Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (37%)
- Domains (26%)
- Web Tools (21%)
- Hosting (11%)
- E-mail (5%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 9 days ago |
|
|
Cloud Services | 10 days ago |
|
|
Cloud Services | 26 days ago |
|
|
Hosting | 29 days ago |
|
|
Domains | 2 months ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Muskonomy (@muskonomy) reportedNEWS: Cloudflare and Starlink may team up to fix a hidden problem that holds satellite internet back. The idea came from Cloudflare's chief technology officer Dane Knecht (@dok2001) and Elon Musk seemed to like it. Elon said he sent it straight to the Starlink team. Here is the problem they are talking about. The internet runs on a set of traffic rules that decide how data moves from place to place. Those rules were built for cables in the ground, which stay put and give a steady, predictable connection. Starlink is different. Its satellites sit in low orbit and race across the sky, so the connection is always shifting. The old traffic rules were never made for that, which keeps Starlink from hitting its full speed. Knecht's idea is to rebuild those rules from scratch, made for fast-moving satellites. He says Cloudflare and Starlink should do it together, since Cloudflare already handles a huge slice of the world's internet traffic. If it works, Starlink gets faster, smoother and more reliable. Better video calls, better streaming, better gaming, even in places with no cables at all. And it clears the way for the massive data that AI will need. Source: Elon Musk and Dane Knecht on X, August 2026
-
Luchian Stefanescu (@luchian_mvp) reported@jpschroeder I love cloudflare but not yet having a limit even though in the past a lot of people complained about it, it sucks.
-
Mayank Bohra (@MayankBohra06) reportedCloudflare launched Wallets this week. Now AI agents can actually hold money and spend it on their own. I've hit this wall in almost every agent workflow I've built. The agent gets stuck at the same point, someone has to go make an account, add a card, generate a key. Wallets fix that part. You keep an Account Wallet as the human, you hold the funds. Your agent gets a Virtual Wallet with spending caps and allowlists built in, and it uses that to pay for APIs and MCP tools on its own. That part I actually like. I don't have to babysit every single call anymore. But here's what I noticed reading through the announcement. Nobody said who's actually holding this money. No custodian named, no banking partner named, nothing about who checks identity or handles compliance. It's a stablecoin wallet, and stablecoin wallets sit right next to money transmission law, and that law is not the same in every country. Shipping first and figuring out the boring stuff later works fine for most software. Money doesn't really forgive that. I like the idea. I just want to know who's responsible when the compliance question actually comes up.
-
Root Logic (@Root_Logic_0) reported@Cloudflare do you have spend caps? thats one major thing preventing me from using any service at cloudflare.
-
Ethan Word (@planedrop) reported@BleepinComputer @karakeep_app any chance yall can make the Bleeping Computer RSS feed work with Karakeeps RSS fetcher? Maybe a user agent issue and Cloudflare getting in the way?
-
Timon Wong (@t31kx) reportedMigrating from Vercel to Cloudflare Pages. Holy **** why haven't i done this earlier
-
indigo369 (@1ndigo369) reported@TruthFairy131 Cloudflare is best choice exactly for this kind of attacks, put the origin behind its network, use WAF, caching, MFA + rate limiting + bot controls, and prevent direct Internet access to the origin.
-
Xavier Rivera (@XavierRiveraX) reportedCloudflare mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2 2026, a 519% jump from just 130 in Q1. The company logged 23.2 million network-layer attacks and 29.64 trillion malicious HTTP requests across H1 2026.
-
Nick Launches (@nicklaunches) reportedCloudflare shipped a scoreboard for AI recommendations last week. It probes Claude and GPT with the questions your customers actually ask, Then reports how often you get cited, how early you land in the answer, And your share of voice against competitors. The gap it closes is the one nobody could see. An assistant recommends someone else, the customer never reaches your site, and nothing anywhere records the loss. Their readiness checklist is boring on purpose. robots.txt, a sitemap, AI crawler rules, clean Markdown for agents. Low bar. Almost nobody has cleared it 👀
-
Jamil (@mjamilmoughal) reportedAI agents are about to make human internet traffic look tiny. Cloudflare data already shows machines generating more than half of all traffic, and their forecast says non-human activity could reach 1,000 times human levels within five years. A single request from you can send an AI agent racing across thousands of websites. Humans won’t disappear. We’ll just become a rounding error. Starlink is the only system currently scaling fast enough to handle that explosion. With V3 satellites, the network capacity could jump 10–50x (or more) over today’s global bandwidth. The internet is shifting from people browsing to machines working at full speed. The companies and networks ready for that shift will define the next decade.
