What this error means
Cloudflare reached the network but the origin refused the connection. The browser or proxy message describes the symptom, not necessarily the root cause. HostWithShery therefore checks the origin reachability and HTTP availability evidence that can be observed publicly before recommending a configuration change.
Most likely causes
These are the first explanations to test because each can produce this exact symptom. Treat them as hypotheses until the matching public evidence is present.
- Origin web server is offline — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Firewall blocks Cloudflare IPs — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Service is not listening on the required port — Verify service is not listening on the required port from the public Internet and compare it with the value the responsible provider says should be live.
What to check on your domain
Use the embedded scan to compare the failing layer with adjacent layers that can produce the same visible error. This prevents a DNS change from being used to “fix” a TLS problem, or an SSL-mode change from masking an origin failure.
- Origin web server is offline — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Firewall blocks Cloudflare IPs — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Service is not listening on the required port — Verify service is not listening on the required port from the public Internet and compare it with the value the responsible provider says should be live.
- Confirm the web server is running — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Allow Cloudflare IP ranges — Verify allow Cloudflare IP ranges from the public Internet and compare it with the value the responsible provider says should be live.
Fixes in the recommended order
Change the smallest confirmed layer first. Preserve working DNS and mail records, document the current value, apply one repair, and then retest before moving to the next possibility.
- 1. Confirm the web server is running. Confirm the public result after this step before making another unrelated change.
- 2. Allow Cloudflare IP ranges. Confirm the public result after this step before making another unrelated change.
- 3. Verify port 80/443 service binding. Confirm the public result after this step before making another unrelated change.
How to confirm the repair
The redirect chain should terminate at one intended HTTPS URL without a loop or unnecessary hop, and the final response should be the expected application page.
If the error remains
Capture the checked hostname, exact timestamp, final DNS addresses, redirect/TLS result and the failing public status before escalating. That evidence gives a hosting or provider support team something testable instead of only the browser message. If results differ by resolver or network, include those differences rather than assuming the failure is universal.
What not to change
Do not replace nameservers, delete unrelated mail records, disable security controls, remove IPv6 blindly or purge the entire configuration merely because this message appears. Diagnose the failing layer first; broad changes can turn one isolated fault into several independent faults.
Technical references
These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.