1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 43% Cloud Services (43%)
  • 21% Domains (21%)
  • 21% Hosting (21%)
  • 7% E-mail (7%)
  • 7% Web Tools (7%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Hosting 17 hours ago
New York City Cloud Services 20 days ago
Los Angeles Cloud Services 21 days ago
Paris Cloud Services 1 month ago
New York City Hosting 1 month ago
Manchester Domains 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • petehanssens
    Peter Hanssens is tinkering! (@petehanssens) reported

    Howdy, I'm looking for a contract and/or consulting gig to get me through to February next year. Can be anywhere between 3 and 5 days a week - 3-4 days being ideal as I work on my company but can dial that down if 5 days in necessary. Things I've been working on recently: - ClickHouse + Postgres + Fly AppDev - Golang API's + Solidjs frontend - Internal Mailchimp replacement via CloudFlare Email Sends - Marketing automation agentic+skills platform for generating all of my marketing banners and emails - Drover Agentic Framework using Unikraft Cloud - Drover-code - a claude code replacement - Drover-gateway - an AI gateway based on Bifrost - Self-hosted DeepSeek v4 Flash on 4x RTX 6k Pro's on Akamai Cloud - Evals platform with Langfuse with the aim to fine tune a model for my use cases If any of those things sound interesting or you just want some data platform / migration support please do reach out.

  • CapyToolkit
    CapyToolkit (@CapyToolkit) reported

    @h_meow_meow @TeeDevh Actually these cause 2 separate issues. Crawler Hints with Cloudflare caching made thousands of unnecessary URLs to be submitted via IndexNow. Bot Fight mode was blocking legitimate Bingbot and OpenAI IPs (not detecting them as Verified).

  • AgenticOperator
    The Agentic Operator (@AgenticOperator) reported

    After auditing dozens of brands and tracking thousands of AI citations this year, these are the 10 things that actually move the needle. Not theory. Patterns from real data. Bookmark this. Come back to it. Check your brand against each one. 1. Answer the question in sentence one. AI extracts from the top and heavily weights the first 200 words. If your answer is sitting in paragraph 3 behind a brand story and a mission statement, AI moves on to the next source. The page that answers first wins. Not the page that answers best. 2. Your own website is the source AI trusts least. Third-party content gets cited 3x more than brand-owned pages. The same information on someone else's domain can carry much more weight. Guest posts. Contributed articles. Earned media. Review sites. That's where AI often looks first. Your site is confirmation. Not always the source. 3. Mentions beat backlinks. 3x stronger. Correlation between brand mentions and AI visibility: 0.664. Backlinks: 0.218. Three times the signal. 20 years of link-building strategy just got outweighed by something much simpler: Being talked about across independent sources. Being referenced matters more than being linked to. 4. Reviews on 1 platform don't count. Reviews on 5 platforms do. 4,000 reviews on your own site can look like one unverified source to AI. 340 reviews across Amazon, Trustpilot, Reddit, G2, and Google looks more like consensus from multiple independent sources. AI cares about the spread. Not just the volume. 5. Update your top pages every 2–3 weeks minimum. Pages updated within 30 days earn 3.2x more citations. AI has a freshness bias that most brands don't budget for. You don't need to rewrite the whole page. One new data point. One fresher stat. Something that signals the page is still alive. Publish and walk away, and that citation can lose value surprisingly quickly. 6. Comparison content gets cited 7x more than product pages. 59.5% of AI citations come from listicle and comparison content. Product pages account for 8.5%. The content most brands never bother writing is often the content AI cites most. Publish your own comparisons. Name competitors. Be honest about where you win and where you don't. Because if you don't write the comparison, someone else will. 7. Make sure AI crawlers can actually reach your site. 73% of businesses on Cloudflare are blocking AI crawlers by default. Check your bot protection. Check your robots.txt. Check your redirect chains. If you have more than 2–3 hops in a redirect, many AI crawlers may quit. One hop. Clean path. Open door. 8. Your price must be in raw HTML. Not JavaScript. If your price loads through a JavaScript toggle, dynamic app, or client-side rendering, AI crawlers may not see it. Right-click your product page. View source. Ctrl+F your price. If it's not there in plain text, AI may not be able to match you to price-based queries. You can be disqualified before the comparison even starts. 9. Build your entity across Wikipedia, Crunchbase, LinkedIn, and your own schema. AI needs enough signals to understand who you are and distinguish you from similarly named entities. Organization schema. sameAs links. Consistent profiles. Consistent name. Consistent description. Consistent category. Entity confusion can kill visibility before any content strategy gets a chance. 10. Track all 4 engines. Not just ChatGPT. ChatGPT dropped from 89% to 63% of AI referral share. Claude went from 1.4% to 18.5%. Gemini quadrupled. Perplexity doubled. Claude converts at 16.8%. The platform most brands have barely checked is becoming a major source of high-intent traffic. One-engine strategy is a 63% strategy. Track all four. Optimize across all four. Measure probability, not position. None of these are hacks. None are shortcuts. They're structural advantages that compound over time. The brands that nail 7 out of 10 will have a very different AI shelf than everyone else. Most brands right now aren't even close. That gap is the opportunity.

