Guide

Cloudflare error 520: what it means and how to fix it

Error 520 is Cloudflare reporting a bad answer from the site's own server. The causes Cloudflare lists, what visitors can do and what owners must send.

HProxy Team··Updated October 10, 2026·6 min read
HProxy.Guide

Skip the dead lists.

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump.

Open the free proxy list→

Cloudflare error 520 means the site's own server, which Cloudflare calls the origin, answered Cloudflare with an empty, unknown or unexpected response. Cloudflare sits between you and that server, so it shows the error in place of the page. Every cause it lists sits on the site's side. The causes are a crashed server, a firewall that blocks Cloudflare, a bad HTTP/2 setup or a broken answer. The one you can sometimes clear yourself is oversized cookies. As a visitor, retry once, try a private window, and report the error with its Ray ID. Only the site owner can fix the origin.

We read Cloudflare's docs and the HTTP standards on 10 October 2026. We also checked two answers from our own server. One was the trace of our own site behind Cloudflare, and one was a 520 that did not come from Cloudflare.

What does error 520 mean?

A 520 is not a standard HTTP status code. The IANA registry, last updated in September 2025, lists 512 to 599 as unassigned, so 520 is Cloudflare's own. It belongs with 502 Bad Gateway. The HTTP standard defines 502 as a gateway or proxy getting an invalid response from the server behind it, and 520 covers an answer that was empty, unknown or unexpected.

Cloudflare's docs name the error "web server returns an unknown error". The error page carries a Ray ID, also called the cf-ray. That number is what the site owner needs to find your request in the logs.

What causes a Cloudflare 520?

These are the causes Cloudflare lists, last updated on 16 June 2026.

CauseWho can fix itWhat to do
The origin server crashed or is set up wrongly, which Cloudflare says is common with some PHP appsThe site owner or hostRead the origin's error logs at the time of the error
A firewall or security plugin at the origin blocks Cloudflare's IP addressesThe site owner or hostAllow Cloudflare's address ranges at the origin
Headers over 128 KB, often from too many cookiesThe visitor first, then the ownerClear the site's cookies; the owner trims cookies and headers
An empty or broken answer, or missing response headersThe site ownerMake the server send a status code, headers and a body
HTTP/2 accepted at the origin but handled wronglyThe site ownerFix it, or turn off HTTP/2 to Origin in Cloudflare
Authenticated Origin Pull switched on, but the origin is not set up for itThe site ownerSet up the origin, or switch the feature off

The cause is not always in the origin's own logs. Cloudflare asks owners to check any load balancers, caches, proxies or firewalls between Cloudflare and the origin too.

How do I fix error 520?

If you are a visitor

  1. Reload once after a minute. If the server had a short failure, the page may load.
  2. Open the page in a private window. It starts without the site's cookies, the one listed cause you can remove. If the page loads there, clear that site's cookies in your normal window.
  3. Report it to the site. Cloudflare's docs say its support only helps the domain owner, and that a visitor should report the problem to the site. Send the error code, the time and timezone, the URL and the Ray ID.

People search for error 520 together with large sites such as ChatGPT and Betway. If a site like that shows it, waiting and reporting are all you can do.

If you own the site

  1. Read the origin's error logs at the time of the 520. Look for crashes first, since Cloudflare names PHP apps that crash the web server.
  2. Allow Cloudflare's IP ranges in every firewall and security plugin in front of the origin.
  3. Measure your headers and cookies. Cloudflare names headers over 128 KB as a cause.
  4. Check HTTP/2 at the origin. If the origin accepts HTTP/2 but does not handle it, Cloudflare returns 520. Turning off HTTP/2 to Origin in the Cloudflare dashboard tests this quickly.
  5. Compare what the origin sent with what Cloudflare served. An origin 200 that became an edge 520 was likely malformed, Cloudflare says, for example oversized headers or an early close.
  6. Use the workaround only to confirm. Cloudflare's temporary workaround is a DNS-only record or pausing Cloudflare, which also removes Cloudflare's protection while it lasts.
  7. Send Cloudflare support the evidence if the 520 continues: the full URL, the cf-ray from the error, the output of /cdn-cgi/trace, and two HAR files, one with Cloudflare on and one with it off.

How do you tell a Cloudflare 520 from any other 520?

Look at who sent it. A 520 from Cloudflare comes with the header server: cloudflare and a cf-ray header, and the error page shows the Ray ID. Any server can send the number 520 on its own, and that answer looks different.

