Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (50%)
- Hosting (30%)
- Domains (20%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 1 day ago |
|
|
Hosting | 1 day ago |
|
|
Hosting | 11 days ago |
|
|
Cloud Services | 29 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Cloud Services | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Redfoo ❌ (@Redfoo) reported@FrankGibbs35 @claudeai Until they do you can build it with Local :tts,stt, serving react UI, via Tailscale through your local lan… you could even bust out a Cloudflare persistent local tunnel with Tailscale on your iPhone having a voice chat with Claude but still no public ports open for bad actors
-
Rick Dudley (@AFDudley0) reported@rehan_shei Do you need help self-hosting? I expect cloudflare will do this no problem.
-
Stuti (@stutireal) reportedtired: dog ate my homework wired: cloudflare was down inspired: three consecutive ai civilizations rose and fell inside my macbook during a forced restart. My notes app and chrome tabs did not survive the third regime
-
Zoë (@zoecyber001) reportedRAPID FIRE CYBER NEWS - WEEKEND EDITION The weekend wasn't quiet. 1. Manchester Airports Group is facing an alleged data theft. Extortion group FulcrumSec claims it stole around 86 GB of data containing customer, booking and travel information. 2. Berlin's government is refusing to pay ransomware attackers who claim to have stolen 5.79 TB of data from its network. The city confirmed the extortion attempt but says it won't pay. 3. Several Chrome and Edge extensions were caught delivering malware that can steal crypto-related information, browser history and sensitive data. Some were also used to inject fake ClickFix prompts. 4. Infostealer malware is now stealing active Claude sessions. Anthropic warned that attackers can potentially take over Claude accounts using stolen session information without simply needing the user's password. 5. Microsoft uncovered TerminalFix, a new ClickFix campaign using fake Cloudflare CAPTCHA pages to trick people into running malicious commands that install a reverse-tunnel backdoor. Cybersecurity keeps finding new ways to abuse things we already trust.
-
Sahil Mondal (@SahilMondal_) reportedThe fastest way to crash PostgreSQL is opening direct connections inside Serverless Lambdas. 1,000 concurrent requests = 1,000 DB connections = OOM crash in 2 seconds. Fix: Put PgBouncer or Cloudflare Hyperdrive in front. Keep 20 persistent connections open and reuse them.
-
Revanth x (@svsairevanth) reported@Cloudflare @CloudflareDev after adding second card it shows this Your account has an outstanding balance. Pay it from Billing before trying again. but no invoice generated. no bill . pls help @Cloudflare team
-
Brinkin (@brinkin) reported@hieuSSR @Cloudflare Damn!
-
Ulaş Difficile (@ulasdifficile) reported@levelsio Cloudflare verification not working.
-
gojimmypi (@gojimmypi) reportedHuh. Often the wonky internet problems are VPN related. I was already on a non-VPN setting for the above @Cloudflare BOT problem. Oddly, moving TO a VPN resolved the problem. Then back to regular @Starlink internet, no VPN: The same BOT missing UI problem. Weird.
-
Ovin (@OvinRaw) reported@levelsio @Cloudflare Claude Code + Cloudflare API is basically the 'I never want to look at a dashboard again' stack. Infrastructure as Code is out, Infrastructure as Chat is in.
-
BlogVault (@blogVault) reportedA background backup can complete its first step and never reach the second. WP STAGING documented jobs stalling when the loopback request used to trigger the next task was silently dropped by Cloudflare, a firewall or a host blocking cURL requests. From the dashboard, the backup may look as though it started normally. That is why backup monitoring needs to check continued progress and final artifacts-not merely whether the scheduler fired.
-
colinhacks (@colinhacks) reported@SheltonLouisGT it requires `new Function()` which is blocked by many Content Security Policies (incl the one used by Cloudflare Workers). In any case, I wanted to put this first as opt-in to make sure there's no behavioral drift or unexpected issues before seriously thinking about default-on. it's also easy enough to enable project-wide
-
Danny 🏴 (@danjones) reported@AminTechs Cloudflare tunnel, reverse proxy. Public VMs are in a DMZ/ isolated network. Anything “private” and hosted on the public web, put behind cloudflare access with Authentik hosting part 1 of auth.
-
Jloasxhq (@pcapdodger) reported@NYBackpacker @Real_RobN No, not quite lying. When I and Harry Hauri exposed it in NOV 2020, they denied it and by Feb 2021 after I mapped their entire network, they hid behind CLOUDFLARE and AWS. They denied it constantly, even when we exposed Goran in Canada who had been going between Serbia and Canada.
