Cloudflare Error 1013: HTTP hostname and TLS SNI hostname mismatch

The TLS SNI (the hostname used for the certificate) differs from the HTTP Host header in the same request.

Seen on: Cloudflare

Meaning

Some clients reuse a connection for another hostname, or proxies/tools set Host differently from SNI. Browsers rarely cause it; custom HTTP clients and misconfigured proxies do.

Common causes

  • Client sets a Host header different from the connection hostname
  • Proxy rewriting Host without changing SNI
  • HTTP/2 connection reuse across different zones

⚡ Quick fix

  1. Make Host and SNI identical (connect to the same hostname you send in Host)
  2. Fix the proxy’s SNI settings (proxy_ssl_server_name on)

Detailed fix by platform

Nginx

  1. nginx
    proxy_set_header Host api.example.com;
    proxy_ssl_server_name on;
    proxy_ssl_name api.example.com;

How to diagnose

  1. Client — Host vs SNI values
  2. Proxy — Rewrites Host?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.