FTP Connection Errors: Why They Happen and How to Fix Each One

"Connection refused." "Connection timed out." "530 Login incorrect." "Could not connect to server." If your FTP client is throwing one of these, you're not alone — this is the most common support topic on every hosting provider's site. This guide is tool-agnostic: it explains what each error actually means, where the problem most likely lives (your network, the client, or the server), and how to fix it.

Connect Now — access your FTP server

Stuck right now? 3 quick checks

Before you dig into any single error, run these three checks — they clear most failures in under a minute.

Host & port: 21 vs 22

Verify the hostname and port you're typing. Plain FTP uses port 21; SFTP uses port 22 (and some hosts run either on a custom port). Connecting to the right address with the wrong port — or selecting FTP when the server only offers SFTP, or vice versa — produces a refused or timed-out error every time. Copy the exact host and port from your hosting provider's welcome email or control panel rather than typing from memory.

Credentials: case, format, and existence

FTP usernames and passwords are case-sensitive. Shared hosts also often require the username as user@domain rather than just user — check the exact format your host displays in its control panel. And remember that an FTP account is not the same as your hosting login; on cPanel-style hosts you create it separately under Files → FTP Accounts. See our cPanel FTP guide for where these live.

Retry from another network

If you can, test from a second network — a phone on mobile data, a different Wi-Fi, or a colleague's connection. If the same credentials and server work elsewhere, the problem is almost certainly a local firewall, a router rule, or an upstream network block on the network you're sitting on.

530 Login incorrect / authentication failed

The server accepted your connection and then rejected your credentials. The good news: this error is almost always about the account, not the network — so it's usually quick to fix.

Wrong password, or the username wasn't created

Re-enter the password carefully — lowercase/lowercase typos and a trailing space are the usual culprits, and passwords are case-sensitive. If the host gave you a temporary password, the login may also fail because you haven't changed it yet. Confirm the FTP account actually exists: an FTP account is separate from the hosting account, and on many hosts it isn't created automatically. In cPanel it lives at Files → FTP Accounts; other hosts call it "FTP users" or "SFTP users" in their panel.

FTP account ≠ hosting account

Your cPanel or dashboard login is not an FTP login on most hosts. The FTP account is created in the control panel with its own username and password, often tied to a home directory and a disk quota. If you've never created one, create it first, then connect with those exact credentials.

Password reset lives in the control panel

No FTP client can recover your password for you — the client only sends what you type to the server. Reset the password from the host's control panel (cPanel: Files → FTP Accounts → Change Password), then reconnect. Our cPanel FTP guide walks through the exact screens.

SFTP vs FTP: the account may be one, the other, or both

Some hosts create a single account usable for both FTP and SFTP; others keep them separate, and some (like Bluehost) only enable SFTP after SSH access is switched on. If FTP works but SFTP says authentication failed — or the reverse — check whether the account is enabled for that protocol in the host panel. If SFTP itself is the problem, the SFTP connection errors guide covers host-key verification, publickey, refused, and timeout fixes.

IP blocks that mimic 530

Some hosts reject logins from blocked countries, flagged IPs, or after several failed attempts, and present it as a generic authentication failure rather than a distinct message. If the credentials are definitely right, wait a few minutes (failed-login lockouts usually expire), or try from a different network to see whether the block follows the IP rather than the account.

Connection refused / ECONNREFUSED

Refused means someone reached the server and was told "no" — a packet came back resetting the connection. Something on the other end is listening and saying no, or a firewall is actively rejecting you. It's a different signal from a timeout, and the causes are usually more concrete.

Wrong host or port — the most common cause

Double-check the hostname (a typo can resolve to a server with nothing on that port) and confirm the port: 21 for FTP, 22 for SFTP. FileZilla's literal message for this case is ECONNREFUSED — Connection refused by server, and it means exactly what this section describes — nothing to do with FTP specifically, just the TCP connection being rejected. (And if you'd rather not use FileZilla at all, our FileZilla alternatives page compares free desktop and no-install options.)

