Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (43%)
- Domains (21%)
- Hosting (21%)
- E-mail (7%)
- Web Tools (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Hosting | 5 hours ago |
|
|
Cloud Services | 19 days ago |
|
|
Cloud Services | 20 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Hosting | 1 month ago |
|
|
Domains | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
CEO Govibe.org (@govibeorg) reportedi dont use AWS or Cloudflare i host my own DNS servers with in LA and NY tier1 fiber and myself as tier2 operator of my own network low latency, i dont depends on other if Cloudflare or Amazon crash its doesnt affect my servers..
-
S41R4J (@s41r4j) reportedI recently ran into an interesting Cloudflare Turnstile issue while looking at abuse hitting my own domain/server! One thing that surprised me: The Turnstile sitekey is public by design! That does NOT mean someone can directly bypass Turnstile just by having the sitekey; But this is where it gets interesting! An attacker can take: `your domain + your Turnstile sitekey` and feed it into CAPTCHA-solving infrastructure to obtain a real, valid Turnstile token! So the flow can effectively become: sitekey → automated solver → valid token → protected endpoint The attacker is not breaking Cloudflare, they are simply solving the challenge at scale! "Which means Turnstile should never be treated as the entire security layer!" Your backend should still: • Verify every token using Siteverify • Validate the hostname • Validate the expected action • Restrict allowed hostnames • Rate-limit the actual endpoint • Add abuse detection around sensitive actions CAPTCHA ≠ authorization!!! And a public sitekey ≠ a secret! A small implementation detail, but a pretty important distinction when building abuse-resistant systems!
-
PromptKing | The Governance OS for AI Agents (@PromptKing32) reported@Cloudflare Optional scopes fix the consent problem. The remaining problem is independent proof that the agent actually stayed inside those scopes once it started running across systems.
-
Nir Galon (@nirgn975) reported@thdxr The problem is, GitHub actions are free and already where we host our code. Maybe will try Cloudflare because that’s where our code runs.
-
BITx (@getbitx) reported@xrpcafe @XRPXolo It’s possible your ISP is using CGNAT which can cause Cloudflare to block your shared public IP address. Asking your ISP to allocate you a fixed IP might resolve your issue.
-
Alexander Zuev (@zlxndr) reported@vicentesandev + retries, timeouts, DI, error taxonomy is trivial and not an issue even without effect - the only core reason for me to consider the transition is to make the logic more maintainable and more reliable And the most confusing bit of this is handling errors / translating them at the boundaries: - tanstack server fn handle them one way - server api routes expect a response - cloudflare workflow have specific control flow requirements with nonRetryableError - cf durable objects have their own nuances with alarms - cf queues need to ack/retry - cron just logs at the boundary That’s where probably most of integration effort lies
-
Richie Young (@Poor__Old) reportedAn underrated part of doing your own thing is all the tangential skills you learn. Just had a client from last year hit me up because their website was not showing online. Getting a "1001 error". Something about Cloudflare. Site built through carrd. Hosted on namecheap. Both renewed in the past year. Carrd reset to "offline draft". Namecheap added another DNS record. And it toggled ' on for the existing records. Carrd has its own ceriticate of security, so the toggles and extra DNS record were creating a problem. Honestly, I can't speak it the lingo exactly. But I knew the language enough to trouble shoot, find another back door tab in Carrd, and troubleshoot the problem. Site back up this morning. With a little help from the AI lords and the ability to speak(screenshot) the problem, it's all better now. Good start to the day. Especially after the little one was up from 11-2 last night!
-
Joseph Miclaus (@josephmiclaus) reported@Cyberlane That's what I was thinking. One VPS, optionally some Cloudflare services in front of it. Are you using the $4/mo droplet for your experiment server? Do you feel that's enough to run a few small projects with no issues?
-
Oddysey AI (@OddyseyAI) reportedAn agent fleet that watches around the clock has an awkward requirement: Something has to be awake around the clock to run it. We don't run a server. $Oddysey runs entirely on @Cloudflare. → A Cron Trigger fires the sweep every 15 minutes and re-enters the same Worker over a service binding, never taking a trip out to the public internet. → D1 holds every watch, every draft, and the ledger of what was decided. → Per-IP limits are counted at the edge, so our unauthenticated x402 endpoint can't be looped into an outage by anyone who feels like it. No origin. No box to keep alive. The fleet is a Worker that wakes up.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Please, fix human verification
-
Zyte (@zytedata) reportedWhy? Japan never really adopted the Western web stack. No Cloudflare everywhere, no AWS defaults. They built their own CDNs and hosting providers and just... kept using them.
-
UWillC (@uwillc) reportedFour stories from August. One lesson. Cisco: one HTTP request to the VPN service reloads the firewall. Actively exploited. Fortinet: a wildcard setting lets random credentials into the WAF console; a CLI option lets an attacker impersonate a managed FortiGate. Cloudflare: gives AI agents verifiable identities, because "you need to know who sent it." Anthropic: authentication fails, five services degrade within minutes. Different vendors. Same plane: authentication and the management console. Attackers are not chasing your data first. They are chasing your console. Whoever owns the console owns the network. I wrote the same rule a week ago. August keeps proving it: verify, don't trust. The peer, the request, the agent. How many management planes in your estate would pass that test today?
