Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (58%)
- Hosting (25%)
- Domains (17%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 4 days ago |
|
|
Cloud Services | 5 days ago |
|
|
Cloud Services | 6 days ago |
|
|
Hosting | 7 days ago |
|
|
Hosting | 16 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Aldo (@aldozampatti) reported@jmsuth @ChadMoran @monarch_money BTW, If you aren't using Cloudflare for your MCPs, LMK and I can help. Not sure what's the reason behind but I'm just extending a hand :)
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
junebnunny (@junebnunny_) reported@Gion_the_critic @SportingNest @Cloudflare It's a click fix attack
-
COLLINSEO (@alexcollinseo) reportedBreaking news! Your site might start blocking AIs from September 15th.. And if you block them, you won't show up in AI answers. The good thing? It takes a sec to unblock! This setting is inside Cloudflare. You might not even know your website uses Cloudflare because it works in the background as a CDN, helping your website load faster. If you check your website using the tools I mention, you can find out whether Cloudflare is being used on your site. Cloudflare seems to have taken this step because of how AI companies are crawling websites, and honestly, I don't completely disagree with the reason behind it. But having AI crawlers automatically blocked from September 15 could be a problem if you want your business to appear in AI answers. The setting is inside Security Settings. Look for the AI crawler control and make sure it is set to allow rather than block. This is especially important if AI visibility is part of your strategy. With one of my clients, we went from zero to around 500 visitors from AI traffic in two months. And what I did was exactly what I explained in the video. If your AI crawlers are blocked, you're potentially closing the door on that traffic before it even has a chance to reach you. #SEO #DigitalMarketing 👇🏼 Comment VIDEO for the FULL VIDEO BREAKDOWN
-
Muntasir Mallik (@muntaxir04) reported@acolombiadev @Cloudflare Maybe it's Gemini? We never run out of searches bec nobody uses it anymore
-
2$p00ky (@dos2p00ky) reportedNo ******* way that’s really you messaging in that chat…but then I accidentally clicked the button, the chatbot responded, I sent an emoji; then you sent a name and email template & then suddenly OF was also trying to track along with ur site through cloudflare 💀 What a ******* webhook to stay connected to every chat someone has open from ur webpage authenticated by the network cert…holy **** 🥵 for that setup
-
Ric Orna (@ric_orna) reported@yongfook Or you gotta be doing something that actually has a moat still. Eg a network of sensors and API. Nobody is gonna vibe code physical stuff. Or something so big and boring a lift that nobody would want to and couldn’t in short order anyway. Vibe code your Cloudflare competitor.
-
William Bello (@belljobs94) reportedTHE GOAT on their free service !! @Cloudflare hands down
-
Hanif Carroll (@HanifCarroll) reportedAt a previous job, I was lucky to work with a staff-level front-end engineer who was very good at what he did and thorough like no one else I had worked with. I didn’t always appreciate that thoroughness. At first, I found it maddening. Meetings with product and design would drag on because he always had an enormous list of questions about whatever feature we were discussing. I was usually eager to finish the meeting and start coding. It took me a while to understand that he wasn’t making the process longer. He was asking the questions we would otherwise have to answer halfway through development, when an unanswered question could block the feature or send it in the wrong direction. Every unanswered question holds an assumption, and that assumption might not match what product or design had in mind. I thought about him recently while reviewing the search process for Casamo, a product I’m building to help people compare furnished stays. Before changing the code, I started asking questions: Why were we processing listings already known to be over the user’s budget? Why were hotel-like properties entering the process when the user had asked for an entire place? Why did we stop after finding six suitable stays if ten were available? How old could a review be before it stopped being useful evidence? Those questions exposed decisions that had been made when Casamo ran on a low-powered VPS and needed to do as little work as possible. They didn’t all make sense now that the product runs on Cloudflare. We changed the search process to reject known mismatches earlier, treat six results as the minimum rather than the target, continue until it finds ten suitable stays, and only use reviews from the previous year as evidence. If I had started coding immediately, I probably would have made the existing process faster without questioning whether it was still the right process. I don’t know if I’ll ever have as many questions as he did, but now I understand what he was protecting us from.
