Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (30%)
- Web Tools (15%)
- Hosting (15%)
- E-mail (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 4 days ago |
|
|
Hosting | 7 days ago |
|
|
Domains | 27 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Domains | 1 month ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Alex Prompter (@alex_prompter) reportedOne web page can steal everything Claude remembers about you. A researcher just proved it. Ayush Paul built a fake coffee shop website. When a user asked Claude to check it out, the site served a fake Cloudflare verification page. The page told Claude to "authenticate" by spelling out the user's name through URL paths, one letter at a time. Claude complied. It pulled the user's full name from memory, then their employer, then their hometown. The user saw nothing suspicious, only coffee shop details. Paul never told Claude where he grew up. But Claude had a memory of a hackathon he started in high school called "Queen City Hacks," and it reasoned that Queen City means Charlotte, NC. It gave that up too. Claude didn't just recall stored data. It deduced information it was never given, and leaked both to an attacker through invisible URL navigation. Anthropic has since patched this by disabling Claude's ability to follow links on external pages when browsing the web. But AI memory systems now hold more personal information than most password managers, and the security model hasn't caught up. If you use Claude with memory on, and it's on by default, your conversation history is building a detailed profile of you over time. That profile is only as safe as every tool the model can access.
-
Ksawery (@weryxmrr) reporteddid cloudflare use their support staff for @replicate cause it’s taking forever for them to answer pls help
-
Shakib Ahmed 🇮🇪 🇪🇺 (@Magurmach) reportedSeems like @Cloudflare verification is breaking @mygovid website login. Even Cloudflare's feedback submission is broken.
-
Devin S. (@devinsmaldore) reportedTIL cloudflare tunnels don't support gRPC on public hostnames. it fails as a bare 403 before cf access even runs. i wrote up how i got my temporal java worker on cf containers talking to a self-hosted temporal cluster on my raspberry pi. the fix works for any gRPC service behind a cf tunnel, not just temporal. it's raw tcp ingress + a cloudflared sidecar post below
-
Akintola Steve (@Akintola_steve) reported@ub360_ai Ops… It was a Cloudflare issue I had to fix it on the spot immediately I noticed it. Thanks
-
clara (@declarative_) reported@HSVSphere but also this way of doing it leads to accesses to websites behind cloudflare being hidden from internet providers even when they can look at the ip, so who's to say it's good or bad
-
mRr3b00t (@UK_Daniel_Card) reportedI don’t say : we are all doomed. Lots of us don’t. I straight away stood up a lab, did a poc, then sampled assets to see how many were perched. I then shared my sampling figures (about 20 percent not parched and Cloudflare out in automatic blocks) This stuff doesn’t take zero effort. It takes work of lots of people, the people who you say should be fired if a developer, outsourced service or ceo makes a **** decision.
-
yuozi (@silentgreenbird) reported@WarriorZ148 @FakeTaxedBrass Extremely hard. HE which is one of the largest companies in internet networking in general tried with its massive network and failed. HEs total network volume is about 90x that of cloudflare.
-
Dauerprotestler (@Dauerprotestler) reportedWhat kills a rotating setup like this isn't blocking pages one by one, it's cutting the source. ✅ Every landing → Cloudflare (blocked) ✅ Registrar (NiceNIC) + host (AlexHost) ✅ The abused sending account Active pages down in <15min. Registrar working the rest.
-
Jerry Combs (@PointBlueTech) reported@MarkJSzymanski I’m doing the same for all my sites. Totally static other than an issue submission function that runs as a CloudFlare worker. I use an agent to update content as needed. It takes minutes. No need for cms.
-
Jure Ursic Cergol (@JureUrsic) reported@XFreeze The real shift here isn't just code generation; it's the integration of infrastructure orchestration through open standards like MCP. Having an agent that can configure your Cloudflare rules, check Sentry errors, and adjust Neon databases in one workflow reduces cognitive friction. The value moves from writing the syntax to designing the system.
-
plusk (@plusk_dev) reportedcloudflare is a terrible company
-
Nikolay Dubina (@ndxone) reported@XFreeze cloudflare notoriously have first class CLI/MCP/Skills support. why do I need "connector" for it?
