INTEGRITY Cloudflare Docs

ERR_SSL_PROTOCOL_ERROR

If visitors to your site experience SSL protocol errors such as:

These errors indicate that the SSL/TLS handshake failed. This can happen for many reasons, including certificate issues, protocol incompatibilities, or network interference.

Rule out common causes first

Before investigating protocol-specific issues, verify that the error is not caused by:


Test HTTP/3 (QUIC) compatibility

HTTP/3 uses the QUIC protocol over UDP, which some networks, firewalls, or devices do not fully support. If visitors experience intermittent SSL protocol errors, HTTP/3 may be the cause.

When to suspect HTTP/3 issues

How to test

Temporarily disable HTTP/3 to determine if it is the cause:

  1. In the Cloudflare dashboard, go to the Protocol Optimization page. Go to Settings ↗
  2. Turn off HTTP/3 (with QUIC).
  3. Ask the affected visitor to test again.

If disabling HTTP/3 resolves the issue, the visitor's network likely blocks or mishandles UDP traffic on port 443. Re-enable HTTP/3 after testing and work with the visitor to identify the specific network issue.


Test TLS 1.3 compatibility

TLS 1.3 is the latest version of the TLS protocol and provides improved security and performance. However, some network security devices that perform SSL/TLS inspection may not fully support TLS 1.3.

When to suspect TLS 1.3 issues

How to test

Temporarily disable TLS 1.3 to determine if it is the cause:

  1. In the Cloudflare dashboard, go to the Edge Certificates page. Go to Edge Certificates ↗
  2. Find TLS 1.3 and turn it off.
  3. Ask the affected visitor to test again.

If disabling TLS 1.3 resolves the issue, the visitor's network has a middlebox (firewall, proxy, or antivirus) that does not support TLS 1.3. Re-enable TLS 1.3 after testing and ask the visitor to:

If you cannot identify the root cause, contact Cloudflare Support with packet captures from the affected visitor showing the failed TLS handshake.


ISP and network interference

Some Internet Service Providers (ISPs) and corporate networks deploy security features that can interfere with HTTPS connections:

How to identify network interference

Ask the affected visitor to:

  1. Try a different network - Use mobile data instead of Wi-Fi, or try a different ISP
  2. Use a VPN - If the site works through a VPN, the ISP or local network is likely interfering
  3. Disable local security software - Temporarily disable antivirus or firewall software to test
  4. Check with their ISP - Some ISPs have security features that can be disabled upon request

If network interference is confirmed

If the issue is caused by the visitor's ISP or network:


Collect diagnostic information

If the above steps do not resolve the issue, collect the following information from affected visitors:

  1. Cloudflare diagnostic data - Ask the visitor to access https://your-domain.com/cdn-cgi/trace and share the output
  2. Exact error message - The full error text and error code from the browser
  3. Browser and OS version - Including any security software installed
  4. Network information - Whether they are on a corporate network, using a VPN, or have any proxy configured

Check Cloudflare Status to verify there are no ongoing incidents affecting SSL/TLS.

If the issue persists and affects many visitors, contact Cloudflare Support with the diagnostic information collected.