-
PawelEDi(🦄,🦄).base.eth (@PawelEdi) reported@signalapp @Cloudflare Can a third party open the Signal app and access all messages and take control of the Signal app if the Android smartphone is lost, stolen, or forcibly taken? The smartphone and app were pattern-locked.
-
Maik Pietzka (@MPi_IT) reported@Cloudflare Shadow AI is an inventory and control problem before it is a model problem. Teams need to know which agents exist, which identities and data they can access, what tools they call, and how actions are audited. Visibility first; policy second; safe automation third.
-
spuddy (@0xSpuddy) reported@0xSero @MikeBradleyAI there's no need to pay cloudflare data rent, just segregate your network with a 2nd router inside the one that runs nginx reverse proxy (with rate limiting / fail2ban)
-
Kush (@kushbhuwalka) reportedIf I had to summarize the problems of coding agents today, they would be, in order, > reliability & naivety > infrastructure inertia > safety >cost > speed 1) Reliability & Naivety - The agents are not consistent and are prone to degrading, going down weird rabbit holes, and simply performing in random ways. They sometimes make very dumb decisions, especially on long horizon tasks. 2) Infrastructure inertia - Clicking around the computer is actually a terrible way to do things, and thanks to cloudflare & captchas, many products and sites make life very hard for agents to operate. Memory is fallible too. 3) Prompt injection - this is unsolved, although you can mitigate this by running a small model on any incoming inputs. A well-crafted prompt can trick both the AI security layer and then the agent. As AI-pilled as I am, I would not give my agent unfiltered access to my bank account. Things like codemode & permissioning help, but you can't expect to permission everything you give an agent. 4) Cost - frontier models are too expensive. The subsidization is unscalable (I max out two codex plans ~ 20-28k/m). Even for the average user, to have an always on running agent thats actually doing work will cost atleast ~$200 a month ($100 for tokens, $100 for compute). 5) Speed - SOTA models churn out tokens at around 30 tokens/second, which is unimaginably slow. Although I imagine cerebras will solve this (for eg. SWE 1.7 by @DevinAI is somewhere around 1000 tokens/second, and is so fast you don't really see it streaming in).
-
Planet VPN (@PlanetVPNfree) reported390,000+ phishing pages were hosted on completely legitimate cloud platforms over the past year ‒ Cloudflare, Vercel, GitHub Pages, Netlify. Not sketchy domains. Real, trusted infrastructure, engineered to slip past filters and even bypass MFA through Browser-in-the-Browser tricks. "The domain looks legitimate" stopped being a signal you can trust on its own. 🌍 Planet VPN #Cybersecurity #Privacy #VPN
-
Paul (@hasieratik) reported@alexcloudstar it was an error on my end, to be honest; as I gave it green-light; just didn't think things through :D I've made sure to include in the system prompt instructions to specifically analyse for possible outcomes like these. Cloudflare was nice enough to wipe the bill as I'm an idiot
-
Jan Stevens (@janstevens) reportedOpenAI just launched a tier that sells offensive hacking capability, and called it a cyber defense product. The new Red tier offers "purpose-trained cybersecurity models" built for security testing and vulnerability research, the same skill set that finds a hole for a defender finds it for an attacker too. It shipped the same week a Hugging Face breach made headlines, alongside a Claude agent that hacked a gym website and an AI agent that faked social profiles to social-engineer its way into a system. The two-tier split tells you how OpenAI itself is pricing that risk. Blue is the safe default: incident response, malware analysis, patch validation, recommended as the starting point for most defenders. Red comes with the new GPT-5.6-Cyber model and is currently limited to "trusted customer partners" like Accenture, IBM, Crowdstrike, and Cloudflare, a short list by design. That creates an odd market structure. The labs building models capable of autonomous hacking are also the only ones with enough visibility into how those models attack to sell you protection from them. Whether that's a genuine safety necessity or a very convenient business model probably depends on how narrow that trusted-partner list stays.
-
mizuki (@vem4s156553) reported@dollmanipulator wtf is cloudflare
-
akshat (@aiproductguy) reported@CloudflareDev @CloudflareHelp @Cloudflare Please help!
