Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (29%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 11 days ago |
|
|
Hosting | 13 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 1 month ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Xoge (@ClassyXoge) reportedThe only self custody is complete ownership of code, node and wallet. To ensure your ip is not logged, to ensure no down server or cloudflare reroute can stop you. Be your own bank, has never been more real than madlab
-
Leo (@0xGKBRK) reported@FuckKoroks It’s not like Cloudflare puts itself in the middle by hacking the website. The person running the website wants to use Cloudflare. If you’re gonna complain to someone, complain to the website that subjects you to that crap. Or vote with your wallet and go to a normal website.
-
Grigori Karapetyan (@GregKara6) reported@59thProfile first of all, i think that also went over your head, my whole premise is that i have exhausted my ego and accepted llms into every part of my workflow. if i had an ego id be the other side of the argument. don't confuse me calling an llm a tool for some type of strength you have over me, that's cute and hilarious. also i don't know what's wrong with you, but my memory of our interaction is completely different, i remember mentoring you, putting you on the right track, validating your work, telling you good job, and also praising you in the cloudflare post and calling your sandbox implementations better than theirs, do you not remember that? do you not remember me teaching you about propper kernel isolation? do you not remember me putting you on the right track when you were trying to hand bake sandboxing by hand? do you not remember me telling you that if you take that approach you are making a weaker sandbox because you can never handle all the edge cases yourself? do you not remember me telling you to use microVMs instead? to me that was a positive interaction. very concerning my friend.
-
mrusu.jp (@mrusu_) reportedthis cloudflare crap is messing me up technically done though
-
Alvin (@Alvin1492840) reportedFix 2: He changed the DNS server from their ISP's to Cloudflare's. He asked if they knew what DNS was. They didn't. Nobody does. DNS stands for Domain Name System. Every time you type a website name into a browser or open an app that connects to the internet, the DNS server translates that name into an IP address the numerical location of the actual server. It's the phone book of the internet. Your device asks the DNS "where is Netflix?" and the DNS responds with the address. By default, every router uses the DNS server provided by the ISP. The ISP's DNS works. It resolves the requests. But ISP DNS servers are notoriously slow, overloaded, and sometimes unreliable. Every web request passes through them, and every millisecond of delay compounds across every page load, every app refresh, every stream buffer. He opened the router's WAN settings and changed the DNS from "Automatic" to manual. He typed in two addresses: 1.1.1.1 and 1.0.0.1 Cloudflare's public DNS servers. Cloudflare operates one of the fastest DNS networks in the world. Google's public DNS 8.8.8.8 is another popular alternative. Both are free. Both are faster than virtually every ISP's default. The change applies to every device on the network simultaneously. Every phone, every laptop, every tablet, every smart TV, every game console all now routing DNS requests through a faster server without any individual device needing to be touched. Web pages started loading noticeably snappier. Not because the bandwidth increased the speed test wouldn't show a difference but because the time between typing a URL and the first byte of data arriving dropped by 30–50 milliseconds on every single request. Multiply that across thousands of requests per day across 23 devices and the cumulative effect is a WiFi network that feels materially faster.
-
Ara T. Howard (@drawohara) reportedtoday, with the help of 3 agents, I managed to create a cloudflare API token JFC
-
Arkfile (@Arkfile_OSP) reportedCloudflare Turnstile is getting to be a serious problem (broken) on Brave Browser.
-
PUNK SQUAD (@PUNKSQUADcom) reported@MaxUrus254 @DailyLoud Cloudflare then bot detection router. But no 99.9% of the site you need to login.
-
Janek Mann (@janekm) reported@doodlestein @yzhang390 But that's not really the issue... it's that e.g. Huggingface and Microsoft and Cloudflare and Fireworks can be easily stopped from hosting them with misguided regulation. Literally only harming US companies at the expense of Chinese ones, ultimately.
-
Toolport (@toolportapp) reportedCloudflare's CTO, Dane Knecht, emailed their entire customer list about running every AI agent through MCP portals, with scoped tool access and a Code Mode they say cuts token costs ~93%. We build Toolport. This is our exact category. A few notes from the small end of the pond. 1. The announcement is two products wearing one trenchcoat. AI Gateway is a model-layer proxy. It routes your OpenAI/Anthropic calls and meters model spend, same lane as OpenRouter or LiteLLM. MCP portals are the tool layer, deciding which servers and tools each agent can touch. Different problems, different failure modes. If you're evaluating either one, don't let the bundle blur that line. 2. Their ~93% Code Mode number lands in the same range we've been measuring with lazy discovery for the past three months. Loading dozens of tool schemas into context on every request was always the wrong default. It's nice that it's no longer just indie gateway builders saying so. 3. The structural difference. Their portals require being a Cloudflare customer and routing agent traffic through their edge. Toolport runs on your own machine and works with Claude Desktop, Cursor, and 25 other clients, with no vendor in the traffic path. When the traffic is your prompts, your credentials, and your tool outputs, where it flows is not a detail. 4. Scoped access is becoming table stakes. The harder question is whether the tool you approved yesterday is the same tool running today. Toolport pins tool integrity, quarantines drift, and scans for injection. A DLP scan on the wire doesn't catch a server that changed underneath you. Watching a giant walk into your category is a strange feeling. It's also the strongest signal yet that this layer needs to exist. We just think it should live on your machine, not in someone else's cloud.
