Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (43%)
- Domains (21%)
- Web Tools (14%)
- Hosting (14%)
- E-mail (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 18 days ago |
|
|
Cloud Services | 19 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Hosting | 1 month ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Emjay🎀 (@chinwe20496848) reportedMTN why is your network playing with me, since yesterday, I can’t login into cloudflare with your network. Don’t piss me off.
-
ctoxyz (@_ctoxyz) reported@cloudflare literally just PREVENTED that company from getting a SALE from me. nice work **** HEADS
-
edwin 🐸 (@pescatios) reportedthe honest starting point i see with all this is that scraping can’t structurally be blocked right now. robots.txt and no-ai tags are basically just requests, not walls, and thus they only bind crawlers that choose to listen. glaze/nightshade only work against the specific architectures they were built for. and even if your own site is a fortress it doesn’t matter much when your work is sitting mirrored on instagram, pinterest, and aggregators you don’t control. so “blocking” at internet scale really just means three achievable things: raising the cost, changing defaults, and creating consequences the defaults part is actually shifting right now: cloudflare, via their monetization gateway, is going to start blocking ai training bots by default this september + charging crawlers per fetch, with machine-payment rails behind it (x402). free scraping is genuinely ending for the compliant majority of crawlers. the catch, however, is that those payments go to whoever owns the domain, not the artist whose work sits on it. and rogue scrapers like the ones that hit cara will just continue to ignore the whole system anyways. there’s also an emerging class of encrypted-by-default hosting where crawling is literally impossible and every view is keyed to an identity. doesn’t beat the screenshot problem, but it flips theft from free and anonymous to expensive and traceable, which is its own kind of consequence so the way i see it is that the effort is twofold. the legal one you’re pushing people towards (actual consequences), and building the economic layer alongside it, where consent, credit, and payment travel with the work itself so that paying artists becomes cheaper and easier than stealing from them. so not about accepting the theft, but making the legit path the most profitable one
-
VaTsaL (@Codat_V) reportedCloudflare once had a React bug that helped take down its dashboard and several APIs A useEffect depended on an object that was recreated on every render. React treated it as a new value each time, ran the effect again and sent more API requests. This happened during an update to the backend service receiving those requests. It got overwhelmed and failed to recover the surprising thing was that a loop in the frontend could put enough pressure on a critical backend service to cause a much larger outage
-
codinglog.com (@codinglogcom) reported@fforres @Cloudflare I don't like everything placed at one place, even broken sometimes prefer some level of decentralisation
-
Ral_Is_Tired🏳️⚧️ Hellhound Slinger Specialist (@RalisTired) reportedif anyone gets any problems with connecting to twitch, youtube and/or steam, you might need to reconnect ur DNS, had the same issue cus google and cloudflare are **** hosting companies and are incompetent LMAO
-
Frantisek (Frank) Borsik (@FBorsik) reportedHey @Cloudflare @CloudflareRadar - can you help, please? I want to turn off that absolutely useless and unhelpful "AI" in Radar.
-
Goose (@0xGooseOps) reportedYet another reason why you as an engineer should be reviewing what's happening in your code and what the AI's output is. Today I was working on a ticket for a DNS monitoring script. The script assumes Cloudflare is the registrar and DNS provider. Ok, so AI was helping me through this, and we got to the point where we needed to determine how to log the DNS records that were proxied by Cloudflare. Since the goal was to alert on dns changes, and Cloudflare proxied records don't change from the external perspective if a proxied record value changes, one could make a change to a dns record and the external monitor would not be able to see it. AI's solution (had I not intervened or read the output noticing a bad choice) would have been to only alert on the change in "proxy" status or "grey" cloud vs "orange" cloud. This means that not only would we not see changes to the records that we control, but we also wouldn't see the change in the values of Cloudflare's proxy records either. It didn't flag this except to show its reasoning and then make the change (a quick text output on the command line that I might've missed had I not been reviewing the comments). It didn't try to find other alternatives or better solutions. It just assumed the limitation and built. Ok, so what's the point? Well the whole point of building out a dns monitoring script, is to be able to externally monitor if something changes that you weren't expecting, alert on it, and then whoever receives the alert can take action should they need to. In this case, AI decided that the solution was to alert/log the only thing visible from the outside public internet, built it, and then said it was finished. Had I not properly reviewed what it was doing and questioned it's decisions, it would have shipped a functional script that basically alerted on a very narrow part of the attack surface. I know there are countless wins for AI and countless stories of what I'm trying to demonstrate which is that you should make sure to review what your AI does. So I add my experiences to the list, should somebody see it and slow down, and pay attention. Oh, and what did we build instead? A change counter. Something that instead of reporting on changes to public records that don't necessarily actually demonstrate meaningful changes to the infrastrucutre, we created a change counter that measures external and internal changes to DNS as well as a change to the token. This counter is only clearable through a code change. So instead of a noop on a DNS change behind the Cloudflare proxy, we get an actually latched alert that we can tie to a Grafana dashboard that gives us a real "something's up" indicator when anything in our DNS system changes. Moral of the story, review your AI's output. Don't just let it cook.