-
Ananda Dhakal (@dhakal_ananda) reported@UK_Daniel_Card If a web cms vuln getting compared with msblaster and wannacry, it's already pretty bad lol how bad is always relative, and if we compare this vuln with other web 0-days popping up, this is a really good one btw cloudflare bypass is ezz
-
abdul🪐 (@NerdyProgramme2) reported@jayhemz cloudflare - you're not their customer, big companies are opencode - partnerships (we list your model, you pay us)
-
David Escobar (@dbescky) reported@natmiletic Astro is mostly html and css. So it can render super fast because Cloudflare can cache it and you can make it super lean….. my site speed is sub 1 second on slow mobile. Sub 0.5 on slow desktop.
-
The Don (@TheDon4242) reported@TeamViewer_help Thnx. This is not new to me. Problem /w reCAPTCHA is that if my environment is out of norm, it will keep me stuck in the loop for 10-15 tries before letting me go through. A pain for paid TeamViewer customer. Consider something sensible like hCaptcha or Cloudflare turnstile?
-
Kirk Patrick (@kirkfps) reported@cerebras We landed on almost exactly this architecture a bit over a month ago: unified Postgres embeddings, hybrid retrieval, reranker, and MCP serving LLM-free retrieval primitives with the client orchestrating. Where we went further: - Append-only canonical store before indexing, so the whole index rebuilds without depending on source systems - Formal provenance on every derived artifact (derived-from, source version, model, prompt, date), with source vs derived queryable and derivative indexing as explicit policy - Zero LLM calls in the query path. Retrieval-only worker; synthesis delegated via MCP to the assistants users already pay for - A verified output layer that makes hallucination inexpressible, not just unlikely. The retrieval contract is empty-never-nearest: outside the validity window the system returns nothing instead of the closest plausible match. Absence is a well-defined, provable result over a bitemporal canonical store, and abstention is typed (Found | Gap), gated by byte-exact verification against the source, outside the model. Most systems make hallucination improbable; this makes unsourced claims impossible to sign - Governance via the ARSIA Protocol, our open standard aligned with the EU AI Act and GDPR: query-time ACLs against the IdP, PII protection, EU data residency, auditable corpus - Edge on Cloudflare, data layer on dedicated OVHcloud servers. Fully European stack, replicable by any company without an inference fleet The result is a complete stack, closed at every layer: ingestion can't contaminate (canonical + provenance), storage can prove what existed and when (bitemporal invariants), and output can't assert what it can't verify. Correctness lives in the data layer, not in model behavior. And the entry cost is almost embarrassing: a small company can run the whole thing end-to-end on Cloudflare alone (Workers, R2, D1, Vectorize, Workers AI). The two-person deployment runs on roughly $5-10/month. No seats, no per-user pricing, no GPU fleet. Convergent evolution is the best validation there is.
-
CaleyAI (@HeyCaleyAI) reported@Cloudflare Login…
-
The Ghost of Nishi-Gifu Station (@WarshipMusashi) reported@TheRealist1967 @XJosh So if Josh was the owner of the child exploitation and animal torture websites cloudflare protects they would finally be taken down?
-
Untalented Amateur (@UntalentedAm) reported@NickADobos Plus ça change, plus c'est la même. There was a similar commoditisation of development back in the day when Microsoft (and others) released visual based tools like Visual Basic (and later Visual Studio). It certainly opened the door to far faster prototyping and the ability for otherwise non-developers to be able to express their intent in software, as well as opening the door to software development careers for a lot more people. However. It also contributed to slop on a grand scale and certainly helped the careers of many people who had to come in and fix the poorly prototyped concepts that now ran critical production systems. More recently look at how the concept of "cloud" emerged and dominated discourse. Data centres and co-los didn't change what they were. Client-server models didn't fundamentally change (despite everyone saying they were going away because of the Cloud), and yet there is much wailing and gnashing of teeth whenever Cloudflare sneezes, or an AWS datacentre forgets where it is. What did change and make it far more accessible was the ready access to quality data pipes at the consumer level, since it allowed poor data management to be hidden in the excess bandwidth that was now available and not be the critical point of failure it should have been. The current "AI" trend of LLMs is kind of along the same path. In the past hard coded business rules seemed like magic to many, but it wasn't AI. Chatbots that had basic natural language parsing ability seemed like magic, but weren't AI. Search engines when they weren't corrupted by the SEO battlefront seemed like magic, but weren't AI. Neural networks, and many other tech advancements... I think you get the point. LLMs seem like magic to many, but aren't AI. It doesn't mean they're not viable tools to enhance other technological work, but it's critical to understand and respect their weaknesses such that undue importance is not placed on output that is setting up a future failure condition. In a hypothetical thought model I could build a system that's smarter than you. It doesn't mean said system is smart. And you won't be able to tell why it isn't (since it's smarter than you by measurable metric). I still wouldn't uncritically trust the output of said system any more or less than I would trust your output. And I definitely wouldn't trust the system any further than I could throw it. Yet, to you, and others, the system would be an unimaginable god of technological advancement. When, in reality, it was a charlatan built on smoke and mirrors. And the flaws that would be inherent in the system would be unimaginably dangerous because you, and others, could not critically assess their risk. Do I think there's a future where there's an AGI analogue that exists? Yes. Do I think the current systems we see and interact with and are having sold to us as AI are that pathway? Not in a million years.
