Cloudflare Enterprise Errors 525, 526 and 1014, and the www Hostname

Updated October 9, 2026 · 6 min read

After you enable the Cloudflare Enterprise add-on, your site is served through Cloudflare’s Enterprise edge, which connects to your xCloud server as the origin. Most problems after activation show up as a Cloudflare error page with a code. The code tells you which layer failed, and almost every case comes down to one of four things: the www hostname, a DNS record, the origin certificate, or doing the DNS cutover too early.

This guide goes code by code. Before you start, open the site in xCloud and go to its Cloudflare Enterprise page. The Ownership Verification section and its Records list are the source of truth for every record mentioned below.

First rule: verify before you cut over

Every failed activation we see follows the same pattern: the routing records were changed before verification finished.

  1. Add only the verification and certificate validation records the dashboard shows.
  2. Click Refresh status and wait until the domain shows Verified.
  3. Only then add or change the routing records (the CNAME for the hostname, or the A records for an apex domain on a DNS provider without CNAME flattening).

Each DNS name can hold only one A, AAAA or CNAME record. Adding the routing record replaces whatever is live for that name, so do it last. If your zone is connected to xCloud through the Cloudflare integration, Verify & Add Records does all of this for you.

Error 1014: CNAME Cross-User Banned (usually www)

What it means. The hostname points directly at the xCloud edge hostname (edge.xcloud.app) instead of the Cloudflare Enterprise CNAME target assigned to your site. Cloudflare refuses the request because the record crosses between two Cloudflare accounts. The apex typically works while www fails, because www was set up earlier or by hand.

Fix.

  1. On the site’s Cloudflare Enterprise page, open Ownership Verification and find the www row under Records. Copy the CNAME target shown there.
  2. In your DNS provider, edit the www record: type CNAME, target = the value you copied. If the record is proxied in your own Cloudflare account, leave it as the dashboard instructs.
  3. Back in xCloud, click Refresh status.

If you do not want a separate www site, you still need www to resolve correctly before a redirect can work. Set the record as above, then handle the redirect in the site’s Domains settings rather than in your own Cloudflare rules.

Error 526: Invalid SSL certificate

What it means. The Enterprise edge connected to your origin with strict certificate checking, and the certificate it received does not validly cover the requested hostname.

Most common cause: www is not on the certificate. If www.example.com exists only as a redirect target on the site, it is excluded from the origin certificate.

Fix.

  1. Open the site → Domains and add www.example.com as a regular (non-redirect) additional domain.
  2. Save. xCloud reissues the origin certificate to cover every listed hostname.
  3. Wait a few minutes and reload the www URL.

Other cause: the origin certificate was not installed during activation. On the site’s Cloudflare Enterprise page, click Disable for the domain, wait for it to finish (you are notified), then click Enable. Re-enabling re-registers the domain and reinstalls the origin certificate. While disabled, the site serves directly from your server, so confirm DNS still points at it if the site is unreachable in that window.

If the 526 persists after both, contact support and mention “origin SNI”. The edge may be connecting with the wrong hostname, which support corrects from their side.

Error 525: SSL handshake failed

What it means. The edge reached your server but the TLS handshake between Cloudflare and the origin did not complete. This is on the connection between the Enterprise network and your server, not on your DNS and not on your browser.

Fix.

  1. Do not change your SSL mode, and do not reissue certificates from your own Cloudflare account or your previous host. Your server’s certificate is almost always fine.
  2. If the dashboard shows an Origin field for the domain and it is empty, enter your server’s IP address there and refresh the status. The dashboard now asks for this directly when it cannot detect the origin automatically.
  3. If the error continues, contact support with the domain and the time you saw the error. This one needs a check of the add-on’s origin settings for your domain.

Error 1000: DNS points to prohibited IP

What it means. Your apex domain uses Cloudflare nameservers and you pointed it at Cloudflare’s own IP addresses (for example as fallback A records). Cloudflare rejects this.

Fix. Remove those A records. On Cloudflare DNS, use the CNAME the dashboard shows for the apex; Cloudflare flattens it automatically. Use A records only on providers that cannot do CNAME flattening, and only the ones the dashboard lists.

What it means. Requests through the Enterprise edge are limited to roughly 8 KB of request headers. A site that sets many cookies, or one very large cookie, trips this limit only when Enterprise is enabled, which is why the error seems to appear out of nowhere after activation.

Fix. Raise the header buffers on the site with Nginx Customization as described in How to Fix “400 Bad Request: Request Header or Cookie Too Large”, then look at which cookies are growing and trim them.

“Cannot add the CNAME, an A record already exists”

DNS providers do not allow a CNAME next to an A record for the same name. Delete the old A record for that hostname, then add the CNAME the dashboard shows and click Refresh status. If the zone is connected to xCloud, use Verify & Add Records instead.

Still not working?

Open a ticket with:

  • the domain and whether the apex, www or both are affected,
  • the exact error code and the time you saw it,
  • a screenshot of the Records list on the Cloudflare Enterprise page.

If you run into any issues with the add-on, feel free to reach out to our support team.

Frequently asked questions

My main domain works but www shows Error 1014. Why?

The www record is pointing straight at the xCloud edge hostname instead of the Cloudflare Enterprise CNAME target shown on the site’s Cloudflare Enterprise page. Point www at that target and click Refresh status.

Do I need to add www as an additional domain on the site?

Yes, if you want www to be served (not only redirected). Add it as a regular additional domain under the site’s Domains settings so it is included in the origin certificate. A www that exists only as a redirect target is left out of the certificate and fails Cloudflare’s origin check with a 526.

Should I change my SSL mode or reissue a certificate when I see a 525 or 526?

No. Leave the SSL mode and certificates alone. These errors come from the hostname or origin configuration, and changing SSL settings usually makes them harder to trace. Follow the steps for the specific error code instead.