FTP service stopped on the server

If the server's FTP/SFTP service isn't running, the port answers with a refusal. On shared hosting the service runs on the host's side — you can't start it yourself, so this one ends with a support ticket to your host. On your own VPS you can check (e.g. systemctl status vsftpd or ss -ltn) and start it.

Firewall or antivirus on your computer

Desktop FTP clients are sometimes blocked by the client machine's own firewall or antivirus — Windows Defender, third-party suites, and corporate endpoint products all do this. Add an exception for the client executable, or test with a different machine to rule it out.

The server is blocking your IP

Servers with geo/IP allowlists reject connections from outside the allowed range — often as a refusal, sometimes as a timeout. If the same client works from another network or a VPN, your IP is the problem.

TLS-only servers reject cleartext clients

Many hosts have moved to FTPS (FTP over TLS) and disabled plaintext FTP. A client that connects in cleartext gets refused or an upgrade-required message. Check whether your host requires "explicit FTPS" and enable TLS in the client — or switch to SFTP where it's offered.

Connection timed out

Timeout means your request went out and nothing came back — packets are being dropped, not rejected. Where "refused" is a door slammed, "timed out" is a door that was never reached. The fix depends on where the silence happens.

Firewall dropping traffic — not refusing it

Firewalls are often configured to silently drop rather than reject. The effect is a timeout. If a host worked before and times out now, check whether its firewall rules (or your cloud provider's security group) changed — for example, whether TCP port 21/22 is open from your IP range.

Server down, or DNS points at the wrong IP

A powered-off or crashed server never answers. DNS can also be stale or wrong, sending you to an IP where nothing listens. Check with a tool (see the next section) whether the host resolves and whether the port answers at all.

Outbound port 21 blocked by your network

ISPs, corporate networks, and school networks sometimes block outbound FTP ports; and many destinations block FTP on standard ports from datacenter or residential ranges. This is the classic case where the same creds work from a phone hotspot. When in doubt, move to SFTP on port 22, which is far less often blocked — or test from another network.

Home-LAN server without port forwarding

An FTP server on your home network is reachable from that network but invisible from the internet unless the router has a port-forward rule for port 21 and the server's address is stable. Without it, outside connections time out — and sadly, a browser-based client still can't reach it (see the FAQ below): relayed connections need a publicly reachable host.

Connects but directory listing hangs / "data connection could not be established"

This one is special: the login succeeds, then the folder listing — or a transfer — stalls forever or fails with a message about a data connection. The control connection (login) works; the data connection (the actual listing/transfer) can't be made.

Active vs passive mode in plain English

FTP uses two connections. The one you log in on is the control connection. For listings and transfers, either the client connects out to a port the server advertises (passive), or the server connects back into the client (active). Active mode requires the server to reach your computer on a random port — and that inbound path is blocked by virtually every NAT router and most firewalls. That's why modern clients default to passive.

"227 Entering Passive Mode" with a private IP — a server-side misconfiguration

In passive mode the server answers with an address and port for the client to dial. If the server advertises a private IP (like 192.168.x.x or 10.x.x.x) instead of its public address — a classic misconfiguration behind NAT — your client tries to connect to an unreachable address and the listing hangs. That fix is server-side: the host must configure its passive IP and port range. No client setting can fix a bad passive announcement.

When to stop fighting config and ask the host

If the login works but listings always hang, the problem is usually on the server side — passive range misconfiguration, or a firewall not allowing the passive ports. On shared hosting you can't touch those settings, so the honest move is a support ticket quoting the exact 227/425/426 message you see.

