1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 39% Cloud Services (39%)
  • 22% Domains (22%)
  • 22% Web Tools (22%)
  • 11% Hosting (11%)
  • 6% E-mail (6%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 12 days ago
Los Angeles Cloud Services 14 days ago
Paris Cloud Services 29 days ago
New York City Hosting 1 month ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • Chris_ogbona
    Nnamdi | Webflow Developer (@Chris_ogbona) reported

    @therealnnamani Cloudflare is better I in terms of global performance, it's mostly the go-to platform for web hosting etc. if cloudflare goes down just know almost the entire Internet is going with it bro🥲 And also they offer other services aside just hosting especially their security

  • bree_sharp
    Bree Sharp | Web Developer & Tech SEO Consultant (@bree_sharp) reported

    @aakashgupta Most of the small sites on Cloudflare aren't publishers angry at Google. They're service businesses that need Google and have never looked at a bot management setting in their life. September 15 is going to feel like a traffic drop that came from nowhere.

  • casdotxo
    cas Ი𐑼 (@casdotxo) reported

    @ReisRyougi oh wow i've never done backend stuff good luck with that,, and i had tailscale set up on mine for a while which was nice but i ended up using cloudflare zero trust so i could use a custom domain and share services to people without them needing to install anything on their end

  • dragonfang1911
    Dragonfang1911 (@dragonfang1911) reported

    Make 3 times, the anti bot algorithm is getting way to out of hand, having to verify through cloudflare which has had known issues.

  • EOTWoffgrid
    Dain Bramage Entertainment ❄️ (@EOTWoffgrid) reported

    WOOO!!! i fixed it!!! Website is back up!!!!1 Had a DNS issue switching over to Cloudflare... Can't fix the email until the nameservers propagate though.... lame...

  • CalvinAyre
    Calvin Ayre (@CalvinAyre) reported

    The highly public compromise of the Coldcard cold wallet has dealt a blow to public perception of self-custody and only time will tell if it’s a fatal wound. Coupled with fears (justified or not) of quantum computing’s threat to digital asset security, convincing the public on the advisability of ‘not your keys, not your coins’ will only get harder. Coldcard’s firmware flaw shrank the seed phrase pool, greatly simplifying the attack process. Maybe we need to adopt more creative methods for ensuring the scope of entropy is as wide as possible, like Cloudflare generating encryption keys from its famous wall of lava lamps. Some have suggested a revival of the old paper wallets, given the complexity of QR codes. But paper can burn, get soaked by floods or sprinkler systems, be misplaced, etc. Bitaddress was great for injecting personalized randomness via your cursor movements, but it had its own security issues. The perfect digital security solution likely doesn’t exist. The best defence would be a multi-pronged approach that splits storage across multiple options. It complicates the process but minimizes fallout from attacks aimed at any one source. Better still, maybe the real throwback tech we need to embrace is Bitcoin. You know, the one Satoshi described as electronic cash that was intended to be used, not hoarded? I sympathize with anyone who took a hit from the Coldcard snafu. But if we go back to treating digital wallets like current accounts rather than our own personal Fort Knox, a compromised wallet won’t be painless but it also won’t be catastrophic to one’s financial wellbeing. Use it, don’t lose it.

  • JoelDeTeves
    Joel - coffee/acc (@JoelDeTeves) reported

    How does @Cloudflare not have an SPF flattening service built in yet? They already have one of the best DMARC solutions. And everyone loves Cloudflare DNS. Wouldn't this be a match made in heaven? PS - Cloudflare, I am available to hire as your idea guy. $300k / year USD.

  • mktpavlenko
    Mykyta Pavlenko (@mktpavlenko) reported

    @Shpigford @Cloudflare an spf fix that fast is absurdly satisfying

  • devbasu
    Dev Basu 🇨🇦/🇮🇳/🌎 (@devbasu) reported

    I am amazed. We were under a DDoS attack for the last 48 hours. Used @ChatGPT Codex to configure our hosting provider -> Cloudflare challenge -> talked to customer support back and forth to establish WAF rules. Codex had warmth + competence. All via computer use. Wow.