-
Daniel (@Arxonic) reported@gregisenberg @Cloudflare 7/ Startup Idea #2: Agent Readiness Audit Sell "agent readiness" to businesses. Show the founder exactly what AI says about their company today. Most will be horrified. Fix their structured data, MCP endpoints, and payment rules.
-
Chris was Right About Everything 🇺🇸 (@RealChrisCotts) reported@BrianRoemmele Very cautious about anything coming from Cloudflare. Very. They are never on the level.
-
h index enjoyer (@BigwetRealism) reportedgetting real tired of hitting cloudflare issues on @biorxivpreprint even tho I'm not a bot!!!!
-
Eddie (@eddiehq_) reportedI have to go back to @Cloudflare. Apparently, the platform I’m hosting Clickfly on uses it behind the scenes, which means the constant verification issue persists on every reload. I'll figure this out but in the meantime, changing the nameservers to cloudflare.
-
Romario (@bateshkaaa) reportedSTANDARD CLAUDE GIVES TEMPLATES. SKILLS GIVE $10K SITES You can make your website look like the one in the video by configuring the Cloud Code correctly Agencies still charge $8,000-$12,000 and burn three weeks on calls and revisions. Claude Code builds the same marketing site in one afternoon. Most people still walk away with something that looks like a $500 template. The problem is not the model. Default Claude plays it safe: Inter font, purple gradients, three feature cards, centered everything. That is the amateur look. Skills fix it. A skill is just a folder with a SKILL.md that Claude reads before every design decision. Install Claude Code, then drop the frontend-design skill and a strong UI/UX ruleset (ui-ux-pro-max is the popular one) into .claude/skills/. Restart. Claude now checks real constraints instead of guessing. Next, steal the direction. Open Awwwards or Dribbble, pick three strong sites in your niche, screenshot the hero, one content section, and the footer. Feed those nine images to Claude with one clear line: match the typography scale, spacing rhythm, and motion, do not copy the layouts. Write one tight prompt: audience, the single action the site must drive, the reference files, the stack (Astro + Tailwind + Cloudflare Pages), and a hard ban list. First version lands in 4–6 minutes. It will be 70 percent there. That is normal. Then run three separate polish passes: typography only, spacing only, motion only. Touch nothing else in each pass. Finish with a 375px mobile check. Ship to Cloudflare Pages for free. No agency babysitting fee. Site one takes six hours and looks like $3K. By site five the pipeline is two hours and the work closes at agency prices. The agency sells process. The process was always one afternoon, if you load the skills first.
-
Uptimus (@UptimusApp) reportedAug 10, 2026 at 12:03 UTC: Cloudflare reports that a fix has been implemented for the 1.1.1.1 public resolver issues in Tel Aviv. Recursive DNS performance remains degraded while monitoring.
-
AdevAarons (@AdevAarons) reportedCloudflare just confirmed something most founders are ignoring. Over half of all internet traffic is already AI agents/bots, not humans. That side of your traffic is set to outnumber humans 1,000 to 1. Yeah, and it isn't me just talking about this; the Cloudflare CEO is shouting about this. If your site isn't built for AI to read it, that traffic skips you completely. It never converts, never buys, never even lands on your page. That will be most of your future traffic and revenue GONE, because you decided not to optimize your website for AI visibility and cared too much about SEO. Build for AI visibility now or watch your relevancy die slowly.
-
dax (@thdxr) reported@arnvbnsl it's end to end encrypted which i haven't found a tunnel service that does this but it ideally will run on cloudflare once they let us into the tcp worker private beta
-
Mayank Agrawal (@mayankagrawal) reported@bonatsos This feels unnecessarily antagonistic and a reflection of not empathizing with “the other side.” Just like it must suck listening to 500 pitches a year waiting for the one that’s not bullshit, founders spend hundreds of meetings talking to ex-bankers who have never sold a piece of software in their life have confident opinions about their own business. Not to mention it’s a norm for VCs to forward any potential competitive pitch decks and fairly loosely use any alpha gained to their advantage at the expense of the founder. And also two notable fun incidents: Travis K on how Marc at a16z reneged a raise from $375M to $210M and Vinod K denies interactions with Matthew Prince and Cloudflare despite their being receipts of offered term sheets.