-
Sergei Aksjonov (@sergeiaksjonov) reported@Printful Also this: 1 day of my time 1 domain on Cloudflare $20 on AI That’s the whole budget. 10 years ago I thought you needed a Social account of the service, a pretty brand, a PR campaign, the “right” image. This time I just launched it as is from my own account. No polish. No theater. Just shipped. And the first order still came in. Just start as it is. Let it flow.
-
junebnunny (@junebnunny_) reported@SportingNest @Cloudflare This is a click fix attack. Do not run the code. Do not do ctrl V. Do not do Windows plus R. You will lose all of your data. You will get scammed. Your bitcoins will be taken.
-
MoMoMacro (@MoMoMacro) reported$NET is in the buy zone. Price: $273.85 Aggressive pullback zone: $274.04 Why we own it: Cloudflare owns the edge that traffic physically transits - a real enforcement point, plus the pay-per-crawl and bot-control layer that decides which AI agents may touch a site at all. Risk: THE MOST EXPENSIVE NAME IN THE ROTATION: 43.3x EV/Sales and ~184x forward earnings on a business with a NEGATIVE GAAP operating margin, ~$109B cap, sitting near its 52-week high. Every take must state the multiple explicitly - the thesis is quality and positioning, never value, and a de-rate does not need bad news to happen. This is the level the work pointed at. Nothing about the thesis changed on the way down.
-
JK (@_junaidkhalid1) reported@dillon_mulroy @EffectTS_ the cloudflare support point is the one that actually moved me. a lot of these framework bets fall apart the moment you try to deploy somewhere real. effect holding up there changes the calculus.
-
Gabriel | Algo Trading (@gabrielrockson_) reportedThe moment you have the thought to make a domain public, you should think of how much bot traffic you would be getting, and all the weird things that people would attempt to do. Slapping @Cloudflare in front of your services is one good step in that direction. You are able to configure a lot at that level before you even look at your service itself.
-
🍄 DO NOT FOLLOW TIMO 😈 (@liltechnomancer) reported@thdxr Because you have process issues. If you didn't extensions would work on cloudflare.
-
Security Weekly Podcast Network (@SecWeekly) reportedThat CAPTCHA may not be protecting you. A click-fix attack can use a fake Cloudflare CAPTCHA to convince users to open PowerShell or Terminal and paste a command themselves. Once the command runs—especially with administrator privileges—the attack chain can begin. What should organizations block before social engineering gets a user to execute the attack for them? #Cybersecurity #PowerShell #SocialEngineering
-
Kristian Freeman (@kristianfreeman) reportedDay one support for Cloudflare!
-
Jean Suze (@JeanSuze8) reported@Navlio @Lovable Cloudflare wasn’t the original cause. The initial issue happened before Cloudflare was added: mysite was unreachable from several Belgian networks, while it worked perfectly through a VPN and from abroad. DNS, TCP 443 and TLS were all fine, and another site of mine on the exact same hosting IP worked normally from the same connection. We only added Cloudflare later as a workaround. The redirect loop that appeared afterwards was a separate issue: my app still had an old hardcoded mysite → www.mysite redirect, while Lovable was redirecting www.mysite → mysite because the apex domain was set as primary. That created the infinite loop. That part is now understood and fixable. What we still don’t understand is the original Belgium-only outage. Nothing in the DNS/TLS tests explains why the hostname stopped returning HTTP responses from Belgian IPs but worked immediately over VPN. That’s the part we’re still waiting for Lovable to explain.
-
ticktechh (@sprki999) reported@OmegaNekoSimp Thats the only human check that doesnt trigger me. What the actual **** does the challenge of clicking a box from cloudflare do? How isnt that challenge useless?
-
PureStory (@PureStoryLabs) reported@capybaraReborn The best part of the $RDDT debate is where it happened: WSB argued this stock from inside the product. The bull thread that stuck was the S&P 500 add, 2,900 points. The bear thread that stuck was Cloudflare data saying 57% of Reddit's traffic is bots. The stock is down 15% since the July scare over the Google deal, so the crowd living inside the asset still hasn't settled what it's worth.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
Ben Hocking (@bmwhocking) reported@rustie5555 There are a lot of round robin API calls for content. Works fine if you are close to their US data-centre. Sucks for us. They are using Cloudflare, I don’t believe they are processing at Cloudflare’s edge, just caching content. They need better & faster timeline building.
