522 means Cloudflare TCP-connected nowhere: your origin never answered the handshake. It is almost always a firewall or a dead listener, not Cloudflare.
nginx/apache down, wrong port, or the server itself is wedged by load.
Your origin firewall blocks or silently drops Cloudflare's ranges — connections time out instead of being refused.
SYN backlog full under traffic spikes; handshake times out.
curl -vk --resolve yourdomain.com:443:<ORIGIN_IP> https://yourdomain.com/ --max-time 10
ss -tlnp | grep -E ':443|:80'
# pull https://www.cloudflare.com/ips-v4 and allow 443 from those only
uptime && ss -s
A clean timeout (not refused) usually means firewall DROP, not a dead server — a dead server answers fast with a refusal.
Cloudflare made a TCP connection to your origin and it timed out — the origin never completed the handshake. 521 = origin refused outright; 522 = it accepted nothing in the window. It's an origin-side or network-path problem, not a Cloudflare bug.
The origin (or a middlebox like a NAT) exhausts connections under load: everything queues past Cloudflare's timeout. That's a capacity problem at the origin — worker processes, listen backlog, or a load balancer's connection table.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.
One short email when new fixes and production templates drop. No spam, unsubscribe anytime.