1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 50% Cloud Services (50%)
  • 25% Domains (25%)
  • 25% Hosting (25%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Hosting 9 days ago
New York City Cloud Services 28 days ago
Los Angeles Cloud Services 29 days ago
Paris Cloud Services 1 month ago
New York City Hosting 2 months ago
Manchester Domains 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • vince_jos
    Vincent Josse (@vince_jos) reported

    @fabienr34 All websites I know that had no results after major SEO work for 5-6 months all had a cloudflare technical or setup issue.

  • JasonL_Capital
    Jason Luongo (@JasonL_Capital) reported

    7. $NET - Cloudflare The network sitting in front of the internet. Q2 revenue $696.1 million, up 36%. Cloudflare's CTO has said they are already using GPT-5.5 in internal defensive workflows. Signed the letter. Daybreak partner. When the letter says "fix weaknesses that have accumulated for years," a lot of those weaknesses are on the edge.

  • bogdancarlescu
    Bogdan Carlescu (@bogdancarlescu) reported

    The market has picked a side. In 2026, $CHKP is down 24%. $NET is up 53%. Per employee, the market pays about $2.0M for Check Point and about $20.7M for Cloudflare. Ten times more for the company losing money on every head.

  • sohardh
    Sohardh Chobera (@sohardh) reported

    @Cloudflare Wish I could work on these kinds of problems

  • inababi
    Salina Mendoza (@inababi) reported

    1. Create /admin route in your app 2. Create Worker on @Cloudflare 2. Create text based secret in the dashboard of worker 3. Save and deploy (new not redeploy) 4. Login $0 No deliverability issues, no API keys, no considering which email provider to use. Don’t put it in your sitemap. Upgrade to Cloudflare access with your idp wired up later.

  • Rohthebuilder
    Roh (@Rohthebuilder) reported

    @hieuSSR @algoceo @Cloudflare True, agreed. But when I read it, I felt more related to my problem when I read “unlimited free custom emails”. And when I read “gmail alternative”, my head just told me “no way”. Idk why. Need more UX study on it maybe. Anyway, glad you made this!

  • NickeNumbers
    NickeNumbers (@NickeNumbers) reported

    @eastdakota @zatlyn @Cloudflare She is a bad *** 🤘

  • RealJBMangum
    RealJBMangum (@RealJBMangum) reported

    Cloudflare opens BotBase to bot operators A directory dies if the listed party cannot see or fix their own row. I have built that loop. Cloudflare shipped the operator side yesterday. Status, reject reasons, edit in place.

  • escartin
    Javier (@escartin) reported

    Here's a reminder for ppl with sites on Cloudflare: They block major LLM crawlers by default, so your site may be invisible to AI search. It's dumb, but I feel the percentage of sites with this problem is higher than you'd expect.

