflare's IPs.

What you'll see

Root causes

Origin down or wrong IP in DNS

The A record Cloudflare proxies to is stale or the server is offline. Test the origin directly: curl -I --resolve your.domain:443:<origin-ip> https://your.domain/.

Origin firewall drops Cloudflare ranges

Cloudflare connects from published IP ranges (https://www.cloudflare.com/ips/). If your origin firewall whitelists nothing or blocks datacenter IPs, Cloudflare can't reach it while you still can.

Nonstandard port or router/NAT miss

Cloudflare proxying only connects on specific ports (80, 443, 8080, 8443...). An origin on port 3000 with no reverse proxy = unreachable by design.

Fix it

  1. Test the origin directly, bypassing Cloudflare
    curl -vI --resolve your.domain:443:<origin-ip> https://your.domain/   # connects = firewall/DNS issue; fails = origin down
  2. Verify DNS records point at the live origin
    dig +short your.domain @1.1.1.1   # proxied records return Cloudflare IPs; check the A record value in the Cloudflare dashboard instead
  3. Whitelist Cloudflare's ranges at the origin
    # for cf in $(curl -s https://www.cloudflare.com/ips-v4); do ufw allow from $cf to any port 443 proto tcp; done
  4. Confirm the origin listens on a proxied port
    ss -tlnp | grep -E ':(80|443)\b'   # app on 3000? put nginx/caddy in front on 443

Field note

523 vs 522: 523 = no TCP connection established at all (routing/firewall/down); 522 = TCP connected but timed out during handshake. Different debug paths. For a true Cloudflare-Tunnel setup, 523s usually mean the tunnel daemon (cloudflared) is down on the origin.

Common questions

523 but I can load the site fine from my browser. Why?

You're likely bypassing the failure — browser cache, or your network reaches the origin while Cloudflare's edge can't (firewall blocking CF ranges). Reproduce with curl --resolve against the origin IP to see what Cloudflare sees.

How do I check if my origin firewall blocks Cloudflare?

Temporarily allow Cloudflare's published ranges (they're stable and machine-readable at cloudflare.com/ips). If 523 turns into 200s, the firewall was the story — then tighten to only the ports you proxy.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.

Get new fixes by email

One short email when new fixes and production templates drop. No spam, unsubscribe anytime.

Partner pick — sponsored

Vultr — our lab-environment pick for this stack

Spin up a cloud server in 60 seconds and reproduce this fix yourself — pay by the hour.

Get Vultr →
Also vetted

Sentry — Free tier: see the exact line of code that broke, before users report it.

Get Sentry →

We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush