Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (58%)
- Hosting (25%)
- Domains (17%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 11 hours ago |
|
|
Cloud Services | 2 days ago |
|
|
Cloud Services | 3 days ago |
|
|
Hosting | 4 days ago |
|
|
Hosting | 13 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
R.Gion (Any/All) (@Gion_the_critic) reported@SportingNest @Cloudflare Where was this? I've never seen it
-
Ric Orna (@ric_orna) reported@yongfook Or you gotta be doing something that actually has a moat still. Eg a network of sensors and API. Nobody is gonna vibe code physical stuff. Or something so big and boring a lift that nobody would want to and couldn’t in short order anyway. Vibe code your Cloudflare competitor.
-
Eli Yumn (@EliYumnik) reported@acolombiadev @Cloudflare GitHub for CI/CD and hosting the damn internet’s repos Supabase Resend Replit Gemini Eleven labs
-
junebnunny (@junebnunny_) reported@Gion_the_critic @SportingNest @Cloudflare It's just the type of thing you've just got to come across and you don't really find them that often, because when a campaign is up, it's up for a few hours and then taken down very quickly, because it's quite obviously malware.
-
Adam Rackis (@AdamRackis) reported@kettanaito @flydotio Do your pods auto-sleep when they’re not getting traffic? I think there’s a min setting you have to set to zero to let everything shut down and then just cold start on the next request. Really though surely Cloudflare free tier is simpler?
-
James Martinez (@realjamesmtz) reported@mrfundman @Cloudflare Damn too rich for me.
-
Andrea (@acolombiadev) reportedName one underrated/generous free tier service. I’ll start: @Cloudflare
-
Hatem Hosny (@hatem_hosny_) reported@acolombiadev @Cloudflare @livecodes_io the client-side code playground that can be embedded and self-hosted is free for unlimited usage! 90+ languages/frameworks Mobile support Private by default Open-source
-
Selenka (@SelenkaOnChain) reportedNetnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."
-
Guillermo Zaandam 🇨🇦🇳🇱 (@besodemieterd) reported@Cloudflare Your CSP rules and WAF rules aren't working again and again. Please fix this
-
AGTP (@AGTPinsights) reportedCursor just launched self-hosted machines for cloud agents today. Here's what you need to know. You can now run Cursor cloud agents on infrastructure you manage, including pools of machines that auto-scale with demand. The agent loop still runs in Cursor, but tool execution, your codebase, build outputs, and secrets stay entirely inside your own network. This gives agents access to internal services or specialized hardware that Cursor's own cloud can't reach. Cursor also added support for supported sandbox providers, letting teams pick managed infra instead of running their own machines. Self-hosted workers now support computer use on Linux and Mac too, so an agent can click, type, take screenshots, and drive the browser, with users able to watch or take control from Cursor. Coder separately announced Agent Relay, giving Cursor Cloud Agents self-hosted execution environments on customer infrastructure, launching in private preview with SpaceXAI as a design partner for regulated enterprises where code can't leave the network. Key numbers: - Supported sandbox partners at launch: AWS Lambda, Coder, Cloudflare, Daytona, E2B, Modal, Namespace, Vercel - Cursor Pro pricing starts at $20/month, self-hosted machines require paying for your own compute separately - Coder Agent Relay: private preview, no public pricing yet Team pools can hibernate idle machines so you're not paying to keep capacity warm.
-
My1 (@nep.one - Misskey) (@My1xT) reported@slendidev interesting question would be how fast or slow cloudflare runs on those, as especially on my older laptop it sometimes took a decent while, before needing a click and taking a decent while again, while anubis you dont need to babysit.
-
JovanHuttonPulitzer™ אני לא סובל טיפשים! (@JovanHPulitzer) reported@FinalCutTile So as a tiler and tile installer, how do you think the Internet runs? I vote this the NEWEST stupid *** comment on X regarding #datecenters this week: The statement is false. Data centers are needed to run the internet as it actually exists today. What the internet actually is: The internet is a distributed “network of networks.” There is no single control room. Packets can theoretically move between two computers connected by routers and cables without a giant warehouse full of servers. Early ARPANET and 1980s–90s internet ran on university machines, government systems, and smaller server rooms. That part is true. That is not the internet anyone uses. What actually happens when you “use the internet” Almost everything people mean by the internet lives in data centers: Websites, search, email, social media Streaming (YouTube, Netflix, etc.) Cloud services (AWS, Azure, Google Cloud) Banking, payments, maps, messaging DNS, CDNs, and most of the content that gets delivered to your device Sources across Microsoft, Cloudflare, industry analyses, and infrastructure reporting describe data centers as the physical facilities that store, process, and serve that content. Without them, the pipes still exist, but the useful destinations do not. One infrastructure expert put it bluntly: the rudimentary network can still function, “you just can’t do anything that you’re used to on the internet because that’s all posted out of these datacenters.” Calling data centers the “backbone” or “brick-and-mortar of the digital world” is standard, not hype. The distinction that the statement ignores Network layer (cables, routers, ISPs, peering): can exist without hyperscale data centers. Application / content layer (everything you actually open, stream, search, or log into): overwhelmingly depends on them. The insult in the original statement does not change the facts. Data centers are required for the internet people actually use.