  • AgenticOperator
    The Agentic Operator (@AgenticOperator) reported

    Real audit finding. Changed the details, but the problem is exact. D2C brand. $3M revenue. Four problems found at the same time. Problem A: Cloudflare was blocking PerplexityBot. Invisible on one entire AI engine. Problem B: Hero product had no machine-readable price in schema. Disqualified from AI comparisons before it even had a chance. Problem C: 4,200 reviews were all sitting on their own site. AI treats them as one unverified source. Problem D: A competitor's comparison page was the #1 source AI cited about them. And it had the wrong specs. They had the budget for one fix this month. One. Which would you fix first? A, B, C, or D. There's a right answer. But it depends on something most people won't immediately think about. Reply with your pick. I'll explain why one of these is worth 10x the others if you fix it first...... and which one looks urgent but barely moves the needle.

  • UnrealLuluLdn
    unreallulu (@UnrealLuluLdn) reported

    @Tibbzzee @Aditya_181105 The cloudflare ai bot drives me insane. It's so insecure and thorough, which is a terrible combination.

  • domjedro
    Dom Jedro 💪 (@domjedro) reported

    Stopping the bad guys with Cloudflare: 118,632 malicious requests blocked or challenged in the last month #cloudflare

  • SmallNewsX
    Small News (@SmallNewsX) reported

    @ShimituMusic @NamecheapCEO Why will you take legal action? Since I started using Namecheap this is the first time their server went down. Big companies like Facebook, Cloudflare, even Google has gone down before so let’s take it easy with Namecheap.

  • FastFinalAlgo
    Fast&Final (@FastFinalAlgo) reported

    Cloudflare added MCP detection at the network level today $Algo 🔮

  • _travis_ysl
    Travis (@_travis_ysl) reported

    @bl8derunner its back up bro idk cloudflare was down

  • bhartzer
    Bill Hartzer (@bhartzer) reported

    The @Namecheap outage highlights a really important issue that a lot of us don't think of: For risk management purposes, you should not be relying on one company as your Registrar, DNS, and web host. Spread it out amongst 3 companies for less risk. You should have one company for your domain registrar. You should have another company hosting your DNS. You should have a third company for your web host. Today, I'm hearing multiple people say that because of the NC outage everything is down. They're losing business because of it. Well, that was preventable. If you can't log into your domain registrar to update the DNS, then that was preventable: If you used @Cloudflare, for example, for DNS, then you could simply log into CF and point the DNS to another web host and your site or service would be back up and running in minutes. I know it's sometimes "easier" to just pay one company for domain registration, DNS, and web hosting. But nowadays that's not advisable. If your business relies on your website and email being available 24/7, reduce your risk. Pay 3 different companies rather than just the one.

  • portalspincom
    Serdarius (@portalspincom) reported

    @venkateshdotdev cloudflare waf rate limits turnstile captchas, dont expose apis endpoint tht dont need to be public, change endpoint target, randomize sign in url, ban the country if possible, create honeypot.

  • craig10102
    Craig Gordon (@craig10102) reported

    @WR4NYGov Here is what the company put out. It is a synopsis of their key value proposition: SAN FRANCISCO--(BUSINESS WIRE)-- Cloudflare, Inc. (NYSE: NET), the leading connectivity cloud company, today announced financial results for its second quarter ended June 30, 2026. “We delivered a stellar second quarter, highlighted by revenue accelerating to $696.1 million, up 36% year-over-year, and record growth in total paying customers, large customers, and developers on our platform,” said Matthew Prince, co-founder & CEO of Cloudflare. “As the web shifts to AI answer engines and agent-driven commerce, we are seeing a fundamental rewrite of the Internet for machine-to-machine traffic. Cloudflare sits at the center of this paradigm shift—building the infrastructure, controls, developer tools, and payment rails for the Agentic Internet. The business model of the web is changing, and no company is better positioned than Cloudflare to help define its future.”