-
Anjula Dwivedi (@HeyAnjula) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked.
-
Milk Road AI (@MilkRoadAI) reportedOpen-source is dying and the companies that survive it are about to get very rich (Save this). That's the uncomfortable truth in Dylan Patel's take, American open source AI is basically dead. Meta has gone quiet on Llama, Mistral, once the loudest open source advocate in the West, shifted its flagship models to proprietary licensing while charging five to ten times more than comparable Chinese models for similar performance. So the only frontier level open models left are Chinese, Qwen, DeepSeek, Kimi, GLM and the labs building them barely profit from giving them away. The money instead flows downstream, to whoever hosts, serves and charges for access to those free weights. Qwen overtook Meta's Llama as the most downloaded model family on Hugging Face in 2026, and Chinese open models now out download American ones globally by a wide margin. Kimi K3 was ranked the top open source model in the world by LMArena. None of that revenue lands with the Chinese labs themselves but rather lands with the inference layer running on top. Inference is already the biggest chunk of the AI compute market, with cloud inference alone estimated near $50 billion in 2026 and growing around 60% a year, dwarfing training infrastructure spend. Token pricing has collapsed roughly a thousandfold over three years which sounds bad for margins until volume growth outpaces the price decline, keeping total inference revenue climbing. Mistral's own pivot away from open weights shows what happens when a lab tries to charge premium prices in a market Chinese competitors are commoditizing its newest model is losing on both cost and quality to rivals a fraction of the price. If Chinese labs eventually decide there's no financial reason to keep releasing frontier models for free, the open-source pipeline could dry up overnight. However, here are the publicly traded infrastructure plays positioned to benefit if open source continues to dominate. Nebius provides the same raw compute layer underneath inference demand, without needing to bet on any single model's survival. AMD is chasing that same inference chip opportunity with its MI series accelerators, positioning itself as the main alternative supplier once inference volume keeps compounding. Cloudflare (NET) benefits through its Workers AI platform, which increasingly serves as the delivery layer pushing open weight models out to edge devices and apps cheaply. Microsoft (MSFT), Amazon (AMZN), and Alphabet (GOOGL) all benefit as the hyperscalers whose cloud platforms host the bulk of enterprise inference workloads, collecting compute revenue no matter which model an enterprise ultimately runs. Milk Road Pro is tracking all the biggest beneficiaries of open source AI, if you want access to all our AI trades around this trend, you can come join us for just $1 using the link below!
-
Harman (@itsharmanjot) reportedMost developers scan file extensions and call it security. Attackers don’t care what your file extension check says. There’s an open-source tool that actually scans the bytes before a file ever touches your disk. It’s called pompelmi. A TypeScript toolkit for Node.js that scans uploads in-process, MIME spoofing, ZIP bombs, nested archives, polyglot files, before storage, before your CDN spreads it, before it becomes someone else’s problem. → Scans in-process with zero outbound network calls, bytes never leave your server, no cloud API, no daemon required → Deep ZIP inspection catches nesting depth, file count, and archive traversal tricks that simple extension checks miss entirely → Optional ClamAV antivirus integration plus optional YARA rule support, for teams that want signature-based detection layered on top → Drop-in adapters for Express, Fastify, Koa, NestJS, and Next.js, plus support for Bun, Deno, and Cloudflare Workers → Built-in security scorecard grades your actual upload configuration A through F, so you know your real exposure, not just whether the tool is installed → Quarantine mode auto-moves flagged files with a sidecar JSON report, so a suspicious upload gets isolated automatically instead of silently landing in your storage bucket Any app that accepts user uploads is dealing with a real attack surface most teams treat as an afterthought. pompelmi’s whole design is catching the risk at the entry point, not after the file’s already spread across your systems. 337 GitHub stars.
-
Mārtiņš V. (@MartinMartinV_V) reportedVPN Renegade, falsely accused of SQL injection by Cloudflare’s WAF, currently stuck in a primitive splitting mechanism. Debating whether my hatred of CAPTCHA should be covert or fully public. “Cloudflare Inc … NYQ: NET 262.15 USD +66.13 (33.74%)” @ChatoshiAi "Life is not a problem to be solved, but a reality to be experienced" Søren Aabye Kierkegaard parable comes into mind.
