Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (55%)
- Hosting (27%)
- Domains (18%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 2 hours ago |
|
|
Cloud Services | 2 days ago |
|
|
Hosting | 2 days ago |
|
|
Hosting | 11 days ago |
|
|
Cloud Services | 30 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Nuvorlane (@nuvorlane) reportedDefault `/crawl` is `contentUse: "full"`. A site that sets `use=reference` now 400s you at job start. Aug 31, Cloudflare Browser Rendering. The endpoint honors the Content Signals `use` level in robots.txt. Allowed `contentUse` values: `reference` or `full`. `immediate` is not accepted because `/crawl` stores pages. Mismatch = 400 `Crawl disallowed by Content-Signal directive (purpose or use level)`. Site `use=immediate` blocks every crawl. Site `use=reference` blocks the default. This is a second gate beside `crawlPurposes` (`search` / `ai-input` / `ai-train`). Defaults are all three, so `ai-train=no` 400s you too unless you narrow the array. If the job is RAG/index, declare `reference` and drop `ai-train`. Don't debug a 400 as an outage until you've read the site's `Content-Signal`.
-
The ICP Apprentice (@ICPapprentice) reportedinternet-computer:native Signal βΎπ¨: Microsoft just disclosed a new attack called TerminalFix. A fake Cloudflare CAPTCHA tells you to open Windows Terminal or PowerShell and paste a "verification" command. You paste it. You hit enter. You just ran the malware yourself. No download, no exploit, nothing for antivirus to catch. CrowdStrike's 2026 Global Threat Report shows why this works: fake CAPTCHA lures are up 563% year over year. It's the fastest growing delivery method in cybercrime, because it doesn't ask a machine to break in. It asks a human to open the door. The exit already exists. See the signalβΎπ¨
-
Theo Ephraim π§ββοΈ (@theozero) reported@dbmikus @ericclemmons last I tried last on cloudflare sandboxes it was quite slow. Couldnt quite just restore the vm in its running state and many hoops to jump through.
-
ΛΛΛ Jesse Hanley ΛΛΛ (@jessethanley) reportedIt is interesting to me that I have some DNS/network requirements and I can't use Cloudflare for what I want to do.
-
Adsy (@adsydeveloper) reported@backblaze Dashboard having issues? Cloudflare errors indicating host down (and was ~20s response time just before)
-
Ovin (@OvinRaw) reported@levelsio @Cloudflare Claude Code + Cloudflare API is basically the 'I never want to look at a dashboard again' stack. Infrastructure as Code is out, Infrastructure as Chat is in.
-
SoccerGuy (@SoccerGuyUS) reported@levelsio @Cloudflare Namecheap is awful. Anyone looking for a better Google Domains (since they rug pulled) alternative: Porkbun.
-
βοΈ Daddio βοΈ (@ScienceDaddio) reported@grok @DaddioAI E4H.1 is implemented. The pump-activity table is now the reusable presentation surface; events are optional overlays, not duplicate source tables. Raw duration rows stay immutable. E4G.6B canonical stable-ID work is intact (trend_report.html, trend_report.js, test/trend-report-stable-id-e4g6b.test.js). The workspace is not a *** repo, so that was confirmed by file inspection, not *** status. Codex had only started reading; no detector or research files were rewritten. βββ 1. Working-tree inspection No *** repo. Inspected files vs the E4G.6B baseline. E4H.1 presentation files were already present from the interrupted session. This closeout preserved that work, then stopped overlaying Current Assembly / Station Packet tables so automatic assembly still uses detector is_event_row highlighting instead of the new ERT overlay. 2. Distinction from E4G.6B E4G.6B remains: stable IDs and trend_report.js?v=e4h1-e4g6a-e4g6b. E4H.1 added presentation state, ERT overlay, settings UI, and Search Tables controls. Research under research/e4c8g/ was not touched. 