Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (35%)
- Cloud Services (26%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (9%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 12 days ago |
|
|
Hosting | 15 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Polarbear · App Growth Breakdowns (@polarbeargrowth) reportedPublic app, private admin, zero custom auth code. Cloudflare Access locks /admin/* behind Google login while the rest stays open. • Bake it into IaC so agents build the UI and protect it in one pass • No auth logic to maintain Vibecoded tools ship safe by default. h/t @thdxr
-
haden staab (@staabse) reported@Porkbun @baiaphilia Firstly, I never said there was something wrong with you. You’re more than welcome to give us your pitch. Why should I use Porkbun over Cloudflare?
-
Antraxyz (@antraxone) reportedStopping the bad guys with Cloudflare: 52,485 malicious requests blocked or challenged in the last month #cloudflare
-
Alex🌖⃤ (@axldefi) reportedThe job is not done yet, the person/entity doing these false reports just to slow us down, started reporting on our IMAGES subdomain now. Crazy to me how all of these databases flagged a Cloudflare Image hosting url as phishing when the only thing they do is to serve a image and main website is full GREEN. We'll clear these one out as well, one by one. We got motion now! Never give up! We're building at maximum speed and fire to elevate these blockers in the road! Ride until Valhalla!
-
AM (@finesse24_7) reportedAt three months into their operation did I work for cloudflare? At the same time they will say I never worked at Apple Inc. I personally knew Mr. Jobs during his treatment for cancer, and the prior years. This business is committing consumer fraud and government fraud.
-
Zappy (@noelzappy) reportedapp-01 and db-01 on a private local network. app-01 is the only host with a public interface, sitting behind Cloudflare. db-01 has no public route at all, it's reachable only over the LAN from app-01.
-
ok.dot.alt. (@okdotalt) reported@FuckKoroks Every time i want to download something. Hell, even receipts are ******* blocked. **** cloudflare.
-
Grant Mucha (@grantmucha) reportedOrdering $50,000 in server hardware today and reflecting on a post I read earlier that asked, "Why is it so difficult to build a genuinely good X, Y, or Z, and why do so many products remain 'good enough' for half a decade without ever becoming great?" The answer, in most cases, is not capability. It is priorities. One company pushes X, another pushes Y, and another pushes Z, all because each benefits the seller. I see **** like this every day, it's not what's best for the owner, but rather what's best for the seller. In my experience, greed and ego explain a large percentage of mediocre products and services. Companies CAN build something better, take starlink, starship, building quality is a decision. Most prioritize profit first, investors second, and customers last. Take hosting. I do not need to: > Invest in quality servers > Pay 40k per month for Cloudflare Enterprise > License LiteSpeed Enterprise > Include real WordPress management > Promise zero technical debt > Maintain 90 days of redundant backups I could operate with a fraction of that investment and significantly increase my companies profit. I choose not to because I know exactly how this industry operates. I know companies still running production servers from 2013 on outdated kernels. Can they upgrade? Absolutely. Will they? No. Most people are not aware that Cloudflare Enterprise is modular. Contracts are assembled like Lego blocks. One company may technically offer "Cloudflare Enterprise" with a single component, another may have a handful, and others may have more than 100 enterprise features and configurations enabled. All of them advertise the same label, yet they are not remotely the same product. Now consider the customer's side. Within 48 hours, I can move a business owner into what is effectively a top 1% WordPress hosting environment, complete with real WordPress management, for $1,490 per year or about $124 per month. Consider for a moment that some companies charge $200/mo or more for WordPress management alone, and let that sink in for a minute. No technical burden. No infrastructure management. All existing technical debt resolved. Full WordPress management. No worrying about backups, performance, security, updates. etc. Owners focus on business, and for $124/mo, this is a joke to the vast majority making money, every day, 365 days a year. Circling back to mindset, I believe the people who fail to see it are often operating from the same greed-and-ego framework. They have to sell X, so they recommend it to everyone relentlessly, whether it's right or not. And the why is simple! It comes down to what you choose to prioritize, the decisions you make, and whether you are willing to put quality ahead of profit. More importantly, it is whether you are willing to put the customer ahead of yourself and your business, and prioritize a genuine win-win relationship. At which point, I believe there is no limit in business.
-
Punyapal Shah (@MrPunyapal) reported@peterfox What if Laravel Cloud had a static site support via Cloudflare R2 bucket 👀 Exactly like AWS S3
-
ObsidianIntel 𐎡𐎼𐎠𐎴 🇮🇷 (@IntelObsidian) reported@TMobile Most importantly, why did it take half a day before you acknowledged it? Learn from Cloudflare, they go down nearly daily, but at least they are quick to announce it, then they are detailed in their after action report.
-
りっか (@7sistere2) reportedchatgpt 502 Bad Gateway cloudflare
-
Pocket Sponsor (Old-timer * 57 years) (@PocketSponsor) reported@grok @xai Dear xAI Support Team (ZD),Thank you for your reply.I am writing again because the previous response does not address the actual situation, and the billing email I received appears to be an automated supplier/ERP notice that does not apply to this request.Summary of what happened:First incident (approx. $10): Unauthorized bot usage on an exposed API key. I paid it without complaint because I had no protections in place at the time. Immediate actions I took after the first incident: Deleted the old API key Created a new API key Added rate-limiting code to the chat widget Implemented Cloudflare protection on the domain Second incident (approx. $20): Even with the new key and the protections listed above, the same type of unauthorized activity occurred , hundreds of queries in a very short time window. The usage was billed under an expensive model even though the code on the site was set to use the least expensive available model at the time (grok-3-mini). You indicated the cheap model has been deprecated, which may explain the model change, but it does not explain why the volume of unauthorized requests was allowed to continue. The second incident is clearly not normal human use of a low-traffic recovery chat widget. It is consistent with automated abuse of the API key. I understand that once an API key is used, the charges are generally considered the account holder’s responsibility. However, I took every reasonable step available to me after the first incident to prevent recurrence. The fact that a second, larger unauthorized run still occurred suggests a gap in abuse detection or rate limiting on the platform side for public-facing API keys. Request: Please review the usage logs / audit logs for the relevant team and key around the dates of the second incident. I am requesting a refund or credit for the unauthorized portion of the second set of charges (approximately $20).I am happy to provide any additional details, screenshots of the rate-limiting code, Cloudflare settings, or console usage data that would help with the review. Thankyou for looking into this. Shelly
-
schmitt trigger 🛠🛩️ (@vaizaragorn) reported@ntbrown01 @Cloudflare I already have a server with lots of other stuff I'm hosting, so hosting wasn't the issue. I was wondering about what type of website would be better
-
Ride The Leaders (@ridetheleaders) reported@RichardMoglen $NET has one of the strongest weekly bases in $IGV Inference has to live near the user and Cloudflare already owns a 300 city network. The weekly backs it up with a six month base, RS line at new highs ahead of price, handle forming 9% off highs. Undercut and reclaimed the 21ema today while $IGV broke. Earnings in 10 days should resolve the base...
-
Lain on the Blockchain (@CryptoCyberia) reported@Valen_T_N So many major internet outages the last 2 years, more than the previous 28 years I have had on Earth. Amazon store went down for hours a couple months ago, and they held an emergency meeting where they reportedly told devs to stop using LLMs to code because it's sloppa. Cloudflare went down, killing most of the internet. Windows 11 updates have broken devices a half dozen different updates now. Nvidia had to unrelease a driver package, the first time doing so in decades. There are many more examples too of LLMs causing the final product to be significantly worse. The real spooky part is that when you try to name software that was newly made, had features added, or was upgraded in user experience in any way because of the magical power of LLM coding, you literally cannot think of even one (1) example.
