530 with code 1016 means Cloudflare tried to resolve your origin's hostname and DNS failed. It's the proxied-record-points-at-a-name pattern — and the fix is a specific one.
When a proxied record's content is a hostname, Cloudflare must resolve it at request time. NXDOMAIN or a CNAME chain ending nowhere → 1016.
A trailing dot, a stale provider hostname (renamed app service), or a resolver that won't follow the chain at the edge.
# Cloudflare dashboard → DNS → look for CNAME/target-of-record values; then test: dig +short <target-hostname> @1.1.1.1
# confirm the exact target string (no trailing dot for provider hostnames, correct region prefix)
# switch the record content from the hostname to the provider's IP — sidesteps edge-side resolution entirely
dig +trace <target-hostname> 2>&1 | tail -5 # full chain resolves everywhere, not just your resolver
530 can carry other 1xxx codes — always read the code at the bottom of the error page; 1016 is the origin DNS one. Records pointing at provider hostnames should be tested after every provider migration — renamed hostnames silently NXDOMAIN.
It usually can — 1016 means resolution failed from the edge: the target is genuinely unresolvable, mis-typed, or in a broken chain. Verify with dig @1.1.1.1 from a different network than yours.
If your provider offers a stable IP, pointing at it removes the dependency on edge-side DNS and fixes 1016-class errors. If the IP rotates (PaaS), keep the hostname and fix the resolution issue instead.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.