Is a Website Down or Just Me? How to Check and What the Errors Mean
When a website won't load, the first question is whether it's broken for everyone or only for you. The answer decides whether you wait, fix something on your side or tell the owner. Here's how to tell in a couple of minutes, what the common errors mean, and what site owners should check first.
Down for everyone, or only for you?
The quickest test is a check from somewhere else. Our Website Uptime Checker has our server, in the Cloudflare data centre nearest you, request the page. Your Wi-Fi, router, provider's DNS and browser cache play no part in that request, so:
- Down there too: the problem is almost certainly the website. Waiting, or telling the owner, is all you can do.
- Up there, but not for you: something between you and the site is at fault. Work through the fixes below.
Your phone is a second test: switch from Wi-Fi to mobile data. If the site loads only on mobile data, look at your home or office network.
Some cases fool any outside check. Sites that block automated requests may answer them with 403 Forbidden while working fine in a browser, and a site can be up while one part, such as login or checkout, is broken.
Browser errors: no answer from the website
If the browser shows its own error page, it never got a proper answer from the website. Google's Chrome help page on common errors explains these codes; other browsers word them differently.
| Error | What happened | Usual causes |
|---|---|---|
| ERR_NAME_NOT_RESOLVED | The name couldn't be turned into an IP address (a DNS failure) | A typo, an expired domain, broken DNS records, or your own DNS resolver |
| ERR_CONNECTION_TIMED_OUT | No reply arrived in time | A server that's down or overloaded, a firewall, or a poor connection |
| ERR_CONNECTION_REFUSED | The server answered but refused the connection | The web server isn't running, or something is blocking you |
| ERR_CONNECTION_RESET | The connection was cut part-way | An unstable connection, a VPN, a firewall or security software |
| "Your connection is not private" | The secure (TLS) connection failed its checks | An expired or mismatched certificate, or your device's clock is wrong |
| ERR_TOO_MANY_REDIRECTS | The site kept sending the browser round in a loop | A site misconfiguration, sometimes stale cookies |
A TLS error means your browser reached a server but couldn't confirm it's the real site. Don't click through where you sign in or pay. Our SSL certificates guide explains why.
HTTP status codes: 4xx versus 5xx
If the server does answer, it sends a three-digit status code, defined in RFC 9110. Codes starting with 4 mean the server thinks the request is the problem; codes starting with 5 mean the server has failed. That split tells you who has to act.
| Code | Meaning | What it tells you |
|---|---|---|
| 301, 308 / 302, 307 | Moved permanently / temporarily | Normal; browsers follow redirects |
| 401 | You need to sign in | Not an outage |
| 403 Forbidden | The server understood but refuses | Often a firewall or bot block |
| 404 Not Found | Nothing at that address | One page is missing; the site may be fine |
| 410 Gone | Removed, probably for good | Look for a new address |
| 429 Too Many Requests | You're being rate-limited (defined in RFC 6585) | Wait, then try again |
| 500 Internal Server Error | Something unexpected broke on the server | The owner's problem |
| 502 Bad Gateway | A proxy or CDN got an invalid answer from the server behind it | The owner's problem |
| 503 Service Unavailable | Overloaded or down for maintenance | Usually temporary; it may say when to retry |
| 504 Gateway Timeout | A proxy or CDN waited too long for the server behind it | The owner's problem |
A 404 on one link doesn't mean the site is down. A 5xx on the home page usually means it is, for everyone.
Cloudflare's 520 to 526 errors
These codes aren't in the official IANA status code registry; they're Cloudflare's own. You see them when a site sits behind Cloudflare and Cloudflare couldn't get a proper answer from the site's own server, which it calls the origin. According to Cloudflare's documentation:
- 520: the origin sent an empty, unknown or unexpected response.
- 521: the origin refused the connection, because the web server is offline or blocking Cloudflare.
- 522: Cloudflare timed out reaching the origin, for example no reply to its connection attempt within 19 seconds.
