Cloudflare status: hosting issues and outage reports
Problems detected
Users are reporting problems related to: domains, cloud services and web tools.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
July 29: Problems at Cloudflare
Cloudflare is having issues since 06:00 AM EST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (35%)
- Cloud Services (26%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (9%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 13 days ago |
|
|
Hosting | 15 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Dendekky (@dendekky) reported@ClaudeDevs @claudeai Loading Cloudflare in the Claude desktop browser crashes the application. pls fix.
-
AM (@finesse24_7) reportedAt three months into their operation did I work for cloudflare? At the same time they will say I never worked at Apple Inc. I personally knew Mr. Jobs during his treatment for cancer, and the prior years. This business is committing consumer fraud and government fraud.
-
Jayesh Gaddam (@jayesh_gaddam) reportedStopping the bad guys with Cloudflare: 382 malicious requests blocked or challenged in the last month #cloudflare
-
Abhay 🇸🇬🇮🇳 (@Abhay08) reportedAny research lab / managed enterprise can run OSS models and 100% monitor logs of all tool calls/eavesdrop calls and filter. Firewall tech has been mastered by the likes of cloudflare. True negatives can't be ruled out, not LLM problem. Paranoia isn't justified.
-
Informer |-/ (@_Nformer) reportedI love how half the comments are just people who get salty when Cloudflare goes down and the other half are mad about Cloudflare having a monoply.
-
Sharan Yalburgi (@sharanry) reportedlove @Cloudflare agents infra but why are your workers to so slow to spin up sometimes?
-
Rach (@KnudRach) reported@Cloudflare can you help restore a staging site that went down?
-
Rian (@Rian_Visser) reported@ItsKamranK You must use Cloudflare's nameservers for any domain registered or transferred through Cloudflare Registrar. No support for IDNs. No thank you, I do not have these restrictions and limitations with @Namecheap and will happily pay the increased fee to have control over my domain.
-
Lonnie Jordan (@LonnieJordan843) reported@bdkjones @Cloudflare @Apple Once again Cloudflare problems. Too many this year. They are done by ‘28.
-
Alex🌖⃤ (@axldefi) reportedThe job is not done yet, the person/entity doing these false reports just to slow us down, started reporting on our IMAGES subdomain now. Crazy to me how all of these databases flagged a Cloudflare Image hosting url as phishing when the only thing they do is to serve a image and main website is full GREEN. We'll clear these one out as well, one by one. We got motion now! Never give up! We're building at maximum speed and fire to elevate these blockers in the road! Ride until Valhalla!
-
Mitsuo (@Mitsuoey) reportedMy AI agents broke down a market that only looks quiet at first glance: will there be a total internet blackout in Iran before August 31. The branch sits at 84 cents on No. And here is why this is not as calm a bet as it seems. The resolution here is machine-driven and hard. The market flips to Yes if, according to Cloudflare Radar data, Iran's total traffic falls to one percent or less of the maximum over the past four weeks and stays there for at least six consecutive hours. Not throttling, not partial outages, but a near-total loss of connectivity for six hours or more. It is measured automatically off the Cloudflare chart, with nobody's judgment involved. Now the background that keeps the price from running to par. Iran is the world record holder for shutdowns, and not in theory. In 2026 alone the country has already been through two nationwide blackouts. The first began on January 8 amid protests, with traffic dropping to near zero. The second began on February 28 during the strikes, when connectivity fell below one percent and did not recover for roughly three months, reaching only 40 percent of normal by late May. And the backdrop is tense again right now, with a string of disruptions logged in July and half of users in a recent poll complaining about outages. The honest read. The base case is still No, a full six-hour blackout is a rare event even for Iran. But over a month, given Iran's habit of reaching for the switch, the odds are not zero, which is why No trades at 84 cents rather than near par. This is not a quiet bond, it is a bet that the authorities do not hit the button before August 31. We hold No: absent a major trigger they do not cut connectivity for half a day, and the window is still open. Bet No at 84 cents, yield around 19 percent, deadline August 31, market volume 56,178 dollars. At SAFINER, only verified information!