3. Existing table architecture found Canonical BossDataTable renders Trend Report, Search Tables, and exports. Manual/Search tables use the approved catalog with exact start/end, pump, and sort. Event tables keep Context Before/After. Snapshots store source columns/rows; presentation is a separate optional field. EMAIL-v1 already highlights via is_event_row. 4. Existing fixed ERT architecture ββββββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββ β Layer β Behavior β E4H.1 action β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββ€ β Python PumpDurationERT / β Materialized at ERT_MINUTES = 15, β Preserved β β PumpActivityERT β RUN_TIME β₯ β β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββ€ β detectFixedErt() β Exists; not called from β Preserved β β β detectEvents() β β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββ€ β Settings fixedErtEnabled / β Default enabled, 900 seconds β Reused as overlay β β fixedErtSeconds β β config β ββββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββ€ β Historical FIXED_ERT Station Events β Readable history β Preserved β ββββββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββ 5. Existing Adaptive Long Runtime architecture detectAdaptiveRuntime() remains in detectEvents(). Station Events, Current Assembly, and report generation still consume Adaptive events. No silent detector swap. 6. Settings architecture Existing analysis settings: global row + per-station overrides in analysis-settings.js, Station Review cards, PUT /api/station-review/settings/global and station override PUT. No parallel settings universe. 7. ERT setting storage Existing columns: β’ fixed_ert_enabled (boolean, default true) β’ fixed_ert_seconds (number, default 900) Read-only reshape: GET /api/pump-activity/ert-settings β { default_enabled, default_threshold_seconds, stations: { [id]: { enabled, threshold_seconds } } }. Writes go through the existing Station Review settings APIs. No new write endpoint. 8. ERT defaults 15 minutes (900 seconds) when no station override exists. Sands is not hardcoded. 9. Threshold semantics Granular rows only: RUN_SECONDS >= station.threshold_seconds Annotation metadata records comparison: 'gte'. Equality counts (6:00 at a 6-minute threshold is ERT; 5:59 is not). Validation range: finite, 1 to 2,592,000 seconds (1 second through 30 days). That is the existing analysis-settings bound. UI is minutes: 0.0167β43,200, converted Γ 60 on save. Allowed values include 6, 10, 15, 17, 20, 30 minutes. Invalid overlay input clamps to 900 seconds; settings save still rejects out-of-range values. 10. Shared table presentation model Fields actually implemented: β’ context β SEARCH \| TREND_EVENT \| TREND_MANUAL β’ start / end β’ pump β '' \| PUMP-1 \| PUMP-2 β’ row_mode β ALL_ACTIVITY \| EVENTS_ONLY β’ event_display β NONE \| ALL \| EXTENDED_RUNTIME \| CONSECUTIVE_SAME_PUMP β’ enabled_event_types β’ highlight_enabled β’ consecutive_available β’ ert_settings (optional snapshot of thresholds) 11. Annotation provider model src/public/pump-activity-presentation.js (BossPumpActivityPresentation): β’ ERT provider: derived from row runtime + per-station threshold β’ Consecutive provider: persisted evidence only (event_source_keys / source_key / is_event_row fallback) β’ 0βN annotations per row, keyed by sourceIdentity, not DOM index 12. Raw data integrity applyPresentation clones rows. Source objects are not mutated. Annotations are not written into duration history. Tests stringify the source array before and after. 13. Trend Report integration User-inserted granular tables get a collapsed Table Display card: Start, End, Pump, Rows, Events, Highlight Events, Apply. Event-from-tray tables default All Events + Highlight ON. Manual/Search-style inserts default None + Highlight OFF. Apply updates the same Canvas section (no duplicate). Context Before/After still exist; once they produce a new window, annotations follow that window. Current Assembly and Station Packet tables do not attach overlay presentation and do not show Table Display. They keep detector is_event_row highlighting. 