525 SSL Handshake Failed
A Cloudflare-specific code: in Full or Full (strict) SSL mode, Cloudflare could not complete TLS with the origin.
The SSL/TLS handshake between Cloudflare and the origin failed.
525 is an unofficial status code used by Cloudflare. It is not part of the HTTP standard or the IANA registry.
What HTTP 525 SSL Handshake Failed Means
The SSL/TLS handshake between Cloudflare and the origin failed.
A Cloudflare-specific code: in Full or Full (strict) SSL mode, Cloudflare could not complete TLS with the origin.
Common Causes
- No valid SSL certificate on the origin
- Cipher suite or TLS version mismatch
- Origin not configured for HTTPS on the expected port
- SNI handling problems
How to Fix It (For Visitors)
- Contact the website owner
How to Fix It (For Developers/Admins)
- Install a valid certificate on the origin
- Match supported TLS versions and cipher suites
- Ensure the origin listens on 443 with HTTPS
- Verify Cloudflare SSL mode matches origin capabilities
How to Troubleshoot Cloudflare Errors
Every Cloudflare error page shows a Ray ID and tells you whether the browser, Cloudflare, or the origin host is failing. To test the origin directly while keeping the correct hostname, bypass Cloudflare with curl:
# Replace 203.0.113.10 with your origin server's IP
curl -svo /dev/null --resolve example.com:443:203.0.113.10 https://example.com/If this request fails or is slow, the problem is on the origin, not at Cloudflare. Also make sure your firewall, security plugins, and rate limiters allow Cloudflare's IP ranges.
Test the TLS handshake against the origin directly:
openssl s_client -connect 203.0.113.10:443 -servername example.com
Frequently Asked Questions
What does HTTP 525 SSL Handshake Failed mean?
A Cloudflare-specific code: in Full or Full (strict) SSL mode, Cloudflare could not complete TLS with the origin. In short: The SSL/TLS handshake between Cloudflare and the origin failed.
Is 525 an official HTTP status code?
No. 525 is not registered in the IANA HTTP Status Code Registry; it is specific to Cloudflare. A client that receives an unrecognized status code treats it like the generic 500 code of its class.
How do I fix a 525 SSL Handshake Failed error?
Install a valid certificate on the origin. Match supported TLS versions and cipher suites. Ensure the origin listens on 443 with HTTPS.
Specification Status
525 SSL Handshake Failed is not an official HTTP status code. It is not registered in the IANA HTTP Status Code Registry and is specific to Cloudflare. Other servers and clients may not recognize it.