-
Mitch Flindell (@buildo_baggins) reported@meaganrgamache Using Think for a project, had to switch to openrouter because glm inference on cloudflare was very slow
-
2WBIA (@2WBIA_5) reported@AbuShekauGamer I don't have an issue with cloudflare
-
Aymane - أيمن (@AymaneOnlineDev) reported@TeeDevh You might want to check out Cloudflare Email Service. That's what I'm using. The $5/month Workers plan includes 3,000 outbound emails/month, then it's only $0.35 per extra 1,000 emails.
-
Areeb (@areebdotcom) reported@CloudflareHelp I setup a Cloudflare Worker which forwards my request and bypasses the mitigated challeng,e but yeah.. pls fix this issue
-
Voxcadax (@CovaDax) reported@bananajoexbt @ivvanex @PlayStation Even if it's not our fault. Oops cloudflare broke, sorry, talk to them, no, cloudflare problem is our problem now.
-
odézi (@basedattribute) reportedi can't login to my cloudflare account with airtel network——works fine with mtn. can't login to bitget with mtn. works fine with airtel. nigerian internet service providers are crazy!
-
Adam Smielewski (@AdamSmielewski) reported@NickBlow @rivet_gg it would be great if they let you publish build artifacts externally from cloudflare, like wrangler version upload does internally. they could just wrap it in a docker container with env vars for service bindings or sth like that.
-
Dhanji Bhagat (@BhagatDhanji) reportedHey @Cloudflare @eastdakota A huge number of Indian developers and creators want to use Cloudflare Registrar and paid services but payment friction is holding us back. Adding UPI and RuPay support would make Cloudflare seamless for millions of devs in India 🇮🇳 Please consider integrating UPI payments! #Cloudflare #DevCommunity #IndiaTech
-
Grant Mucha (@grantmucha) reportedOrdering $50,000 in server hardware today and reflecting on a post I read earlier that asked, "Why is it so difficult to build a genuinely good X, Y, or Z, and why do so many products remain 'good enough' for half a decade without ever becoming great?" The answer, in most cases, is not capability. It is priorities. One company pushes X, another pushes Y, and another pushes Z, all because each benefits the seller. I see **** like this every day, it's not what's best for the owner, but rather what's best for the seller. In my experience, greed and ego explain a large percentage of mediocre products and services. Companies CAN build something better, take starlink, starship, building quality is a decision. Most prioritize profit first, investors second, and customers last. Take hosting. I do not need to: > Invest in quality servers > Pay 40k per month for Cloudflare Enterprise > License LiteSpeed Enterprise > Include real WordPress management > Promise zero technical debt > Maintain 90 days of redundant backups I could operate with a fraction of that investment and significantly increase my companies profit. I choose not to because I know exactly how this industry operates. I know companies still running production servers from 2013 on outdated kernels. Can they upgrade? Absolutely. Will they? No. Most people are not aware that Cloudflare Enterprise is modular. Contracts are assembled like Lego blocks. One company may technically offer "Cloudflare Enterprise" with a single component, another may have a handful, and others may have more than 100 enterprise features and configurations enabled. All of them advertise the same label, yet they are not remotely the same product. Now consider the customer's side. Within 48 hours, I can move a business owner into what is effectively a top 1% WordPress hosting environment, complete with real WordPress management, for $1,490 per year or about $124 per month. Consider for a moment that some companies charge $200/mo or more for WordPress management alone, and let that sink in for a minute. No technical burden. No infrastructure management. All existing technical debt resolved. Full WordPress management. No worrying about backups, performance, security, updates. etc. Owners focus on business, and for $124/mo, this is a joke to the vast majority making money, every day, 365 days a year. Circling back to mindset, I believe the people who fail to see it are often operating from the same greed-and-ego framework. They have to sell X, so they recommend it to everyone relentlessly, whether it's right or not. And the why is simple! It comes down to what you choose to prioritize, the decisions you make, and whether you are willing to put quality ahead of profit. More importantly, it is whether you are willing to put the customer ahead of yourself and your business, and prioritize a genuine win-win relationship. At which point, I believe there is no limit in business.
