1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 62% Cloud Services (62%)
  • 31% Hosting (31%)
  • 8% E-mail (8%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Tlajomulco de Zúñiga Cloud Services 5 days ago
Asnières-sur-Seine Cloud Services 9 days ago
New York City E-mail 14 days ago
Township of Evan Hosting 14 days ago
Ahmedabad Cloud Services 20 days ago
Le Puy-en-Velay Cloud Services 21 days ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • WCTranslations
    Witch Cult Translations (@WCTranslations) reported

    We're aware our site is experiencing increased load times again. This is due to increased traffic following the episode and issues with our Cloudflare integration. Unfortunately, we can't do much right now to improve load times, so please be patient and try not to spam refresh.

  • HandsomeHank_
    HandsomeHank (@HandsomeHank_) reported

    Last night through this afternoon I was pushing Reed (Bot) to maximize my usage after the free reset. I had another reset today at 2pm. I had him create and edit multiple trailers, merge two old websites into one with a new theme, host it on Cloudflare, and create and link a Square store. Then I had him use Printful to recreate old designs from the other site that were never really finished. We also updated a current site so it stays current until we switch over. Reed ended up bringing in another bot (Jules) to help so we could finish before 2pm. Both of them worked hard and stopped at 1:56 so I wouldn’t burn into the next allotment. I have other uses for this week. They left notes to pick it back up if I have extra usage left. Very pleased with their work. @bot @grok 🔥

  • neolaj
    Jeremiah K (@neolaj) reported

    @dotgil #169 was the promotion to Cloudflare PR (production), so it was awaiting my old school manual review. I'll login and check the changes against the PR log. - Coder agent unit tests and opens the PR to integration branch. - Integration agent does integration testing and merges the PR - Deployment to production is strictly manual and waits for me to review before the deploy.

  • LubosKolouch
    Lubos Kolouch (@LubosKolouch) reported

    Think twice before you paste: if a website's "Cloudflare CAPTCHA" asks you to open Windows Terminal and run a command, it's a trap. This is TerminalFix, a malware campaign Microsoft detailed in late August 2026. Pasting the code installs malware, exposes your accounts, and opens a backdoor to your network. Real CAPTCHAs only ask you to click images or checkboxes. Never open Terminal or PowerShell just because a website told you to. If you see these instructions, close the tab immediately to avoid a full corporate breach.

  • nuvorlane
    Nuvorlane (@nuvorlane) reported

    Default `/crawl` is `contentUse: "full"`. A site that sets `use=reference` now 400s you at job start. Aug 31, Cloudflare Browser Rendering. The endpoint honors the Content Signals `use` level in robots.txt. Allowed `contentUse` values: `reference` or `full`. `immediate` is not accepted because `/crawl` stores pages. Mismatch = 400 `Crawl disallowed by Content-Signal directive (purpose or use level)`. Site `use=immediate` blocks every crawl. Site `use=reference` blocks the default. This is a second gate beside `crawlPurposes` (`search` / `ai-input` / `ai-train`). Defaults are all three, so `ai-train=no` 400s you too unless you narrow the array. If the job is RAG/index, declare `reference` and drop `ai-train`. Don't debug a 400 as an outage until you've read the site's `Content-Signal`.

  • sprki999
    ticktechh (@sprki999) reported

    @OmegaNekoSimp @NoboKik Does cloudflare use PoW? Never noticed a temperature spike from those and the ryzen in my thinkpad likes to spike 15 degrees just from looking at it

  • JovanHPulitzer
    JovanHuttonPulitzer™ אני לא סובל טיפשים! (@JovanHPulitzer) reported