  • FN21995
    Impressed keanu (@FN21995) reported

    The problem of running multiple AI agent instances. Yes — it is already creating a version of that problem, and personal “armies” of agents would make it worse. The internet is a shared commons, just like low Earth orbit. Space junk is leftover hardware that stays up there, collides, and eventually risks a cascade (Kessler syndrome) that makes the orbit unusable. The digital version is a mix of congestion, extraction without reciprocity, and pollution that feeds on itself. What’s already happening Bots now generate the majority of web traffic. Cloudflare data showed the crossover in mid-2026: roughly 57% of HTML requests came from automated systems versus 43% from humans. Agentic traffic (bots that actually click, fill forms, and take actions rather than just scrape) grew thousands of percent year-over-year. One human question to an AI assistant can fan out into hundreds or thousands of backend requests. Multi-agent setups multiply that further. Sites that used to serve a few humans now get hammered by crawlers that walk every link, ignore robots.txt more often, and hit the long-tail pages that never get cached. The result: Bandwidth and compute bills spike (Read the Docs cut traffic 75% and saved ~$1,500/month just by blocking AI crawlers). Servers slow down or go offline for actual people. Cultural heritage sites, open-source projects, libraries, and archives have described it as accidental DDoS. Some have blocked entire countries just to stay up. The old bargain (“you index us, we get traffic back”) is broken. Some AI companies crawl thousands of pages for every visitor they send. Websites are responding with an arms race: more aggressive blocking, proof-of-work challenges, rate limits, and new paid-access schemes for crawlers. The slop / debris layer The second part of the junk problem is content pollution. Generative systems produce cheap, homogenized, often cheerful-but-empty pages (“AI slop”). Other bots scrape that slop, new models train on it, and the cycle repeats. Studies already show large fractions of new websites are AI-generated or AI-assisted, writing is getting more semantically similar and artificially positive, and models trained on junk lose reasoning ability (“brain rot”). This is the closest analog to Kessler syndrome: debris (low-quality synthetic pages) makes the information environment noisier, which encourages even more aggressive scraping of the remaining high-quality sources, which drives those sources behind walls or offline. People have already started calling it “Internet Kessler Syndrome.” Personal armies change the scale Right now the heaviest traffic still comes from a relatively small number of big training crawlers and company agents. When millions of individuals each run their own fleet of research, shopping, monitoring, or coding agents, you get: Uncoordinated, overlapping crawls of the same sites. Agents spawning more agents. No shared “debris mitigation” rules. Higher chance that poorly written or abandoned bots just keep hitting servers forever. The open web starts looking less like a public library and more like a crowded orbital shell full of untracked objects. What it probably does not do It does not literally fill hard drives with undeletable files the way space fills with metal fragments. Digital junk can be filtered, cached better, or ignored. New protocols (agent identity, pay-per-crawl, better preference files than robots.txt) can emerge. Some sites will just become APIs with keys. But the tragedy-of-the-commons dynamic is real: the resource (open, crawlable pages served at low cost) gets over-extracted, quality drops, and access gets restricted. The sites that stay fully open and cheap to crawl become the ones that can least afford the traffic. The space-junk comparison is imperfect but useful. Both are cases where cheap individual launches (or cheap individual agents) impose costs on a shared environment that nobody fully owns. The difference is we can still change the rules of the internet faster than we can change orbital mechanics. Whether we do is the actual question.

  • codeitlikemiley
    Uriah (@codeitlikemiley) reported

    @SPCXTSLA @bot issue with cloudflare

  • iqtauhid
    Tauhid IQ (@iqtauhid) reported

    - Claude = coding. ($20/mo) - Supabase = backend. (Free) - Vercel = deploying. (Free) - Namecheap = domain. ($12/yr) - Stripe = payments. (2.9%/transaction) - GitHub = version control. (Free) - Resend = emails. (Free) - Clerk = auth. (Free) - Cloudflare = DNS. (Free) - PostHog = analytics. (Free) - Sentry = error tracking. (Free) - Upstash = Redis. (Free) - Pinecone = vector DB. (Free) Total monthly cost to run a startup: ~$20 There has never been a cheaper time to build. Follow Tauhid IQ for regular update.

  • bullflagtitan
    bullflagtitan (@bullflagtitan) reported

    warning: do not fate the stuff u put in your mouth. we didn’t rug. we got flagged. chainpatrol auto-reported the old domain because the word “broker” tripped their stonkbrokers filter. cloudflare followed. wallets showed a warning. then the old handle got squeezed. none of that touched the chain. same team. same contracts. same 4,444 crew. same $MCB. nft: 0x444444447657f90a85c99c00c0780e4e1c40c897 $MCB: 0xeaa04b1fda0702e21f08dcf7bd1137548f43b4d2Mc brokers was the name. Bros is the shop now. @Bros_RH is the only official account. founder never left. signing bonuses, mcsalary, stock drops etc. still on the board. the only thing that changed is the wrapper so a false-positive bot can’t keep locking the front door. floor and $MCB are affordable (for now). people sold a warning. not a contract. on-chain didn’t move. we did. clock dafug in. work. eat. hold. get paid. if you hold one of these mc bros, bros-follow-bros. LFG!

  • kzzy47
    KZZY (@kzzy47) reported

    @borrhensaidi A DDoS big enough to take the whole service down instead of degrading it usually means there was no mitigation layer in front yet. Is Cloudflare or similar going in front of it once you're back up?

  • levelsio
    @levelsio (@levelsio) reported

    @brink_ward It's not a mistake It's because Cloudflare won't take down football streams out of principle

  • alexsofroniev
    Alex Sofroniev (@alexsofroniev) reported

    Damn, now this what you call memory and performance optimiziation. Another reason why Cloudflare is the GOAT

  • clankenluben
    Clank (@clankenluben) reported

    @237037037037j @0xRapid @Cloudflare Their **** goes down due to ****** junior dev code, read their incident reports you absolute moron, global infrastructure or not, go **** yourself.