- 523: Cloudflare couldn't reach the origin at all, often a routing problem.
- 524: Cloudflare connected, but the origin sent no response before the timeout, 125 seconds by default.
- 525 and 526: the secure connection to the origin failed, or the origin's certificate couldn't be verified.
In each case the fault lies with the site's server or settings, not your device. One quirk: our checks run on Cloudflare Workers, which Cloudflare says always verify certificates strictly, so a site with a broken certificate may show 526 in our tools even if it doesn't use Cloudflare. The SSL Checker shows what's wrong.
What to try on your side
- Check the address for typos, then reload once.
- Try another network, such as mobile data instead of Wi-Fi. If the site works on one, restart the router on the other.
- Turn off your VPN, proxy or ad blocker for a moment, and try a private (Incognito) window, which skips extensions and cookies.
- Flush your DNS cache. Your computer remembers DNS answers, including failed lookups, for a while. On Windows, open Command Prompt and run
ipconfig /flushdns; Microsoft's documentation says this clears the resolver cache, including those negative entries. On a Mac, open Terminal and runsudo killall -HUP mDNSResponderand enter your password; it's the command Apple's archived support article gives for OS X 10.10.4 and later. Restarting the device also clears the cache. - Compare DNS answers. Our DNS Lookup asks Cloudflare's public resolver (1.1.1.1) directly from your browser. If it finds an address but your browser can't, your router's or provider's DNS is the likely culprit; try a public DNS service on your device.
- Check your device's date and time if you see certificate errors; Google notes a wrong clock can cause them.
If the site fails on one network only, that network may be blocking it: a workplace or school firewall, parental controls, or your internet provider.
What site owners should check
- Is the server answering? Run the Ping Test on port 443. "Connection refused" means nothing is listening, so restart the web server; a timeout points to a firewall or a machine that's off (see our port guide).
- Does DNS point to the right server? Compare the A and AAAA records in DNS Lookup with your server's addresses; after a change, use the DNS Propagation Checker and our DNS records guide.
- Has the domain or certificate expired? The WHOIS Lookup shows the domain's expiry date and the SSL Checker the certificate's.
- What changed? Check recent deployments, software or plugin updates, firewall rules, disk space and the server's error logs.
- Slow rather than down? The Ping Test connects to the server several times and shows how long each connection takes. If connecting is quick but the page still crawls, the delay is in the website itself, not the network.
How to check with our tools
- Open the Website Uptime Checker, type the site in Web address and click Check. We add https:// if you leave it out, so type http:// yourself for a site without HTTPS.
- Read the result: Up or Down, the status code, the response time and the city our check ran from. Down means a final status of 400 or more, a failed connection, or no answer within 10 seconds. Check failed means our check itself didn't run, for example because your own connection dropped.
- To watch an outage, choose Every minute, Every 5 minutes or Every 15 minutes under How often. The log and the "Up while you watched" figure build up while the page stays open; click Stop when you're done.
- For detail, paste the address, or up to 10 addresses one per line, into the HTTP Status Checker and click Check. It shows each redirect with its code and timing, the important headers and the full list, and it flags redirect loops.
- If the name won't resolve, enter the domain in DNS Lookup, leave Record type on All common records and click Look Up. "Doesn't exist" means there are no DNS records for it at all.
Limits: each check runs from one place, so an outage in another region may not show, and pages behind a login count as Down because they answer 401 or 403.
Quick checklist
- Down in our checker too: it's the site. Wait, or tell the owner.
- Up for us but not for you: mobile data, no VPN, private window, flush DNS.
- 4xx: the request or that page. 5xx: the server. 520 to 526: the server behind Cloudflare.
- Certificate warning: check your clock, then tell the owner. Don't enter passwords.
- Owners: server, DNS, domain and certificate expiry, then recent changes.
Sources
Spotted a mistake or something out of date? Tell us and we'll fix it.