-
Chris Board (@chrisboard_) reportedIs anyone else experiencing intermittent timeout, that I think is a TLS @Cloudflare issue although not 100% sure. For the last few hours I have uptime kuma monitoring several endpoints that hit multiple servers and domains and they are all intermittently timing out. From a script I've tried running on a couple of servers it looks like I am getting sometimes slow TLS connections usually sub second, occassionally > 3 seconds and then other times I get a timeout. I don't think its related to anything my side as its affecting multiple servers, across multiple domains and nothing has changed on my side for quite some time, it just randomly started happening a few hours ago.
-
STJ (@thibautone) reported@bdkjones @Cloudflare @Apple Azure: "users are reporting a problem. System shows everything is ok. The users must be wrong."
-
Efikcoin Eternal (@EfikcoinEternal) reportedStopping the bad guys with Cloudflare: 525 malicious requests blocked or challenged in the last month #cloudflare
-
Adam Smielewski (@AdamSmielewski) reported@NickBlow @rivet_gg it would be great if they let you publish build artifacts externally from cloudflare, like wrangler version upload does internally. they could just wrap it in a docker container with env vars for service bindings or sth like that.
-
Jeromy Sonne (@JeromySonne) reportedSlack is failing, some web apps are throwing me cloudflare 504s. Incoming cloudflare outage in 3, 2, 1
-
Jaynal Abedin (@jayuiux) reportedHosting sites usually sell specs. We designed one that sells confidence. Cloudzyro, managed WordPress and WooCommerce hosting: Speed as the headline promise Pricing above the fold fatigue line 4 tiers, 1 obvious pick Migration, Cloudflare, security, support framed as risk removed SaaS founders, your homepage has 8 seconds. Use them.
-
Quirk 📐 (@AdamCQuirk) reported@BrianRoemmele @grok Trying to export ~926 ChatGPT business-account chats with scrapemychats. Tool works, login, discovery, resumable export all good. ~40 done so far. But large runs hit Cloudflare timeouts + HTTP 403 rate limits early. Pace drops from ~15s/chat to minutes, and the VM stalled overnight on one chat. Anyone exported 500+ chats reliably? Linux cloud VM vs local Mac? Tips for throttling at this scale welcome.
-
Publisher in a Box (@publisherinabox) reportedClick-through on the number one organic result drops about 58% where an AI Overview appears. @ahrefs measured it across 300,000 keywords. That number sits inside a data-heavy breakdown of where AI search stands right now. Five points matter most for operators: 1. Citations alone are not the whole picture. Wil Reynolds tracked a 1,900% month-over-month jump in ChatGPT citations to a single page on his site. Business impact: close to zero. Counting how many times an AI engine mentions you is half a metric. It does not tell you whether you were recommended or just named, whether the description was accurate, or whether it happened on the engine your buyers actually use. 2. Google's own reporting confirms the gap. The new AI performance report in Search Console shows impressions only. No clicks, no queries, no CTR. Marketers asked for attribution data and got a vanity counter. You cannot make a business decision on impressions alone. 3. The click loss is quantified, not anecdotal. The 58% is measured click-through on position one across 300,000 keywords. Publishers who depend entirely on organic search clicks are watching a measurable decline, not an imagined one. 4. Most agentic infrastructure is not being read. Ahrefs studied 137,000 sites and found 97% of llms.txt files never get read by a crawler. Meanwhile Cloudflare reported in June 2026 that bot and agent traffic crossed 50% of all internet traffic for the first time. Technical retrievability is the whole game here. Schema, llms.txt, crawler access. It is the gap that closes fastest and the one almost nobody has verified actually works. 5. GEO demand is climbing from a standing start. "Generative engine optimization" now pulls 7,900 US searches a month, up 997%. The entire AI attribution keyword cluster is up 430% year over year. Operators are searching for this because they feel the traffic shift and want a playbook. Here is the part most people skip. GEO gets you cited inside the AI answer, SEO gets you ranked in a list of links. Four engines answer differently, ChatGPT, Claude, Perplexity and Gemini, and most publishers appear on one and are invisible on the other three. Sentiment counts as much as volume, because being named is not the same as being recommended. We built our GEO scoring before most teams knew the term, and we ran it on our own properties before we ran it for anyone else. The AI referral traffic