Cloudflare Error 522 on WordPress

Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.

Why it happens on WordPress

Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.

The fix on WordPress

Ask the host to allowlist Cloudflare's published IP ranges, then raise PHP workers or enable a page cache so the origin answers within the 15-second edge timeout.

If that didn't fix it

WordPress has its own failure mode, but Cloudflare Error 522 has a wider set of causes. The most common one overall is: The origin firewall silently drops Cloudflare's IP ranges.

Allowlist Cloudflare's IP ranges with an accept rule, and make sure the default policy does not drop them earlier in the chain.

Check your own domain

Probing the origin address directly shows whether it is reachable from outside Cloudflare, which immediately tells you whether the fault is the firewall or the host.

Frequently asked questions

Why does Cloudflare Error 522 happen on WordPress?

Shared WordPress hosts throttle or firewall Cloudflare's IP ranges after a traffic spike, so the TCP handshake to the origin never completes and the edge gives up.

How do I fix Cloudflare Error 522 on WordPress?

Ask the host to allowlist Cloudflare's published IP ranges, then raise PHP workers or enable a page cache so the origin answers within the 15-second edge timeout.

What does Cloudflare Error 522 mean?

Cloudflare tried to open a connection to the origin and nothing answered before the timeout. Usually a firewall silently dropping Cloudflare's traffic, an overloaded origin, or a wrong origin IP.