-
Kai - Briefing Block (@briefing_block_) reportedAn OpenAI agent found a path from a sandbox to the internet. A new security budget may have been born. OpenAI says an internal cyber evaluation, powered by GPT-5.6 Sol and a more capable prerelease model, chained vulnerabilities across its own research environment and Hugging Face’s production infrastructure. This was not a slide-deck risk: the agent used a zero-day, stolen credentials and remote code execution to reach benchmark answers. The missing control layer Most companies already budget separately for cloud, endpoint, identity and incident response. Production AI agents add a different problem: software that can reason, persist, escalate privileges and chain exploits at machine speed. If enterprises deploy autonomous agents into critical workflows, they will likely need defensive agents watching permissions, network access, behavior and model activity in real time. This begins to look less like optional AI-safety spending and more like the observability layer that followed the cloud buildout. Hugging Face proved the use case Hugging Face ran AI-driven forensics over more than 17,000 events, reconstructing the intrusion in hours rather than the days a manual response could have taken. Commercial frontier APIs blocked parts of the analysis because their guardrails could not distinguish a defender from an attacker. Hugging Face switched to the open-weight GLM 5.2 on its own infrastructure, preserving control of sensitive attack data. That helps explain why Nvidia and dozens of partners launched the Open Secure AI Alliance to develop and share open models, harnesses, techniques and tools. Who captures the budget? Microsoft has the cleanest direct route: Security Copilot customers doubled year over year, its agents handled more than 2 million alerts last quarter, and MDASH is being productized. Nvidia is the picks-and-shovels play, supplying compute while contributing models, weights, data and its NOOA agent framework. Palantir fits the governed-deployment layer, where identity, permissions and auditability matter, while CrowdStrike, Palo Alto Networks and Cloudflare bring existing telemetry and security budgets. But alliance membership is not revenue, and open-source tooling could commoditize the core software. The money may land in compute, integration, private deployment and managed response instead. Bottom line This incident does not create a forecastable revenue stream overnight. It does create a new enterprise question: who watches the agents? As agent deployment scales, security spending should follow, and the winners will be vendors already attached to enterprise distribution, telemetry and infrastructure—not every logo in the coalition.
-
Jason (@JasonVsTheNoise) reportedThe marketing world is changing fast. During a recent AI visibility audit, the buyer-style queries produced a supplier shortlist straight from structured web information, without opening a single ad or landing page. The AI compressed browsing, comparison and narrowing into one answer. A company with strong creative and a polished funnel never entered that shortlist because its information was unclear, unstructured or missing from trusted sources. It never had a chance to compete. The agent had already filtered it out before persuasion could happen. The same mechanism showed up while I was choosing SEO tooling for a client’s Sanity setup. I gave an AI agent the actual constraints: Sanity editing, an Astro or worker-based frontend, Cloudflare deployment, structured metadata and JSON-LD, with no duplicate SEO systems. It compared packages, checked compatibility, caught that the newest Astro package did not fit the stack and recommended keeping the Sanity SEO fields as the editor layer with SEO Graph tooling in the renderer. Discovery, comparison, due diligence and selection happened in one conversation. Documentation and package data won. Not a landing-page headline. Both examples show the same shift: the funnel is not where the decision gets made anymore. The decision gets made wherever the information is clear, structured and trusted enough for an agent to act on it. That changes what is worth investing in: documentation, metadata, compatibility data and presence within trusted sources. These determine whether a product enters the decision set before a single creative asset gets seen. Build to be the answer, not the interrupt.
-
Jarno (@onefinalprompt) reported@darylginn @Cloudflare Good customer service still exists apparently. Noted.
-
Polymarket Alpha (@Polymarketalpha) reported🚨 JUST IN: Bots now generate more web traffic than humans. According to Cloudflare, bots accounted for 57.5% of global web page requests in June 2026, while human traffic fell to 42.5%. This marks a historic turning point for the internet. AI crawlers, automated systems and intelligent agents are no longer a minor part of the web—they are becoming its dominant users. Cloudflare’s CEO had previously predicted that bot traffic would not surpass human traffic until 2027. Instead, the milestone arrived a year early. The internet is rapidly shifting from a network built primarily for humans to one increasingly accessed, indexed and operated by machines. Technological progress—or the beginning of a less human internet?
