Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (57%)
- Hosting (29%)
- E-mail (7%)
- Domains (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 2 days ago |
|
|
Cloud Services | 6 days ago |
|
|
10 days ago | |
|
|
Hosting | 11 days ago |
|
|
Cloud Services | 16 days ago |
|
|
Cloud Services | 18 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
BucketShop (@RealBucketShop) reportedSigh. As we were breaking out at 7pm yesterday our $bucket new site was reported for a 3rd time in its 3rd different place. Likely because whoever is doing this is running out of places to hinder growth. Nothing has been compromised. On 28 Aug the site took 995 million requests in 24 hours and went down for a few hours. The protocol never stopped. Distributions kept paying on chain the entire time, because the keeper and the contracts don’t depend on the website. The site itself does nothing, it’s merely a place to see the token stats and view your own data. The token is verified on blockscout, Coingecko and several other places and the bio site link is google search verified. Contracts are immutable, LP is burned, ownership is renounced. All checkable without trusting me. @X blocklist isn’t cleared because they have no team. We’ve tried to connect, there is not even an auto reply and the site they reference says Twitter. @Cloudflare was appealed immediately. Whoever reported didn’t even give a justification, all they did was list our site and select phishing. It’s market as in review, we have no clue how long they take. It’s becoming increasingly obvious this is coordinated. We’ve appealed to cloudflare on who’s reported this. Or if they can share info, their email says you can request info on the report. That being said. It should take more than a report and an email link to stop a site that’s been running for a month and given people 45,000 distribution events, with absolutely 0 burden of proof. For now. Just use the old site that’s Google safe search reviewed and approved. It’s identical anyways. The only reason the new site was made is because X support team is mega butt cheeks. Full timeline below.
-
Nathan Flurry 🔩 (@NathanFlurry) reportedAI-generated Rivet Actors / Workflows are (finally) here 🥂 Some design notes on Dynamic Apps: Powered by agentOS → provides lightweight sandbox-as-a-library V8 isolate runtime → generated apps scale to 0, cold starts in ms, 22 MB per app, native JS performance (not slower WebAssembly like QuickJS) Novel Node.js-compatible runtime → ground truth agents already know & existing libraries work, native performance No nested virtualization → pure userspace, like Chromium & Cloudflare Workers Self-hostable → Dynamic Apps can run anywhere, including Kubernetes, Railway, EC2, etc (which don't support microVM / KVM) SQLite sharded by actor → scalable, fast, cheap, uses no compute when idle A Rivet namespace per app → isolates its actors, separates billing, and nothing to provision Builds run inside agentOS → npm install & build steps in the WASM sandbox, like a Dockerfile without the Linux VM Dynamic Apps also supports plain REST backends & static frontends deploy the same way
-
LUIS- LUIS- (@LUISLUIS532957) reported@itz_pippo still not working, akira is blocked by cloudflare, please include always other hosts, thanks.
-
Julian Schubert (@julian_durian) reported@Gaus450 Before I bought mine at Namecheap, I moved everything to Cloudflare after their huge outage.
-
Girish (@spectragai) reported@UthaaleReDeva @acolombiadev @Cloudflare It serves different purposes. But I’m just answering the post: name a generous free tier service
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Hatem Hosny (@hatem_hosny_) reported@acolombiadev @Cloudflare @livecodes_io the client-side code playground that can be embedded and self-hosted is free for unlimited usage! 90+ languages/frameworks Mobile support Private by default Open-source
-
James Martinez (@realjamesmtz) reported@mrfundman @Cloudflare Damn too rich for me.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
Winston Gao (@Winston_Gao) reportedThe lean tech stack we use to run cross-border physical operations (China OEM ➔ EU fulfillment) with zero legacy banking friction: 1. Modern FinTech Rails: • 𝕏 Money Card (physical + virtual sub-accounts) for instant micro-disbursements & isolated expense budgets. • Stripe US/EU for automated customer settlements. 2. Resilient Network Egress: • Cloudflare WARP + dedicated WireGuard tunnels. • Eliminates random geolocation flags and authentication freezes across international portals. 3. Automated Customs & Compliance: • Lightweight Python + OCR parsing ERP bill-of-materials into EU EN 1493 Declaration of Conformity specs. • Cut compliance verification from 72 hours to 15 minutes. 4. Local 48h Physical Spares Buffer: • Dedicated Italian consignment warehouse so European workshops never wait on 4-week ocean freight for a seal replacement. Heavy global commerce used to require an army of back-office staff. In 2026, code and modern rails let a small team run an entire international supply chain.
-
Selenka (@SelenkaOnChain) reportedNetnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."