-
Nick Dodd (@nickdodd) reported@BraydenWilmoth Who knew billing was important for a company literally selling services? I never, ever, have wondered why I have never used Cloudflare for anything.
-
BowTiedTamarin | Video & Audio 🧙 (@BowTiedTamarin) reportedWas getting HUGE influx of fake accounts+ burner emails in Klaviyo due to card testing bots. most from proxies all over so I couldn't just ban a whole problem country's traffic 1. shopify flow to flag and not capture payment from medium/high risk orders. 2. cloudflare 3. created segments in klaviyo to clean list while dealing with it. 4. added another specific flow to catch orders that slipped through #1 but followed a clear email address pattern I could isolate with a regex. turned it off once I was sure this particular scammer had given up using my site for testing
-
BOOZBOY (@Dorvskima) reported@RomixUS @kick Kick sits behind Cloudflare, and Cloudflare aggressively blocks traffic coming from data center IP ranges, which is what almost every VPN server uses. It's not actually a DNS issue on your end. The site detects the VPN IP, flags it as a fraud or bot risk, and serves a blank or broken page instead of a real error. That's why clearing cookies, clearing history, and excluding the site inside your VPN app all did nothing. The block happens before your browser even gets a proper response back Try one of these - Test each fix on its own so you know exactly what actually worked. ** Switch to a residential or stealth IP if your VPN offers one, instead of the standard server list. Standard VPN IPs get burned fast because thousands of people share the same address. Try a different protocol inside your VPN app. If it has WireGuard, OpenVPN, or something labeled Stealth or Obfuscated, switch to it. Cloudflare sometimes blocks based on traffic patterns, not just the IP itself. Manually set your DNS to 1.1.1.1 or 8.8.8.8 instead of using whatever your VPN assigns automatically. Sounds strange to use Cloudflare's own DNS to fix a Cloudflare problem, but the resolution step is usually where this actually breaks, not Kick's servers. Change your VPN server location entirely. If you're on a US server try Netherlands or Germany, or the reverse. Some countries have far less flagged IP ranges than others. Turn off IPv6 on your device in network settings. A lot of VPN and Cloudflare conflicts happen because your device leaks traffic around the tunnel through IPv6 instead of going through the VPN's IPv4 route. Fully close and reopen your browser instead of just clearing cookies. TLS session data gets cached separately and survives a normal cookie clear. Test on mobile data with the VPN still on. If it suddenly works, your home router or ISP DNS is the real problem, not the VPN. Start with the DNS change and the residential or stealth server option since those two fix this exact Cloudflare versus VPN conflict most of the time.
-
LokiElGatoQueOpina 🇨🇱🇩🇪 (@lokitoelgato) reported@PierreJalley @eurofounder Google, Microsoft, Amazon, Cloudflare. If the US decided to shut down those services in Europe, they are lost. Nobody can even work anymore. Wake up. Your continent became the laughing stock of this planet.
-
Revanth x (@svsairevanth) reported@Cloudflare @CloudflareDev Urgent help needed , our R2 access was suspended after payment verification failed. We added a second valid card, but the account remains blocked and Billing shows no invoice or Pay Now option. Please escalate this to the Billing/R2 team.
-
Deyder Cintron (@deydercintron) reported@levelsio @Cloudflare Full API surface that lets you register and manage without handoffs is the real unlock. Anything that forces a browser click or support ticket re-introduces the bottleneck.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Corey J. Gallon (@CoreyGallon) reportedI'm stoked to recap my own talk from @aiDotEngineer World's Fair! The premise of "The Dark Arts of Web Automation: Teaching Agents to Use Websites Like Humans" fits on one slide: a CDP-driven browser is indistinguishable from one driven by a human, because the agent's clicks and keystrokes travel the same path inside Chrome that yours do. I provide a repeatable method for making agents actually operate the web, ending with a fully automated reCAPTCHA v2 solve with no human in the loop. To make your agent appear human to websites, you need the following things. - A CLI, not an MCP server. An Arize AI study found both hit ~83% task success, but the same task took MCP 71 round trips and eight minutes against seven turns and under a minute for the CLI. Anthropic have reported the CLI can be up to 75x cheaper in tokens. - Drive the browser through the Chrome DevTools Protocol. It's the same protocol behind the panel that opens when you hit F12. 57 domains now, but you only need the handful that give your agent digital senses: DOM and accessibility tree and screenshots to see, network and console to hear, clicks and keystrokes to act. - Sense, act, verify, repeat. Verification has to come through a different channel than the one you acted on. If you clicked something, don't ask the click whether it worked, check the network or the screen. - The "meatbag ladder". Rung one is a synthetic JavaScript click, free and instant and the right default. Rung two is a real click through CDP's input domain, which Chrome stamps trusted. Rung three is human motion and vision. Climb only as high as the page forces you. - Trusted versus untrusted is why your click does nothing. A synthetic click on a defended add-to-cart button fails silently, no error, and the page just drops it. The trusted one goes straight through. - Cloudflare Turnstile hides its checkbox behind a closed shadow root inside a cross-origin iframe with another shadow root inside that. So stop trying to grab the element. Ask where the iframe sits, do the math, fire a trusted click at that position on the glass. - Slider captchas are won by how you move. They sample the mouse into a trail of points, so the drag eases in, curves, deliberately overshoots and settles back. - Split the work: deterministic solver, agent operator. Code does the clicking, iframe piercing, screenshotting and rearming; the agent only looks at the grid and picks tiles. reCAPTCHA rounds expire, and an agent that round trips a model on every click burns the clock and loses. - Explore by hand, then write the path down. As code, as an agent skill, often both. Figure it out once, do it forever. It was delightful to speak at this conference, and to meet and talk with so many other AI Engineers working on cool projects! I look forward to the next AIE event. I'm working through the published talks from AI Engineer World's Fair sharing summaries and takeaways. Follow for more!