  • jgwifi
    Joshua Gardiner (@jgwifi) reported

    @Cloudflare Hope you can help. I was double charged for a registrar change. Attempted to open a ticket but the support platform says no tickets for my free account. I asked the AI bot, it says I should be able to open a ticket. Any advice? :)

  • Abdella6if
    Abdellatif (@Abdella6if) reported

    @harisbuild @Cloudflare interesting, will look into it. Does cloudflare support BYOK?

  • Bukumzzy001
    Bukumzzy (@Bukumzzy001) reported

    @juiceboy_of_abj No lies bro Couldn't access my cloudflare while connected to this Airtel 5g till I switched back to my Normal phone network(Glo).. Didn't know it's an Airtel thing till It happened again while connected to my Airtel mifi 😭😭😭

  • tobeycodes
    @tobeycodes (@tobeycodes) reported

    anyone having issues with gitCheckout in cloudflare sandboxes today? seems to always timeout and can never close. it was working fine before today

  • Waffl3x
    Waffl3x ❤️‍🩹 🩹 👁‍🗨 (@Waffl3x) reported

    @LinusMixson I'm currently of the mind that it doesn't have to be anonymous as it isn't meant to contend with something like TOR. However 2 hosts operating in the walled garden shouldn't being able to correlate that a user on both of their platforms is the same person. There are some strategies I've heard brainstormed to mitigate non-anonymity but it isn't the problem I want to solve right now. (Not that it isn't important mind you.) And I'm 100% sure that hosts on the network should not be able to boot people out of the walled garden. I don't intend to give more power to large sites, more take the burden of moderation off small ones. Of course if a user is violating rules of the walled garden (sharing an identity with other people, running unannounced scrapers) that would be grounds for losing access. I wouldn't want to impose how moderation of a particular host must be done, if they want to ban for particular opinions that's their own (bad) choice. It can't be opinionated on things outside its 'jurisdiction' lest hosts and users won't have incentive to use it. Hosts should also be allowed to accept connections from outside the walled garden, provided they don't forward those connections into it arbitrarily, or perform arbitrary lookups on their behalf. That would defeat a lot of the utility. This is probably essential to obtain a userbase, it would fracture the web. Right now non-normies are forced to use platforms that normies are on. If the walled garden required hosts reject all connections from outside of it, it would just be immediately killed and non-normies would never have the opportunity to join. Hosts could still choose whether they support external connections or not, arbitrarily turning it on and off depending on what's happening. Sudden DDOS attack? Just turn off the unprivileged portal. Obviously Cloudflare already does a lot of this so there isn't a huge inventive. But it should be trivial from a technical perspective. Hosts that don't care to cater to normies and would rather sacrifice quantity for quality would likely opt to operate totally within the walled garden. Part of my goal is to bring communities that have slipped off the open web into their own smaller walled gardens, back into the open. Forums for example are a big example. Touching on non-anonymity again, part of my thoughts on it are that outside of using a VPN we are already effectively not anonymous. Governments can subpoena it in the snap of a finger. I'm hoping this design would still allow one to connect to the walled garden using a VPN, but they would still need a 'personalized' id which would need to be turned over. If they did everything right, all that would reveal about them is their VPN connection and the vouch chain for the identity. Speaking of that, I'm pretty strongly of the opinion the right mechanism for this is vouches. The reason is that if an individual vouches for too many bad actors, they can lose vouch privileges, and everyone they vouched for retroactively needs new vouches to access the garden. This would ripple down, and up, the chain. The principle here is that you can't just vouch for anyone because it reflects back on you. I intend for people to think about who they vouch for, whether they trust them to follow the rules or not. I initially played with this idea as a way of preventing cheating in online games. I'm sure some of the design reflects that. It should be obvious, while it isn't anonymous, it wouldn't require government ID to participate. Online games also made it clear that doesn't work anyway, in Korea elderly people just sell their ID to kids, they make a new account and start cheating again. It isn't infallible but it increases the cost of making sock puppet accounts greatly. That should ultimately be the goal, increase the cost of turnover. Long winded post, I'll probably do a real write up on it in the future that isn't all over the place and is a bit more concise. If you want to reach out to discuss it on a synchronous medium I would be interested

  • HouseHackerJon
    Jon ONeill (@HouseHackerJon) reported

    On the software company side an issue I’m seeing building with @Cloudflare is that as a start up everything is aimed at @vercel and @supabase, but I’m a big fan of having everything run through Cloudflare once I discovered its system

  • Samuel_Orobosa
    Orobosa (@Samuel_Orobosa) reported

    Consider using Cloudflare WARP. It solves this issue

  • OgFyaz
    FYAZ (@OgFyaz) reported

    🚨 A Spectre attack leaked a JWT from a co-located Cloudflare Worker. Researchers demonstrated the attack in Cloudflare’s production environment at up to 12 bits/second, 360× faster than the 2021 result. No customer data was accessed. Cloudflare says the attack is now mitigated. Thoughts?