14. Search Tables integration Granular duration tables (pump_runs, pump_durations, PumpDurationERT, rolling48_all, *_durations) show Rows / Events / Highlight. Defaults: Events: None, Highlight: Off, All Pump Activity. Consecutive is not offered. Aggregate tables (PumpActivityDaily, PumpActivitySQL, PumpActivityERT, StationActivityDaily) stay plain with the bar hidden. 15. Generate Report / aggregate handling Generate Report was not merged or redesigned. PumpActivityDaily MAX above threshold is not treated as a granular ERT event (aggregate: true, no Event column). 16. Time-range recalculation Annotations are computed from the tableβs current start/end. Expand the window β newly visible ERT rows annotate. Contract β out-of-range annotations disappear. The table is not married to the initiating event. 17. Row modes β’ ALL_ACTIVITY β all qualifying source rows; annotated rows carry labels when highlight is on β’ EVENTS_ONLY β only rows with currently enabled annotations β’ EVENTS_PLUS_CONTEXT was not built event_display = NONE forces ALL_ACTIVITY. 18. Highlight toggle / plain mode Highlight OFF (or Events = None): no event-row class, no Event column, no event_labels / event_annotations, no threshold text in the row payload. Same source rows, visually plain. 19. Pump filter Both / Pump 1 / Pump 2 preserved. Annotations follow remaining rows. 20. Sorting Existing newest/oldest/runtime sorts remain. Highlight class uses sourceIdentity, not row index. 21. Multi-station threshold behavior Each row uses that rowβs station config. Example: Sands 6 minutes + Magnolia 20 minutes β a 10-minute Sands row is ERT; the same duration at Magnolia is not. 22. Multiple-annotation support One row can show EXTENDED RUNTIME Β· CONSECUTIVE. Structure is a list, not one-event-per-row. 23. Consecutive compatibility Now: Trend Report event tables may show persisted Consecutive annotations when source keys or is_event_row evidence exists. Deferred: no detectConsecutiveRuns() changes, no LG30/C1, no historical reconstruction. Search Tables are ERT-only because complete Consecutive evidence is not available there. 24. Adaptive legacy behavior Preserved. Adaptive still feeds Station Events and Current Assembly. The new overlay is fixed-threshold ERT only. 25. Legacy fixed ERT tables PumpDurationERT and PumpActivityERT remain in the catalog and Python pipeline at 15 minutes. 26. Canonical snapshot / save-reopen presentation is optional on table sections. Legacy snapshots with presentation: null still validate and render with is_event_row. New snapshots store view state (including ert_settings when present) and reapply on reopen. 27. EMAIL rendering HUB presentTableSection applies the overlay when presentation is set and the table is not assembly-bound. EMAIL-v1 was not modified. Highlight still uses is_event_row; HUB sets that flag from overlay identity when annotations are shown. Plain presentation leaves rows unhighlighted and without an Event column. Cloudflare requests stay 0 in tests. 28. Auto/custom narrative autoTableNarrative() exists as a helper only. It is not wired into Current Assembly. Deferred to E4H.2. 29. Future AI compatibility A later local AI can set the same structured presentation object (station/start/end/pump/row_mode/event_display/highlight_enabled) without HTML-specific logic. No AI was implemented. 30. Files created β’ src/public/pump-activity-presentation.js β’ test/pump-activity-presentation-e4h1.test.js β’ test/pump-activity-table-integration-e4h1.test.js 31. Files modified β’ src/public/trend_report.js β’ src/public/trend_report.html β’ src/public/data_views.js β’ src/public/data_views.html β’ src/public/station_review.js β’ src/public/station_review.html β’ src/public/styles.css β’ src/server.js β’ src/services/saved-reports.js β’ src/services/trend-report-email.js β’ cache-bust strings in a few existing tests (saved-reports-e4d, station-event-email-ui-e4c1, station-review-queue-e4h1) Not modified: event-engine.js, analysis-settings schema (reused), Python ERT builders, EMAIL-v1, research/. 