-
yenkel (@yenkel) reported@jfroma @vercel @Cloudflare railway is v popular it seems. any reliability issues?
-
Dragos Dunica (@dragos_dydy) reported@divinprnc why not cloudflare also for sending/receiving? i think they support that too.
-
ORBS Official (NASDAQ: $ORBS) (@Iamhuman_ORBS) reported@Cloudflare reported on July 1 that more than half the traffic it sees across its network is now non human. AI training crawlers went from 22% of crawler requests in spring 2025 to 52% by June 2026. In some heavily crawled sectors, human traffic fell by as much as 40% in under a year. @worldnetwork's World ID answers this at the person, not the packet. Verify once in person at an Orb. Carry a private proof you are a unique human. The proof travels, your identity does not. $ORBS holds 301.9M $WLD, ~8% of circulating supply, the largest publicly disclosed institutional position globally. $WLD is the token that powers the World ID proof of human network.
-
Attick (@Attickk) reported@imagesaicouldnt blame her for cloudflare being down
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Jiten Bansal (@bansal_io) reportedI’m building a SaaS where customers will use their own custom domains. Can anyone familiar with Cloudflare for SaaS clarify this for me? The pricing page says $0.10 per additional hostname. Is that $0.10 per hostname per month, or a one-time charge? Any confirmation from someone who has actually used Cloudflare for SaaS billing would be really helpful. It’ll help me choose the right stack for my SaaS. @CloudflareDev @threepointone
-
The Civic Lens (@OriginalOGDAW) reported@TorBox It people knew they could just use free cloudflare and make there own Debrid service for free with 10tb monthly limit
-
developing valhalla (@valhalla_dev) reportedNotably, most technology that has been lifechanging and revolutionary is technology that the average person does not at all care about. The average person doesn't care about Linux, or Docker, or the HTTP protocol, or virtual hosting, or React. They don't have to. They like what comes downstream of that technological progress. So the argument that "AI doesn't matter to most people" is moot, because the downstream effects of AI do matter. Yes, AI People need to stop pretending like AI is going to steal everyone's jobs yesterday, yes they need to stop shoehorning AI into places that don't matter. But the answer to "why should the average person give a damn about AI" is generally "they probably shouldn't." The market is going to get kinda crazy, there is going to be a lot of tumult around data centers and inference buildout, and a lot of new consumer facing and business facing tech is going to be released at an accelerating rate. But the average person shouldn't really have to care about AI, any more than they care about what a VPS is or how CloudFlare Pages work.
