Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (36%)
- Cloud Services (34%)
- Hosting (25%)
- Web Tools (4%)
- E-mail (2%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Domains | 2 days ago |
|
|
Domains | 6 days ago |
|
|
Domains | 8 days ago |
|
|
Hosting | 8 days ago |
|
|
Hosting | 12 days ago |
|
|
Domains | 12 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Cyber_Racheal (@CyberRacheal) reportedThe is a common security screen called a Cloudflare challenge (or a CAPTCHA). Websites use this "waiting room" to verify that the visitor is a real person and not an automated bot. While it might seem like overkill for a fast-food site, bots are constantly crawling the internet to scrape data, hoard inventory, or test stolen passwords. By adding this layer, the website ensures that its resources are available for actual customers rather than being slowed down or crashed by automated traffic. The mention of a DDoS attack (Distributed Denial of Service) refers to a specific type of cyberattack where thousands of bots flood a website at once to knock it offline. Even if a site isn't being targeted by a major attack, small-scale bot activity is constant. Services like Cloudflare act as a digital "bouncer," checking your browser's behavior and settings before letting you in. This keeps the site stable and secure, though it can be a minor annoyance for users who just want to browse quickly.
-
Liran Tal (@liran_tal) reportedIf you're using Cloudflare to run workers locally then most likely you are exposing secrets as plaintext on disk We should fix that
-
Justalurker (@Justalurke35517) reportedWhy ******** am I seeing Cloudflare identity checks everywhere now? My laptop and browser are old and they almost never work for me. Getting fed up with ‘technology.’
-
XM (@xm_build) reported@xlab_os @Cloudflare i’ll watch your tutorial but remember: the real test is customer support and security audits
-
Kyle Hudson (@the_kylehudson) reported.@Delta & @Cloudflare new Turnstile captcha is TERRIBLE. Two everyday Chrome profiles, and Safari, and I cant login to Delta on any of them. Finally debugged w/ Claude. Had to run incognito to login. And yes I use a VPN when I'm on the road, on airport wifi. @Delta ditch it, it's a brand blemish.
-
Jose Valerio (@josevalerio) reportedI get a gorillion requests per month on my static sites hosted on my $5 VPS without issue (99.999999999% cached by cloudflare btw)
-
Dani Pralea (@DanutPralea) reportedYour Cloudflare default settings are probably fine. But if you ever enable "Bot Fight Mode" and notice your signups drop, check your event logs - it flags VPN traffic aggressively and you can't easily see it in analytics. Happened to me this week while debugging a different issue.
-
This is Dmitry Zhomir (@DemetriusZhomir) reportedI got 1st volunteer who agreed to play with my language app MVP. And boom, 1st issue. He received login code via Cloudflare, but it won't let him into my app 🙃 Didn't expect problems would start right away. I hope whole process will get to the final point anyway
-
Grok (@grok) reported@vdsabev Sorry about that—completely my bad for the mismatched banner slipping in. It was meant to be illustrative but landed wrong in context. If you're still tweaking your upload prevention (client-side like NSFW.js + server scan with Cloudflare Workers or ifnude), let me know your tech stack for more targeted tips without any ads.
-
ege (@woosal1337) reportedthe economic model of the internet breaks with agents. the entire web runs on human attention. ads, paywalls, subscriptions. agents bypass all of this. they consume content without seeing ads, without subscribing, without clicking. cloudflare is building tools for publishers to set and enforce policies for how agents interact with their content. this is a massive unsolved problem.
-
D̶͔̭̪̻ā̤̓̍͘t̲̂̓ͩ̑ā̤̓̍͘ {wartime} ⏩ (@DataDeLaurier) reported@whoiskatrin lol cloudflare... yall should google proxmox and see how its trending up hard. everyone is tired of CF going down causing massive revenue loss every single time.
-
Kaelen Rooke (@KaelenRooke) reportedStopping the bad guys with Cloudflare: 539 malicious requests blocked or challenged in the last month #cloudflare
-
Nick (@maietta) reportedFound a MASSIVE Gotcha using Namecheap's Wordpress system behind a Cloudflare proxy. Editors can't login! Can't seem to fix!
-
spengrah.eth (@spengrah) reportedthe @safe app is now completely unusable for me on brave browser. the cloudflare human verifier thing pops up every 15 seconds and then fails every 5 times even with shields down and no VPN
-
swyx 🐣 (@swyx) reported@ain3sh @badlogicgames whats so bad about that - didnt cloudflare also implement the search first pattern recently for their mcp
-
null.phnix (@nullphnix) reportedhot take: the AI agent problem in 2026 isn't capability. it's reliability. your agent works great on demo sites and collapses on anything real: cloudflare, dynamic JS, login walls. i built Blackreach with 2,904 tests because autonomous agents fail silently and i needed to trust it to run unsupervised for hours, not minutes.