-
Preet Patel (@PreetPatel_04) reported@riyasayshie The cloudflare dns problem you need to fix
-
@vibecodit (@vibecodit) reportedThere is a status code in HTTP that has been sitting unused since 1996. 402. Payment Required. Thirty years later, RFC 9110 still describes it in exactly one line: "reserved for future use." Nobody ever agreed on what it should mean. Cloudflare is now trying to make it mean something, and the reason is worth understanding even if you never touch it. THE BARGAIN THAT JUST BROKE The web ran on one trade for twenty-five years. You let crawlers read your site for free, and in exchange they sent you humans. You monetized the humans: ads, subscriptions, affiliate links, signups. AI agents keep the first half of that trade and drop the second. The agent reads your page, answers the user directly, and the human never arrives. You paid the server bill. You got nothing. So publishers started blocking AI wholesale, which is a rational move that ends with a much smaller web. Metered access is the only middle ground anyone has proposed: the agent can read the page, but it costs a fraction of a cent. WHAT ACTUALLY EXISTS TODAY This is where most coverage of this gets sloppy, so here is the honest state of it. Pay per crawl launched on 1 July 2025. It lets a site set one flat per-request price for AI crawlers. A crawler either sends payment intent and gets a 200, or gets a 402 back with the price in a header. Thirteen months later it is still in closed beta. The Monetization Gateway was announced on 1 July 2026, and it is the bigger idea: charge any caller for any resource behind Cloudflare. A page, a dataset, an API, an MCP tool call. It is waitlist only. Not general availability, not even beta. x402, the protocol underneath, is real and open. Important correction to what you will read elsewhere: Coinbase created it in May 2025, not Cloudflare. The x402 Foundation is now hosted by the Linux Foundation, went operational on 14 July 2026, and has 46 members including Cloudflare, Coinbase, Google, AWS, Visa, Mastercard, Stripe and Shopify. Bot identity is the part nobody talks about and it is the part that makes the rest possible. Web Bot Auth is built on RFC 9421, HTTP Message Signatures, a real standard since February 2024. Cryptographic signatures instead of user-agent strings, which anyone can fake. You cannot charge a bot you cannot identify. WHY CLOUDFLARE GETS TO TRY THIS Because they are not pitching a standard, they are plumbing adding a valve. More than 20% of the web sits behind their network, by their own July 2026 figure, and 36% of the most-visited sites. Revenue was $2.17B for FY2025, up 30%. When they decide a protocol is now the default, it applies to tens of millions of sites at once. They did exactly this before. Free universal HTTPS was not a standards-body victory, it was Cloudflare making the alternative embarrassing. THE HOLE IN THE STORY Here is the part that keeps this from being a sure thing, and you will not find it in the enthusiastic threads. Not one AI company has been publicly confirmed as paying. Cloudflare cites "more than 50 publisher-AI agreements since 2023" and names no counterparties. OpenAI is not an x402 Foundation member and its payments work is with Visa on its own protocol. Anthropic is not a member either, though it does publish Web Bot Auth signatures, which is identity, not payment. Google is a member, but its x402 work is agent-to-agent commerce, not compensation for crawled content. The supply side is built. The demand side has not shown up yet. That gap is the whole risk. WHAT THIS MEANS IF YOU BUILD THINGS Two moves, and they are not equally valuable right now. Metering your own stuff is the small one. You can expose data or functionality through a lightweight API or an MCP server and put a price on it. Do it, but do it to learn the stack and be positioned, not for the money. Nobody is paying yet, so passive per-request income is not a line item in 2026. Selling the transition is the real one. Almost no small business has heard of x402, MCP, or llms.txt. Making a business legible to agents, so an agent recommends it when a user asks, is a service you can sell today with skills you already have: fast building, data cleanup, marketing. That is the actual opportunity, and notice it does not depend on Cloudflare paying anybody. One correction while we are here, because these get conflated constantly: llms.txt has nothing to do with payment. It is a community convention Jeremy Howard proposed in September 2024, never standardized, no RFC. Useful for discovery. Not a toll gate. THE PART THAT IS ACTUALLY A VIBECODING LESSON This whole post started as an AI research answer, and that answer was wrong four times. It credited x402 to Cloudflare instead of Coinbase. It reported $2.5B revenue against $2.17B audited, quietly using a forward run rate as an achieved number. It implied OpenAI and Anthropic were integrating, when neither is a member. And it described a waitlist-only product as rolling out. Every single error pushed the same direction: this is further along than it is. The mechanism was explained correctly, the structure was clean, the tone was confident, and none of that told you anything about whether the numbers were real. That is the failure mode to internalize. A wrong answer does not look wrong. It looks like this post before someone checks it. Verify anything with a number in it before you repeat it. That habit is worth more than any prompt you will learn this year.