502 Bad Gateway and 504 Gateway Timeout Through a Proxy: Who Failed, and How to Tell
A 502 Bad Gateway means a server acting as a gateway got an invalid response — or none — from the server behind it. A 504 Gateway Timeout means it waited too long for one. Through a proxy there can be several gateways in a row: your proxy, a CDN such as Cloudflare, and the website's own load balancer. The first job is to find out which one answered, because a 502 from the proxy is fixed by retrying on another exit, while a 502 from the website is fixed by nobody but the website.
- troubleshooting
- http errors
- 502
- 504

Table of contents
Which gateway answered?
| Clue | It came from | What to do |
|---|---|---|
Error during CONNECT, before TLS | Your proxy | Retry on a new session or exit |
cf-ray header, Cloudflare-branded page | Cloudflare, in front of the site | Wait or report to the site; codes 520–527 add detail |
server: nginx or awselb with a plain page | The site's own load balancer | The site is having problems |
| Proxy provider's branded error page | Your proxy | Check the dashboard; contact support with the timestamp |
For HTTPS targets the distinction is especially clean. The proxy can only speak to you before the tunnel is up; once TLS is established, everything you receive comes from the website side. A 502 in the CONNECT response is the proxy. A 502 inside the page is not.
curl -v -x http://USERNAME:PASSWORD@PROXY_HOST:PROXY_PORT https://example.com -o /dev/null 2>&1 | grep -E "^< HTTP|cf-ray|server:"502 Bad Gateway from the proxy
- The exit could not reach the site. Residential exits are real devices that go offline; retry with a new session tag.
- DNS failed at the exit. Rare, but it shows up as a 502 for one hostname only.
- The site refused the exit's network at the TCP level. Try a different country or ASN.
- The target port is not allowed by the proxy. Most proxies tunnel 80 and 443; exotic ports may be refused.
Retry a proxy-side 502 once on a fresh exit, not five times on the same one. If a new exit works, the old one was the problem; if ten different exits all fail, stop — the site is down or blocking that network entirely.
504 Gateway Timeout
Someone in the chain gave up waiting. That can be the proxy timing out on a slow target, a CDN timing out on a slow origin, or the origin's own load balancer timing out on its application. The fixes, in order of how often they work:
- 1Reduce concurrency. Too many parallel requests to one host slow every response down past the timeout.
- 2Raise your client timeout if the page is genuinely slow — heavy search pages and report exports can take 30 seconds or more.
- 3Retry with backoff. A transient 504 usually clears on the second attempt after a pause.
- 4Pick a closer exit. A US target through an Asian exit adds latency to every round trip.
Low-latency exits for slow targets
ISP proxies from €1.80/IP with 10 Gbps and under 50 ms latency; residential from €1.20/GB with country and city targeting.
502 and 504 from Cloudflare
Cloudflare uses its own 52x range to be more specific: 520 for an unknown origin error, 521 when the origin refused the connection, 522 when it timed out, 524 when the origin took too long to respond. All of them are on the site's side, and no proxy change will fix them. A plain 502 or 504 with a cf-ray header means Cloudflare itself struggled to reach the origin.
Handling them in code
RETRY_ON_NEW_EXIT = {502, 503}
RETRY_SAME_EXIT = {504}
for attempt in range(3):
r = session.get(url, timeout=45)
if r.status_code in RETRY_ON_NEW_EXIT:
session = new_sticky_session()
elif r.status_code in RETRY_SAME_EXIT:
time.sleep(2 ** attempt * 5)
else:
breakThe rest of the status codes you will meet through a proxy are in proxy error codes explained, and cURL's own exit codes in cURL proxy errors.
Sources
Frequently asked questions
What does 502 Bad Gateway mean when using a proxy?
A gateway in the chain received an invalid or no response from the server behind it. If the 502 arrives in reply to the CONNECT request, the proxy could not reach the website. If it arrives inside the page after the tunnel opened, the website's own infrastructure failed.
What is the difference between 502 and 504?
502 means the upstream server sent a bad response or none at all. 504 means the upstream server did not respond before the gateway's timeout ran out.
How do I fix a 502 error from my proxy?
Retry once on a new exit by changing the session identifier. If a fresh exit works, the previous exit was offline or blocked. If every exit fails for the same site, the site is down or refusing that network.
How do I fix a 504 Gateway Timeout?
Lower the number of parallel requests to the site, raise your client timeout for genuinely slow pages, retry with backoff, and choose an exit geographically closer to the target.
Are Cloudflare 520 to 527 errors caused by my proxy?
No. They describe problems between Cloudflare and the website's origin server, such as refused connections or timeouts, and cannot be fixed by changing proxies.
The seamless team runs residential, ISP and datacenter proxy infrastructure and writes these guides from day-to-day operational experience.
Ready to try seamless proxies?
Residential, ISP and datacenter proxies with no data expiry.
Browse PlansKeep reading
Proxy Error Codes Explained: 407, 429, 502 and the Rest
Which errors come from the proxy and which from the target, why that distinction saves hours, and the specific fix for each code.
TroubleshootingcURL Proxy Errors Explained: Exit Codes 5, 7, 28, 35, 56 and 97
cURL is the fastest way to prove whether a proxy works — once you can read what it is telling you. Every exit code maps to one leg of the connection.
TroubleshootingHTTP 429 Too Many Requests: How Rate Limits Work and How to Survive Them
429 is the one error that gets worse the harder you try. Read the headers, back off properly, and spread load across identities instead of hammering one.