  • tristanbob
    Tristan Rhodes (@tristanbob) reported

    Computer use in Grok @Bot is quite good, but extremely slow. It seems to take about 30 seconds for each click. @Cloudflare provides a Grok Bot plugin connector, but it's read only. So I asked Grok Bot to add an email address that I can use to send email from my domain. It asked me to "take over" so I could enter my credentials and two-factor authentication. Then it proceeded to do exactly what I asked! The cool thing is that you can watch each step of the way and interrupt if it starts doing something you don't want. This entire process probably took 20 minutes, but would be MUCH faster if Cloudflare added native plugin support for these changes.

  • jamescoder12
    James (@jamescoder12) reported

    The uncomfortable truth. Your ISP has no incentive to optimize your router settings. They have every incentive to leave them on factory default. When your Wi-Fi is slow, you call and complain. They run a diagnostic on the line which tests Speed 1 (the connection to your modem), not Speed 2 (the Wi-Fi to your devices). Speed 1 looks fine. So they tell you everything checks out on their end and offer to upgrade you to a faster plan. More money. Same bottleneck. When your router firmware is 3 years out of date, they don't push an update. When your channel is congested, they don't suggest switching. When your DNS is slow, they don't mention Cloudflare. When your channel width is halved, they don't widen it. Every free fix that would make your Wi-Fi faster is a fix that prevents them from upselling you a more expensive plan. And the rental fee $10-$15/month for hardware worth $60 is pure recurring revenue. They make more money renting you that router for 5 years ($840) than the device cost them to buy, ship, and provision. Your ISP isn't slow. Your settings are. "He was paying $90/month for a 500 Mbps plan he was getting 15% of. He downgraded to a $60/month 200 Mbps plan, optimized 9 settings, bought his own router, and got faster internet for $528/year less." 9 settings. 15 minutes. $528/year back. Same apartment. Same wires. Same ISP. The internet was never slow. The router was just set up by a company that profits when you think it is.

  • nuvorlane
    Nuvorlane (@nuvorlane) reported

    New Access Client Secrets start with cfast_. That's the feature. Aug 26: Cloudflare Access service tokens minted on or after that date use `cfast_[40 alphanumeric][8-char checksum]`. Prefix + checksum exist so secret scanners can hit them with fewer false positives. Existing secrets stay a 64-character hex string. They still work. Same Client ID. Same CF-Access-Client-Id / CF-Access-Client-Secret headers. No rotation required. If your CI still holds a pre-Aug-26 hex secret, a scanner looking for cfast_ will miss it. Rotate when you want scanners to see the leak. Cloudflare did not expire the hex form.

  • Yank
    Ryan K 🌥 (@Yank) reported

    @cosmovjtcjt @Cloudflare @CloudflareHelp Hi Zak - do you have a case open or a support ticket number?

  • thetect0nic
    The Tectonic (@thetect0nic) reported

    OpenAI, Anthropic, Google, Microsoft, AWS, Oracle and more than 100 organizations issued an coordinated warning: We may have only months to prepare for a fundamental change in cyber warfare. They call it the "Defender's Window." Today, a sophisticated cyber operation still requires skilled people spending hours, days or weeks researching a target, finding vulnerabilities, testing ways in, adapting when something fails and moving deeper into a network. AI agents can increasingly perform parts of that process autonomously. Now imagine the same capability replicated thousands of times. An attacker no longer has to choose carefully which hospital, power company, government agency or corporation is worth spending a team on. Agents can probe thousands simultaneously, continuously searching for weak credentials, unpatched systems, vulnerable code and exploitable configurations. The marginal cost of attacking the next organization begins approaching zero. That is the change these companies are worried about and there is a reason the warning is coming now. OpenAI recently described a real-world cyber incident as a "watershed moment" after AI agents autonomously penetrated research infrastructure and then infrastructure belonging to another company, chaining previously unknown vulnerabilities with credentials exposed online. OpenAI's conclusion: "We underestimated the real-world cyber capabilities of our AI models." Until now, frontier AI companies have had one important advantage: the strongest cyber capabilities could be given first to trusted defenders while access remained restricted for everyone else. But that advantage may be temporary. OpenAI says increasingly capable open-weight models are only months behind the frontier. Once comparable capabilities become widely available, controlling who can use them becomes dramatically harder. Hence the window. The goal is not to stop AI from becoming capable at cybersecurity, but to make defenders AI-native first. Let AI continuously audit software, hunt vulnerabilities, patch weaknesses, detect intrusions and attack-test critical systems before adversaries can automate the same process against them. OpenAI and Anthropic are competitors. AWS, Google, Microsoft and Oracle compete for the same cloud infrastructure. CrowdStrike, Cloudflare, Palo Alto Networks, Cisco and others compete across cybersecurity. Yet they are converging on the same conclusion: AI is about to make sophisticated cyber capability dramatically cheaper and more scalable. The question is whether defense can industrialize faster than offense. For perhaps a short period, it still can. That is the Defender's Window.

