Error diagnosis

Cloudflare Error 522

Cloudflare timed out while trying to communicate with the origin server.

Last updated: 2026-08-07

Free · No account · Public configuration only

What this error means

Cloudflare timed out while trying to communicate with the origin server. The browser or proxy message describes the symptom, not necessarily the root cause. HostWithShery therefore checks the DNS resolution and delegation evidence that can be observed publicly before recommending a configuration change.

Most likely causes

These are the first explanations to test because each can produce this exact symptom. Treat them as hypotheses until the matching public evidence is present.

  • Offline or overloaded origin — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
  • Cloudflare IP ranges blocked or rate limited — Verify Cloudflare IP ranges blocked or rate limited from the public Internet and compare it with the value the responsible provider says should be live.
  • Wrong origin IP in DNS — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
  • Network packet loss — Verify network packet loss from the public Internet and compare it with the value the responsible provider says should be live.

What to check on your domain

Use the embedded scan to compare the failing layer with adjacent layers that can produce the same visible error. This prevents a DNS change from being used to “fix” a TLS problem, or an SSL-mode change from masking an origin failure.

  • Offline or overloaded origin — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
  • Cloudflare IP ranges blocked or rate limited — Verify Cloudflare IP ranges blocked or rate limited from the public Internet and compare it with the value the responsible provider says should be live.
  • Wrong origin IP in DNS — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
  • Network packet loss — Verify network packet loss from the public Internet and compare it with the value the responsible provider says should be live.
  • Verify the origin IP — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.

Fixes in the recommended order

Change the smallest confirmed layer first. Preserve working DNS and mail records, document the current value, apply one repair, and then retest before moving to the next possibility.

  • 1. Verify the origin IP. Confirm the public result after this step before making another unrelated change.
  • 2. Check origin availability and firewall rules. Confirm the public result after this step before making another unrelated change.
  • 3. Ask the host to investigate dropped connections. Confirm the public result after this step before making another unrelated change.

How to confirm the repair

Authoritative DNS should publish the intended record and independent resolvers should converge on that answer as their previous cached TTLs expire.

If the error remains

Capture the checked hostname, exact timestamp, final DNS addresses, redirect/TLS result and the failing public status before escalating. That evidence gives a hosting or provider support team something testable instead of only the browser message. If results differ by resolver or network, include those differences rather than assuming the failure is universal.

What not to change

Do not replace nameservers, delete unrelated mail records, disable security controls, remove IPv6 blindly or purge the entire configuration merely because this message appears. Diagnose the failing layer first; broad changes can turn one isolated fault into several independent faults.

Technical references

Provider interfaces and standards change. These references are used to verify the technical behavior described above.