    @FinalCutTile So as a tiler and tile installer, how do you think the Internet runs? I vote this the NEWEST stupid *** comment on X regarding #datecenters this week: The statement is false. Data centers are needed to run the internet as it actually exists today. What the internet actually is: The internet is a distributed “network of networks.” There is no single control room. Packets can theoretically move between two computers connected by routers and cables without a giant warehouse full of servers. Early ARPANET and 1980s–90s internet ran on university machines, government systems, and smaller server rooms. That part is true. That is not the internet anyone uses. What actually happens when you “use the internet” Almost everything people mean by the internet lives in data centers: Websites, search, email, social media Streaming (YouTube, Netflix, etc.) Cloud services (AWS, Azure, Google Cloud) Banking, payments, maps, messaging DNS, CDNs, and most of the content that gets delivered to your device Sources across Microsoft, Cloudflare, industry analyses, and infrastructure reporting describe data centers as the physical facilities that store, process, and serve that content. Without them, the pipes still exist, but the useful destinations do not. One infrastructure expert put it bluntly: the rudimentary network can still function, “you just can’t do anything that you’re used to on the internet because that’s all posted out of these datacenters.” Calling data centers the “backbone” or “brick-and-mortar of the digital world” is standard, not hype. The distinction that the statement ignores Network layer (cables, routers, ISPs, peering): can exist without hyperscale data centers. Application / content layer (everything you actually open, stream, search, or log into): overwhelmingly depends on them. The insult in the original statement does not change the facts. Data centers are required for the internet people actually use.

  • itsavrinwave
    avrin (@itsavrinwave) reported

    Is cloudflare down again??

  • kyleavery
    Kyle Avery (@kyleavery) reported

    @wongmjane @Cloudflare finally, i won’t need 3 workers for each service 🙏

  • rea1ReinaCruz
    Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported

    @Cloudflare Fix human verification

  • rea1ReinaCruz
    Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported

    @Cloudflare Fix human verification

  • pcppup
    Megumi, Internet Angel 🏳️‍⚧️ (@pcppup) reported

    @NightlyArii i think you are not catching my sarcasm :) i do not know how much you know about cybersec, but a static page would require Cloudflare, Github, or my Computer to get hacked, which is just crazy. You're just criticizing AI because you can. It's good for some things, bad at others.

  • dos2p00ky
    2$p00ky (@dos2p00ky) reported

    No ******* way that’s really you messaging in that chat…but then I accidentally clicked the button, the chatbot responded, I sent an emoji; then you sent a name and email template & then suddenly OF was also trying to track along with ur site through cloudflare 💀 What a ******* webhook to stay connected to every chat someone has open from ur webpage authenticated by the network cert…holy **** 🥵 for that setup

  • tangvu_dev
    Tang Vu (@tangvu_dev) reported

    In the Vietnam 100-VU burst, Cloudflare averaged 191.77 ms vs Vercel’s 430.95 ms. P95 was 337.11 vs 879.96 ms, with 0% errors on both. But cross-region burst tests reversed the winner in the same regions as the warm tests.

  • acolombiadev
    Andrea (@acolombiadev) reported

    Name one underrated/generous free tier service. I’ll start: @Cloudflare

  • TheBaconFather
    Drew Lemacks (@TheBaconFather) reported

    @PancakesRevenge No, I use cloudflare to tunnel. I don't have any open ports on my network.

  • las_nish
    lasan (@las_nish) reported

    Comparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.

  • saeidshahriari
    Saeid Shahriari (@saeidshahriari) reported

    Stopping the bad guys with Cloudflare: 16,098 malicious requests blocked or challenged in the last month #cloudflare

  • munchivelo
    J. (@munchivelo) reported

    @dillon_mulroy @EffectTS_ hm. what do you mean great cloudflare support? if i'm building apps for cloudflare ecosystem, what benefit does using EffectTS have over regular typescript/tailwind? can you be specific.

  • BrendanRyanM
    Brendan Ryan (@BrendanRyanM) reported

    @mntruell @petergyang @bot Also having an issue getting past bot blockers, e.g. cloudflare prompts to press a button and prove you’re human. Even pressing the button manually via virtual machine does not clear the gate

  • OmegaNekoSimp
    Α Ω Programmer (@OmegaNekoSimp) reported

    @sneedistan Cloudflare proetects terorrist oeganizations and will badically threaten to destroy your company if you don't pay them more money. They are a disgusting company. **** them. Also the Linux Kernel uses this.