  • SimonHoiberg
    Simon Høiberg (@SimonHoiberg) reported

    @infomiho Exactly. Though worth noting that Hetzner has its own DDoS protection in place as well, just not as sophisticated as Cloudflare. But yes, if you expect recurring, frequent heavy DDoS attacks on your servers, go with Cloudflare, I agree. Most products won't really have this issue though.

  • SafeBrowz
    SafeBrowz (@SafeBrowz) reported

    8/ We hit Cancel to see where it fell back to. whitelistportal[.]com/callback That domain is the attacker's. Registered 1 August 2026. Under 3 weeks old. Registrant redacted, St. Kitts & Nevis, sitting behind Cloudflare. Then we requested the root of it.

  • algotradingdesk
    Manish Malhotra (@algotradingdesk) reported

    Cloudflare is proving that cybersecurity is becoming an infrastructure business rather than simply a software category. The company recently crossed $2 billion in annual revenue, while its network spans more than 330 cities globally. But the more important number is the amount of internet traffic passing through infrastructure like this. As AI agents multiply, automated traffic and cyberattacks increase alongside legitimate users. That creates a structural shift. Every new AI agent becomes another potential customer. Every new attack becomes another reason to pay for protection. Cloudflare isn't merely selling security. It is positioning itself between the internet and the companies trying to operate on it. In the AI era, the companies controlling digital traffic may become as strategically important as the companies generating it.

  • ainewsusa
    AI News (@ainewsusa) reported

    The numbers are brutal: 85% fewer open issues, powered by agentic AI inside GitHub Actions. Cloudflare paired Flue (their agent framework) with triagebot on Workers to auto-classify, reproduce, and even patch bugs. Human reviewers only see the final diff. That’s not automation—th

  • Kamx336
    𝙁𝙧𝙚𝙚 𝙆 (@Kamx336) reported

    @juiceboy_of_abj I just connected my VPN to sign in to cloudflare then I saw this.

  • abdvlkadr
    Former Child (@abdvlkadr) reported

    @santos__vito Why did you guys host on Vercel? Never do that lmaooo! Just set up a Cloudflare worker and host for free.

  • cyrusradfar
    Cyrus Radfar (@cyrusradfar) reported

    @ravikiran_dev7 the lack of any protections for customers from a company at the scale of Cloudflare is their mistake. Rate limits, rational max/scaling rules that would need to be manually overridden by the customer with understanding of the scale they expect. I'm thankful they recognized this is their mistake and they made things right.

  • SW4FlorianM
    Florian M (@SW4FlorianM) reported

    Three findings from the audit of an industrial manufacturer. Fixing all three: about three days of configuration. No code. The site is Webflow behind Cloudflare, and the stack was never the problem.

  • gagansuie
    Gagan Suie (@gagansuie) reported

    104 resolve the proxy hostname over DNS-over-HTTPS through Cloudflare or Google, so no plaintext DNS query appears on your network. The advertised premium servers in JP, SG, CA, AU and TR returned no A record. They do not exist.

  • SimonHoiberg
    Simon Høiberg (@SimonHoiberg) reported

    Since we moved from AWS → self-hosting on Hetzner, our products have been much more stable/reliable. Our uptime is near-100% and we're never blocked from shipping. So the whole "self-hosting is fun until servers break at 2 AM" is a meme. You know which services go down all the time? - Supabase - AWS - GitHub - Cloudflare Ask my competitors 😬 They would know!

