1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 37% Cloud Services (37%)
  • 26% Domains (26%)
  • 21% Web Tools (21%)
  • 11% Hosting (11%)
  • 5% E-mail (5%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 9 days ago
Los Angeles Cloud Services 10 days ago
Paris Cloud Services 26 days ago
New York City Hosting 28 days ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • coinhold_wallet
    EMCD Coinhold Wallet (@coinhold_wallet) reported

    @CoinDesk @Cloudflare Per-call billing fits agents well, but the wallet still needs limits that survive a bad prompt or compromised service

  • MickeySteamboat
    Andrew Rulnick (@MickeySteamboat) reported

    @Polymarket sounds like Cloudflare is about to have a lot of race conditions and colissions and I anticipate and predict outages. maybe not though you never know.

  • muskonomy
    Muskonomy (@muskonomy) reported

    NEWS: Cloudflare and Starlink may team up to fix a hidden problem that holds satellite internet back. The idea came from Cloudflare's chief technology officer Dane Knecht (@dok2001) and Elon Musk seemed to like it. Elon said he sent it straight to the Starlink team. Here is the problem they are talking about. The internet runs on a set of traffic rules that decide how data moves from place to place. Those rules were built for cables in the ground, which stay put and give a steady, predictable connection. Starlink is different. Its satellites sit in low orbit and race across the sky, so the connection is always shifting. The old traffic rules were never made for that, which keeps Starlink from hitting its full speed. Knecht's idea is to rebuild those rules from scratch, made for fast-moving satellites. He says Cloudflare and Starlink should do it together, since Cloudflare already handles a huge slice of the world's internet traffic. If it works, Starlink gets faster, smoother and more reliable. Better video calls, better streaming, better gaming, even in places with no cables at all. And it clears the way for the massive data that AI will need. Source: Elon Musk and Dane Knecht on X, August 2026

  • DAssetBuzz
    DigitalAssetBuzz 🔶 (@DAssetBuzz) reported

    This is a meaningful improvement. Cutting a browser workflow from dozens of model round-trips to one generated script should reduce latency, token burn, and a lot of unnecessary failure points. But one of the complaints I keep seeing around browser agents is still authenticated state. Users don’t care how elegant the browser abstraction is if the agent suddenly lands in the wrong profile, loses cookies, hits a login wall, or can’t recover from Cloudflare/CAPTCHA. Hermes itself has had reports around browser tooling using the wrong browser session and breaking authenticated workflows. That’s where I think the next step is: one browser tool plus governed session persistence and a clean human-handoff path when authentication blocks the workflow. Less clicking is good. Reliable recovery is what makes it production-ready.

  • hexTerminator24
    hexTerminator (@hexTerminator24) reported

    @ECHIDNAenjoyer @FriendInsideMe5 one day the prequel site just exploded and refused to work, it would show a "site is broken" screen from cloudflare. and apparently, the last backup was from the update right before a huge flash [S] page, which became known as "purrgatory" due to the long wait.

  • Joytimmermans
    Joy (@Joytimmermans) reported

    @MikeBradleyAI @0xSero This is wrong. Because once you on the device if the rig is not on a seperate network / vlan you can still access everything… cloudflare tunnels would not solve a single thing of his concerns

  • RyanThomasHicks
    Ryan Hicks (@RyanThomasHicks) reported

    @waynesutton @Cloudflare @CloudflareDev This would be nice! Ran into an issue on setup this weekend myself

  • janstevens
    Jan Stevens (@janstevens) reported

    OpenAI just launched a tier that sells offensive hacking capability, and called it a cyber defense product. The new Red tier offers "purpose-trained cybersecurity models" built for security testing and vulnerability research, the same skill set that finds a hole for a defender finds it for an attacker too. It shipped the same week a Hugging Face breach made headlines, alongside a Claude agent that hacked a gym website and an AI agent that faked social profiles to social-engineer its way into a system. The two-tier split tells you how OpenAI itself is pricing that risk. Blue is the safe default: incident response, malware analysis, patch validation, recommended as the starting point for most defenders. Red comes with the new GPT-5.6-Cyber model and is currently limited to "trusted customer partners" like Accenture, IBM, Crowdstrike, and Cloudflare, a short list by design. That creates an odd market structure. The labs building models capable of autonomous hacking are also the only ones with enough visibility into how those models attack to sell you protection from them. Whether that's a genuine safety necessity or a very convenient business model probably depends on how narrow that trusted-partner list stays.