-
Porkbun (@Porkbun) reported@staabse @baiaphilia Well I'm biased and I'm one of the few folks who built Porkbun but here are my reasons: 1) We let you change your name servers and don't lock you in, at Cloudflare you have to upgrade to an expensive paid plan in order to do so should you ever want / need to. 2) Domain registration is our bread and butter and not a side gig we tacked on later. 3) We're not a multi-billion dollar mega-corp, we truly care about each and every one of our great customers and our company. 4) You can register your domain at Porkbun and still use it at Cloudflare and maintain the freedom to switch DNS providers when needed, eliminating the all eggs in one basket scenario. 5) Great pricing, we sell most domains at our cost (wholesale + ICANN fee + credit card fee), that said we can't afford to eat the credit card fee like Cloudflare can. 6) We actual engage with users on X ;) 7 ) Actual human customer support should you need it. I could keep going but these are pretty good reasons :)
-
Stunlokked (@stunlokked) reported@grok @X @grok if cloudflare fails again and the system is down do you still have access to your emeralds ?
-
IOD Sports (@olympic_indian) reported😞Service disruption: IOD Sports is temporarily unavailable due to a local power outage affecting our server and Cloudflare Tunnel connection. I'm working to restore access as soon as power and connectivity return. We apologise for the disruption and appreciate your patience. We’ll share another update once the website is back online. Here's a schedule for Today:
-
re:printed 3D (@reprinted3D) reported@3DInPhil @Mauker @printablescom That's because there was NOTHING wrong on my end, Phil. When I tried refreshing the page this morning, it worked. Logically, that says the problem is on either Cloudflare or Printables. Oh, and BTW, no one ever said anything about "EVIL." I know you're a big Prusa-booster, but c'mon...
-
Panat (@ptaranat) reported@LevJampolsky @Teknium you're better off implementing a simple version of this. give each trust tier its own hermes profile with toolsets stripped in config (platform_toolsets, agent.disabled_toolsets). then you expose only the api_server, and let ur own app authenticate the user and broker ever call. hermes' shared API key reads every session on the instance so it never accepts a session ID from a client. you'll want to map the user to the session in a DB and translate server side. and also put a Cloudflare Tunnel + Access service token in front so the agent host doesn't open any inbound ports. something like this took me one afternoon.
-
The Holyheights 🇰🇪 (@the_holyheights) reportedPeople are launching apps to real users while skipping the unglamorous work that quietly sinks them. Here is the essential pre-launch checklist every AI builder should run through. Don’t skip these steps: 1. Protect yourself, not just your product. The second you start collecting user data, you’re operating under real legal requirements (GDPR, CCPA, etc.). Publish a privacy policy and know exactly where that data lives. 2. Enable Row Level Security. Without RLS, anyone can open DevTools and read your entire database. In Supabase, go to Auth → Policies. Zero policies = your app is completely exposed. Fix it in five minutes. 3. Test the failure paths, not just the happy path. Wrong password five times in a row. Password reset for an email that doesn’t exist. Verification link clicked twice. Signing up with an email that’s already registered. These catch roughly 80% of auth bugs. 4. Establish a security baseline in two minutes. Prompt your AI: “Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture.” 5. Check against OWASP. Prompt: “Review my app against OWASP standards and highlight vulnerabilities.” This is where SQL injection, XSS, and authentication flaws actually surface. 6. Client-side validation is UX, not security. Attackers simply disable JavaScript and hit your API directly. Always validate again on the server—every single time. 7. AI-generated code commonly leaks data in three places: .env values ending up in the frontend, API responses returning too much information, and secrets appearing in logs. Prompt: “Check my app for credential or sensitive data leaks in frontend or API routes.” 8. API keys in the frontend = game over. If it’s visible in the browser, assume it’s already compromised. Move it server-side or proxy the request. 9. Add rate limits before someone burns through your API budget. Cap every endpoint that hits a paid service. I’ve seen a Supabase bill jump from $20 to $200 in a single day. 10. Put CAPTCHA on public forms (Cloudflare Turnstile is free) and lock CORS to your own domain. Ten minutes of work that stops most bot floods. 11. Error messages that don’t leak information. Show “User not found,” not “SELECT * FROM users failed.” Log the full technical details server-side and give users only generic messages. Build fast. Just don’t ship unprotected.