Cloudflare Error 525: SSL Handshake Failed
Cloudflare couldn’t complete a TLS handshake with your origin (SSL mode Full / Full strict).
Meaning
The origin accepted TCP on 443 but TLS failed: no certificate configured, no SNI support, incompatible ciphers/protocols, or port 443 serving plain HTTP.
Common causes
- No SSL certificate installed on the origin
- Origin listens on 443 without TLS
- Origin doesn’t support SNI or TLS 1.2+
- Cipher mismatch
- Firewall dropping TLS from Cloudflare IPs
⚡ Quick fix
- Install a certificate on the origin (Cloudflare Origin CA or Let’s Encrypt)
- Test:
openssl s_client -connect ORIGIN_IP:443 -servername example.com - Enable TLS 1.2/1.3 on the origin
- Temporarily switch SSL mode to Flexible only to confirm (not a fix)
Detailed fix by platform
Nginx
- Origin TLS with a Cloudflare Origin CA cert:nginx
server { listen 443 ssl http2; server_name example.com; ssl_certificate /etc/ssl/cloudflare/origin.pem; ssl_certificate_key /etc/ssl/cloudflare/origin.key; ssl_protocols TLSv1.2 TLSv1.3; }
How to diagnose
- Origin TLS — openssl s_client against the origin IP
- SSL mode — Full / Full (strict)?
- Protocols — TLS 1.2+ enabled?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026