How HTTP Works
5xx · Server errorNon-standard · Cloudflare
< HTTP/1.1 530 Origin DNS Error

530 Error with 1xxx Codes (Cloudflare)

Cloudflare 530 never appears alone: it comes with a 1xxx error such as 1016 Origin DNS error or 1033 Tunnel error. Read the code in the page body and fix it.

Reviewed 3 min readintermediate4 sourcesTry itMarkdown
Cacheable
No
Retry?
No, until the origin DNS is fixed
Usually sent by
Cloudflare edge
Spec
Cloudflare 5xx errors
On this page

TL;DR: Cloudflare returns 530 only together with a 1xxx error, and the 1xxx code in the page body is the real diagnosis. 1016 means Cloudflare cannot resolve your origin hostname; 1033 means a Cloudflare Tunnel has no connected cloudflared. Read the code, then use the matching fix below.

What it means

Most Cloudflare 5xx errors say something about the TCP or TLS connection to the origin. 530 is different: the failure happened before Cloudflare even tried to connect (DNS, a banned target, a tunnel with no connector). The status line is 530, and the page body names a 1xxx code.

HTTP/2 530
server: cloudflare
cf-ray: 8a1b2c3d4e5f6a7b-FRA
content-type: text/html; charset=UTF-8
Error 1016
Origin DNS error
Ray ID: 8a1b2c3d4e5f6a7b  •  2026-10-04 11:32:07 UTC
What happened? You've requested a page on a website (app.example.com) that is on the Cloudflare network. Cloudflare is currently unable to resolve your requested domain (origin.internal.example.net).

Grep for it quickly:

curl -s https://app.example.com/ | grep -o -E 'Error 1[0-9]{3}|Origin DNS error|Tunnel error' | head

The 1xxx codes you will meet

CodeNameTypical cause
1016Origin DNS errorThe A/AAAA/CNAME target Cloudflare should use as the origin does not resolve (deleted record, typo, expired domain, CNAME to an unresolvable name).
1033Cloudflare Tunnel errorThe hostname is routed to a Cloudflare Tunnel, but no active cloudflared is connected.
1014CNAME Cross-User BannedA CNAME on your zone points to a hostname in another Cloudflare account’s zone without the setup that allows it.
1001DNS resolution errorCloudflare could not resolve a DNS name it needs for the request (for example a CNAME target outside the zone).
1018Could not find hostCloudflare cannot match the hostname to a zone or origin, commonly after a partner/hosting change. Status for this one is not documented as 530.

Cloudflare’s 1xxx reference does not list the HTTP status for each code, and not every 1xxx page is a 530 (1020 Access denied, for example, is a firewall block and arrives with a 403). Match the code in the body, not just the status.

Fix 1016: Origin DNS error

  1. In the Cloudflare DNS dashboard, find the record for the hostname. Is the content an IP or hostname that exists?
  2. If it is a CNAME to another name, resolve that target from outside:
dig +short origin.internal.example.net
dig +short CNAME app.example.com @1.1.1.1
  1. A record that points to a name only resolvable in your private network (internal DNS, split-horizon) fails here, because Cloudflare resolves via public DNS. Use a public record or a Tunnel.
  2. Domain expired, nameserver delegation changed for the origin zone, or DNSSEC misconfigured on the origin’s zone: check dig +dnssec.

Fix 1033: Tunnel error

# On the machine that should run the connector
cloudflared tunnel list
cloudflared tunnel info my-tunnel
systemctl status cloudflared
journalctl -u cloudflared -n 50 --no-pager

Checks: cloudflared is running and shows registered connections, the tunnel in Zero Trust is Healthy, the public hostname route points at this tunnel (a tunnel deleted and recreated gets a new ID, so the old CNAME to <UUID>.cfargotunnel.com goes stale), and the machine can reach Cloudflare on the ports cloudflared uses (outbound 7844 TCP/UDP). After a Docker or Kubernetes redeploy, make sure the token or credentials secret still matches the tunnel.

Fix 1014: CNAME cross-user banned

You cannot CNAME an arbitrary hostname to a different Cloudflare customer’s proxied zone. Point at the provider’s documented origin, or ask the provider to enable the shared setup (for SaaS, Cloudflare for SaaS custom hostnames).

If you are a visitor

Nothing you can do. The site owner’s DNS or tunnel is down; the Ray ID is what they need.

Frequently asked questions

What does Cloudflare 530 mean?

It is a wrapper status: Cloudflare returns 530 together with a 1xxx error code printed in the page body, and the 1xxx code is the real diagnosis. The common ones are 1016 (origin DNS error) and 1033 (Tunnel error); 1014 (CNAME cross-user banned) and 1001 (DNS resolution error) are related DNS-side errors. the Cloudflare docs do not publish which HTTP status goes with each 1xxx code, so read the code in the page body rather than trusting the status alone.

How do I fix Cloudflare error 1016 Origin DNS error?

Cloudflare could not resolve the origin hostname. Check that the DNS record points at a real IP or a resolvable hostname, that a CNAME target exists and is not itself missing, and that you did not point at a name inside a zone that has since been removed.

Why do I get 530 with error 1033 using Cloudflare Tunnel?

Cloudflare has a DNS record routing the hostname to a tunnel, but no healthy cloudflared connector is attached to that tunnel. Start or restart cloudflared, check the tunnel shows Healthy in Zero Trust, and confirm the public hostname maps to the right tunnel ID.

Is 530 an origin server error?

Not in the sense of the origin returning it. Cloudflare generates 530 at the edge. In the DNS and tunnel cases it never reached an origin application at all, so web server logs will be empty.

Does 530 appear without a 1xxx error?

The 530 page in Cloudflare documentation says the response body contains a 1xxx code. If your page shows only 530, view the page body or the Ray ID; the 1xxx number is displayed under the headline and in the support text.

Sources

  1. Cloudflare: Error 530developers.cloudflare.com
  2. Cloudflare: Troubleshooting Cloudflare 1XXX errorsdevelopers.cloudflare.com
  3. Cloudflare Tunnel: Troubleshootingdevelopers.cloudflare.com
  4. RFC 9110 Section 15.6: Server Error 5xxrfc-editor.org

Keep going

Browse /search