-
Zely (@0xZely) reportedThe MIT professor who crashed 10 percent of the internet at 22 posts the free course that runs every AWS outage, every Uber ping, and every Slack notification on earth. MIT charges $85,000 a year to sit in that classroom. He posted every lecture to MIT OpenCourseWare for nothing. Millions have opened lecture one. Almost no engineer has finished all twenty. His name is Robert Morris. He is a professor at MIT CSAIL and one of the four cofounders of Y Combinator, the seed fund behind Airbnb, Dropbox, Stripe, Reddit, and Coinbase. In November 1988 he was a 22-year-old Cornell graduate student. He released a small program that was supposed to count the computers on the internet. It replicated so fast it crashed roughly ten percent of every machine online, and made him the first person ever convicted under the Computer Fraud and Abuse Act. He got three years probation, 400 hours of community service, and a $10,050 fine. Ten years later he cofounded the online store Viaweb with Paul Graham and sold it to Yahoo for $49 million. Seven years after that he cofounded Y Combinator with the same partner. Its portfolio is now worth over $600 billion. The clip in this video is one lecture from MIT 6.824 Distributed Systems, filmed at MIT and posted for free. The words on the board behind him are fault tolerance, availability, recoverability. Those three words decide whether Instagram loads when you open it, whether your Uber arrives, and whether your paycheck hits your account on the first of the month. Morris covers the entire logic of distributed systems in twenty lectures. Everything fails, all the time. A single computer fails once every few years. Ten thousand computers fail hundreds of times a day. The only design that survives is one that assumes failure is normal. Every retail user cursing a spinning wheel is looking at the wrong problem. The miracle is that most of the time it does not spin. Availability beats consistency. You cannot always have both. When the network splits, a system either serves stale data or refuses to serve at all. Amazon picks stale. Your bank picks nothing. Every user who screams at the Slack status page wants Amazon's answer. Every user who screams at a double charge wants the bank's. Replicate everything, trust nothing. Data in one place disappears when that place burns. Data in three places survives two fires. Every photo you have ever taken on an iPhone lives on three continents already. iCloud, Google Photos, and Dropbox are built off the exact lecture on the board. Concurrency is where bugs live. One user at a time is easy. A million users at the same second is not. Race conditions, double spends, lost messages, ghost bookings. Every airline that oversold your flight, every trading app that ate your order, every Ticketmaster that showed you a seat already gone, is a concurrency bug Morris warned about. Partial failure is worse than full failure. A dead server is easy. A slow server that answers half the time is a nightmare. It fools every retry, wastes every resource, and confuses every operator. Every "is it down or is it just me" Twitter search you have ever run is Morris's third slide. Every senior engineer at AWS, Google, and Meta has watched this course. Every startup that raised a Series A in cloud infrastructure hired an alumnus of 6.824. Every AI company training a trillion-parameter model on a cluster is running the same lecture in production. "A distributed system is one in which the failure of a computer you didn't even know existed can render your own computer unusable." That is Leslie Lamport, the Turing Award winner Morris quotes at the opening of 6.824. It is the exact sentence that explains why your Slack goes down when a data center in Virginia loses power. The full course is free on MIT OpenCourseWare. The lecture notes are on Morris's website. Every equation on the board fits on one screen of code. Almost every senior engineer at AWS, Google, Cloudflare, and Meta has watched 6.824. Almost no founder promising 99.99 percent uptime on their pitch deck has opened lecture one. That is the entire moat. The course is free. The willingness to sit through twenty lectures on partial failure before uploading your money to a payment app, storing your photos in the cloud, or handing your health records to a portal is a much rarer commodity than the confidence to click without them.
-
Uben (@Ubendev) reported@aiwithadb just shipped the version 4 of my CRM extension. mostly Cloudflare worker issues fixes.
-
SK64 (@stonkeykong64) reportedIs Cloudflare main site down or what?
-
erik@try.works (@trydotworks) reported@korinne_dev @Cloudflare Interesting. I just built a plugin for DeepSeek Harness to build it's own tools from cloudflare primitives and blueprints. Let me try this. But please, say agentic engineering instead of vibe coding, otherwise I'll feel bad about it
-
Aidan Sunbury (@aidansunbury) reported@michael_chomsky @thdxr We are running lots of cloud agents. The basic idea is it's OpenCode + the tooling we need for local development in a VM. If the OpenCode server is able to run in a cloudflare durable object, it can spin up much faster, and we can keep it's session history persisted forever for cheap. Then, the dev box VM can get spun up and down if needed, or resized if needed, without having to worry about migrating the OpenCode session or its context. It's just a much better architecture overall for the agent to not run in the same place as the sandbox. It unlocks so much. They are working on it, and I just really really want that functionality
-
Tito (@mynameistito) reportedAdding on to this, I'm pretty sure you'd even be able to fully host a game server on the Cloudflare network exclusively with workers/containers, with a contain working as a TURN switch for UDP traffic... Although, it wouldn't be feasible, might try have a play w/ this lata!
