Cloudflare Error 530 (1016): Origin DNS Error

530 with code 1016 means Cloudflare tried to resolve your origin's hostname and DNS failed. It's the proxied-record-points-at-a-name pattern — and the fix is a specific one.

What you'll see

Root causes

Origin hostname doesn't resolve from Cloudflare's view

When a proxied record's content is a hostname, Cloudflare must resolve it at request time. NXDOMAIN or a CNAME chain ending nowhere → 1016.

CNAME flattening/chain issues or typo in the target

A trailing dot, a stale provider hostname (renamed app service), or a resolver that won't follow the chain at the edge.

Fix it

  1. Find the record whose content is a hostname
    # Cloudflare dashboard → DNS → look for CNAME/target-of-record values; then test: dig +short <target-hostname> @1.1.1.1
  2. If the target resolves, re-check record type and content spelling
    # confirm the exact target string (no trailing dot for provider hostnames, correct region prefix)
  3. If your provider gives an IP, use it directly
    # switch the record content from the hostname to the provider's IP — sidesteps edge-side resolution entirely
  4. Provider-specific: for App Service/CloudFront-style hostnames, keep the hostname but verify it from outside your network too
    dig +trace <target-hostname> 2>&1 | tail -5   # full chain resolves everywhere, not just your resolver

Field note

530 can carry other 1xxx codes — always read the code at the bottom of the error page; 1016 is the origin DNS one. Records pointing at provider hostnames should be tested after every provider migration — renamed hostnames silently NXDOMAIN.

Common questions

Why can't Cloudflare just follow the CNAME like my browser does?

It usually can — 1016 means resolution failed from the edge: the target is genuinely unresolvable, mis-typed, or in a broken chain. Verify with dig @1.1.1.1 from a different network than yours.

Should I switch the record to the IP instead?

If your provider offers a stable IP, pointing at it removes the dependency on edge-side DNS and fixes 1016-class errors. If the IP rotates (PaaS), keep the hostname and fix the resolution issue instead.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.