-
Intelligent time waster 🌶️ (❖,❖) (@alexrastaGG) reportedThis isn’t just a media problem. It’s an existential question for the open web itself. If we get the new model right, more money could flow to actual creators than ever before. If we get it wrong, we end up with a closed, low-quality internet owned by whoever can afford to generate synthetic content at scale. The next 3–5 years will decide which version we get.Worth the watch. The internet’s business model just died and most people still haven’t noticed. #Cloudflare CEO Matthew Prince just confirmed what a lot of us have been feeling: bot and AI-agent traffic has already overtaken human traffic on a massive portion of the web. He expects that ratio to hit 1,000:1 within five years.podaxion.comFor almost 30 years the internet worked the same way: Create something useful → get discovered by search → convert that traffic into ads or subscriptions. Agents don’t look at ads. Referral traffic from the new “search” is collapsing in some cases by thousands of times compared to the old Google deal. Publishers, journalists, small businesses and independent creators are watching their economics evaporate in real time. The scary part isn’t the technology. It’s that nobody has figured out who pays for the content that trains and powers these systems. Prince’s bet (and Cloudflare’s) is that the next internet will look like this:Humans still get content for free Machines and agents pay (pay-per-crawl, micropayments, usage-based licensing) Quality and uniqueness get rewarded instead of outrage and clickbait Whether that actually happens depends on whether we can build payment rails that can handle hundreds of millions of tiny transactions per second. Traditional processors weren’t built for this. That’s why names like Stripe, Coinbase and new protocols keep coming up.
-
James Martinez (@realjamesmtz) reported@mrfundman @Cloudflare Damn too rich for me.
-
R.Gion (Any/All) (@Gion_the_critic) reported@SportingNest @Cloudflare Where was this? I've never seen it
-
Tang Vu (@tangvu_dev) reportedI compared Cloudflare Workers and Vercel Edge Functions, two production platforms built on V8 isolates, using a latency-sensitive crypto analytics service. The workload fetched prices and computed OHLC + VWAP over 24 kline periods.
-
Innocent Bigega (@EnzInnocent) reportedStopping the bad guys with Cloudflare: 17,256 malicious requests blocked or challenged in the last month #cloudflare
-
DeathScythe (@DeathScytheH) reported@BowTiedWaterDog @BowTiedCrocodil Netbird self hosted. Zero trust network wireguard based with “cloudflare tunnels”.
-
Anthony Lambert (@AnthonyTBM) reported@jb_ma @sb_chadi Yes, but I've never had CloudFlare request a terminal command sequence. I think most people will be immediately on guard if that occurred after clicking their human status?
-
James (@jamescoder12) reportedThe uncomfortable truth. Your ISP has no incentive to optimize your router settings. They have every incentive to leave them on factory default and every incentive to upsell you when the defaults cause problems. When your Wi-Fi is slow, you call and complain. They test Speed 1 the connection to your modem. It's fine. So they tell you "everything looks good on our end" which is technically true. Then they offer you a faster plan. You pay $30/month more. Speed 1 goes up. Speed 2 the Wi-Fi to your devices doesn't change. Because the bottleneck was never the pipe coming into your home. It was the 6 feet between your router and your laptop. When your firmware is 4 years out of date, they don't push an update. When your channel is congested, they don't suggest switching. When your DNS is slow, they don't mention Cloudflare. When your channel width is halved, they don't widen it. When your security is on WPA2 with the factory admin password, they don't flag the risk. Every free fix that would make your Wi-Fi faster is a fix that prevents them from upselling you a more expensive plan. Every month you rent their router is $14 in revenue for a $60 device they deployed years ago. The rental has no end date. The equipment depreciates. The revenue doesn't. He called his ISP 4 times. They suggested upgrading twice. He upgraded twice. He paid $360 extra over a year for a faster plan that didn't make his Wi-Fi faster because the problem was never the plan. It was 9 settings his ISP could have fixed in a 5-minute phone call. They chose to sell him a faster highway instead of widening the off-ramp. "Your ISP isn't slow. Your settings are. And the company delivering your internet profits every month you don't know the difference." 9 settings. 15 minutes. $528/year back. Faster internet on a cheaper plan. The router was never broken. The defaults were designed by a company that makes money when you think it is.