Fix Cloudflare Error 522: when this repair path applies
Confirm the correct origin IP and make sure the host allows Cloudflare connections. Use these steps when Cloudflare times out reaching the origin, but first run the embedded diagnostic so the DNS resolution and delegation evidence supports this provider-specific path rather than a neighboring DNS, TLS, application or mail cause.
Find the authoritative setting before editing
Cloudflare DNS > Records for DNS changes, and SSL/TLS or Rules only when the diagnosis specifically points to those layers. For Fix Cloudflare Error 522, confirm the active nameservers and exact service owner before changing verify A/AAAA against the hosting provider. A DNS-looking screen at cloudflare has no public effect when another provider is authoritative for the zone.
Evidence to save for Fix Cloudflare Error 522
Record the current public state for verify A/AAAA against the hosting provider, check whether the origin is online, review firewall/rate limits for Cloudflare IPs. This gives the repair a before/after comparison and prevents a cached answer or a separate working service from being confused with the configuration that produced the symptom.
- Verify A/AAAA against the hosting provider — Compare IPv4 and IPv6 separately. A healthy A record can hide a broken AAAA path that affects only visitors whose network prefers IPv6.
- Check whether the origin is online — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
- Review firewall/rate limits for Cloudflare IPs — Verify the public endpoint and response before changing DNS. A proxy error can originate from an offline service, blocked proxy ranges, stale origin address or overloaded application.
Repair steps in cloudflare
Confirm the correct origin IP and make sure the host allows Cloudflare connections.
- 1. Verify A/AAAA against the hosting provider. After this step, check the public value tied to verify a/aaaa against the hosting provider before changing another unrelated setting.
- 2. Check whether the origin is online. After this step, check the public value tied to check whether the origin is online before changing another unrelated setting.
- 3. Review firewall/rate limits for Cloudflare IPs. After this step, check the public value tied to review firewall/rate limits for cloudflare ips before changing another unrelated setting.
Why this order matters for cloudflare
The sequence begins with the provider/authority decision, then moves through verify A/AAAA against the hosting provider, check whether the origin is online, review firewall/rate limits for Cloudflare IPs. That keeps the change scoped to the failed DNS resolution and delegation path and avoids replacing nameservers, mail authentication or another healthy service just to make a provider dashboard indicator change.
Verify Fix Cloudflare Error 522
Authoritative DNS should publish the intended record and independent resolvers should converge on that answer as their previous cached TTLs expire. Compare the same verify A/AAAA against the hosting provider and check whether the origin is online evidence used before the change; a repair is complete when the public result agrees, not merely when the cloudflare interface reports that a save succeeded.
If cloudflare and the public result disagree
Check whether the edited zone is authoritative, whether the exact root/www/subdomain was changed, whether a proxy state alters the visible endpoint, and whether a prior TTL can still exist in recursive caches. Do not add a second conflicting verify A/AAAA against the hosting provider value to force validation.
Mistakes to avoid for this repair
Do not copy tenant-specific or region-specific values from another account, delete working email records during a website repair, change nameservers as a shortcut, or alter SSL/proxy modes without evidence from the origin. Fix Cloudflare Error 522 should change only the settings required by this diagnosis.
Technical references
These primary standards and provider documents are used to verify the behavior described on this page. Provider dashboards can change, so use the current official value for tenant-specific DNS records rather than copying an example from another account.