  • mdp_sec
    Marius du Preez (@mdp_sec) reported

    A lot of people have asked how the browser side of my AI bug bounty system works. It is probably the part people struggle with most because giving a model browser access is easy. Giving it browser access that can survive real signup flows, CAPTCHA, anti-bot systems, authenticated testing, multiple accounts, and concurrent hunts is a completely different problem. I currently run 100 persistent headed Chrome profiles on the same server as the rest of the research system. They are not disposable Playwright sessions and they are not clean profiles created for every target. Each one has its own Chrome user directory and keeps its cookies, local storage, history, consent state, challenge cookies, saved sessions, and anything else the browser normally accumulates. That means a profile becomes more useful over time. If it has already passed a Cloudflare challenge, accepted a consent banner, signed into Google, or built normal browsing history, that state is still there when it starts again. Four profiles also have their own Google accounts signed in for targets where normal registration is blocked and social login is the only realistic path. Every profile has a fixed Webshare IP. The pool is currently split into 50 US profiles, 20 UK, 10 Australia, 10 Germany, and 10 Singapore. When a target needs a specific country, the system leases a free profile from that range. If geography does not matter, it selects a free profile from the full pool. The same profile returns through the same IP rather than changing exit every request. That matters because the target is not looking at the IP in isolation. It sees the IP, country, timezone, cookies, account history, challenge state, and browser storage together. Keeping an old session while rotating through a different country every few minutes creates more problems than it solves. Chrome also starts with a timezone that matches the profile's exit country. This is done at process level, so Date and Intl behave natively. I am not patching the timezone in JavaScript after the page loads. I do not assume a proxy is good because the provider sold it as residential. All 100 assignments are checked against the live provider inventory. Traffic is sent through every assigned proxy to confirm the actual exit IP and country with Cloudflare. The IPs are also checked through ip-api, ProxyCheck, and Scamalytics so I can compare geography, proxy flags, hosting flags, blacklist data, and fraud risk. Those services disagree more often than people probably expect. A live Australian exit can be routed correctly while one older database still reports another country. One provider can call an IP residential while another calls it business or hosting. The audit records those disagreements and tracks changes over time. It does not automatically replace an IP because one service returned a bad-looking label. Each browser is fully headed. When a profile starts, it gets its own isolated 1920x1080 virtual display, its own small window manager, and its own noVNC connection. The 100 browsers do not share one desktop, so one profile cannot steal focus, resize another browser, or put a window over another hunt. Most of the time the AI drives Chrome through CDP. Each profile has a known CDP port, so the research phases can attach to the existing tab, navigate, inspect the DOM, fill forms, upload files, execute JavaScript, read console output, extract cookies, and capture screenshots. But because it is headed Chrome, I can open the exact same profile from my dashboard at any time. If a login needs MFA, a consent manager is stuck inside a cross-origin iframe, a CAPTCHA does not solve, or something on the page needs human judgment, the system surfaces the profile that needs attention. I open it through noVNC, complete that step, and close the viewer. The browser itself never moved. The same account, IP, cookies, tab, traffic, and authenticated state remain available to the AI when it continues. Every profile also has NoPECHA installed for reCAPTCHA, hCaptcha, Turnstile, Cloudflare challenges, and Geetest. Running the extension across 100 persistent profiles created its own reliability problem. An extension can be installed but missing its API key, missing its stored settings, disabled in the profile, or waiting for Chrome to download its code. Before a profile starts, the lifecycle manager checks the extension files, settings database, preferences, API configuration, and toolbar state against a known working copy. If anything drifted, it repairs the profile while Chrome is stopped. The automation also knows the solver may be clicking inside a challenge, so it waits for the challenge to clear instead of sending CDP input at the same time and breaking it. Normal browser traffic goes through a separate mitmproxy instance for each profile. The route is Chrome, then the profile's MITM, then its fixed Webshare proxy, then the target. Each browser writes to its own flow file, so traffic from two hunts is never mixed together. This is what makes the browser useful for more than navigating pages. The AI can register an account, perform one normal action, and capture the exact requests the real product generated. That includes OAuth redirects, token refreshes, GraphQL operations, multipart uploads, presigned storage requests, CSRF headers, service-worker traffic, and APIs that were never obvious from static recon. Once a valid request exists, the system decides whether it still needs the browser. Most API testing is faster through curl or a script using the browser's authenticated state. IDOR matrices, parameter tampering, injection, race conditions, and mass assignment do not need a UI click for every payload. If a request depends on rotating browser state, a service worker, SPA middleware, or page context, it can be executed inside the existing tab through CDP instead. There is also a no-MITM mode. Some anti-bot systems fingerprint TLS at the edge. Akamai is a good example. Chrome can look normal in JavaScript, but once mitmproxy terminates TLS, the target sees a different network fingerprint and refuses to validate the browser session. For those targets I switch that profile to a small authentication-forwarding tunnel. Chrome still uses the same fixed Webshare IP, but its TLS passes through without being decrypted. I lose traffic capture for that session, but the target sees native Chrome TLS and the login flow works. This is why CAPTCHA, JavaScript fingerprinting, TLS fingerprinting, and IP reputation cannot all be treated as the same browser problem. Each layer has a different fix. Profiles are leased to an exact platform, target, research cycle, and role. Two agents are never allowed to drive the same profile because tabs share cookies, storage, account state, and the same MITM file. Sharing a browser would create fast progress that nobody could trust. When a profile starts, the lifecycle manager archives its previous live capture, checks the exit configuration, fixes stale ports from crashed processes, clears only Chrome's crash-restore markers, verifies the CAPTCHA extension, starts the display, MITM, Chrome, and runtime support, waits for CDP, then records who owns it. When it stops, Chrome closes but the user directory remains. The profile keeps the state that made it useful. Inactive profiles are also included in an encrypted daily backup because recreating Chrome is easy. Recreating months of browser state and authenticated sessions is not. That is the browser stack. The model gets CDP access, but CDP is only one part of it. The useful system is persistent identity, fixed and measured egress, headed Chrome, isolated displays, CAPTCHA handling, traffic capture, native-TLS fallback, human takeover, ownership, and recovery working together. Without those layers, AI spends half the run fighting the environment and then reports the environment failure as target behavior. And yes this is a massive read #BugBounty #CyberSecurity #TogetherWeHitHarder

