Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A Cloudflare 520 means Cloudflare received an empty, unknown, unexpected, or malformed response from your origin server. The proxy reached the origin (or an intermediary on the way), but could not interpret a usable HTTP response. The durable fix is normally at the origin, firewall, load balancer, reverse proxy, or origin-protocol configuration—not in your browser.
Use the error page’s cf-ray ID and UTC time to correlate logs, then test the origin path layer by layer. This guide explains what 520 means, how it differs from nearby Cloudflare errors, and how to prevent recurring incidents.
What a 520 response means
Cloudflare labels 520 “web server returns an unknown error.” In its Error 520 guidance, Cloudflare says the condition occurs when the origin server returns an empty, unknown, or unexpected response to Cloudflare. That response might be generated by your application server, web server, load balancer, cache, firewall, or another intermediary between Cloudflare and the origin.
A normal origin response includes a valid status line, headers, and (where appropriate) a body. A 520 is produced when Cloudflare cannot parse what came back—for example, a connection that closes before headers, an invalid status line, or headers that exceed the supported limit. It is therefore different from an application deliberately returning a normal 4xx or 5xx page.
#1 Best Overall
- Funny design. funny HTTP status code featuring a green thumbs up and the words "200 OK". A fun tee for any web developer or web programmer with a sense of humor
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
520 compared with other Cloudflare 5xx errors
| Error | What Cloudflare observed | First layer to inspect |
|---|---|---|
| 520 | Empty, unknown, unexpected, or malformed origin response | Origin response formatting, crashes, headers, protocol and intermediaries |
| 521 | The origin web server refused Cloudflare’s connection | Origin process, listening port, firewall and Cloudflare IP allow-list |
| 522 | Cloudflare timed out while connecting to the origin | Network path, routing, firewall drops and origin availability |
| 524 | Cloudflare connected, but the origin did not return a response within the applicable time | Slow application work, database calls and origin timeout limits |
These distinctions come from Cloudflare’s 5xx and error-response documentation (updated June 5 and May 5, 2026). Start with the number: a 521 is a refusal, a 522 is a connection timeout, a 524 is a response-time timeout, and a 520 is an unusable response.
Document the incident before changing settings
- Copy the complete failing URL, including its path and query string.
- Record the exact time in UTC. Do this for one failure and, if possible, one successful request.
- Copy the
cf-rayvalue shown on the Cloudflare error page. - Save the output of
/cdn-cgi/tracefrom the affected zone while the problem is occurring. - Note whether the failure affects every visitor, one URL, one data center, one HTTP method, or only requests with cookies or authentication.
These details let a host or Cloudflare support match the proxy request to origin logs instead of searching an unbounded time range.
Fix a 520 step by step
1. Check the origin and application logs
At the recorded UTC time, inspect the web server, application, PHP/runtime, container, load-balancer and operating-system logs. Look for process crashes, out-of-memory kills, worker exhaustion, connection resets, upstream disconnects, malformed status lines and deployments immediately before the first failure. A server that works when tested manually can still fail intermittently when a pool is exhausted or a particular request triggers a crash.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Check all origin nodes, not only the load balancer. If only one node emits malformed responses, remove it from rotation, preserve its logs, and repair or roll back that node before returning it to service.
2. Test the origin without Cloudflare
From a permitted network, request the origin hostname or address directly, using the same Host header, path, method and authentication conditions as the failing request. Compare the raw status line, headers and body with a request through the proxied hostname. If the direct request is also empty or malformed, Cloudflare is only exposing an origin defect. If direct requests are valid while proxied requests fail, continue with the intermediary, firewall and protocol checks below.
Do not permanently expose an origin merely to test it. Restrict a temporary test listener by IP, use a staging hostname, or perform the check from an approved management network.
3. Allow Cloudflare IP ranges through every firewall
Review the host firewall, cloud security group, web-application firewall, intrusion-prevention system, rate limiter, security plugin and fail2ban-style rules. Confirm that the published Cloudflare IP ranges are allowed to reach the correct ports and are not being challenged, reset, or rate-limited. Check both IPv4 and IPv6 rules if your zone uses both.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →A security rule that blocks or abruptly closes Cloudflare connections can produce an empty response. Preserve protection for other traffic; create a narrowly scoped allow rule for Cloudflare at the network layer and keep application-level authentication in place.
4. Reduce oversized response headers and cookies
Cloudflare identifies response headers larger than 128 KB as a common 520 cause. Excessive tracking, session, experiment and authentication cookies are frequent contributors. Capture the complete response headers from the origin, including every Set-Cookie, and calculate their total size. Remove obsolete cookies, shorten values, avoid storing large serialized state in cookies, and keep per-user data server-side.
Check redirects as well as the final page: a single oversized header on an intermediate response can fail the request. Re-test after clearing old cookies and in a clean browser profile so you can distinguish a request-specific cookie problem from a server-wide problem.
5. Validate the HTTP response itself
Confirm that every origin path sends a valid HTTP status line such as HTTP/1.1 200 OK or a deliberate 4xx/5xx, followed by correctly formatted headers. Investigate responses that close immediately, contain illegal header bytes, send duplicate or contradictory framing headers, or generate output before the server writes the status line. Proxies and application servers must agree about Content-Length and chunked transfer framing.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Pay special attention to error handlers. A crash while rendering a custom error page can leave Cloudflare with no usable response, turning an expected application error into 520.