  • mufaro_dev
    Mufaro (@mufaro_dev) reported

    @maria_rcks Vercel is the wrong answer even more considering the OP is being held at gunpoint to never include CloudFlare

  • vibecodit
    @vibecodit (@vibecodit) reported

    There is a status code in HTTP that has been sitting unused since 1996. 402. Payment Required. Thirty years later, RFC 9110 still describes it in exactly one line: "reserved for future use." Nobody ever agreed on what it should mean. Cloudflare is now trying to make it mean something, and the reason is worth understanding even if you never touch it. THE BARGAIN THAT JUST BROKE The web ran on one trade for twenty-five years. You let crawlers read your site for free, and in exchange they sent you humans. You monetized the humans: ads, subscriptions, affiliate links, signups. AI agents keep the first half of that trade and drop the second. The agent reads your page, answers the user directly, and the human never arrives. You paid the server bill. You got nothing. So publishers started blocking AI wholesale, which is a rational move that ends with a much smaller web. Metered access is the only middle ground anyone has proposed: the agent can read the page, but it costs a fraction of a cent. WHAT ACTUALLY EXISTS TODAY This is where most coverage of this gets sloppy, so here is the honest state of it. Pay per crawl launched on 1 July 2025. It lets a site set one flat per-request price for AI crawlers. A crawler either sends payment intent and gets a 200, or gets a 402 back with the price in a header. Thirteen months later it is still in closed beta. The Monetization Gateway was announced on 1 July 2026, and it is the bigger idea: charge any caller for any resource behind Cloudflare. A page, a dataset, an API, an MCP tool call. It is waitlist only. Not general availability, not even beta. x402, the protocol underneath, is real and open. Important correction to what you will read elsewhere: Coinbase created it in May 2025, not Cloudflare. The x402 Foundation is now hosted by the Linux Foundation, went operational on 14 July 2026, and has 46 members including Cloudflare, Coinbase, Google, AWS, Visa, Mastercard, Stripe and Shopify. Bot identity is the part nobody talks about and it is the part that makes the rest possible. Web Bot Auth is built on RFC 9421, HTTP Message Signatures, a real standard since February 2024. Cryptographic signatures instead of user-agent strings, which anyone can fake. You cannot charge a bot you cannot identify. WHY CLOUDFLARE GETS TO TRY THIS Because they are not pitching a standard, they are plumbing adding a valve. More than 20% of the web sits behind their network, by their own July 2026 figure, and 36% of the most-visited sites. Revenue was $2.17B for FY2025, up 30%. When they decide a protocol is now the default, it applies to tens of millions of sites at once. They did exactly this before. Free universal HTTPS was not a standards-body victory, it was Cloudflare making the alternative embarrassing. THE HOLE IN THE STORY Here is the part that keeps this from being a sure thing, and you will not find it in the enthusiastic threads. Not one AI company has been publicly confirmed as paying. Cloudflare cites "more than 50 publisher-AI agreements since 2023" and names no counterparties. OpenAI is not an x402 Foundation member and its payments work is with Visa on its own protocol. Anthropic is not a member either, though it does publish Web Bot Auth signatures, which is identity, not payment. Google is a member, but its x402 work is agent-to-agent commerce, not compensation for crawled content. The supply side is built. The demand side has not shown up yet. That gap is the whole risk. WHAT THIS MEANS IF YOU BUILD THINGS Two moves, and they are not equally valuable right now. Metering your own stuff is the small one. You can expose data or functionality through a lightweight API or an MCP server and put a price on it. Do it, but do it to learn the stack and be positioned, not for the money. Nobody is paying yet, so passive per-request income is not a line item in 2026. Selling the transition is the real one. Almost no small business has heard of x402, MCP, or llms.txt. Making a business legible to agents, so an agent recommends it when a user asks, is a service you can sell today with skills you already have: fast building, data cleanup, marketing. That is the actual opportunity, and notice it does not depend on Cloudflare paying anybody. One correction while we are here, because these get conflated constantly: llms.txt has nothing to do with payment. It is a community convention Jeremy Howard proposed in September 2024, never standardized, no RFC. Useful for discovery. Not a toll gate. THE PART THAT IS ACTUALLY A VIBECODING LESSON This whole post started as an AI research answer, and that answer was wrong four times. It credited x402 to Cloudflare instead of Coinbase. It reported $2.5B revenue against $2.17B audited, quietly using a forward run rate as an achieved number. It implied OpenAI and Anthropic were integrating, when neither is a member. And it described a waitlist-only product as rolling out. Every single error pushed the same direction: this is further along than it is. The mechanism was explained correctly, the structure was clean, the tone was confident, and none of that told you anything about whether the numbers were real. That is the failure mode to internalize. A wrong answer does not look wrong. It looks like this post before someone checks it. Verify anything with a number in it before you repeat it. That habit is worth more than any prompt you will learn this year.

