What Is a 525 Status Code?
A 525 status code is a Cloudflare error, "SSL handshake failed", returned when the TLS handshake between Cloudflare and the origin server fails while the zone’s SSL mode is Full or Full (strict). The visitor’s connection to Cloudflare is fine; the origin has no valid certificate, has port 443 closed, lacks SNI support, or shares no cipher with Cloudflare.
- Code
- 525
- Name
- SSL Handshake Failed
- Class
- Cloudflare extension
- Retry?
- No, fix the cause first
What causes error 525?
- →No valid SSL certificate installed on the origin.
- →Port 443, or the custom secure port, closed on the origin.
- →No SNI support on the origin server.
- →No cipher suite in common between the origin and Cloudflare.
How do you fix error 525 when web scraping?
- →Do not retry in a tight loop. A 525 is a configuration problem and lasts until the owner fixes it.
- →Use a cached copy of the page, or come back later.
How do you fix error 525 on your own server?
- →Install a valid certificate on the origin. A free Cloudflare Origin CA certificate works.
- →Open port 443 and confirm the origin answers TLS with SNI.
- →Compare the origin’s cipher suites with the list Cloudflare supports.
How do you handle error 525 in a retry loop?
525 is not in RETRYABLE, so raise_for_status() raises on the first response instead of spending retries on a request that will fail the same way. Fix the cause, then send the request again.
import random
import time
import requests
RETRYABLE = {408, 429, 500, 502, 503, 504, 520, 521, 522, 523, 524}
def fetch(url: str, max_attempts: int = 5) -> requests.Response:
for attempt in range(max_attempts):
try:
response = requests.get(url, timeout=(10, 60))
except requests.Timeout:
time.sleep(2**attempt + random.uniform(0, 1))
continue
if response.status_code not in RETRYABLE:
response.raise_for_status()
return response
retry_after = response.headers.get("Retry-After", "")
backoff = 2**attempt + random.uniform(0, 1)
time.sleep(min(int(retry_after) if retry_after.isdigit() else backoff, 60))
raise RuntimeError(f"Gave up on {url} after {max_attempts} attempts")
How does Context.dev handle error 525?
Context.dev retries the fetch for you, and by default Scrape can reuse a capture made in the last 3 days (maxAgeMs), so a page that is briefly down may still come back from cache. If no capture is available, the failed output carries an error_code and message inside an HTTP 200 response, and a request where every output fails is not charged.
See what the web scraping API does on every request, or read how to fix HTTP errors in web scraping for a longer walkthrough.
Frequently asked questions about error 525
What does error 525 SSL handshake failed mean?
Cloudflare could not complete a TLS handshake with the site’s origin server. The problem is the origin’s TLS setup, not your browser.
What is the difference between 525 and 526?
A 525 means the handshake itself failed. A 526 means the handshake worked but Cloudflare could not validate the certificate in Full (strict) mode.
Can a visitor fix a 525 error?
No. The fix is on the origin server or in the site’s Cloudflare SSL settings.
Which status codes are related to 525?
Sources
Last reviewed