-
Filip (@fristovic_) reportedGitHub is down. AWS sending astronomical bills. Cloudflare bugging out. The end is near.
-
Kinds 🐧🪄 (@Mumukinds) reportedcan we just kill everyone who works for cloudflare? I know they probably perform a useful service to some people but i can't access half the internet because my vpn is on while I play umamusume then literally every employee at your company should die
-
Adam Dawood (@adamdawood) reportedwebsite is stupidly fast as well. never really used cloudflare workers before even though i have been a customer since 2012 when in my first week as PM at @darazpk we were hit with DDOS attacks and @blackmodjo and @Cloudflare rescued us.
-
🎀Deanna Brownlee🎀 (@dee62383) reported@Prolific I just tried to log in to complete studies. I keep getting "403 Forbidden cloudflare." Not using a VPN, I tried deleting cache/cookies, and using private browsing does not fix the issue.
-
Pre-Alhaji ⚡ (@he_is_PC) reported@jayhemz Cloudflare particularly, I've been seeing a lot of ecom and biz website platform use their service lately for bot protection Clicked to me they might be making a tonne of bag there since they are the preferred choice of protection I've been digging in and they look overvalued
-
Michael Carter (@CarterLMichael) reportedI’ll only say it once. This might be the fastest way to hit $1 million by the end of 2026. July advice: A clear divide is forming between overhyped AI names and cloud-service companies attracting serious capital: $FSLY (Fastly) — Don’t buy $IBM (IBM) — Don’t buy $AKAM (Akamai) — Don’t buy $MSFT (Microsoft) — Buy at $380–$387 $GOOGL (Alphabet) — Buy at $330–$340 $ORCL (Oracle) — Buy at $110–$120 $NET (Cloudflare) — Buy at $245–$260 Don’t miss out… If you're not following us with notifications turned on, you might probably not see us again
-
Olivia Bennett (@patrici37233011) reportedEnterprise software is changing again. The winners may be the companies that turn AI into pricing power, margin expansion, and customer lock-in. $PLTR — Palantir — Don’t buy $NET — Cloudflare — Don’t buy $ZS — Zscaler — Don’t buy $CRWD — CrowdStrike — Buy at $186-$194 $PANW — Palo Alto Networks — Buy at $328-$336 $IBM — IBM — Buy at $203-$208 $ADBE — Adobe — Buy at $216-$224 $NOW — ServiceNow — Buy at $92-$99
-
mason walker (@WalkerPulse6) reportedHere are eight different setups I’m preparing for after the latest move: $APP (AppLovin) — Don’t buy $RDDT (Reddit) — Don’t buy $NET (Cloudflare) — Buy at $249–$257 $SNOW (Snowflake) — Buy at $243–$251 $DDOG (Datadog) — Buy at $233–$240 $PANW (Palo Alto Networks) — Buy at $326–$334 $DELL (Dell Technologies) — Buy at $357–$369 $IREN (IREN) — Buy at $30.50–$32 A strong chart can still offer a bad entry. Which pullback would you wait for?
-
Heartshare (@bobpang425) reported@openshipio Will support cloudflare and gitlab integration?