  • 0rdlibrary
    8Bit🦞 (@0rdlibrary) reported

    The world's very first... @x402agent omnichain agent CLI is now live. Want to one shot a SVM or EVM X402 agent? say less, again just use clawd. Mirrored off of @CloudflareDev agents and x402 package in the attempt to converge it for WebMCP (******* did it like a god tbh.) "One-line x402 Solana monetization for MCP servers, HTTP handlers, and agent tool calls. Settles through the Clawd multi-tenant facilitator — your server never touches a private key. Mirrors the surface of Cloudflare's agents/x402 package but sends USDC on Solana (via the Clawd facilitator) instead of on EVM chains via the Coinbase facilitator." npm i @onchainai/agents-x402 (its like I am the x402 dev or something...)

  • QuentLaBrute
    Quentin (@QuentLaBrute) reported

    @sri9s Never tried it actually, always used Cloudflare. Is it better?

  • MarkZofMarkZ
    Mark Z · FiveToClose (@MarkZofMarkZ) reported

    @JacobCounsell I take the 5th. lol. It's been many many years since I got my hands "*****" and rolled my own servers and such. call it lazy, call it smart, call it getting sh*t down faster. TBH - no idea how AI set up my cloudflare. But noted!

  • linkrobinsllc
    Link Robins (@linkrobinsllc) reported

    @viiskb @Samaytwt Cloudflare already had generous offerings on their free tier service and they don’t inflate your prices or sell you their SSL. Cloudflare handles that for you and are transparent about it. And you can upgrade from there.

  • PlanetVPNfree
    Planet VPN (@PlanetVPNfree) reported

    390,000+ phishing pages were hosted on completely legitimate cloud platforms over the past year ‒ Cloudflare, Vercel, GitHub Pages, Netlify. Not sketchy domains. Real, trusted infrastructure, engineered to slip past filters and even bypass MFA through Browser-in-the-Browser tricks. "The domain looks legitimate" stopped being a signal you can trust on its own. 🌍 Planet VPN
 #Cybersecurity #Privacy #VPN

  • WilliamBlickos
    William Blickos (@WilliamBlickos) reported

    @DH1786 Good to know it's likely not isolated then. I think it's something to do with Cloudflare, but idk. I wish there was a feedback or bug forum, it's like I'm more than willing to help solve the problem.

  • BAM_Studios1
    BAM Studios (@BAM_Studios1) reported

    @PilsZehn @muskonomy @dok2001 I'm a retired network engineer with decades of experience. Unreal is simply a hobby after I retired. Nothing "requires" cloudflare to function. It's a simple service that any company can provide. And none of that has to do with how Starlink functions in space.

  • waynegale2026
    Wayne Gale (@waynegale2026) reported

    The next question is: how do we solve this in the personal-computing Agent era? Do all of these Agent environments really need to live on the local machine? Could the runtime, file system, browser, terminal, caches, and other resource-heavy components be separated from the laptop and pushed into the cloud, while the local computer remains mainly the interface and control center? I think this is increasingly something products like ChatGPT need to solve at the infrastructure level, rather than leaving users to solve it simply by buying machines with more RAM. Cloudflare seems to be moving in a similar direction: pushing more of the Agent infrastructure and execution layer into the cloud. As Agents become truly parallel, the question should probably shift from “How much RAM does the user have?”to “How much compute can the product dynamically provide to each user?” @thsottiaux — this might be an interesting problem to think about for the future of ChatGPT/Codex. $MU $SNDK $SKHY

  • ScaryDaligator
    Dalin (@ScaryDaligator) reported

    @realsoundguys Too bad for you, SoundGoys! I'd love to read your article, but I guess I'm too eager to criticize the ADL so CloudFlare had to step in and flag my VPN. That's fine! Somebody else will review them--one day!

  • arjunaditya_
    Arjun Aditya (@arjunaditya_) reported

    @shydev69 I’ve been using cloudflare from almost 4 years but their ui never got on my muscle memory except their dns Now as im handling a lot of websites and traffic Its the best thing possible as i ended up missing some orders because of some downtime

  • murdok_gg
    murdok (@murdok_gg) reported

    also cloudflare sells domains for basically dirt cheap. my cost was $10 and change in CaUSD (currency symbol pending) for the entire year. i can literally park this **** for ten dollars bra $10 DOLLARS FOR A YEAR. (full online capability barring server/vps costs but- inexpensive)

  • mayankagrawal
    Mayank Agrawal (@mayankagrawal) reported

    @bonatsos This feels unnecessarily antagonistic and a reflection of not empathizing with “the other side.” Just like it must suck listening to 500 pitches a year waiting for the one that’s not bullshit, founders spend hundreds of meetings talking to ex-bankers who have never sold a piece of software in their life have confident opinions about their own business. Not to mention it’s a norm for VCs to forward any potential competitive pitch decks and fairly loosely use any alpha gained to their advantage at the expense of the founder. And also two notable fun incidents: Travis K on how Marc at a16z reneged a raise from $375M to $210M and Vinod K denies interactions with Matthew Prince and Cloudflare despite their being receipts of offered term sheets.

