525 SSL Handshake Failed — Causes & Fix
HTTP 525 (SSL Handshake Failed) means the SSL/TLS handshake between Cloudflare and the origin server failed — they couldn't agree on a secure connection.
- Applies to
- Any website or web server (HTTP standard)
- Time to fix
- 15 minutes – 2 hours
What it means
Causes include a missing/expired/invalid origin certificate, a cipher/protocol mismatch, or the origin not supporting HTTPS on the expected port. This is a Cloudflare-specific status code (not part of the HTTP standard). Cloudflare returns it when it sits in front of a site and has a problem reaching or getting a valid response from the origin (your) server — so the fix is almost always at the origin, not with the visitor.
Symptoms
- Cloudflare "Error 525" page
- HTTPS to the origin fails
How to fix it
- 1
Fix the origin certificate
1. As the operator: install a valid (unexpired) SSL certificate on the origin. 2. Consider a Cloudflare Origin Certificate.
- 2
Match SSL settings
1. Ensure the Cloudflare SSL mode (Full/Full Strict) matches the origin's HTTPS setup and supported ciphers.
Frequently asked questions
What causes Error 525?
The TLS handshake between Cloudflare and your origin failed — usually an expired/invalid origin certificate or an SSL setting mismatch. Fix the origin cert and SSL mode.
Last updated July 20, 2026
Guidance only — always consult a qualified professional or the official service manual before carrying out repairs.