Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A Cloudflare 520 means Cloudflare received an empty, unknown, or unexpected response from a website’s origin server. It does not identify one specific fault, and the code alone does not prove your scraper caused the problem. If you are scraping someone else’s site, preserve the error details and report them to the site owner. If you administer the site, correlate the request with origin and intermediary logs, then check the response, firewall, headers, and HTTP/2 configuration.

What a 520 means—and what it does not

Cloudflare describes the error as occurring when “the origin server returns an empty, unknown, or unexpected response to Cloudflare.” The origin is the server or service Cloudflare contacts to fetch the requested page. Cloudflare may then show a 520 to the visitor when it cannot use the response it received.

That description is a symptom, not a root-cause diagnosis. Possible causes include an origin crash or misconfiguration, Cloudflare IP addresses being blocked, an empty or malformed response, oversized response headers, incorrect HTTP/2 handling at the origin, or a mismatch in Authenticated Origin Pull configuration. The error might come and go, and the relevant evidence may be in a proxy, load balancer, cache, or firewall log rather than the web server log. See Cloudflare’s Error 520 guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you are a scraper user without access to the target’s infrastructure, you can document the incident but generally cannot establish or repair its server-side cause. Do not assume that changing a user agent, switching proxies, or retrying is a fix; Cloudflare does not document a universal scraper-side remedy.

If you are scraping someone else’s site

  1. Record the exact request. Save the complete URL, including the path and relevant query parameters, and note when the failure occurred with its timezone. Avoid sending credentials or sensitive query values when reporting it publicly.
  2. Preserve the response evidence. Save the error response body or a screenshot and record any cf-ray identifier visible on the page. If your client exposes response headers and status, keep those too.
  3. Check whether the result repeats. Try the same URL again later if appropriate and record whether the outcome changes. A retry can show whether the failure is intermittent, but a successful later request does not reveal what caused the earlier 520.
  4. Send a useful report to the site owner. Include the URL, time and timezone, the error page or response details, and the cf-ray value if present. Cloudflare directs site visitors to contact the site owner; the owner is the party able to investigate the origin and account configuration. See Cloudflare’s general 5xx guidance.

Do not try to evade a site’s access controls or increase request volume to “test” the error. The available 520 documentation does not establish that bot detection, scraping frequency, a particular library, or a particular proxy caused an individual incident.

If you own or administer the site

1. Correlate the incident with logs

Start with the exact timestamp, URL, and cf-ray value, then search for the matching request in origin web-server and application logs. Check for crashes, worker exhaustion, application exceptions, or an aborted response around that time. Also inspect each component between Cloudflare and the application: load balancers, reverse proxies, caches, firewalls, and other security tools. Cloudflare notes that a 520 cause may not appear in origin logs alone.

Cloudflare’s Error Analytics use a 1% traffic sample, according to its general 5xx guidance. Treat analytics as sampled evidence rather than a complete ledger of every affected request. For an individual report, request-specific logs and the Ray ID can help narrow the search.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

2. Verify that the origin response is valid

Look for an origin response that is empty, truncated, malformed, or otherwise not a parsable HTTP response. Check whether the application or an upstream service closes the connection before returning a complete response, and whether required response headers are present and properly formed. Compare the response for the failing request with a successful request to the same endpoint, if available.

Cloudflare lists response headers larger than 128 KB among possible 520 causes. Excessive cookies are one way a header set can grow too large. Inspect the actual response headers and cookie volume rather than assuming page content size is the issue.

3. Check firewall and Cloudflare connectivity

Confirm that origin firewalls and security products permit Cloudflare IP ranges and are not resetting or rejecting the relevant connection. Review security events and firewall logs at the time of the reported failure. A rule that blocks Cloudflare at the origin can interrupt the exchange even when the site is otherwise reachable from another network.

4. Check HTTP/2 and authenticated origin pulls

If HTTP/2 is enabled between Cloudflare and the origin, verify that the origin server actually supports and correctly handles that protocol. An origin that advertises HTTP/2 but does not respect or support it can return behavior Cloudflare cannot interpret. Also verify that the origin’s Authenticated Origin Pull configuration matches the certificates and settings Cloudflare expects; a mismatch is one of the documented possible causes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Interpret origin status alongside cache status

When reviewing Cloudflare request logs, do not interpret OriginResponseStatus 0 in isolation. Cloudflare says it must be read together with CacheStatus: a cache hit or revalidation can mean the request did not contact the origin, while a cache miss or expired entry with status 0 indicates Cloudflare contacted the origin but did not receive a parsable HTTP response. Use the request’s cache state and timing to decide which logs and systems to inspect.