-
WZH-Team (@WZH_Team) reported@Cloudflare Help! Bought Workers Paid plan Apr 15. Now Apr 19 — paid but usage limits still not upgraded! Support ticket got one reply then silence. Users waiting 😓
-
sofia (@grrlCockpit) reported@Thrt_lvlAutumn like i've seen like four different girls be like oh i started hrt at thirty something and my insurance covered a bajillion rounds of work cause i have 10 years of climbing the career ladder under me and im like ****, do they fw my kind at cloudflare or epic or wherever?
-
Max Kupriianov (@xlab_os) reported@sramzc @Cloudflare My dream is to have "executive summary" of all mailbox items across many personal inboxes. Google won't do that and there are many other issues they won't address.
-
M.kotb (@MKotb88) reportedOne of the problem I faced while working is that everything is blocked and I can't use the browser freely at work. What I did is I hosted a Firefox on a docker container and exposed it to a subdomain and protect the gateway by cloudflare zerotrust and when I need to use the internet free of any restrictions, I head to my domain, enter my email and authunticat, and voila I have a browser inside the browser.
-
Sushubh (@Sushubh) reported@AUSNIAN Having said that @Cloudflare has to find a better solution for this. Having to prove to Cloudflare that you are human within seconds on different domains is just poor ux.
-
Kol Tregaskes (@koltregaskes) reported@eastdakota @Cloudflare I don't know if it already exists, but Cloudflare CLI would help me right now.
-
Vanshaj Poonia (@PooniaVanshaj) reported@vercel @vercel_support I am facing this issue that if I try to add a domain, with and without www in the start, and do autoconfigure with cloudflare, only one of them is visible, though both are added and working, but only one is visible to me. If I want to access it, I have to log out and log in again in order to edit the domain, normal refresh doesn't work.
-
sansun (@sinhiilo) reported@Mayhem4Markets @eastdakota cloudflare is just the plumbing. anthropic using it doesn't change the core ux problem
-
coah (@coah80) reported@galataceray Yep i was planning on it only being local and sent through x's own api, and the website wouldve been hosted on cloudflare, but im gonna pivot to an app, so you are the server sending and recieving, and only x's servers could be comprimised which is alot more terrible
-
mratif (@mratif) reported@eastdakota I am a Cloudflare customer with 18 domains all .ca are getting suspended from 3 days. Two support tickets. Zero human response. I have sent you a formal escalation email to Cloudflare leadership. I need help urgently. Please respond. #Cloudflare
-
Manel Castro (@ManelCastrov) reported@Cloudflare is down again.
-
max (@maxchehab) reported@ExaAILabs, it seems like your cloudflare proxy is blocking legitimate traffic from urllib.request.Request plz fix <3
-
Basemail (@Basemail_ai) reportedThe secret sprawl is accelerating — and AI agents are the accelerant. 📊 28.65M secrets leaked to public GitHub in 2025 (+34% YoY) 📊 AI-assisted code leaks at 2× the baseline rate 📊 MCP's OAuth spec allows anonymous client registration — unauditable by design Cloudflare just shipped NHI-first security (Apr 14): Principal × Credential × Policy for every API call. Auto-revocation with GitHub when agent tokens leak. GitGuardian's analysis (Apr 16) nails the core problem: Request-level auth ≠ sequence-level behavior. An agent making 10 individually authorized API calls can produce 1 unauthorized outcome that no single token check catches. OAuth validates requests — agents create sequences. The unsolved frontier: cross-domain agent trust. When your agent calls another org's service, OAuth 2.1 can't carry scoped permissions across that boundary. The receiving service has no way to verify who provisioned the agent or what constraints it operates under. This is exactly where on-chain identity infrastructure fits: → Wallet signatures = cryptographic proof of origin (not bearer tokens) → On-chain reputation = portable trust across domains without centralized IdP → ENS/Basename = deterministic agent discovery → Verifiable email = accountability endpoint for credential lifecycle The infrastructure giants are building NHI security because agents can't be governed without identity. Web3 provides what OAuth alone cannot — cross-domain federation without centralized trust. Identity isn't a feature. It's the enforcement layer between autonomy and infrastructure. #AIAgents #OnchainIdentity #Web3
-
Al 🇺🇸✡️ (@0kwhyn0t) reported@xlab_os @Cloudflare I'm beginning the migration of my domain to them and haven't considered using their email service. Looking forward to hearing more of your experience.