521 means Cloudflare reached your origin and it actively refused the connection. That's a dead listener, not a slow one — check the web server process first.
nginx/apache crashed, failed config test after an edit, or the server rebooted and the service didn't come up.
After a config change the server listens on 8080 instead of 80, or binds to 127.0.0.1 only.
REJECT (not DROP) answers fast with a refusal — that maps to 521. A DROP would give you 522 instead.
ss -tlnp | grep -E ':80 |:443 '
systemctl status nginx; nginx -t
systemctl restart nginx && ss -tlnp | grep 443
curl -I https://yourdomain.com/ --max-time 10
Keep an uptime check on the origin itself (not through Cloudflare) so you can tell 'origin down' from 'Cloudflare can't reach origin' in seconds. The distinction chooses your whole fix path.
The origin actively refused the connection — nothing listening on that port. Server down, web server crashed, or the wrong port published. It's the origin-side equivalent of ECONNREFUSED.
The web server likely failed to restart after the cert change (nginx -t before reload catches it) — the old process died, the new one didn't come up. Check the service status: it's refusing because it's not running, not because of TLS.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.