6. Escalate with a complete evidence package

If the cause remains unclear, follow Cloudflare’s instructions and provide the complete affected URL, the cf-ray value, output from /cdn-cgi/trace, and HAR captures. Include the error code, timestamp and timezone, and relevant intermediary logs. Cloudflare’s support guidance on collecting site troubleshooting details is at Gathering information for troubleshooting sites.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

How to distinguish 520 from nearby Cloudflare errors

Error Cloudflare-described symptom Where to focus first
520 Origin returned an empty, unknown, or unexpected response. Response validity, origin and intermediary logs, headers, firewall rules, and origin protocol configuration.
522 Cloudflare timed out while contacting the origin. Origin reachability, connection handling, and response timing. See Cloudflare’s Error 522 guidance.
502 or 504 Cloudflare could not establish contact with the origin; the cause may be at the origin or Cloudflare. Identify which side generated the response, then investigate origin health and intermediary services. See Cloudflare’s Error 502 or 504 guidance.

These codes are not interchangeable diagnoses. Cloudflare’s error response documentation distinguishes errors generated by Cloudflare from origin-generated 5xx responses that Cloudflare passes through. Establish which response you received before choosing a fix.

Should you retry, change a proxy, or pause Cloudflare?

A limited retry may be useful to see whether the same URL continues to fail, but it is an observation—not a diagnosis. Changing a scraper’s user agent or proxy can alter the route or request, but the official 520 guidance does not establish either as a reliable fix. Repeated retries also do not give a scraper operator access to the origin logs needed to identify the fault.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a site owner, Cloudflare describes switching a DNS record to DNS-only mode or temporarily pausing Cloudflare as possible workarounds. These are diagnostic or temporary measures, not proof of a universal, permanent fix. They change how traffic reaches the site and may change the protections or proxy behavior in use. Consider the operational and security consequences, coordinate with the team responsible for the domain, and use the resulting evidence to isolate the origin or Cloudflare-path issue rather than treating a bypass as a root-cause repair. The official options are described on the Error 520 page.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your immediate job is to capture a page as evidence, ScreenshotNeo offers a screenshot API; it is not a fix for a 520 or a substitute for origin logs. A screenshot can preserve what a browser showed, while the Ray ID, response details, and server-side logs remain important for diagnosis. ScreenshotNeo can remove cookie banners, newsletter popups, and chat widgets before a capture, and its response identifies page verdict and billing status: bot checks, blank pages, failed loads, and cache hits are not billed. It also has an MCP server for AI agents using Claude, Cursor, or another MCP client.

One GET request returns an image or PDF. For example, capture the affected URL as WebP (replace the example target with the URL you need to document):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/affected-page -o shot.webp

See the ScreenshotNeo API documentation for request options and response details. Free includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. ScreenshotNeo is made by Yorker Media. Sign up for free: get 1,000 screenshots a month with no card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common troubleshooting mistakes

  • Assuming 520 means Cloudflare blocked the scraper: the code describes an unexpected origin response, not a specific bot-block diagnosis. Check the site owner’s evidence before drawing that conclusion.
  • Looking only at the application log: the failure may be recorded by a load balancer, cache, proxy, or firewall. Correlate all components on the request path.
  • Treating status 0 as proof the origin failed: first check cache status; a cache hit or revalidation may mean there was no origin request.
  • Changing many things at once: if you control the site, make a controlled change and correlate it with request-specific logs. Otherwise, you cannot tell which change mattered.
  • Confusing an intermittent recovery with a fix: a later success does not explain the earlier empty or unexpected response. Preserve the failing request’s time and Ray ID.
  • Using a Cloudflare bypass as the permanent answer: DNS-only or pausing Cloudflare may help isolate a path issue, but does not by itself correct a malformed response, origin crash, header problem, or protocol mismatch.

Frequently Asked Questions

Can I fix a 520 on a site I do not control?

Usually, you can document and report it, but only the site owner or hosting team can inspect the origin path and make server-side changes.

Does a 520 mean the website is down for everyone?

No. The code describes a response Cloudflare could not interpret for a request; it does not establish that every URL, visitor, or request is failing.

Can a screenshot prove the cause of a 520?

No. It can preserve the visible error page, but determining the cause requires request-specific response information and, for the site owner, relevant infrastructure logs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.