# 530 Error with 1xxx Codes (Cloudflare)

> Cloudflare 530 never appears alone: it comes with a 1xxx error such as 1016 Origin DNS error or 1033 Tunnel error. Read the code in the page body and fix it.

Source: https://howhttpworks.com/status-codes/530
Last reviewed: 2026-10-04

> **TL;DR:** Cloudflare returns 530 only together with a 1xxx error, and the 1xxx code in the page body is the real diagnosis. 1016 means Cloudflare cannot resolve your origin hostname; 1033 means a Cloudflare Tunnel has no connected `cloudflared`. Read the code, then use the matching fix below.

## What it means

Most Cloudflare 5xx errors say something about the TCP or TLS connection to the origin. 530 is different: the failure happened before Cloudflare even tried to connect (DNS, a banned target, a tunnel with no connector). The status line is 530, and the page body names a 1xxx code.

```http
HTTP/2 530
server: cloudflare
cf-ray: 8a1b2c3d4e5f6a7b-FRA
content-type: text/html; charset=UTF-8
```

```text
Error 1016
Origin DNS error
Ray ID: 8a1b2c3d4e5f6a7b  •  2026-10-04 11:32:07 UTC
What happened? You've requested a page on a website (app.example.com) that is on the Cloudflare network. Cloudflare is currently unable to resolve your requested domain (origin.internal.example.net).
```

Grep for it quickly:

```bash
curl -s https://app.example.com/ | grep -o -E 'Error 1[0-9]{3}|Origin DNS error|Tunnel error' | head
```

## The 1xxx codes you will meet

| Code | Name | Typical cause |
|---|---|---|
| 1016 | Origin DNS error | The A/AAAA/CNAME target Cloudflare should use as the origin does not resolve (deleted record, typo, expired domain, CNAME to an unresolvable name). |
| 1033 | Cloudflare Tunnel error | The hostname is routed to a Cloudflare Tunnel, but no active `cloudflared` is connected. |
| 1014 | CNAME Cross-User Banned | A CNAME on your zone points to a hostname in another Cloudflare account's zone without the setup that allows it. |
| 1001 | DNS resolution error | Cloudflare could not resolve a DNS name it needs for the request (for example a CNAME target outside the zone). |
| 1018 | Could not find host | Cloudflare cannot match the hostname to a zone or origin, commonly after a partner/hosting change. Status for this one is not documented as 530. |

Cloudflare's 1xxx reference does not list the HTTP status for each code, and not every 1xxx page is a 530 (1020 Access denied, for example, is a firewall block and arrives with a 403). Match the code in the body, not just the status.

## Fix 1016: Origin DNS error

1. In the Cloudflare DNS dashboard, find the record for the hostname. Is the content an IP or hostname that exists?
2. If it is a CNAME to another name, resolve that target from outside:

```bash
dig +short origin.internal.example.net
dig +short CNAME app.example.com @1.1.1.1
```

3. A record that points to a name only resolvable in your private network (internal DNS, split-horizon) fails here, because Cloudflare resolves via public DNS. Use a public record or a Tunnel.
4. Domain expired, nameserver delegation changed for the origin zone, or DNSSEC misconfigured on the origin's zone: check `dig +dnssec`.

## Fix 1033: Tunnel error

```bash
# On the machine that should run the connector
cloudflared tunnel list
cloudflared tunnel info my-tunnel
systemctl status cloudflared
journalctl -u cloudflared -n 50 --no-pager
```

Checks: `cloudflared` is running and shows registered connections, the tunnel in Zero Trust is **Healthy**, the public hostname route points at this tunnel (a tunnel deleted and recreated gets a new ID, so the old CNAME to `<UUID>.cfargotunnel.com` goes stale), and the machine can reach Cloudflare on the ports `cloudflared` uses (outbound 7844 TCP/UDP). After a Docker or Kubernetes redeploy, make sure the token or credentials secret still matches the tunnel.

## Fix 1014: CNAME cross-user banned

You cannot CNAME an arbitrary hostname to a different Cloudflare customer's proxied zone. Point at the provider's documented origin, or ask the provider to enable the shared setup (for SaaS, Cloudflare for SaaS custom hostnames).

## If you are a visitor

Nothing you can do. The site owner's DNS or tunnel is down; the Ray ID is what they need.

## Related

- [520 Web Server Returned an Unknown Error](https://howhttpworks.com/status-codes/520)
- [521 Web Server Is Down](https://howhttpworks.com/status-codes/521)
- [523 Origin Is Unreachable](https://howhttpworks.com/status-codes/523): DNS fine, routing to the origin fails.
- [525 SSL Handshake Failed](https://howhttpworks.com/status-codes/525) and [526 Invalid SSL Certificate](https://howhttpworks.com/status-codes/526)
- [502 Bad Gateway](https://howhttpworks.com/status-codes/502)