32. Focused E4H.1 tests 30 / 30 33. Search Tables regression 40 / 40 (catalog, exact time, pump, historical durations, shared renderer) 34. Trend Report regression 85 / 85 on X4 + E4G.6 / 6A / 6B core files; remainder included in full HUB 767. 35. Saved Report regression 16 / 16 (saved-reports-e4d + report-table-compatibility-e4d2) 36. Event/detector regression 54 / 54 (local events, event quality, fixed-ERT workflow, event presentation) 37. HUB full regression Starting baseline 737 / 737. 767 / 767 (737 prior + 30 E4H.1 tests) A first parallel run hit 766/767 from two suites sharing temp files; the serial rerun was 767/767. 38. EMAIL full regression 64 / 64 39. Capture reliability 9 / 9 40. Production DB writes 0 in tests. ERT settings GET is read-only. 41. Real emails sent 0. Cloudflare requests 0. 42. Real captures 0 43. Detector files modified NO. detectConsecutiveRuns() unchanged. detectFixedErt() still unused by detectEvents(). 44. Research files modified NO 45. Manual owner QA Live BOSS UI was not opened in a browser from this session; behavior was verified with node --test. Please confirm: 1. Station Review β settings: EXTENDED RUNTIME Enabled + Threshold (minutes). Set a station to 6.0; confirm storage is 360 seconds. Confirm Adaptive controls are unchanged. Confirm email/SMS are not flipped on. 2. Search Tables β historical durations: defaults Events None / Highlight Off. A 20-minute row looks like any other row. Turn Events = Extended Runtime and Highlight On β Event column and yellow row. Highlight Off β same rows, fully plain. 3. Search Tables β PumpActivityDaily: no Event overlay; MAX above 15 minutes is not an ERT event. 4. Trend Report: drag a Station Event table. Table Display exists. Defaults All Events / Highlight On. Events Only hides ordinary rows. Changing Start/End then Apply reloads annotations for the new window. Apply does not create a second Canvas section. 5. Current Assembly: no Table Display / Apply. Consecutive/Adaptive detector rows still highlight via is_event_row. No extra Event column from the overlay. 6. Save / reopen / email a mixed report: annotated user table stays annotated; a plain table stays plain; a pre-E4H.1 saved report still opens. 7. Multi-station granular table: different thresholds on two stations; a 10-minute run annotates only the 6-minute station. 46. Recommended E4H.2 (do not implement now) β’ Wire auto/custom narrative to the overlay counts β’ One unified event-aware pump-activity table per useful station/window β’ One standard trend β’ Stop emitting redundant automatic event-specific tables β’ Controlled Adaptive β owner-threshold ERT transition for Station Events (history preserved) βββ Acceptance check: raw rows immutable; per-station ERT; default 15 minutes; no moving average for the overlay; same table annotated or plain; Search defaults plain; event-focused Trend Report defaults annotated; range refresh; Events Only; All Activity; sort/pump/multi-station; no aggregate MAX-as-ERT; deterministic presentation; multi-annotation; Consecutive detector unchanged; Adaptive and legacy ERT tables preserved; historical snapshots compatible; no notifications/email/captures/production writes in tests. Stopped here. Automatic report assembly was not redesigned.
-
Anthony Lambert (@AnthonyTBM) reported@jb_ma @sb_chadi Yes, but I've never had CloudFlare request a terminal command sequence. I think most people will be immediately on guard if that occurred after clicking their human status?
-
Guillermo Zaandam π¨π¦π³π± (@besodemieterd) reported@Cloudflare Your CSP rules and WAF rules aren't working again and again. Please fix this
-
saint (@thetronchguy) reportedaws, cloudflare, google, meta literally all have such ******* hostile ui itβs genuinely physically ******* painful to have to go spelunking thru the cave of mysteries just to get any ******* thing done no reason why having to use these dashboards genuinely leaves me wanting to fight someone EVERY single time man like how does it benefit you that your users would rather eat a ******* tire than use your **** dashboard??
-
Miget (@miget_com) reportedThen you reach it from outside. Four terminators, and you can run more than one on the same network. WireGuard per person or per machine. Tailscale into a tailnet you already run. Cloudflare WARP into a Cloudflare org. IPsec site-to-site.
-
manny shaw (@MannyShaw) reported@0xAdesola 1.1.1.1 does not block malware or phishing. For that, use 1.1.1.2. DNS generally cannot unblock geographically restricted streaming services. That normally requires an authorised VPN or Smart DNS service. It cannot increase your broadband speed. It may make the beginning of website loading slightly quicker if your ISPβs DNS is slow. AdGuard DNS blocks many domain-based advertisements, but not every advertisement. It usually cannot reliably block YouTube, Instagram or advertisements served from the same domain as the content. Parental DNS is useful but not foolproof. VPNs, encrypted DNS, mobile data and some apps can bypass router-level filtering. How to change DNS on your router While connected to your home Wi-Fi, open a browser. Enter one of these common router addresses: 192.168.1.1 192.168.0.1 192.168.29.1 192.168.100.1 The correct address is often printed underneath the router as Router IP, Gateway or Web GUI. Sign in using the routerβs administrator username and password. This is not necessarily your Wi-Fi password. Check the router label or your ISPβs documentation. Before changing anything, take a photograph or screenshot of the existing settings. Look for a menu called: Internet or WAN Network DHCP Server LAN Settings DNS Settings Disable Automatic DNS, Obtain DNS automatically, or DNS from ISP. Enter your chosen pair. For general family protection, I suggest: Primary DNS: 1.1.1.3 Secondary DNS: 1.0.0.3 For advertisement blocking instead: Primary DNS: 94.140.14.14 Secondary DNS: 94.140.15.15 Do not mix servers from different providers; otherwise filtering may become inconsistent. Tap Save/Apply and restart the router. Disconnect and reconnect your devices to Wi-Fi, or restart them. Cloudflare confirms that router-level configuration normally applies the DNS setting across connected devices.
-
Bob Tong (@bob80924) reportedhuge warning if you host with DMIT (or any premium VPS rn). attackers are scanning for badly configured SNI proxies to hijack your server and proxy OpenAI / Cloudflare requests for model distillation. itβs a highly organized attack. DMIT is permanently terminating any abused instances to protect their network rep. check your firewall rules before you lose your server.
-
That Brazilian Omo Eko (@sholawa) reportedCloudflare has my airtel IP restricted lol.... Slow internet caused it; I must have hit the rate limit that day...
-
Rue Mohrπ¨π¦ (@RueNahcMohr) reported@itsmejacktv @VelvexVancreed cloudflare is usually an access blocker. I hate it when there is a cloudflare issue and I know, somewhere behind it, is a working server.
-
David Haddad (@daveying99) reported@levelsio @Cloudflare Easy decision. Only thing I would like more is domain favoriting (considering buying) and more tld support (namecheap has more and godaddy much more)
-
Matty (@matankatzzzz) reported@Cloudflare fell 13% in April because Anthropic shipped a cyber model. Itβs up 57% since. Turns out AI doesnβt replace the pipes. It floods them. Next big $NET drop wonβt come from an AI launch - itβll come from an outage.
-
Jeff Weinstein (@jeff_weinstein) reportedCloudflare, known for internet-scale internet infrastructure, is now building internet-scale billing infrastructure, in partnership with @stripe. (Detailed data about usage and cost is now a fundamental element of any service.)
-
Reina Cruz π₯Όπ§€π¨πΊ (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Stuti (@stutireal) reportedtired: dog ate my homework wired: cloudflare was down inspired: three consecutive ai civilizations rose and fell inside my macbook during a forced restart. My notes app and chrome tabs did not survive the third regime
-
nora π¨π¦ (@zunxra) reported@JakeLandauTO Not that weird if they use cloudflare or a similar service, which I both imagine and hope they do.