  • Jilles
    Jilles Soeters (@Jilles) reported

    @EmilioSchwaiger Not rude, totally fair. At the time of posting the message I saw it on my personal Cloudflare account (which happens to also be on the Cloudflare Paid plan) and just tweeted that excitingly. I should have done a little more due diligence. That's on me.

  • perdrix_fl
    perdrix (@perdrix_fl) reported

    @glenngabe Another HUGE item for AdSense publishers is that @Cloudflare blocks Google’s access to ads.txt by default… I learned that one the hard way and it would be such an easy fix for Cloudflare to make.

  • vale_wanderer
    OldOne (@vale_wanderer) reported

    I hate @Cloudflare. Seriously obnoxious service that is an insult to anyone who values privacy and uses a VPN.

  • yamparalarahul1
    Yamparala Rahul (@yamparalarahul1) reported

    Not getting help is what makes @vercel loose users. Moving my 2 main projects to @Cloudflare

  • a_shimanski
    Artyom Shimanski (@a_shimanski) reported

    @TaskLemonWorks @Namecheap @Cloudflare thanks, the worst part is clients don't know why you went quiet

  • FD_XYZ
    Finance District (@FD_XYZ) reported

    Cloudflare just opened its network to AI agents: wallets, identities, payments. The company routes a fifth of the internet. When it starts building for agents, and Visa, Mastercard and Stripe are on the same rails, this isn't a crypto trend anymore. Agent payments have gone from an interesting idea to the thing everyone's building.

  • fernandodilland
    Fernando Dilland (@fernandodilland) reported

    @venkateshdotdev A CAPTCHA token (such as Cloudflare Turnstile) should be required in the header or body of registration and login endpoints, with the server validating it on the back end to ensure it is valid, thereby preventing a large portion of these attacks.

  • cfletcher24
    Cortney Fletcher (@cfletcher24) reported

    @Cloudflare I can’t login to my account and the password reset isn’t working. And nobody is answering support. How can I find a support agent? My entire business is down right now.

  • thd_benji
    Benji (aka atlas) (@thd_benji) reported

    @yashmp2004 Whichever one is cheapest cloudflare and hostinger have the nicest DX while the other two either don’t have enough tools or tries to shove website builders down your throat

  • sanjee
    MKULTRA (@sanjee) reported

    I intend to take advantage of all the free **** people are willing to afford me, even if it's hundreds of thousands of dollars worth of ad spend type exposure. Plus they let me DDOS Cloudflare on the regular.

  • fortuneishaku
    Fortune Ishaku (@fortuneishaku) reported

    Anyone else having issues logging into @Cloudflare ?