Cloudflare 521: Web Server Is Down (Connection Refused)

521 means Cloudflare reached your origin and it actively refused the connection. That's a dead listener, not a slow one — check the web server process first.

What you'll see

Root causes

Web server stopped or failed to start

nginx/apache crashed, failed config test after an edit, or the server rebooted and the service didn't come up.

Listening on the wrong port or address

After a config change the server listens on 8080 instead of 80, or binds to 127.0.0.1 only.

Firewall REJECTing Cloudflare IPs

REJECT (not DROP) answers fast with a refusal — that maps to 521. A DROP would give you 522 instead.

Fix it

  1. On the origin, is anything listening on 80/443?
    ss -tlnp | grep -E ':80 |:443 '
  2. Check the service and its config test
    systemctl status nginx; nginx -t
  3. Fix the listener (port/bind) or start the service
    systemctl restart nginx && ss -tlnp | grep 443
  4. Verify from outside, then check Cloudflare sees it too
    curl -I https://yourdomain.com/ --max-time 10

Field note

Keep an uptime check on the origin itself (not through Cloudflare) so you can tell 'origin down' from 'Cloudflare can't reach origin' in seconds. The distinction chooses your whole fix path.

Common questions

What is a 521?

The origin actively refused the connection — nothing listening on that port. Server down, web server crashed, or the wrong port published. It's the origin-side equivalent of ECONNREFUSED.

Why did I get 521 after a cert renewal?

The web server likely failed to restart after the cert change (nginx -t before reload catches it) — the old process died, the new one didn't come up. Check the service status: it's refusing because it's not running, not because of TLS.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.