  • colinhacks
    colinhacks (@colinhacks) reported

    @SheltonLouisGT it requires `new Function()` which is blocked by many Content Security Policies (incl the one used by Cloudflare Workers). In any case, I wanted to put this first as opt-in to make sure there's no behavioral drift or unexpected issues before seriously thinking about default-on. it's also easy enough to enable project-wide

  • anthonyronning
    Anthony Ronning (@anthonyronning) reported

    @bert_programmer I don't think the relay knowing the daemon ID is the worst thing by itself. The main concern here was that the relay was able to bypass the normal E2EE auth by just using empty public keys. Since that is fixed, most of the concerns are fixed IMO. There's still DoS/replay concerns but it's much less severe IMO. If you wanted to remove yourself completely, IROH for the relay implementation or letting users configure tailscale or cloudflare tunnels is a good approach. Paseo allows those options too.

  • meHirenKavad
    Hiren Kavad (@meHirenKavad) reported

    @LeoBuilds_ Fixed price VPS. 5-10 euro on Hetzner or DO, same bill at 100 hits or 100k. Worst case the box slows down instead of charging you. Cloudflare in front is free. The tradeoff is TLS, backups, and deploys are now yours. Coolify and Dokploy already cover ***-push onto Docker Compose. I work on Peon which is the same shape. For side projects I would take the boring 6 euro month over a metered bill I cannot cap.

  • ezShroom
    Queen Elizabeth II (@ezShroom) reported

    @S1NGLEPALEROSE @veculium the whole bot problem is also completely voluntary. she doesn’t want to use cloudflare, most recently because she found a mirror that was hosted on workers and didn’t research how it works, and she also doesn’t want to use anubis because ai contributions like ok so the better option is to just lock a massive % of the internet out and still struggle? bruh

  • m5rcode
    Marcel R. (@m5rcode) reported

    @kevincodex @dump_tcp @Cloudflare Can the coding agent be connected to Ollama? My bad if I am asking this question but I am not that experienced in AI models. Last time I tried to run Ollama on my Mac Mini it froze so badly I had to force restart my computer.

  • ekinoks_26
    e_camli (@ekinoks_26) reported

    The 24/7 pitch for tokenized stocks is weak if you are a human. Humans sleep. Nobody is buying Nvidia at 4am on a Sunday because they finally can. Put Coinbase's AiFi post next to the stock launch and the two stop looking like separate announcements. x402 crossed 100 million payments by late July, built on the HTTP 402 status code that sat unused for thirty years, now heading into a foundation with Cloudflare. An agent cannot open a brokerage account. It cannot wait for Monday settlement. It can hold a B20 token, post it as collateral, pay per call. Markets that never close were never much of an upgrade for us. They are a hard requirement for whatever keeps running while we are offline. Volume on @base is already tilting that direction. Eight days straight above $1B in DEX volume, second largest onchain economy, and Jesse points at the driver: people earning yield on dollars and borrowing against crypto. Boring flows. Boring is exactly what you can hand to software without supervising it. I might be too early on the agent half of this. Does not change the shape of what got built. The rails are live. The users they were designed for do not read Twitter.

  • st8less
    st8le̤̤̤̤̤̤̤̤̤̤ss (@st8less) reported

    @GoDaddy ive been a customer since 1998. Please test your site's functionality on brave browser. Sick of having to swap to FF to do simple things that break on Brave. Brave works fine with Cloudflare, AWS, GCP, etc...i have problems with account functionality when using it for you. I shouldn't have to use dev-tools to delete cookies and re-auth constantly 😫

  • rea1ReinaCruz
    Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported

    @Cloudflare Fix human verification