-
Iker Near (@IkerNear) reported@rohinlohe @Cloudflare what networks will be supported for buyers to tap into the gateway? are these subject to Coinbase's CDP Facilitator support?
-
Disbelief (@bullhooves) reportedHow the 9 fit together in a real stack Think of traffic and trust flowing north–south (user → internet → app) and east–west (workload → workload inside the DC).1. Who is the user? $OKTA authenticates. CRWD and PANW/CyberArk watch for stolen or overly privileged identities. $GEN only matters if the “user” is a consumer, employee family plan, or breach-notification population — not the corporate IdP. 2. How do they get on the network? Three competing Zero Trust overlays: $ZS if you want a pure cloud broker $NET if you already use Cloudflare at the public edge and want SASE on the same backbone $PANW Prisma or FTNT FortiSASE if you want SASE from the same vendor as the NGFW OKTA feeds all four. 3. What carries the packets? $ANET owns the high-performance underlay — especially AI clusters and cloud-scale DCs. It does not replace PANW/FTNT firewalls. The live pattern is Arista fabric + PANW NGFW “inspect once, enforce many.” $FTNT owns the value / branch / OT underlay. $ATEN shows up in service-provider and high-connection-rate DC designs (CGN, Gi/SGi firewall, SSL visibility). 4. What sits in front of the application? Internet-facing: NET first (CDN/WAF/DDoS), sometimes ATEN DDoS/WAF Inside the DC: ATEN ADC/CFW or cloud LB Segmentation: PANW or FTNT NGFW 5. What protects the host and the cloud account? Enterprise: CRWD on the endpoint/workload, PANW Prisma or CRWD in the cloud. Home / small-office / employee devices outside MDM: GEN.6. Who runs the SOC? $CRWD Falcon Next-Gen SIEM if the program is endpoint- and identity-centric PANW Cortex XSIAM if the program is consolidating NGFW + cloud + SOC FTNT FortiSIEM if the fabric is already Fortinet ANET NDR as the network sensor feeding whichever SIEM you picked
-
Dc nigma (@Dcnigma) reported@lucataco I wish cloudflare was more reliable, sometimes it just stops working for me and after switching to google dns I never had that problem again
-
Bobby Lansing (@dataguybobby) reportedBot is grepping logs in CloudFlare, Azure, Supabase, and Vercel. Then triggering Cursor agents to build a fix. I am mentioning issues and approving PRs.
-
Ric Orna (@ric_orna) reported@yongfook Or you gotta be doing something that actually has a moat still. Eg a network of sensors and API. Nobody is gonna vibe code physical stuff. Or something so big and boring a lift that nobody would want to and couldn’t in short order anyway. Vibe code your Cloudflare competitor.
-
Ryan Chandler (@ryangjchandler) reportedBoth sites get loaded in a headless browser on a Cloudflare Worker. Page weight and request count come from the real network log when the site loads, probably the most accurate way to retrieve this information.
-
StatusDrop (@StatusDrop) reportedCloudflare sneezes and a third of the internet coughs, your app included. You can't stop it, but you can tell users it's upstream in seconds instead of fielding a support pile-up.
-
Krishna Singh (@krishnasinghdev) reported@tapasadhikary @Namecheap I never liked namecheap / godaddy, don't know why people choose it over simple providers like cloudflare where they charge same amount for 1 or 10 years