Other common errors at a glance

ErrorWhat it meansWhat to do
421 Too many connectionsThe server has hit its per-account connection limit — cPanel limits shared accounts by default. Stale sessions from other clients still count.Close other FTP sessions, wait a few minutes, and raise the limit in the control panel if you can (cPanel: Files → FTP Accounts, then "Configure FTP Server" / connection limits).
550 Permission deniedThe server refused the operation — wrong directory, insufficient permissions, read-only folder, or a full disk quota.Check the path you're writing to exists and belongs to your account, and confirm you're not over quota. On shared hosting, quota and folder permissions are set in the control panel.
425 / 426 Can't open data connectionThe data channel failed mid-transfer — almost always the same firewall/passive-range problem as the hanging listing, but now during a transfer.Switch the client to passive mode; if it's already passive, the server's passive range or firewall is the problem — ask the host.
500 Syntax error / command not understoodThe server rejected a command — often a protocol mismatch (e.g. an FTPS-only server with a cleartext client sending AUTH) or a client that's too new/old for the server.Make sure you're using the exact protocol the host supports; where TLS (FTPS/explicit) is required, enable it in the client.

Narrow it down: port check, then a connection test

Instead of guessing, run the diagnosis in two steps. Where it fails tells you which fix applies.

  1. Check the port. Use the FTP Port Checker — it probes TCP from our servers to your host:port and reports open, closed, filtered (timeout), or unreachable. A filtered result points at a firewall dropping packets; closed means the service is off or rejecting; unreachable means DNS or routing is wrong. The checker can probe any port (21, 22, 2121, 990…), so it also tells you whether the port your client is using is even reachable from outside.
  2. Test the login. If the port is open but a real login still fails, use the SFTP Connection Tester with your own credentials — it performs the SSH handshake and stops as soon as the connection is made (it doesn't touch files). For plain FTP, the equivalent question is simply whether the server accepts your credentials when the port is confirmed open.

That gives you the four-way split: DNS (host doesn't resolve → unreachable), TCP (port closed/filtered → service or firewall), auth (port open, login rejected → credentials/account), and data channel (login fine, listing/transfer hangs → passive/active or server firewall).

Fixed? Connect in your browser — and skip client network config entirely

Once the server side is healthy, the client side can trip you up again — especially FTP mode settings. FilePort Pro runs in your browser and relays the data channel through our servers, so there is no passive/active setting on your side to get wrong; the relay handles the data connection from its own network.

Some honest limits, so you're not surprised later:

Ready when the server is: Connect Now — transfer files from your browser

Frequently asked questions

What does "530 Login incorrect" mean?

Credentials were rejected. Check password case, username format (shared hosts often require user@domain), and that the FTP account exists — an FTP account is separate from the hosting login and may need creating in cPanel or the host panel. Passwords can't be recovered from the client side; reset it in your control panel.

Why does my client connect but time out listing folders?

Almost always the data channel: in active mode your router blocks the server's inbound data connection; in passive mode the server must advertise a reachable port range. On shared hosting the passive fix is server-side — contact the host. (Note: a browser client that relays the data connection doesn't need any client-side mode setting, but a misconfigured server-side passive range can still block it.)

What's the difference between "connection refused" and "timed out"?

Refused means the server (or a firewall) actively rejected the connection — something is listening or deliberately resetting. Timed out means no response at all: packets are being dropped by a firewall, the server is down, or DNS points at the wrong IP.

My client literally says "ECONNREFUSED — Connection refused by server." Is that different?

No — that's the same error; "ECONNREFUSED" is FileZilla's message for connection refused. Work through the same checks: port 21 vs 22, firewall/antivirus exception for the client, and whether the server's FTP service is running. If it only happens during directory listing, see the passive/active section.

Do I need to open port 21 on my router just to connect out?

Usually not. Outbound connections mostly work as-is; the direction that breaks is inbound (active mode, or a server behind NAT). If you're on a corporate/school network, outbound FTP ports are sometimes blocked upstream — test from another network before blaming your server.

Can FilePort Pro reach my FTP server on my home network?

No. FilePort relays your connection through a cloud server, so it can only reach hosts that are publicly reachable on the internet; a server on your LAN needs a client running on that network. Also, plain FTP transmits credentials and files in cleartext — if your host offers SFTP, use it; FilePort supports both and verifies SFTP host keys.

More help

Tools and guides that pair with this one:

If a fix ends in "ask your host," that's not a cop-out — stopped services, passive-range misconfigurations, quotas, and IP blocks are all server-side by design. No client setting can reach them.