-
Yash Desai (@yash_d_desai) reportedStopping the bad guys with Cloudflare: 20,273 malicious requests blocked or challenged in the last month #cloudflare
-
ticktechh (@sprki999) reported@OmegaNekoSimp Thats the only human check that doesnt trigger me. What the actual **** does the challenge of clicking a box from cloudflare do? How isnt that challenge useless?
-
Krishna Singh (@krishnasinghdev) reported@tapasadhikary I believe useEffect has been the source of so many production issues, most recent one was with Cloudflare
-
Sameer Bhagtani (@sameerbhagtani) reported@NiceCodeWriter You should make use of cloudflare tunnels. That should solve your problem.
-
Atif (@ioAtif) reported@acolombiadev @Cloudflare @coderhq Although it's not a service but a whole platform
-
Sathz_நிலன் (@nilan_sathz) reportedStopping the bad guys with Cloudflare: 212 malicious requests blocked or challenged in the last month #cloudflare
-
Ozmium (@ozonchain) reported@kennyistyping A lot is pick-and-choose too, but it's been incredibly useful for me personally at least to see and fix areas of the Ozmium front-end and back-end to make it so AI Agents and Humans basically have 100% equal footing on what they can do through the app/domain. I've even used it on some other side non-blockchain things that I realized would greatly benefit from being fully agent-ready (e.g., I run an economic development map to help IRL builders find serious community funding and site selection, data export for all the paperwork data requirements to get the funding, etc.) I've always been a bit biased to Cloudflare because their free plan lets you do so much.
-
Goldman Stacks (@GoldmanStacks) reported@tresokure Your website is down with a DNS resolution error from Cloudflare.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
J. (@munchivelo) reported@dillon_mulroy @EffectTS_ hm. what do you mean great cloudflare support? if i'm building apps for cloudflare ecosystem, what benefit does using EffectTS have over regular typescript/tailwind? can you be specific.
-
Eli (イーライさん) (@niceEli1) reported@tekbog I literally migrated an entire service from one codebase made in C# to Rust with a few seconds of downtime (only was caused by cloudflare tunnels changing the domain from one internal service to another one). It isn’t hard to just make software work without a maintenance period.
-
Eli Yumn (@EliYumnik) reported@acolombiadev @Cloudflare GitHub for CI/CD and hosting the damn internet’s repos Supabase Resend Replit Gemini Eleven labs
-
Serriff (@serriff) reported@xbtactics damn i thought we were all buying cloudflare, no?
-
Noel Ceta (@noelcetaSEO) reported8/ Layer 5: CDN implementation (distribute content): CDN = Content Delivery Network How it works: - Content stored on multiple servers worldwide - User gets content from nearest server - Fast delivery regardless of geography Setup: - Cloudflare (easiest, free tier available) - Akamai (enterprise) - CloudFront (AWS) Impact: 20-40% speed improvement for global sites.
-
Theo Ephraim 🧙♂️ (@theozero) reported@dbmikus @ericclemmons last I tried last on cloudflare sandboxes it was quite slow. Couldnt quite just restore the vm in its running state and many hoops to jump through.
-
avrin (@itsavrinwave) reportedIs cloudflare down again??
-
COLLINSEO (@alexcollinseo) reportedBreaking news! Your site might start blocking AIs from September 15th.. And if you block them, you won't show up in AI answers. The good thing? It takes a sec to unblock! This setting is inside Cloudflare. You might not even know your website uses Cloudflare because it works in the background as a CDN, helping your website load faster. If you check your website using the tools I mention, you can find out whether Cloudflare is being used on your site. Cloudflare seems to have taken this step because of how AI companies are crawling websites, and honestly, I don't completely disagree with the reason behind it. But having AI crawlers automatically blocked from September 15 could be a problem if you want your business to appear in AI answers. The setting is inside Security Settings. Look for the AI crawler control and make sure it is set to allow rather than block. This is especially important if AI visibility is part of your strategy. With one of my clients, we went from zero to around 500 visitors from AI traffic in two months. And what I did was exactly what I explained in the video. If your AI crawlers are blocked, you're potentially closing the door on that traffic before it even has a chance to reach you. #SEO #DigitalMarketing 👇🏼 Comment VIDEO for the FULL VIDEO BREAKDOWN
-
Nuvorlane (@nuvorlane) reportedCloudflare AI Gateway monthly usage invoices no longer break out input and output tokens. Previously you got two lines, e.g. 40k input at $0.000001 ($0.04) and 24k output at $0.000005 ($0.12). Now one line: anthropic/claude-haiku-4.5 — $0.16. Model names on invoices and logs also normalize to provider/model, so dated suffixes disappear from the identifier. Credit-purchase invoices are unchanged. If a FinOps parser keys on token line items or version suffixes, fix it before the next month-start invoice lands.
-
That Brazilian Omo Eko (@sholawa) reportedCloudflare has my airtel IP restricted lol.... Slow internet caused it; I must have hit the rate limit that day...