Rank #3
6. Verify HTTP/2 to Origin
If the origin advertises or accepts HTTP/2 but its implementation is incomplete, Cloudflare may receive a protocol response it cannot use. Review Cloudflare’s origin protocol setting and the origin server’s HTTP/2 support, including TLS and proxy compatibility. As a temporary diagnostic measure, disable HTTP/2 to Origin in Cloudflare’s protocol settings and retest over HTTP/1.1. If that removes 520, correct the origin’s HTTP/2 configuration, upgrade the affected software, and then re-enable the protocol after validation.
7. Check Authentication Origin Pull
When Authentication Origin Pull is enabled, the origin must trust and validate the certificate and settings Cloudflare presents. A mismatch in the trusted certificate, virtual host, or enforcement policy can prevent a valid origin exchange. Verify the certificate chain, host configuration and Cloudflare zone settings together; do not disable authentication as a permanent fix.
8. Isolate caches, load balancers and reverse proxies
Trace the request through every hop. Compare the response from the application directly, from the local web server, from the internal load-balancer address and from the public origin hostname. Check health probes, connection reuse, maximum header settings, idle timeouts and retry behavior. A proxy that retries a crashed upstream and then closes the client connection can turn a backend failure into a 520.
Use DNS-only mode only as a diagnostic bypass
Temporarily changing the DNS record to DNS-only, or pausing Cloudflare, can show whether the proxied path is involved. This bypass does not repair the origin and may expose its address, remove caching and weaken protective controls. Limit the test, monitor the origin, and restore proxying immediately after collecting evidence. If the site fails directly, give the host the direct failure details rather than repeatedly toggling DNS.
What to send when escalating
Provide your hosting provider or Cloudflare with the full URL, UTC timestamp and timezone, cf-ray ID, /cdn-cgi/trace output, and two HAR files: one captured with Cloudflare proxying enabled and one with it disabled. Include relevant origin, firewall, load-balancer and deployment logs, and identify whether the problem is constant or intermittent. Redact passwords, access tokens, private cookies and personal data before sharing.
Prevent recurring 520 incidents
- Keep Cloudflare IP allow-lists synchronized across host firewalls, security groups and plugins; review them after infrastructure changes.
- Monitor origin process restarts, out-of-memory events, worker-pool saturation, connection resets and malformed-response counts.
- Set alerts on response-header and cookie growth before the 128 KB threshold is approached.
- Exercise custom error pages and failure paths in staging, including upstream disconnects and overloaded workers.
- Pin and test HTTP/2, TLS, reverse-proxy and load-balancer changes before production rollout.
- Retain request IDs and timestamps long enough to correlate proxy, edge and origin logs.
- Use health checks that verify a complete, valid HTTP response, not merely that a TCP port is open.
Or skip the browser setup
If you need a reliable screenshot of a page while investigating a visual failure, ScreenshotNeo provides a single website-screenshot API request instead of maintaining a browser. It accepts consent banners like a visitor, removes more than 60 known consent platforms plus newsletter popups and chat widgets before capture, and lets you turn each cleanup step off. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed; the response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server supplies take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.
The API can capture full pages with lazy images, a CSS-selected element, dark mode, device presets or any viewport, retina scale, PDFs with paper size, margins, orientation and page ranges, HTML/CSS, custom JavaScript and CSS, clicks, selector waits, delays, network-idle waits, blocked ads or resource types, custom headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed image links, asynchronous webhooks, bulk jobs for up to 100 URLs and usage data. Existing parameter names used by other screenshot APIs are accepted to ease migration.
Recommended Free Tools
Rank #4
With an API key, the basic call is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the complete parameter reference in the ScreenshotNeo documentation. The Free plan includes 1,000 shots per month without a card; paid plans start at $5 for 3,000 shots. Sign up free for ScreenshotNeo.
Frequently Asked Questions
Can restarting the origin fix a 520?
It can clear a crashed process or exhausted worker pool, but it is only a temporary recovery. Correlate the restart with logs and correct the underlying crash, resource or configuration issue.
Does a 520 mean Cloudflare is down?
Not by itself. The definition points to an unusable response from the origin or an intermediary. Check Cloudflare status separately, but begin with the origin path and its logs.
Will clearing browser cookies solve every 520?
Only when the request carries headers or cookies large enough to trigger the problem. Test a clean session, then measure origin response headers; server-side cookie reduction is the lasting fix.
Is DNS-only mode a permanent solution?
No. It bypasses the proxy for diagnosis and can reduce security and performance. Restore proxying after repairing the origin.
The Bottom Line
A 520 is a protocol-level symptom: Cloudflare received nothing it could interpret from the origin path. Capture the URL, UTC time, cf-ray and trace data; correlate every origin and intermediary log; then fix the specific crash, block, oversized header, malformed response, HTTP/2 mismatch or authentication setting. Use DNS-only only long enough to isolate the layer.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