  • theaaron
    Aaron Makelky (@theaaron) reported

    @nickvasiles just point them at a private github repo or cloudflare artifact where your skills live installing them natively across different agents is a waste of time and they never stay synced to the system of record version

  • mildlysupreme
    Mildlysupreme (@mildlysupreme) reported

    @Namecheap @Cloudflare unfortunately namecheap's web app is so ridiculously slow on top of the price hikes.. this is going to take a while

  • aidansunbury
    Aidan Sunbury (@aidansunbury) reported

    @michael_chomsky @thdxr We are running lots of cloud agents. The basic idea is it's OpenCode + the tooling we need for local development in a VM. If the OpenCode server is able to run in a cloudflare durable object, it can spin up much faster, and we can keep it's session history persisted forever for cheap. Then, the dev box VM can get spun up and down if needed, or resized if needed, without having to worry about migrating the OpenCode session or its context. It's just a much better architecture overall for the agent to not run in the same place as the sandbox. It unlocks so much. They are working on it, and I just really really want that functionality

  • OriginalOGDAW
    The Civic Lens (@OriginalOGDAW) reported

    @TorBox It people knew they could just use free cloudflare and make there own Debrid service for free with 10tb monthly limit

  • Joshua_z0310
    Joshua (@Joshua_z0310) reported

    How to start your solo business with AI tools ChatGPT / Claude = ideation, writing, research. Cursor / Windsurf = coding and debugging. Supabase = backend and database. Vercel = hosting and deployment. Namecheap = domain. Stripe = payments and subscriptions. GitHub = code hosting and version control. Resend = transactional emails. Tally / Typeform = forms and lead collection. PostHog = product analytics. Sentry = error monitoring. Cloudflare = CDN and DNS. Upstash = Redis and rate limiting. Pinecone = vector database. Loom = screen recording and async updates. Notion = docs, wikis, and SOPs. Slack = communication. Canva = design and branding. Billbooks / Wave = simple accounting. The idea is simple: one person can now use AI plus low-cost SaaS tools to cover product, development, deployment, payments, marketing, analytics, operations, and support—without building a large team from day one. #AItool #AI #productivity

  • rea1ReinaCruz
    Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported

    @Cloudflare Please, fix human verification

  • d11cc3s
    dc (@d11cc3s) reported

    @Eric_M_Courage Open source and publish this on GitHub Pages or Cloudflare? Claude should be able to help you do this if not I might be able to help

  • thisdothassan
    Hassan (@thisdothassan) reported

    @rxnnie_tech @ossynoya This tissue is a different one from the Airtel issue. Cloudflare behaves this way sometimes until you use a vpn

  • faye_xiao_
    Faye Xiao (@faye_xiao_) reported

    The spirit of Spirit just sold for $10 million Google is buying Spirit Airlines' data out of bankruptcy. Emails, internal communications, spreadsheets, bookings, frequent flyer and HR records, all de-identified, for $10 million. Judge Sean Lane rules on the sale Wednesday. The obvious read is that Google wants more data. But de-identified data doesn't work for advertising, since you can't target someone you can't name, and Google already sees more airfare information through Google Flights than Spirit ever generated internally. An airline that went under in May is also a strange place to look for pricing wisdom. What's worth buying is the internal material. The emails and the spreadsheets they reference record how work moved through the company: a question gets asked, a document gets built, a decision gets made, a system gets updated. Consumer text is everywhere, and records of how an organization actually functions are not, which is what you need if you want models that operate inside workflows rather than talk about them. Google's own statement uses the word enterprise, and the runner-up bid of $7.5 million came from Mercor, a company whose entire business is sourcing training data for AI labs. When the second bidder isn't another airline, the market has told you what was being priced. The strange part is that Google isn't short on this data at all. It runs Gmail and Workspace and sits on possibly the largest collection of business correspondence in the world, and it has promised enterprise customers it will not train on their content, which is not a promise it can quietly break. So it has the material and no permission to use it. What $10 million buys is clean title, a court approved dataset nobody can sue over, at a moment when everyone else is defending scraping claims. Dead companies can agree to things live ones can't. Any of this is worth paying for because the public supply is running down. Epoch AI's 2024 analysis put the stock of quality public human text at roughly 300 trillion tokens and projected it would be consumed between 2026 and 2032, a window that opens this year, and access has closed faster since than the arithmetic alone suggests. A census of the top 100,000 domains this July found 19.1% blocking at least one AI crawler, and in September Cloudflare begins blocking mixed use crawlers by default across its entire free tier. Private operational records are the obvious next reserve, and they are almost untouched. Epoch left them out of its estimate because private data is fragmented and legally too messy to use at scale, which is precisely the condition a bankruptcy court removes. That makes Wednesday's ruling more interesting than the sale. If it goes through, every bankruptcy from here has a new asset to offer, and the value will depend on how well documented the industry already is. A corner store has nothing worth buying, since you can watch how it works from the sidewalk. A hospital or a law firm is the opposite, because even with names removed the record shows how a case moves through the organization, who escalates what to whom, and which exceptions get made. That knowledge lives in internal systems and in people's heads and appears nowhere public. The catch is that the supply is biased toward failure, since no healthy company would sell its internal record, so every dataset that reaches the market comes from an operation that didn't work. That's useful for learning how a process runs, and much less useful for learning what good judgment looks like.