Error 520 on Cloudflare: causes and fixes
·4 min read
Error 520 is Cloudflare's code for "web server returns an unknown error". Cloudflare reached your origin server, but what came back was empty, malformed or something it could not turn into an HTTP response. The fix is almost always on the origin. Look for a crashed app, a firewall blocking Cloudflare, oversized headers or broken HTTP/2.
A 520 is not in the HTTP standard. Only sites behind Cloudflare's proxy show it.
What does error 520 mean?
Code 520 means the connection to your origin worked but the answer did not. Cloudflare's Error 520 page defines it as the origin returning "an empty, unknown, or unexpected response."
The other 52x codes each name a specific step that failed. A 520 is the catch-all.
| Code | Cloudflare's name | What failed |
|---|---|---|
| 520 | Web server returns an unknown error | The origin answered, but the response was empty, malformed or cut off |
| 521 | Web server is down | The origin refused the connection |
| 522 | Connection timed out | Cloudflare could not complete a TCP connection to the origin |
| 523 | Origin is unreachable | No network route to the origin's IP address |
| 524 | A timeout occurred | The origin accepted the request but sent no response within 125 seconds |
The 125 seconds is the default on Cloudflare's Error 524 page. For a 502, read our 502 Bad Gateway guide.
Common causes of a 520 error
Cloudflare's Error 520 page lists these causes.
- The origin crashed mid-request. The app or web server died after accepting the connection, so Cloudflare got nothing back. Cloudflare notes that 520s are common with PHP applications that crash the web server.
- A firewall or security plugin blocked Cloudflare.
- Response headers over 128 KB. Cloudflare's connection limits cap response headers at 128 KB in total. Too many cookies is the usual reason.
- An empty or malformed response. No status line, no headers, or an error page with no proper HTTP status.
- Broken HTTP/2 at the origin. If the origin advertises HTTP/2 but does not handle it correctly, Cloudflare returns a 520.
- Authenticated Origin Pulls misconfigured. The feature is on in Cloudflare, but the origin is not set up to accept Cloudflare's client certificate.
Causes 5 and 6 follow configuration changes, so check what changed recently first.
Origin or Cloudflare: how to find the fault
Bypass Cloudflare and ask the origin directly. If the origin fails without Cloudflare in the path, the problem is yours.
curl -svI --resolve example.com:443:203.0.113.10 https://example.com/
# add -k if the origin uses a Cloudflare Origin CA certificateA connection reset or "Empty reply from server" means the origin crashed or a firewall killed the request. A huge Set-Cookie block points at the header limit. Add --http2 to the command and compare. If HTTP/1.1 works and HTTP/2 fails, you have found the cause.
Cloudflare's Origin Analytics compares what your origin returned with what Cloudflare served. Per the Error 520 page, an origin 200 next to an edge 520 means a malformed response, such as oversized headers or an early connection close. Its Top endpoints table shows which paths fail.
Then read the origin's error log at the time of the failure.
How to fix error 520
Fix the cause you found, in this order.
- Restart the crashed service and find out why it died. Check PHP-FPM or app logs and
dmesgfor out-of-memory kills. - Allow every range on Cloudflare's IP list in your firewall,
.htaccessand security plugins. - Shrink response headers. Drop stale cookies and trim long Content-Security-Policy headers.
- If HTTP/2 is the problem, turn off HTTP/2 to Origin under Speed > Settings > Protocol Optimization, or fix the origin's HTTP/2 config.
- If you use Authenticated Origin Pulls, configure the origin to accept Cloudflare's client certificate, or turn the feature off.
As a stopgap, Cloudflare suggests setting the DNS record to DNS-only or pausing Cloudflare. If 520s continue, Cloudflare Support asks for the failing URLs, the Ray ID from the error page, the output of /cdn-cgi/trace and two HAR files, one with Cloudflare on and one with it off.
Does error 520 hurt SEO?
Yes, if it lasts. Google treats a 520 like any other 5xx. Its page on how HTTP status codes affect crawling says 5xx errors make Google's crawlers slow down, Google ignores content served with a 5xx, and URLs that keep returning server errors are eventually dropped from the index. A 520 that clears in minutes costs little. One that lasts days does real damage.
Watch /robots.txt closely. If it returns a 5xx, Google stops crawling the whole site for the first 12 hours, per Google's robots.txt spec. A crashed origin takes robots.txt down along with every page.
Affected URLs show up in Search Console's Page indexing report under "Server error (5xx)".
Check your URLs for 520 errors in bulk
Our HTTP Status Bulk Checker requests up to 20 pasted URLs, one per line, and records what comes back. For each URL it returns the status code, where any redirect points, the final URL and the response time, then counts the 5xx, 4xx, redirecting and unreachable URLs. It allows 8 seconds and up to five redirects per URL, and marks a rate limit, bot check or bare 403 as blocked instead of reporting it as broken.
It does not download page bodies, so an error page served with a 200 reads as 200. It does not crawl your site or expand a sitemap. Paste one URL per template, or the list from Search Console's "Server error (5xx)" report, and run it again after each fix. A run costs 20 credits.