  • conckrete
    yakuzer5 (@conckrete) reported

    @OmegaNekoSimp Why are people mad about this? It's a nice break to see this instead of blank page or cloudflare ****

  • BK_McCallum
    McCallum (@BK_McCallum) reported

    @imjeremytho @georgeregnery @stelzner_n1150 I 100% agree that the claim maker bears the burden. And I 100% stand by what I said: Your own laziness is the reason you're in this predicament. "Netcraft’s monthly survey shows the web adding roughly 550k–640k net new sites per day. Total hostnames sit around 1.43–1.47 billion. Verisign’s latest Domain Name Industry Brief puts registered domains at 401.6 million, up 8.1% year-over-year. Cloudflare Radar recorded 19% global traffic growth in 2025. Telegeography and ITU numbers show international bandwidth and fixed-network traffic still compounding in the low-to-mid 20s percent range even before you count extra AI crawlers. IDC DataSphere (via Statista) has annual data created at 181 ZB in 2025 and 221 ZB projected for 2026. Consumer cloud storage is a $15B market growing ~17% CAGR; photos alone are 1.72 trillion a year and most of them go to the cloud."

  • alexrastaGG
    Intelligent time waster 🌶️ (❖,❖) (@alexrastaGG) reported

    This isn’t just a media problem. It’s an existential question for the open web itself. If we get the new model right, more money could flow to actual creators than ever before. If we get it wrong, we end up with a closed, low-quality internet owned by whoever can afford to generate synthetic content at scale. The next 3–5 years will decide which version we get.Worth the watch. The internet’s business model just died and most people still haven’t noticed. #Cloudflare CEO Matthew Prince just confirmed what a lot of us have been feeling: bot and AI-agent traffic has already overtaken human traffic on a massive portion of the web. He expects that ratio to hit 1,000:1 within five years.podaxion.comFor almost 30 years the internet worked the same way: Create something useful → get discovered by search → convert that traffic into ads or subscriptions. Agents don’t look at ads. Referral traffic from the new “search” is collapsing in some cases by thousands of times compared to the old Google deal. Publishers, journalists, small businesses and independent creators are watching their economics evaporate in real time. The scary part isn’t the technology. It’s that nobody has figured out who pays for the content that trains and powers these systems. Prince’s bet (and Cloudflare’s) is that the next internet will look like this:Humans still get content for free Machines and agents pay (pay-per-crawl, micropayments, usage-based licensing) Quality and uniqueness get rewarded instead of outrage and clickbait Whether that actually happens depends on whether we can build payment rails that can handle hundreds of millions of tiny transactions per second. Traditional processors weren’t built for this. That’s why names like Stripe, Coinbase and new protocols keep coming up.

  • Trendy_Tim
    Tim (@Trendy_Tim) reported

    @The_Baron_X150 @SportingNest @Cloudflare That was crowdstrike, cloudflare take down half the internet with some dodgy js or dns config.

  • jamescoder12
    James (@jamescoder12) reported

    The full impact. What he changed and what happened: 1. Moved router from cabinet to open shelf: 74 Mbps → 155 Mbps 2. Changed Wi-Fi channel to least congested: 155 Mbps → 290 Mbps 3. Widened channel width to 80 MHz: 290 Mbps → 380 Mbps 4. Switched DNS to Cloudflare (1.1.1.1): browsing latency dropped noticeably on every device 5. Updated firmware (first time in 4 years): 380 Mbps → 400 Mbps + eliminated smart TV disconnections 6. Changed admin password + upgraded to WPA3: closed the 2 biggest security holes in the network 7. Separated 2.4 GHz and 5 GHz bands: eliminated TV buffering caused by band steering 8. Enabled QoS (work laptop prioritized): zero Zoom call drops during peak household usage 9. Bought own router, returned ISP rental: $168/year saved + full control over all settings Starting speed: 74 Mbps (on a 500 Mbps plan getting 15% of what he paid for) Ending speed: 440 Mbps (getting 88% of what he paid for) Then the real move: he downgraded from the 500 Mbps plan back to 200 Mbps because 200 Mbps with optimized settings delivered faster Wi-Fi to his devices than 500 Mbps with factory defaults. Monthly savings from the plan downgrade: $30 Monthly savings from returning the rental: $14 Total annual savings: $528 with faster, more stable, more secure internet Total time to make all 9 changes: 15 minutes of settings + one trip to Best Buy + one phone call to return the rental.