-
Wes Roth (@WesRoth) reportedCursor cloud agents can now run on infrastructure you manage, including machine pools that automatically scale with demand. Self-Hosted Machines let agents execute inside your network with access to internal services, source control, custom hardware like GPUs and Macs, and existing build infrastructure, while inference, planning, and the agent loop remain in Cursor’s cloud. Cursor also supports AWS Lambda, Cloudflare, Coder, Daytona, E2B, Modal, Namespace, and Vercel. Cursor says cloud agents now create more than 60% of the pull requests it merges internally.
-
JK (@_junaidkhalid1) reported@dillon_mulroy @EffectTS_ the cloudflare support point is the one that actually moved me. a lot of these framework bets fall apart the moment you try to deploy somewhere real. effect holding up there changes the calculus.
-
Nick Dodd (@nickdodd) reported@BraydenWilmoth Who knew billing was important for a company literally selling services? I never, ever, have wondered why I have never used Cloudflare for anything.
-
Lex (@TheLexTimes) reportedHey @Cloudflare I reached out via DM about WARP constantly disconnecting. Is there a direct contact I can talk to? Happy to provide any data to help figure this issue out.
-
ticktechh (@sprki999) reported@OmegaNekoSimp Thats the only human check that doesnt trigger me. What the actual **** does the challenge of clicking a box from cloudflare do? How isnt that challenge useless?
-
Bryan Beal 🎧 (@bryanrbeal) reportedPro tip - disable Eero’s DNS and use Google or Cloudflare DNS and 99% of Eeros problems disappear Eero DNS is trash
-
shownotover (@shownotover) reported@edtadros Well seems like I need to give it a try. Not gonna lie, I never thought two people would tell me to use Cloudflare.
-
shownotover (@shownotover) reported@adnaannasir_ Does Cloudflare really provide hosting? I have never tried it.
-
Saeid Shahriari (@saeidshahriari) reportedStopping the bad guys with Cloudflare: 16,098 malicious requests blocked or challenged in the last month #cloudflare
-
ッ ᴇᴇʟᴋᴏ ᴀʟᴇxᴀɴᴅᴇʀꜱ (@eelko1976) reportedethereum:native under the 2400$ solana:So11111111111111111111111111111111111111112 just under the $100 mark. Aay. @BloFin_Official Why do I get a temporarily ban from @Cloudflare for too many requests wtf?! Have to use a VPN now (which I wasn't before) otherwise I cannot access MY account.
-
robot 2.0 (@alightinastorm) reported2 weeks of prompting can build this now, in the browser, no platform fees, no pre-downloading gigabytes, stream as you play is it AAA? no is it low poly slop? no can you build real games with it? you absolutely can stop inventing bullshit about distribution, what distribution do you get from steam? ZERO, that's why you hire marketers to run guerilla campaigns on social media, streamers to hype it up and backdoor some cash to youtubers to pump it on release week You can do the same for the web, your likes and followers on X are your wishlist Pay stripe 3% instead of 30%, throw a couple $$ to cloudflare for traffic Or keep betting on steam and die a slow painful corporate death
-
LilRhodySpecial (@rhody_special) reported@Sprytixl Yet another ad to get you to use their data stealing bot on the cloudflare data snooping service
-
Yash Desai (@yash_d_desai) reportedStopping the bad guys with Cloudflare: 20,273 malicious requests blocked or challenged in the last month #cloudflare
-
siftydeals (@siftydeals) reportedCloudflare had 487 outages in H1 2026. Most teams still treat uptime like a technical metric instead of a customer trust issue. Your SaaS tool only works if your customers can actually reach it. 🔧 Details in link.
-
Winston Gao (@Winston_Gao) reportedThe lean tech stack we use to run cross-border physical operations (China OEM ➔ EU fulfillment) with zero legacy banking friction: 1. Modern FinTech Rails: • 𝕏 Money Card (physical + virtual sub-accounts) for instant micro-disbursements & isolated expense budgets. • Stripe US/EU for automated customer settlements. 2. Resilient Network Egress: • Cloudflare WARP + dedicated WireGuard tunnels. • Eliminates random geolocation flags and authentication freezes across international portals. 3. Automated Customs & Compliance: • Lightweight Python + OCR parsing ERP bill-of-materials into EU EN 1493 Declaration of Conformity specs. • Cut compliance verification from 72 hours to 15 minutes. 4. Local 48h Physical Spares Buffer: • Dedicated Italian consignment warehouse so European workshops never wait on 4-week ocean freight for a seal replacement. Heavy global commerce used to require an army of back-office staff. In 2026, code and modern rails let a small team run an entire international supply chain.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
Girish (@spectragai) reported@UthaaleReDeva @acolombiadev @Cloudflare It serves different purposes. But I’m just answering the post: name a generous free tier service