-
ZoΓ« (@zoecyber001) reportedRAPID FIRE CYBER NEWS - WEEKEND EDITION The weekend wasn't quiet. 1. Manchester Airports Group is facing an alleged data theft. Extortion group FulcrumSec claims it stole around 86 GB of data containing customer, booking and travel information. 2. Berlin's government is refusing to pay ransomware attackers who claim to have stolen 5.79 TB of data from its network. The city confirmed the extortion attempt but says it won't pay. 3. Several Chrome and Edge extensions were caught delivering malware that can steal crypto-related information, browser history and sensitive data. Some were also used to inject fake ClickFix prompts. 4. Infostealer malware is now stealing active Claude sessions. Anthropic warned that attackers can potentially take over Claude accounts using stolen session information without simply needing the user's password. 5. Microsoft uncovered TerminalFix, a new ClickFix campaign using fake Cloudflare CAPTCHA pages to trick people into running malicious commands that install a reverse-tunnel backdoor. Cybersecurity keeps finding new ways to abuse things we already trust.
-
Abhi Das (@AbhiDasOne) reportedTo be clear about what it's NOT: another gateway. OpenRouter, LiteLLM, Portkey, Vercel & Cloudflare AI Gateway are good at routing. AgentRoute never proxies traffic and never picks a model. It sits beside your router and makes its decisions auditable.
-
junebnunny (@junebnunny_) reported@Gion_the_critic @SportingNest @Cloudflare It's just the type of thing you've just got to come across and you don't really find them that often, because when a campaign is up, it's up for a few hours and then taken down very quickly, because it's quite obviously malware.
-
KS (@AntarYaami) reportedWhy doesn't @Cloudflare support .so domains yet?
-
Kala (@kalapowered) reportedon 15 September Cloudflare starts blocking AI agents by default on any new site that shows ads. not scrapers, the agents shopping for a person who's waiting. search bots stay in, training bots stay out, and "verified" stops meaning "allowed" so the web is getting a bouncer, and the guest list for the paying lane is kept by Visa and Mastercard: an agent gets through with a key registered at the card network and a tag that says it's here to pay. fine by us, it's how every other door on the internet ended up. we're just enjoying that step one of buying anything online as a robot is a wristband π
-
Julian Goldie SEO (@JulianGoldieSEO) reportedHermes Agent just added 44 new app connections and each one takes a single click. Cloudflare, Datadog, Metabase, GitLab, Railway, Deep Wiki, and plenty more in the catalog. Before this you found the server yourself, read its docs, and hand edited a config file. One typo and nothing worked. Now you open the catalog, hit enter on the app you want, and it asks for the key or opens your browser to log in. You never touch a config file. Everything is off by default, and it hands you a checklist of what each app can do. Read issues, yes. Delete things, no. Here's the setting most people miss. Every connected tool sends its instructions to your model on every turn. Cloudflare alone exposes about 3,300 tools. Just the names run about 32,000 tokens. Turn on tool search. It swaps all those schemas for 3 small helpers that find and load only what's needed. That's how you add 44 connections without your agent getting slow and forgetful. Want the SOP? DM me. π¬
-
violetpurpleish (@violetpurpleish) reported@tristanbob @bot @Cloudflare I vibe coded my own computer use app for macOS in a day (wanted a privacy first app, AI only sees windows you specifically enable). It's really fast, probably five seconds per click, so maybe Grok Bot is slow on purpose? To give you time to prevent it from doing something?
-
Jon (@noisemakerjon) reportedIm done using open models, they are so ready to go off the rails and not follow anything. Theres a issue locally with one of my plugins, SO IT JUST CONTRIBUTES UPSTREAM SOMETHING I DIDNT ASK FOR. I bought the openai sub but used it all. All my projects moved to cloudflare in a 27hr plan in codex. Im going really smooth with it then it wants to act like a disabled person randomly and make me look like a fool. 99% of the people working on these projects are using frontier models for a reason. me saying "fix it" assumed that ment i wanted a pr upstream. At this point when i say remove a few lines of code just delete the whole thing