-
Hidden Gem Alert (@kynangonline) reportedStopping the bad guys with Cloudflare: 30,998 malicious requests blocked or challenged in the last month #cloudflare
-
Engr Mustapha (@_Engr_Mustapha) reported@juiceboy_of_abj No wonder I wanted to work on one website after buying domain I thought cloudflare was down 🫠 Am using other company for it
-
Elvis | Web Designer & MVP Developer (@elvi_ssio) reportedIs @Cloudflare Down?
-
Jay Zhang (@jayzhangdev) reported@CodeByPoonam I think third-party CI/CD might matter more. Hope Vercel or Cloudflare support it soon.
-
Brad Gessler (@bradgessler) reported@crqrdotcom Putting your name down for cloudflare.
-
Shan Ali🇵🇰 (@shanaliniz) reportedDear Vibecoders, I need some help. I want to turn my Windows laptop into a hosting server. I want to host my webpages, such as "index.php" and "index.html", directly from my laptop and then point my domain to my laptop’s IP address. I also don’t want to depend on Cloudflare.
-
Faye Xiao (@faye_xiao_) reportedThe spirit of Spirit just sold for $10 million Google is buying Spirit Airlines' data out of bankruptcy. Emails, internal communications, spreadsheets, bookings, frequent flyer and HR records, all de-identified, for $10 million. Judge Sean Lane rules on the sale Wednesday. The obvious read is that Google wants more data. But de-identified data doesn't work for advertising, since you can't target someone you can't name, and Google already sees more airfare information through Google Flights than Spirit ever generated internally. An airline that went under in May is also a strange place to look for pricing wisdom. What's worth buying is the internal material. The emails and the spreadsheets they reference record how work moved through the company: a question gets asked, a document gets built, a decision gets made, a system gets updated. Consumer text is everywhere, and records of how an organization actually functions are not, which is what you need if you want models that operate inside workflows rather than talk about them. Google's own statement uses the word enterprise, and the runner-up bid of $7.5 million came from Mercor, a company whose entire business is sourcing training data for AI labs. When the second bidder isn't another airline, the market has told you what was being priced. The strange part is that Google isn't short on this data at all. It runs Gmail and Workspace and sits on possibly the largest collection of business correspondence in the world, and it has promised enterprise customers it will not train on their content, which is not a promise it can quietly break. So it has the material and no permission to use it. What $10 million buys is clean title, a court approved dataset nobody can sue over, at a moment when everyone else is defending scraping claims. Dead companies can agree to things live ones can't. Any of this is worth paying for because the public supply is running down. Epoch AI's 2024 analysis put the stock of quality public human text at roughly 300 trillion tokens and projected it would be consumed between 2026 and 2032, a window that opens this year, and access has closed faster since than the arithmetic alone suggests. A census of the top 100,000 domains this July found 19.1% blocking at least one AI crawler, and in September Cloudflare begins blocking mixed use crawlers by default across its entire free tier. Private operational records are the obvious next reserve, and they are almost untouched. Epoch left them out of its estimate because private data is fragmented and legally too messy to use at scale, which is precisely the condition a bankruptcy court removes. That makes Wednesday's ruling more interesting than the sale. If it goes through, every bankruptcy from here has a new asset to offer, and the value will depend on how well documented the industry already is. A corner store has nothing worth buying, since you can watch how it works from the sidewalk. A hospital or a law firm is the opposite, because even with names removed the record shows how a case moves through the organization, who escalates what to whom, and which exceptions get made. That knowledge lives in internal systems and in people's heads and appears nowhere public. The catch is that the supply is biased toward failure, since no healthy company would sell its internal record, so every dataset that reaches the market comes from an operation that didn't work. That's useful for learning how a process runs, and much less useful for learning what good judgment looks like.
-
Ryan — building Eazip (@ryan_builds_) reportedVideo transcoding is expensive. AWS MediaConvert → too expensive FFmpeg on Fargate Spot → 30% cheaper, still expensive Considering Cloudflare Stream: upload → encode → download MP4 → delete Has anyone used Stream as a temporary transcoder? Smart shortcut or bad idea? 👀