The origin refused Cloudflare's connection.
Why does this error happen?
- The origin is offline, refusing the port, or blocking Cloudflare IP ranges in a firewall or security tool.
- The effective account, plan, runtime, model, region, or deployment scope may be more restrictive than a headline platform maximum.
- Retries or parallel workers can amplify the condition when they are not bounded or coordinated.
How do you diagnose it?
- Test the origin on the correct port and confirm firewall logs for Cloudflare source addresses.
- Correlate the provider request identifier and UTC timestamp with application logs and metrics without recording secrets.
- Reproduce with the smallest safe request and verify the exact account, plan, endpoint, region, runtime, or model involved.
How do you fix it?
- Start the origin service, open the expected port, and allow current Cloudflare IP ranges.
- Retry only when the documented error is temporary; use bounded attempts, jitter, idempotency, and a dead-letter path.
- Verify recovery with a controlled request, then monitor the same limiter or failure signal under normal traffic.
How do you prevent it from recurring?
Turn the confirmed cause of Error 521 — web server is down into an observable boundary for Cloudflare. Track the relevant request count, token volume, payload size, execution time, connection pressure, billing state, or upstream health before it reaches the documented failure condition. Preserve the platform request ID and timestamp so future incidents can be correlated without logging sensitive payloads.
Test the fix under representative concurrency and failure injection, not only with one successful request. Alert on remaining headroom and repeated retries, and keep the linked limit page and official error source with the runbook so responders can distinguish a configuration problem from temporary service pressure or account state.