We checked both on 10 October 2026. A test service, httpbin.org, answered our request for a 520 with an empty body. Its header said server: gunicorn/19.9.0, and it had no cf-ray. Our own site, behind Cloudflare, answered its trace page with server: cloudflare and a cf-ray header.

Terminal output of our test. hproxy.com/cdn-cgi/trace: status 200, server cloudflare, cf-ray header present, followed by 16 trace fields such as fl, h, ts, visit_scheme, uag, sliver, http, tls, sni, warp, gateway, rbi and kex, with the ip, loc and colo values removed. httpbin.org/status/520: status 520, server gunicorn/19.9.0, no cf-ray header, empty body.
Our own site's Cloudflare trace and a 520 that Cloudflare did not make, 10 October 2026, printed from the saved results. The address, location and data center values were removed. Source: our own measurement.

The trace is the text Cloudflare support asks for. A site behind Cloudflare serves it at /cdn-cgi/trace, and ours had 16 fields. One of them is your IP address, so remove it before you post the trace anywhere public.

Will a proxy or a VPN fix error 520?

No. None of the causes Cloudflare lists for error 520 involves the visitor's address. They all sit between Cloudflare and the site's own server, and only the site owner can change that link. If a 520 appears for you but not on another connection, tell the site owner. Only they can see why their server answered your request badly.

This page therefore points you to no proxy product. Our guide to error 522 through a proxy covers the rest of the Cloudflare 5xx family. For a 502 that comes from a proxy gateway, see fixing 502 Bad Gateway with a proxy.

What this page could not check

We did not produce a Cloudflare 520 ourselves, because that means breaking a site's origin. We did not touch our live site. So this page shows no real 520 page, and its parts come from Cloudflare's docs. Cloudflare does not say whether an origin's bot defense that drops connections produces 520s for some visitors. Our test was two requests on one day: one to our own site's trace and one to a test service. Cloudflare changes its docs without notice, so we will read every source here again by 10 January 2027.

Sources

  • Cloudflare Docs, "Error 520", last updated 16 June 2026: developers.cloudflare.com.
  • Cloudflare Docs, "Cloudflare 5xx errors", last updated 5 June 2026: developers.cloudflare.com.
  • IANA, Hypertext Transfer Protocol (HTTP) Status Code Registry, last updated 15 September 2025: iana.org.
  • RFC 9110, HTTP Semantics, sections 15.6 and 15.6.3, June 2022: rfc-editor.org/rfc/rfc9110.
  • httpbin.org status endpoint, requested 10 October 2026: httpbin.org.
  • Our own measurement: the trace of our own Cloudflare site and one 520 from a test service, 10 October 2026, logged in the research folder for this page.

Frequently asked questions

What does Cloudflare error 520 mean?
The website's own server, which Cloudflare calls the origin, answered Cloudflare with an empty, unknown or unexpected response. Cloudflare shows error 520 in place of the page. The code is Cloudflare's own: the official HTTP status code registry lists 512 to 599 as unassigned.
Is error 520 my fault?
Not in the cases Cloudflare documents. Every cause it lists sits on the website's side: a crashed server, a firewall blocking Cloudflare, a bad HTTP/2 setup or a malformed answer. The one you can sometimes clear yourself is oversized cookies, since Cloudflare names headers over 128 KB, often from too many cookies, as a cause.
How do I fix error 520 as a visitor?
Reload once after a minute, then open the page in a private window, which starts without cookies. If it still fails, report it to the site with the error code, the time and timezone, the URL and the Ray ID from the error page. Cloudflare Support only helps the domain owner.
How do I fix error 520 on my own site?
Check the origin's error logs at the time of the error, make sure your firewall allows Cloudflare's IP ranges, keep headers and cookies under 128 KB, and check HTTP/2 at the origin. If the origin returned 200 but Cloudflare served 520, Cloudflare says the answer was likely malformed, for example oversized headers or an early connection close.
Will a VPN or a proxy fix error 520?
No. None of the causes Cloudflare lists for error 520 involves the visitor's address. They all sit between Cloudflare and the website's own server, which only the site owner can fix.
What does Cloudflare support need for a 520?
For a 520 that keeps happening, Cloudflare asks for the full URL, the cf-ray value from the error, the output of the site's /cdn-cgi/trace page, and two HAR files: one with Cloudflare enabled and one with it temporarily disabled.

Get proxies that are alive right now

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump. When the location has to survive a real check, the paid network holds up.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed