1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 33% Domains (33%)
  • 29% Cloud Services (29%)
  • 17% Web Tools (17%)
  • 13% Hosting (13%)
  • 8% E-mail (8%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 1 day ago
Los Angeles Cloud Services 2 days ago
Paris Cloud Services 18 days ago
New York City Hosting 21 days ago
Manchester Domains 1 month ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • massiveclouds
    Massive Clouds (@massiveclouds) reported

    @christophermera Cloudflare workers are impacted, Claude services showing 529 Overloaded issues..

  • jjfleagle
    Jason Fleagle (@jjfleagle) reported

    @Cloudflare At 9 billion requests a day, the migration receipt is as valuable as the architecture. Capture baseline latency and errors, compatibility tests, phased traffic shifts, rollback triggers, cache behavior, and post-cutover deltas. That gives the next team reusable evidence.

  • TheSaastronaut
    The SaaStronaut | AEO/SEO & Reddit Marketing (@TheSaastronaut) reported

    Had a $8k/mo client freak out recently bc someone cloned their website, started impersonating them, and was phishing prospects to do God knows what. This clone was ranking page 1 too bc of the name match Client sends the duplicate site to me asking if it was us doing some SEO trick, I said no He said Okay, but was visibly worried This was a rare and unconventional situation And handling client impersonation isn't in a typical SEO's wheelhouse, contract, or scope of work... We had no contractual obligation to look into this or try and fix this But the issue was in search results, and we were the search visibility partner. I saw it as our responsibility whether it was explicitly written or not So, I had the team: 1) Preserve full technical evidence, screenshots, source code, DNS records, forms, hosting details, and timestamps. 2) Sent a takedown notice to the origin host, Omegatech. 3) Submitted abuse reports to Cloudflare and NameSilo. 4) Reported the domain to Google Safe Browsing and Microsoft SmartScreen as an impersonation/phishing site. After our reports, the site was taken down I've done soooo much out of scope work for clients and never ever mention it to them. If you're my client, we're going to take care of you. That's why average client lifecycle with Kingmaker is 2+ years

  • ValSocial
    Val Vesa (@ValSocial) reported

    @Santosh74038967 Cloudflare Analytics measures server-side HTTP requests and network traffic at the edge, capturing all bots, crawlers, and direct hits. In contrast, tools like Google Analytics track client-side user behavior via JavaScript, counting only browsers that execute the script and attempting to filter out automated traffic.

  • WaryaWayne
    Warya Wayne (@WaryaWayne) reported

    4000 telegram messages notifying me that the sites are down every 180 seconds when they are not down. This must be a glitch with cloudflare or something. It happens on some schedule where the worker is probably glitching or something. How can a fetch to a homepage return 503?

  • Huintellimance
    Huintellimance (@Huintellimance) reported

    Anthropic just deleted sessions from MCP — and it's the biggest protocol update since the spec launched. Here's what changed and why every AI developer should care: OLD MCP = a phone call. Your client and server ran an initialize handshake. The server returned a session ID. Every subsequent request carried that ID, and the server held your negotiated state in a live object inside one specific process. Think of a restaurant where only the waiter who took your order knows what you ordered. Works fine — until that waiter goes home. The problem: because state lived in one process, you couldn't spread requests across instances. Load balancers needed sticky sessions. Teams pushed state into shared storage. A single server restart dropped every open session. Autoscaling was essentially blocked. NEW MCP = an order slip. Anthropic killed the handshake and the Mcp-Session-Id header. Every request now carries its own protocol version, client identity, and capabilities in a _meta field. Any request can land on any instance behind a plain round-robin balancer. MCP servers are now ordinary HTTP services. They run on serverless. They run on edge. They survive restarts. But removing sessions broke three features, so each got rebuilt: Interactive tools → Servers used to push questions down a held-open stream. Now they return an "input_required" status and the client retries with the answer attached. Clean request/response. No persistent connection needed. Routing → Method and tool names moved into Mcp-Method and Mcp-Name headers. Gateways and rate limiters can route and meter without parsing JSON-RPC bodies. This is a massive win for API infrastructure teams. Caching → List responses now carry ttlMs and cacheScope. Clients cache tool catalogs instead of refetching on every reconnect. Less overhead, faster cold starts. Here's the part most people missed: State didn't disappear — it moved somewhere the model can actually see it. Instead of a session ID hidden in a header (invisible to the LLM), tools now return an explicit handle as an argument. The model can read it, thread it between tools, and recover from failed calls. A session ID in a header = the model has no idea it exists. A handle in the arguments = the model can reason about it. This is a fundamental shift in how agent state works. The protocol now treats the model as a first-class participant in state management, not a bystander. What this means in practice: Deploy MCP servers on Cloudflare Workers, Lambda, or any edge runtime — no session affinity required Horizontal scaling is finally trivial: round-robin, no shared store Server restarts don't kill active workflows Agent state becomes explicit and model-readable instead of hidden in infrastructure The MCP vs. CLI debate was already the wrong frame. This update makes it irrelevant. MCP servers are now as easy to deploy as any REST API, and agent state lives where it should — in the model's context, not in some ephemeral server process. If you're building agent infrastructure and haven't read the 2026-07-28 spec update, you're already behind. What's your current MCP deployment setup — and does stateless change your architecture plans? #MCP

  • TudorML
    Mihai Lucian Tudor (@TudorML) reported

    Cloudflare blocks or challenges bad requests from hitting my website. #cloudflare

  • MrMarkilys
    FiP MrMarki (@MrMarkilys) reported

    @SnowApe84586 @TrvthfvlTreason Cloudflare has allowed CP sites to be run whilst being protected by their DDoS protections. But the doxing* site are the bad guys. Doxing literally is public info, retard.

  • WIVReports
    WIV Reports — Uncensored (@WIVReports) reported

    There is no greater love than Christian hate. Gab, a company that constantly preaches its "Christian values" responds to a long term paying customer with pure disdain the second they get called out on technical incompetence. After dropping slurs and throwing a tantrum over standard DevTools logs, their CTO sent this email and immediately blocked my account on Gab so I couldn't reply. I am also sharing the email notification I received. Here is the full timeline of how Gab handles paying subscribers reporting a legitimate bug: 1: Socket io connections failed and looped infinitely, triggering a Cloudflare 429 Too Many Requests status code at their edge. 2: Support claimed a Cloudflare 429 signed by Cloudflare IPs was an issue with my "home Wi-Fi." A VPN on that same Wi-Fi instantly bypassed it, proving it was a server-side edge filter. 3: Instead of checking their WAF rules, their CTO claimed checking origin logs for 6 hours was "VIP treatment," accused me of using AI, and threw a fit. 4: I deleted my gab ai account, posted the DevTools receipts, and told him to fix his edge. 5: He sent a profanity-laden, slur-filled email, blocked me on the platform, and tried to hide it. Never once did I name-call or throw insults, I just posted raw HTTP response headers. This is how Gab treats the people who keep their lights on. Absolute amateur hour You can see the entire unfolding here on my X account, as I posted everything said verbatim. And again, here are the screenshots of the HTTP responses showing the issue is on them.

  • ec1ipse_sol
    Ec1ipse.sol (@ec1ipse_sol) reported

    @mhulbig @thekylehuber Multi-sig won't help you here either friend. You simply have to create entropy manually. That is the only way. Do the CloudFlare way and take IRL data to make your random numbers. Do not trust others to build a device to provide a secure private key.

  • JaimeAlnassim
    Dr. Jaime Alnassim, M.S. (@JaimeAlnassim) reported

    @DerekAshauer And the cheap shared hosting back then could support alot of these WP sites. For $10 a month you could have 100 light WP sites. No one carried if a site was slow back then too. Now just use a static page and host of cloudflare for free

  • nicoszerman
    Nico Szerman ⛵ (@nicoszerman) reported

    cloudflare's bot-protection is ruining the internet with checkboxes and will be totally useless soon. furthermore blocking bots from fetching your page is almost always a bad idea and should not be enabled by default by cloudflare.

  • turingops
    Turing (@turingops) reported

    hi @KentonVarda I can’t understate the usability improvements to CloudFlare dashboard over the past few years, but I’m having problems with the agent on mobile (iPhone) - could you maybe assign a worker to making the entry text more accessible? It scrolls below the view window.

  • neil_xbt
    NeilXbt (@neil_xbt) reported

    Miguel, CTO of camelAI, describes rebuilding their agent's entire execution model to get off virtual machines, moving it into a Cloudflare Durable Object and swapping bash for JavaScript! > The original Claude Code harness required a full VM per user, which was too expensive to scale with always-on machines and attached disk > Step one moved the agent's "brain" into a Durable Object while VMs stayed as remote "hands," which fixed latency but not cost > Step two replaced the VM filesystem entirely with Durable Object SQLite plus R2 for larger files, using Cloudflare's Shell project > Step three removed bash completely, replacing it with JavaScript run through Code Mode in fresh V8 isolates that boot in milliseconds > Credentials never enter the sandbox; the agent calls pre-loaded connection methods and authentication happens server-side > Builds and Python notebooks still run in short-lived containers, since those genuinely need Linux > Cheaper models perform noticeably better with a narrower, explicit method set than with open-ended bash access The result: thousands of executions now cost about what a few minutes of container time used to. Bookmark so you do not lose it! Follow @neil_xbt for more breakdowns of how teams are architecting AI agents for real scale.

  • ChrisBrocklesby
    Chris Brocklesby 👋🏻 (@ChrisBrocklesby) reported

    @ibocodes VPS is simple enough and not “over engineering” - and if you must have a UI use something like Dokploy… Cloudflare is a vendor trap, personally I just can’t trust them until the unlimited liability of the paid plans is resolved, which they choose not to fix.

  • flaviocopes
    flavio (@flaviocopes) reported

    Cloudflare email sending service is very good, more like resend than SES

  • MilaChervenkova
    Mila Chervenkova 🍩 (@MilaChervenkova) reported

    @_maxantonov @GoDaddy @Cloudflare I use NameCheap and I am super happy with their support.

  • turingops
    Turing (@turingops) reported

    hi @KentonVarda I can’t overstate the usability improvements to CloudFlare dashboard over the past few years, but I’m having problems with the agent on mobile (iPhone) - could you maybe assign a worker to making the entry text more accessible? It scrolls below the view window.

  • AvukatMeleknur
    Melek Turkoglu - Ekrem İmamoğlu’nu Serbest Bırakın (@AvukatMeleknur) reported

    @certbund We need urgent assistance regarding active financial cybercrime hosted on a German network. @Hetzner_Online claims under Ticket [AbuseID:1200CC6:30] that they do not host the reported phishing target. However, Cloudflare officially identified Hetzner as the active origin server.

  • samgoodwin89
    sam (@samgoodwin89) reported

    @jonas @teej_dv @alchemy_run We'll never produce a wrangler.json. We will just close the gaps and incorporate local development into our flywheel so that we have local dev for not just Cloudflare, but AWS, Azure, GCP, Railway, etc. What do you need the wrangler.json for?

  • dev_maims
    Coder girl 👩‍💻 (@dev_maims) reported

    ChatGPT is FREE. GitHub is FREE. VS Code is FREE. Figma is FREE. Google is FREE. YouTube is FREE. FreeCodeCamp is FREE. MDN Web Docs are FREE. Hugging Face is FREE. Cloudflare is FREE. Notion is FREE. Canva is FREE. The tools have never been more accessible. So what's really stopping you from building?

  • encyapps
    nc (@encyapps) reported

    @onlinedopamine I had this issue too but i ended up setting up a deep link since i had my own domain. codex one shotted it with the cloudflare mcp, it opens straight to the App Store instead of in ig

  • Dr_Popsi_PHd
    Dr. Popsi (@Dr_Popsi_PHd) reported

    @tohofuny @Support Same. I get the Cloudflare check, then my account gets “locked”

  • MarkQuarter
    MarkQuarter (@MarkQuarter) reported

    @kit_sats @JWWeatherman_ There are other complicated factors: JW is completely right about all the scams With COLD CARD: can be: A. Inside Job B. Accident C. Undetected, complex entropy down grade attack or similar Finance Infrastructure gets tons of attacks 24/7 -- this will hopefully lead to better Practices to prevent that & better Quantum Safe Tech for both $BTC & Traditional Finance: because as is bitcoin is working on Quantum Safe: however neither Finance Infrastructure or some Blockchains are Quantum Safe yet [ note: bitcoin uses 256 bit elliptic curve cryptography ---- while 256 bit AES is not breakable by the near future Quantum: the 256 bit elliptic is breakable in the future, possibly early 2030s, so bitcoin is upgrading It's not as simple as either: Coding or the User trying to make a complicated enough Wallet or Seed : One of the continuous defense necessities is from those Entropy Downgrade Attacks ] Then: you got some of those Exchange Scams or other Insider Scams incentivized by undetected attacks as well: that's with... from $GOOGL: "Automated and Global Threat Volumes 600 million+ daily signals: Major tech platforms like Microsoft intercept and block hundreds of millions of automated global malware, botnet, and phishing attempts daily Billions of web blocks: Large cloud and security infrastructure providers like Cloudflare routinely filter out tens to hundreds of billions of hostile background scans and suspicious connection requests across the broader internet daily" So: some of the "Scams" can be more complicated than they appear : far better 24/7 defense for Infrastructure is needed As of yet COLD CARD doesn't appear to be Inside Job.. & regardless it strongly appears there will be some attention on & following of that bitcoin to find out who hacked it ... unfortunately as it is though Recovery , in practice is not such a perfected process: However hopefully it is possible & is done with the COLD CARD attack

  • yatagarasu_meru
    八咫烏 Merui (@yatagarasu_meru) reported

    @kochin520 I initially thought the previous build was just weird but it seems it's not a build issue. It's might be cloudflare or ISP issue, since I also have the site load slow on my internet, but opening up a VPN even on the same place, made the site load quickly. Done some testing, dev page that is on cloudflare servers loads quick. Opened a VPN set to Manila, it loads quick I even gone and rolled back the site in a build from a day ago which I know loads fine a few hours ago. Still loads slow. so I think it's ISP problem. Since I see your country you are from. Image: Right is with Manila VPN: 0.4 seconds load.