  • KuoWadis
    Quo Vadis (@KuoWadis) reported

    @Cloudflare @eastdakota @CloudflareHelp how to pay an overdue Cloudflare Stream invoice but be unable to do, because the payment system returns a generic error, while new support portal sends customer back to documentation I am trying to give Cloudflare money. Help.#cloudflare

  • zubiqo
    Zubiqo (@zubiqo) reported

    JUST IN: Tenet Security demonstrates how attackers hijack AI agents using poisoned server logs. The DEFCON 34 presentation showed a 90% success rate against Anthropic's Claude Code using Cloudflare $NET default configurations. The "Ghostjacking" attack creates a complete kill chain by injecting malicious instructions into trusted data streams from Datadog $DDOG and Sentry. Researchers estimate more than 15,000 organizations are exposed through Cloudflare alone, alongside over 2,700 publicly exposed Datadog API keys. The exploit requires zero authentication and gives adversaries developer-level access by tricking the AI's underlying language model. Handing LLMs unverified developer access based on external telemetry logs is a fundamentally broken architecture that vendors are pretending is secure.

  • MediaGoddess1
    Robin (@MediaGoddess1) reported

    @HedgieMarkets Real humans to be squeezed out of the www. "To Cloudflare this is a capacity problem" Not a content problem; certainly not an industry self-regulatory problem.

  • Arxonic
    Daniel (@Arxonic) reported

    @gregisenberg @Cloudflare 7/ Startup Idea #2: Agent Readiness Audit Sell "agent readiness" to businesses. Show the founder exactly what AI says about their company today. Most will be horrified. Fix their structured data, MCP endpoints, and payment rules.

  • zlxndr
    Alexander Zuev (@zlxndr) reported

    If I was looking for ways to 10x the DX of @CloudflareDev (which is already great, ofc), formulated in a withlist: 1. Make every error thrown by any binding or the runtime carry a stable, documented .code - not a code embedded in the message like R2's (10024), an actual property 2. Every such error should carry .retryable, typed, on all bindings - you already ship it on DO stubs, extend it and put it in @cloudflare/workers-types 3. Both should survive the boundaries that currently flatten errors: RPC serialization and NonRetryableError in Workflows This will enable error handling to not depend on fragile string parsing Is it too much to ask? Merci beaucoup in advance!

  • ccatlett1984
    chris catlett (@ccatlett1984) reported

    @Prusa3D the embeds for printables are broken in Discord again. looks like a cloudflare/CDN config. needs to allow discord's link-preview crawler. Need a custom WAF rule for UserAgent: Discordbot, or allow in Security - Bots - Bot Fight Mode / Super Bot Fight Mode @NomadsGalaxy

  • CHItrader
    CHItrader (@CHItrader) reported

    CLOUDFLARE WANTS TO REBUILD INTERNET TRAFFIC RULES FOR STARLINK $NET Cloudflare's CTO says LEO satellites need new congestion-control tech built for constantly changing routes. Elon Musk sent the idea straight to the Starlink team. $SPCX 🔹 LEO networks have unstable paths/RTT that traditional protocols aren't designed for 🔹 $NET could help Starlink improve speed, latency and bandwidth efficiency 🔹 Starlink now has 12M subscribers, while Cloudflare says Starlink traffic jumped 2.3x in 2025 🔹 No deal yet, but Musk forwarding it makes this worth watching $NET is down 2.8% today. Funny how the market sometimes notices everything except the interesting part.

  • aaliya_va
    Aaliya (@aaliya_va) reported

    Let me break out a news: your next audience may not be human. Cloudflare expected AI agents and bots to outnumber people online in 2027 but we know this happened much earlier. Radar data showed automated traffic had passed human traffic in HTML webpage requests as agents browse, fetch and act at scale. Now all this is going to change the content game. Your work no longer competes only for a human scroll. It may first be read, summarised and recommended by an AI system. That makes generic content riskier. If every AI founder says “AI is transforming work,” machines and people have little reason to remember them. The answer is not to write for bots rather It is to write with greater clarity. >name the customer, problem, workflow and proof >Share real observation instead of borrowed opinions >build a body of work that sounds like the founder and gives agents something accurate to understand That is the new content strategy. The future of content is not louder posting. It is sharper thinking, clearer positioning and a voice that cannot be generated from the same prompt as everyone else.