HTTP status code
SSL Handshake Failed
Cloudflare-specific: the TLS handshake with the origin failed.
Cloudflare reached your origin over TCP but could not negotiate TLS with it. The network path is fine; the encrypted connection could not be established. This appears when Cloudflare's SSL mode expects HTTPS to the origin and the origin cannot provide it.
Check the origin certificate is present and unexpired first — an expired origin certificate is the most common single cause. Then confirm your Cloudflare SSL mode matches reality: Full (Strict) requires a valid, publicly trusted certificate on the origin, and a self-signed certificate will fail. Cloudflare Origin CA certificates are free and work with Full (Strict).
This is the failure mode that certificate expiry monitoring exists to prevent. An origin certificate lapsing takes the entire site down with no warning, and it is entirely predictable — the expiry date was known months in advance.
Monitor for 525 responses freeThe TLS handshake between Cloudflare and your origin failing — most often an expired or missing origin certificate, or SSL mode set to Full (Strict) when the origin cannot satisfy it.
No. It means the connection between Cloudflare and your origin failed, so visitors get an error page rather than an insecure connection. Nothing is served over a broken channel.
Monitor the origin certificate's expiry date and alert well before it lapses. Automated renewal fails more often than people expect, and it fails silently — the first sign is usually the outage itself.
Pingura checks your endpoints from five regions and alerts on the status code, not just reachability.
Get Started Free