A Cloudflare 522 identifies an origin-contact timeout, not its cause. Collect DNS, registration and hosting evidence before changing your domain settings.
You finish a domain handoff, point the name at a website, and get a DNS answer. The browser still shows a Cloudflare 522. Does that mean the domain expired, the certificate failed, or the DNS change has not finished? A Cloudflare 522 means Cloudflare timed out contacting the origin web server. It identifies a failed part of the request path, not the underlying cause.
Before changing settings, collect the exact error and separate registration, DNS, certificate and origin evidence. This is a no-change checklist for founders, agencies and domain buyers checking a destination after acquisition or migration. It is not an incident report or a claim that Catches or a particular hosting provider is experiencing an outage.
Why a DNS answer is not a website health check A DNS lookup tells you how a name resolves from the place and time you checked. It does not establish that the application behind the address can respond. When a web record is proxied through Cloudflare, public DNS normally returns Cloudflare's shared edge addresses, not the origin server's address.
The visitor reaches Cloudflare, which then contacts the configured origin. A successful lookup can therefore coexist with a failure farther along that path. Do not compare a public proxy address with a hosting invoice and declare the DNS record wrong. Ask the authorized DNS or hosting owner to compare the configured origin destination with the currently provisioned service.
Keep non-public origin details in the private operational record. What does 522 establish? Cloudflare documents two 522 cases: a timeout before establishing a TCP connection, and a timeout waiting for acknowledgment of its resource request after a connection has been established.
Possible causes include a blocked connection, an overloaded or offline origin, dropped packets, disabled keepalives, or an incorrect configured origin address. That list is a set of possibilities, not a diagnosis for your domain. A browser error alone does not tell you which operator must change which setting. Nor are all nearby error codes interchangeable.
Cloudflare documents 524 separately for a connection that was established but timed out waiting for the expected response, 525 for a failed SSL handshake between Cloudflare and the origin, and 526 for a failure to validate the origin certificate. Preserve the actual code rather than describing everything as an SSL or DNS problem.
Collect this evidence before making changes Layer Record or compare What it does not prove Owner to involve Observed request Exact hostname, scheme, path, error code and message, time with timezone, and Ray ID if shown. A screenshot alone does not identify root cause or every affected path. Site operator.