Skip to content
Troubleshooting

502 Bad Gateway and 504 Gateway Timeout Through a Proxy: Who Failed, and How to Tell

A 502 Bad Gateway means a server acting as a gateway got an invalid response — or none — from the server behind it. A 504 Gateway Timeout means it waited too long for one. Through a proxy there can be several gateways in a row: your proxy, a CDN such as Cloudflare, and the website's own load balancer. The first job is to find out which one answered, because a 502 from the proxy is fixed by retrying on another exit, while a 502 from the website is fixed by nobody but the website.

seamless Team8 min readSeptember 28, 2026
  • troubleshooting
  • http errors
  • 502
  • 504
A chain of client, two relays and a distant slab, the final link severed with its broken end glowing crimson

Which gateway answered?

ClueIt came fromWhat to do
Error during CONNECT, before TLSYour proxyRetry on a new session or exit
cf-ray header, Cloudflare-branded pageCloudflare, in front of the siteWait or report to the site; codes 520–527 add detail
server: nginx or awselb with a plain pageThe site's own load balancerThe site is having problems
Proxy provider's branded error pageYour proxyCheck the dashboard; contact support with the timestamp

For HTTPS targets the distinction is especially clean. The proxy can only speak to you before the tunnel is up; once TLS is established, everything you receive comes from the website side. A 502 in the CONNECT response is the proxy. A 502 inside the page is not.

bash
curl -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o /dev/null 2>&1 | grep -E "^< HTTP|cf-ray|server:"
Two status lines means the tunnel opened and the site answered. One 502 right after CONNECT means the proxy did.

502 Bad Gateway from the proxy

  • The exit could not reach the site. Residential exits are real devices that go offline; retry with a new session tag.
  • DNS failed at the exit. Rare, but it shows up as a 502 for one hostname only.
  • The site refused the exit's network at the TCP level. Try a different country or ASN.
  • The target port is not allowed by the proxy. Most proxies tunnel 80 and 443; exotic ports may be refused.

Retry a proxy-side 502 once on a fresh exit, not five times on the same one. If a new exit works, the old one was the problem; if ten different exits all fail, stop — the site is down or blocking that network entirely.

504 Gateway Timeout

Someone in the chain gave up waiting. That can be the proxy timing out on a slow target, a CDN timing out on a slow origin, or the origin's own load balancer timing out on its application. The fixes, in order of how often they work:

  1. 1Reduce concurrency. Too many parallel requests to one host slow every response down past the timeout.
  2. 2Raise your client timeout if the page is genuinely slow — heavy search pages and report exports can take 30 seconds or more.
  3. 3Retry with backoff. A transient 504 usually clears on the second attempt after a pause.
  4. 4Pick a closer exit. A US target through an Asian exit adds latency to every round trip.

Low-latency exits for slow targets

ISP proxies from €1.80/IP with 10 Gbps and under 50 ms latency; residential from €1.20/GB with country and city targeting.

See ISP proxies

502 and 504 from Cloudflare

Cloudflare uses its own 52x range to be more specific: 520 for an unknown origin error, 521 when the origin refused the connection, 522 when it timed out, 524 when the origin took too long to respond. All of them are on the site's side, and no proxy change will fix them. A plain 502 or 504 with a cf-ray header means Cloudflare itself struggled to reach the origin.

Handling them in code

python
RETRY_ON_NEW_EXIT = {502, 503}
RETRY_SAME_EXIT = {504}

for attempt in range(3):
    r = session.get(url, timeout=45)
    if r.status_code in RETRY_ON_NEW_EXIT:
        session = new_sticky_session()
    elif r.status_code in RETRY_SAME_EXIT:
        time.sleep(2 ** attempt * 5)
    else:
        break
Treat 502 as an exit problem and 504 as a pacing problem until the evidence says otherwise.

The rest of the status codes you will meet through a proxy are in proxy error codes explained, and cURL's own exit codes in cURL proxy errors.

Sources

Frequently asked questions

What does 502 Bad Gateway mean when using a proxy?

A gateway in the chain received an invalid or no response from the server behind it. If the 502 arrives in reply to the CONNECT request, the proxy could not reach the website. If it arrives inside the page after the tunnel opened, the website's own infrastructure failed.

What is the difference between 502 and 504?

502 means the upstream server sent a bad response or none at all. 504 means the upstream server did not respond before the gateway's timeout ran out.

How do I fix a 502 error from my proxy?

Retry once on a new exit by changing the session identifier. If a fresh exit works, the previous exit was offline or blocked. If every exit fails for the same site, the site is down or refusing that network.

How do I fix a 504 Gateway Timeout?

Lower the number of parallel requests to the site, raise your client timeout for genuinely slow pages, retry with backoff, and choose an exit geographically closer to the target.

Are Cloudflare 520 to 527 errors caused by my proxy?

No. They describe problems between Cloudflare and the website's origin server, such as refused connections or timeouts, and cannot be fixed by changing proxies.

SE
seamless Team
Proxy infrastructure

The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.

Ready to try seamless proxies?

Residential, ISP and datacenter proxies with no data expiry.

Browse Plans