ERR_CONNECTION_REFUSED: What It Means and How to Fix It
ERR_CONNECTION_REFUSED means the server was reached and actively rejected the connection. Tell a stopped web server from a firewall or local issue, then fix it.
ERR_CONNECTION_REFUSED is one of the most specific errors a browser can show, which makes it one of the easiest to diagnose. Chrome displays it under This site can’t be reached — example.com refused to connect. Firefox says Unable to connect; Safari says Safari can’t open the page because the server unexpectedly dropped the connection or could not connect to the server.
“Refused” is the key word. Your browser found an IP address for the domain, sent a connection request to it, and got an immediate, explicit rejection back. That is different from a timeout, where nothing answers at all, and different from a DNS failure, where no address is found. Something at that address is alive — the machine, or a firewall in front of it — and it said no to port 80 or 443.
Is it the site, or you?
- Load the site on a phone using mobile data. If it works there, the refusal is happening on your side — a proxy, VPN, security software, or a local DNS entry pointing somewhere wrong.
- Try another site. If every site is refused, your proxy settings or security software are the problem, not the websites.
- Run the domain through the website checker. It connects from an independent server. If it is refused too, the site is genuinely not accepting connections.
If the site refuses everyone
A refusal for everyone means one of three things: nothing is listening on the web port, a firewall is actively rejecting the connection, or DNS is sending visitors to a machine that is not your web server.
| What you find | Cause | Fix |
|---|---|---|
| Port 443 closed, port 80 open | HTTPS listener missing — no certificate configured, or server block disabled | Configure TLS and restart the web server |
| Both ports closed | Web server stopped or crashed | Start it, then find out why it stopped |
| Server running, still refused | Listening on 127.0.0.1 or the wrong port |
Bind to 0.0.0.0 or the public IP on 80/443 |
| Refused from some countries or networks | Firewall or fail2ban rejecting ranges | Review firewall rules and ban lists |
| DNS points to an old IP | Migration left an A record behind | Update DNS to the new server |
The web server is not running
The most common cause. nginx failed to restart after a config change, Apache crashed, a container stopped, or the server rebooted and the service is not enabled at boot. The operating system has nothing bound to port 443, so it rejects every connection instantly.
Check: systemctl status nginx (or apache2, httpd, caddy), and ss -tlnp | grep -E ':80|:443' to see what is actually listening. A config test — nginx -t or apachectl configtest — often reveals why the last restart failed.
Fix: correct the config, start the service, and enable it so it survives reboots: systemctl enable --now nginx.
The application listens in the wrong place
Node, Python, and Go apps commonly bind to localhost:3000. That works on the developer’s machine and refuses every outside connection in production, because nothing is listening on the public interface. The same happens with Docker when a port is not published.
Fix: bind to 0.0.0.0, publish the port (-p 443:443), or — better — put a reverse proxy in front on 80/443 and keep the app on an internal port.
A firewall rejects the connection
Firewalls can drop packets (which produces a timeout) or reject them (which produces a refusal). A REJECT rule in iptables, ufw, a cloud security group, or an intrusion-prevention tool like fail2ban banning your IP all show up as ERR_CONNECTION_REFUSED.
Fix: check ufw status, iptables -L -n, your cloud provider’s security group, and fail2ban’s ban list (fail2ban-client status). If only you are refused, you may have been banned after a burst of failed logins.
DNS points at the wrong machine
After a migration, a leftover A or AAAA record can send some visitors to the old server — which is now switched off or no longer runs a web server. IPv6 is a frequent culprit: the site was moved, the A record updated, and a forgotten AAAA record still points to the old host. Visitors on IPv6 networks are refused while everyone else loads the site.
Fix: dig +short example.com A and dig +short example.com AAAA — every answer should belong to the current server. Remove or update stale records. If the domain resolves to nothing at all, you are looking at an expired domain or a missing record, not a refused connection.
If only you are refused
- Turn off your VPN or proxy. In Chrome, check Settings → System → Open your computer’s proxy settings. A misconfigured proxy refuses everything.
- Pause security software. Antivirus web shields and corporate endpoint tools can block specific domains.
- Check your hosts file (
/etc/hostson Mac and Linux,C:\Windows\System32\drivers\etc\hostson Windows) for a line pointing the domain at127.0.0.1or an old IP. - Flush DNS:
ipconfig /flushdnson Windows;sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponderon macOS. - Developers: if you see this for
localhost, your local dev server is not running or is on a different port than the one you opened.
How to confirm the fix
curl -sv https://example.com -o /dev/null 2>&1 | grep -E 'Connected|refused|HTTP/'
You want a Connected to… line and an HTTP status, not Connection refused. Test from outside your network, and test both IPv4 (curl -4) and IPv6 (curl -6) if the domain has both record types.
The cost of a refused connection
A refused connection is a complete outage: no error page, no branding, nothing a visitor can do. And because it often follows a routine event — a reboot, a config change, a server move — it tends to start quietly overnight and be discovered by a client.
SitesRadar’s free plan checks one site from an independent server on a schedule and emails you the moment it stops accepting connections, with DNS, SSL, and broken-link checks alongside. For the full set of connection-level errors — timeouts, resets, DNS failures — see this site can’t be reached, and use the client site down triage checklist when it is a client’s site at 2 a.m.
FAQ
What does ERR_CONNECTION_REFUSED mean? Your browser reached the server’s IP address, but nothing accepted the connection on the web port — either no web server is running there, or a firewall actively rejected it.
Is ERR_CONNECTION_REFUSED my problem or the website’s? If it happens on other devices and networks too, it is the website. If only your device is refused, check your proxy, VPN, security software, and hosts file.
How do I fix “refused to connect” in Chrome? Clear the browser cache, disable extensions and any proxy or VPN, and flush your DNS. If the site is refused from other networks too, only the site owner can fix it.
What is the difference between connection refused and connection timed out? Refused means something answered and said no — usually no service on that port. Timed out means nothing answered at all — usually a firewall silently dropping traffic or a host that is offline.
Why does localhost refuse to connect? Your local development server is not running, crashed, or is listening on a different port from the one in the URL.