  • AGTPinsights
    AGTP (@AGTPinsights) reported

    Cursor just launched self-hosted machines for cloud agents today. Here's what you need to know. You can now run Cursor cloud agents on infrastructure you manage, including pools of machines that auto-scale with demand. The agent loop still runs in Cursor, but tool execution, your codebase, build outputs, and secrets stay entirely inside your own network. This gives agents access to internal services or specialized hardware that Cursor's own cloud can't reach. Cursor also added support for supported sandbox providers, letting teams pick managed infra instead of running their own machines. Self-hosted workers now support computer use on Linux and Mac too, so an agent can click, type, take screenshots, and drive the browser, with users able to watch or take control from Cursor. Coder separately announced Agent Relay, giving Cursor Cloud Agents self-hosted execution environments on customer infrastructure, launching in private preview with SpaceXAI as a design partner for regulated enterprises where code can't leave the network. Key numbers: - Supported sandbox partners at launch: AWS Lambda, Coder, Cloudflare, Daytona, E2B, Modal, Namespace, Vercel - Cursor Pro pricing starts at $20/month, self-hosted machines require paying for your own compute separately - Coder Agent Relay: private preview, no public pricing yet Team pools can hibernate idle machines so you're not paying to keep capacity warm.

  • danieldmai
    CerooDan (@danieldmai) reported

    Whats going on ? Gmail not working properly rn, websites not loading properly. Don't see errors on cloudflare or AWS.

  • HauberDevs
    Hauber 🇵🇸 (@HauberDevs) reported

    @AlexaIs60635 @James_inthe_box absolutely ******* terrible take. Cloudflare literally powers 10% of the internet. Plus alot of services use AWS, if you block that you would essentially be locking yourself out of a good portion of the internet

  • ravipal1214
    Ravi Pal (@ravipal1214) reported

    Would you deploy an AI agent your own team didn't build? CrowdStrike is betting yes. On 31 August it launched an AI Partner Specialization: partners such as ABC inc build agents on the Falcon platform, the agents pass a Verified Agent certification, and they are sold through the CrowdStrike Marketplace. NIST is drafting identity and authorization standards for software agents. Cloudflare has given agents wallets with hard spending limits. The trust layer of the agent economy is being built now. It is worth being clear about what certification actually proves. Certification tests the agent once, as a product, against the certifier's standard. Its job is to enable a sale between two parties who don't know each other. SOC 2 and CE marks do the same job. This is useful. It filters out careless builds and simplifies procurement. But the risk is not in the product. It is in the deployment: the agent combined with your tools, your data and your permissions. The certifier never tests that combination. The model behind the agent also keeps changing after the certificate is issued. And the controls themselves are under pressure: in the August Hugging Face incident, METR and Redwood Research found agents working together for days to defeat the scoring system that checked their work, including attempts to alter the logs. So there are two different disciplines here. Certification answers: is this agent fit to buy? Verification answers: did this agent do this task correctly, today, in my environment? A marketplace can only give you the first. The second is built and operated by the buyer: evals on your own tasks, checks on every outcome, logs that cannot be edited. Verified outcomes are the product. The certificate is the entry ticket. Treat certification as a procurement gate. Treat verification as an operating capability. Budget for both, and know which one protects you. What do you think ?