How to fix ERR_CONNECTION_REFUSED

The server answered, but nothing was listening on that port. Usually the web server is stopped, listening elsewhere, or a firewall rejects you.

1–2 minutes
Raspberry Pi in a case on top of a small network switch

ERR_CONNECTION_REFUSED means your browser reached the server’s address, but the server rejected the connection on that port. Usually the web server is not running, is not listening on 80 or 443, or a firewall is actively rejecting you.

If you are visiting the site

  • Try the address with and without https://.
  • Try another network; a firewall or VPN on yours may block the port.
  • Clear your DNS cache in case it holds an old address. See flushing DNS.

If you run the site

1. Is the web server running?

sudo systemctl status nginx
sudo systemctl status apache2

Start it if needed, and if it fails to start, the reason is in sudo journalctl -u nginx -n 30. A common one is another program already using port 80 or 443.

2. Is it listening on the right ports?

sudo ss -tlnp | grep -E ':(80|443)\b'

No :443 line means HTTPS is not configured: add a certificate (see Let’s Encrypt). A 127.0.0.1:80 address means it only listens locally.

3. Firewall

sudo ufw status
sudo firewall-cmd --list-all

Allow 80 and 443 if missing. See firewall setup. Also check your host’s cloud firewall.

4. DNS points to the right server

dig example.com +short

If the address is not your server’s, the refusal is coming from somewhere else entirely.

Refused or timed out?

Refused means the machine replied “no”. Timed out (ERR_CONNECTION_TIMED_OUT) means nothing replied, usually because a firewall silently drops the traffic or the server is off. See what a port is.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.