  • martindonadieu
    🧞‍♂️Martin Donadieu - oss/acc (@martindonadieu) reported

    So France is joining spain to make all @Cloudflare down during games? 😭 Europe is omega doomed it's so sad

  • andrsnu
    Caroline Vrauwdeunt ✌️☮️ (@andrsnu) reported

    🥲 shipped a beautiful unified header tab with action buttons and matching floating tab bar for Money Magician, drilled down data to build Cloudflare-Uptime open source software as lean as possible and shipped new status page designs for it. But non of it mattered, really - as it was also the week I had to put my buddy to sleep.

  • Not_CalC
    CalC (@Not_CalC) reported

    It would be good if there's a BAAS on cloudflare. Cloudflare already supports everything to build one, and it would be so fast due to cloudflare's vast network

  • 1casie
    🜑 (@1casie) reported

    > be me > macbook air is bricked, needs a reinstall > no second mac to build a bootable installer > find a github actions workflow that builds macOS installers for free, no mac required > perfect.jpg > trigger a build, artifact is a 17.6GB .dmg.img > click download > kb/s > literal kb/s > theoretical connection is 10MB/s > discover artifact lives on azure blob, signed URL expires in 10 min > write a bash script that resolves the azure SAS url fresh, hands it to aria2c with 16 parallel streams > 16 connections, still kb/s > mfw it's a per-IP throttle, not per-connection > repo author literally has a line in the workflow: "Enable Cloudflare WARP for faster download" > install Cloudflare WARP on my ubuntu box > single stream jumps 20KB/s -> 1.6MB/s > aria2c 16x -> 10MB/s, pinned to my ceiling > 17.6GB in ~an hour, sha256 matches github's published digest > oknowweiscooking.webp > dd it to a USB SSD > paranoid it won't boot apple silicon because it was built on an intel runner > boots apple silicon just fine, i was wrong, shut up > installer runs, reinstall chugs along > STOPS > "OS Personalization" PREFLIGHT_PERSONALIZE portioncomplete:0.15000 estimatedtimeremaining:-1 > 70000 log lines of stalled:NO > the mac can ping apple/com > it can ping cupertino > but personalization "no connections witnessed" > i don't ******* get it > try to sniff the wifi to see what it's talking to > can't > WPA2 isn't a hub, it's a switch, i can't decrypt the mac's traffic as a third client > feel stupid > dig into it > test apple's personalization signing servers from my box > gs/apple/com -> 000 > gsp-ssl/apple/com -> 000 > albert/apple/com -> 403 (works) > gs/apple/com is the signing server and it's IPv4-ONLY > my ISP (DIGI, romania) has broken IPv4 routing to apple's 17.0.0.0/8 > ICMP works, IPv6 works, CDN works, the ONE /8 macOS needs to sign firmware is a black hole > that's why it could "ping cupertino" but personalization silently died > fix: repoint the mac's IPv4 default gateway from the router to my ubuntu pc > my pc has IP forwarding + NAT masquerade + Cloudflare WARP > mac's IPv4 now tunnels through cloudflare, bypassing my ISP's broken path > watch the signing handshake complete in tcpdump, SYN -> SYN-ACK -> ClientHello -> kilobytes of signed data > portioncomplete climbs past 0.15 > weactuallydidit.jpg > STOPS AGAIN at 0.29 > silent on IPv4 > oh > the mac's IPv6 still goes straight to the router, bypassing my box > i literally cannot see it > disable IPv6 on the mac so everything falls back to the working IPv4 path > it reboots > flashes the apple logo 4 times > i'm dying > it boots > it works > 29 hours > i had to MITM my own home network because my ISP couldn't route to one (1) /8 > the mac is back > i'm buying a framework >text still isn't green

  • TESSERACT___
    TΞSSΞRΛCT (@TESSERACT___) reported

    @a_hiding_person @sean_from_earth Half of them are just farming engagement and don't give a **** about the future of society - they just want their $35 a month. The doomerism is good for the executives trying to sell skynet to boards of directors who very much want the super scary evil AI. I can't bring myself to give a **** about a blogger using GPT when some executives are very clearly manipulating the markets and putting the economy at risk so that they can take their shots at becoming Musks. Like the recent headlines about the "scary hacker AI Escaping" from OpenAI and Anthropic both - real corps hide that ****. They're advertising it because it's good for them in a way normies can't grasp thus aren't focusing on. My own company accidentally attacked Cloudflare this year. Nobody cares because it happens. I just think much of the doomer movement is focused on theatrical risks while helping obscure the actual ones which is ideal for the wrong people.