What it means
Cloudflare-specific: the TLS handshake between Cloudflare and the origin failed.
Common causes
- No valid certificate on the origin with Full SSL mode
- No shared cipher suites or TLS versions
- SNI not configured on the origin
How to fix it
As a client or visitor
Nothing to fix locally; retry later.
As the site or API owner
Install a valid certificate on the origin (a Cloudflare Origin CA certificate works) and enable modern TLS versions.
Example response
HTTP/1.1
HTTP/1.1 525 SSL Handshake Failed
Date: Tue, 07 Oct 2025 09:30:00 GMT
Server: nginx
Content-Length: 0 Specification
Not in the IANA registry; used by Cloudflare. Cloudflare
FAQ
› 525 vs 526?
525: the handshake failed. 526: the handshake worked but the certificate is invalid under Full (strict) mode.
› Does Flexible SSL avoid 525?
Yes, but it leaves origin traffic unencrypted. Fix the origin certificate instead.