-
Jake Gevorgian (@JakeGevorgian) reported@_slowstacking @FinancialPhys It's not like I'm not putting money in web. I spend $30k worth of time as I'm also tek savvy and do these seo stuff myself. What I've missed big time was cloudflare integration and schema. But even with that, I see companies who pop up on google first pages that I've never heard of in woodworking communities I am in... Btw, I don't think "competitor" is a valid term in this day and age for craftsmen in wood. It's not like we're selling car parts or plumbing supplies imported from China. :) this is what I'm stressing about---Google should focus on local American creators for people who look for local makers.
-
Eidzoku (@evi77ain) reportedApparently Codex Desktop 26.721.4979.0 can self-destruct just from using its built-in browser. Very agentic.💀 At first I thought Cloudflare was the cause. Nope. Perplexity reproduced the exact same failure, and it's already mentioned in one of the related issues. The actual chain is: webpage loads → Chromium GPU crashes (`101457950`) → Windows blocks the bundled `vk_swiftshader.dll` fallback for not meeting Microsoft signing requirements → GPU relaunch fails (`18`) → Codex dies.
-
Chinmay Purav (@chinmay_purav) reportedHey @Cloudflare , Please bring in support for .IN TLD domains!
-
Ray 🇺🇦🏳️🌈 (@uasneppy) reportedI’ll try to fix snepclub twitter embedder later today, sorry :( I didn’t know about the new updates and me having to have a burner account, plus deploying it on Cloudflare 💀
-
Leo (@0xGKBRK) reported@Puftberry @FuckKoroks I’ve paid for both Cloudflare and BunnyCDN before. Both are great. But if a user complained about either of them I couldn’t shift the blame to the CDN because I put the CDN there. That’s the main issue.
-
RedPocatto (@RedPocatto) reported@PirateSoftware strange - microsoft teams had australia wide problems too today - amazon or cloudflare problem i wonder?
-
Michael Tierney (@Michael_WCD) reportedCloudflare Pages and Workers are ideal for marketing sites. They eliminate server management, scaling issues, and security worries. Edge functions like Workers also reduce latency by running closer to users. A server in a datacenter can't compete with that.
-
tcpdump (@dump_tcp) reported@grok @meaganrgamache ah I don't use workers I use my own server's setup by myself with just cloudflare cdn infront as the proxy setup using dns A record for my domain as I like my control over my server and network overall flexible for me to do anything I want #cloudflare #dns
-
chrißy (@chribdotnet) reportedi need to set up cloudflare today and honestly cloudflare scares ******** out of me if i could make my own cloudflare i surely would but i just learned about /POST last night all this **** is easier than i expected ngl but still hard
-
Repojournal (@repojournal) reportedCachyOS installer getting a typed partition mode refactor across multiple passes, with base system install order shifted and partition mode support reworked. Cloudflare Warp, Claude Desktop, and GitHub Copilot app all bumped in the AUR-derived packages. Ananichy-rules hotfixed and pruned a Java rule that was causing friction. German wiki docs refreshed for Btrfs snapshots, QEMU/VMM setup, and desktop environments. Full diff + who shipped it below.
-
Sachi (@sachi_gkp) reported1/3 🚨 The AI security debate just changed. NVIDIA has launched the Open Secure AI Alliance with 35+ tech companies—including Microsoft, Hugging Face, CrowdStrike, IBM, Cisco and Cloudflare. The message is clear: security is becoming an ecosystem problem, not a model problem.
-
Somi AI (@somi_ai) reported@Complex cloudflare is also the company selling pay per crawl to publishers, so this stat doubles as a sales pitch for their own fix. probably still true though, scrapers run 24/7 and humans don't
-
Ievgen Pyrogov (@gmile) reported@ATimberlake Hi, Andrew! I wanted to read this blog post today, only to discover that your website was down - I get Cloudflare error page Maybe it's a bad luck / timing, e.g. I visited it while you're doing a maintenance? Anyway, just wanted to flag this
-
Igor@hansa.chat (@igorhansachat) reportedTurned out I broke something and my analytics was not working. The root cause was bunny[.]net (EU based cloudflare alternative) default policy was stripping some headers if "shield protect" is enabled. Good for security but breaks analytics :( Still sad as analytics is super important for me and now I have almost no data for last 4 days 🙈 Anyway, FIXED, **** happens but building is going further 😎
-
Michael Timbs (@michael_timbs) reported@thdxr Hahahahha. Improbable. One of the many reasons there’s very serious applications deployed on Cloudflare. Primitives are just wrong with terrible APIs the entire way down
-
Andy Hattemer (@andyhattemer) reported@jewelchidinma No known issues, what exactly is not working for you? We have seen in the past that certain ISPs block DNS for the Tables UI in console, switching to Google or Cloudflare DNS fixes it