HTTP status code

525

SSL Handshake Failed

Cloudflare-specific: the TLS handshake with the origin failed.

What 525 means

Cloudflare reached your origin over TCP but could not negotiate TLS with it. The network path is fine; the encrypted connection could not be established. This appears when Cloudflare's SSL mode expects HTTPS to the origin and the origin cannot provide it.

Common causes

How to fix it

Check the origin certificate is present and unexpired first — an expired origin certificate is the most common single cause. Then confirm your Cloudflare SSL mode matches reality: Full (Strict) requires a valid, publicly trusted certificate on the origin, and a self-signed certificate will fail. Cloudflare Origin CA certificates are free and work with Full (Strict).

Catching 525 before your users report it

This is the failure mode that certificate expiry monitoring exists to prevent. An origin certificate lapsing takes the entire site down with no warning, and it is entirely predictable — the expiry date was known months in advance.

Monitor for 525 responses free

Often confused with

← All HTTP status codes

525 SSL Handshake Failed — questions

What causes Cloudflare error 525?

The TLS handshake between Cloudflare and your origin failing — most often an expired or missing origin certificate, or SSL mode set to Full (Strict) when the origin cannot satisfy it.

Does 525 mean my visitors' connection is insecure?

No. It means the connection between Cloudflare and your origin failed, so visitors get an error page rather than an insecure connection. Nothing is served over a broken channel.

How do I avoid 525 from certificate expiry?

Monitor the origin certificate's expiry date and alert well before it lapses. Automated renewal fails more often than people expect, and it fails silently — the first sign is usually the outage itself.

Know about 525 errors immediately

Pingura checks your endpoints from five regions and alerts on the status code, not just reachability.

Get Started Free