followed. That is the only reason we are confident enough to publish the methodology. For publishers building a real business, GEO is another revenue line sitting alongside Facebook, the website with Google Discover, and the newsletter. Facebook is the base the rest of it is built on. It pays publishers directly and sends readers to the site, and that is what funds every other channel. A diversified publishing business treats each discovery surface as a channel worth measuring on its own. The operators who figure out AI referral traffic now are claiming ground the rest of the field will have to buy back later. The ground in your niche is still open. How we measure it and how you claim it, in the first reply 👇
-
Xoge (@ClassyXoge) reportedThe only self custody is complete ownership of code, node and wallet. To ensure your ip is not logged, to ensure no down server or cloudflare reroute can stop you. Be your own bank, has never been more real than madlab
-
Gregor (@bygregorr) reported@Cloudflare one command gets you a response. figuring out which party in the relay chain broke it is where the actual debugging time goes, and binary HTTP doesn't help you there
-
Milk Road AI (@MilkRoadAI) reportedNvidia just launched a security alliance with over 30 companies and OpenAI and Anthropic didn't join the party. The Open Secure AI Alliance brings together Nvidia, Microsoft, Cisco, Salesforce, Palantir, IBM, Cloudflare, CrowdStrike, Hugging Face and dozens of others to build open source cybersecurity tools specifically for AI agents. The actual trigger for this was a real incident. When Hugging Face got hit with a security breach, its closed AI security tools couldn't tell the difference between the attacker and the defenders trying to investigate so those tools blocked the forensic analysis Hugging Face needed to actually contain the intrusion. Hugging Face had to switch to an open weight Chinese model, GLM 5.2, running on its own infrastructure, to analyze more than 17,000 actions and shut down the breach. That's the case study Nvidia is using to argue closed AI security tools have a structural blind spot. If a defender can't inspect and modify the model doing the defending, they're stuck waiting on the vendor during the exact moment speed matters most. The alliance's core argument is that AI agent security depends on the entire stack like identity, permissions, guardrails, logs not just whether the underlying model's weights are open or closed. Each founding member is contributing a specific piece. Nvidia is open sourcing models and a new agent harness framework called NOOA, Hugging Face is contributing its Safetensors format to prevent remote code execution, Microsoft built a multi model bug hunting scanner, and HPE is contributing zero trust identity standards. Now, why aren't OpenAI or Anthropic in this. This entire initiative is built around open weight models and open tooling as the foundation of AI security, and OpenAI and Anthropic's core business model depends on the opposite, keeping their frontier models closed and proprietary. But to be fair there's also a competitive angle worth naming. Nvidia sells chips to everyone, so it has no downside to championing an open ecosystem where more companies build and compete on top of open models, since Nvidia gets paid on compute regardless of who wins. OpenAI and Anthropic, by contrast, are trying to build durable moats around their specific models and joining an alliance that treats open weights as inherently safer would undercut the entire pitch they make to enterprise customers about why they should pay a premium for a closed, controlled system.
-
swisscheese (@swisscheese4299) reported@OpenAI image generation is still throwing intermittent 520 errors through cloudflare.
-
Jaziu The Chief (@_jaziu) reported@thsottiaux I feel like sol may be more efficient but it tends to overthink so it consumes much more. Example: asked sol high how cloudflare (service) would benefit our project and it thought for 9 mins delivering good pretty answer but it was really expensive 1/2
-
Jonas Templestein (@jonas) reported@thdxr (Not a serious application) Alchemy is v good but unfortunately cloudflare is investing heavily in wrangler for local dev and it sucks not being able to run apps locally So we made a little script that takes env config and secrets in and produces wrangler files and wrangler commands It works quite well for us now - but it does feel like we are building half of IaC because we need to sequence resource creation and tear down and deal with flaky control plane APIs etc
-
Matt Schober (@migratewithmatt) reportedStopping the bad guys with Cloudflare: 2,176 malicious requests blocked or challenged in the last month #cloudflare