-
Engr Mustapha (@_Engr_Mustapha) reported@juiceboy_of_abj No wonder I wanted to work on one website after buying domain I thought cloudflare was down 🫠 Am using other company for it
-
The dogtor (@scalpelinvestor) reported@Iamhuman_ORBS @Cloudflare Who is using this network. I can’t tell if this is a hype machine of potential or real deals are imminent.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Please, fix human verification
-
Aarsh (@aarshps) reported@arvidkahl One sleepy us-east-1 morning plus a locked Google OAuth login can take GitHub and Cloudflare DNS off the desk together.
-
Blue Pastel (@CoyotlCompany) reportedStopping the bad guys with Cloudflare: 23,495 malicious requests blocked or challenged in the last month #cloudflare
-
Patrick Johnson (@pmjohnson) reported@Cnolanminich Cloudflare Tunnels + Portless is really really nice. <branch>.<repo>.localhost (locally) or <branch>.<repo>.local.<mydomain> remotely. Cloudflare tunnels are authed. I also set up a separate service, so the terminal or agent I'm talking to doesn't end availability the minute I close Codex. It is a different world.
-
Uben (@Ubendev) reported@aiwithadb just shipped the version 4 of my CRM extension. mostly Cloudflare worker issues fixes.
-
developing valhalla (@valhalla_dev) reportedNotably, most technology that has been lifechanging and revolutionary is technology that the average person does not at all care about. The average person doesn't care about Linux, or Docker, or the HTTP protocol, or virtual hosting, or React. They don't have to. They like what comes downstream of that technological progress. So the argument that "AI doesn't matter to most people" is moot, because the downstream effects of AI do matter. Yes, AI People need to stop pretending like AI is going to steal everyone's jobs yesterday, yes they need to stop shoehorning AI into places that don't matter. But the answer to "why should the average person give a damn about AI" is generally "they probably shouldn't." The market is going to get kinda crazy, there is going to be a lot of tumult around data centers and inference buildout, and a lot of new consumer facing and business facing tech is going to be released at an accelerating rate. But the average person shouldn't really have to care about AI, any more than they care about what a VPS is or how CloudFlare Pages work.
-
Ryan K 🌥 (@Yank) reported@steven_levey @Cloudflare Sorry to hear about the issues. If you can submit a ticket and share the ticket number with me I can try to make sure the right people see it.
-
Bijoy (@asynchronizd) reported@juiceboy_of_abj I use airtel and cloudflare ******** are you talking about?
-
Michael Flux (@michaelflux) reportedI don’t use Sentry. I don’t use PostHog. I don’t use any dedicated error-monitoring SaaS. Every single error in my stack - backend, frontend, queues, Durable Objects, etc, lands in Cloudflare Observability the moment it happens. Then a tiny custom toolbar app pings my account every 15 minutes, surfaces any new errors, and I fix them typically within a few hours. Over time the apps just… stop breaking. Here’s the exact system (and why Cloudflare is pretty cool);
-
Jon ONeill (@HouseHackerJon) reportedOn the software company side an issue I’m seeing building with @Cloudflare is that as a start up everything is aimed at @vercel and @supabase, but I’m a big fan of having everything run through Cloudflare once I discovered its system
-
Southpaw | ZZZ Optimizer v6 is LIVE (@Southofpaw) reported@JaIdabaoth Nevermind sorry just checked enka and it’s up. I might need to check cloudflare to see there’s an issue
-
CapyToolkit (@CapyToolkit) reported@h_meow_meow @TeeDevh Actually these cause 2 separate issues. Crawler Hints with Cloudflare caching made thousands of unnecessary URLs to be submitted via IndexNow. Bot Fight mode was blocking legitimate Bingbot and OpenAI IPs (not detecting them as Verified).
-
Phillip Shoemaker (@pbsIdentity) reportedIndia just ordered hundreds of Google Firebase accounts shut down after authorities found scammers using the platform to impersonate major banks. At least 57 Firebase-hosted websites and databases were targeted for takedown this month alone. Some mimicked banks. Others distributed malicious Android apps. Some were designed to steal financial information from phones. Here's what I find interesting. Firebase isn't some shady hosting company operating out of a basement. It's Google infrastructure. That's exactly why criminals want it. We've spent years teaching people to look for obvious signs of scams. Weird domain. Broken English. Sketchy hosting. Browser warning. No HTTPS. But increasingly the attacker doesn't need to build suspicious-looking infrastructure. They borrow legitimate infrastructure. Google. Microsoft. Cloudflare. GitHub. Dropbox. Whatever gives the attack credibility and reliability. Now imagine the average person inspecting the link. They recognize Google. The connection is encrypted. The page loads perfectly. The certificate is valid. Everything their brain has been trained to interpret as: SAFE may technically be true. Except the person controlling the page is a criminal. That's an important distinction. HTTPS proves your connection to the website is encrypted. It does not prove the person operating the website is honest. A Google URL proves Google is providing infrastructure. It doesn't necessarily prove Google created the content you're looking at. The little padlock was never a morality detector. We just accidentally trained an entire generation to treat it like one. India says scammers have increasingly shifted toward Firebase because its legitimate development tools and database functionality make it useful infrastructure for fraudulent sites and apps.
-
Odogwu engineer exploring ML (@slycreator1) reportedBeen doing software for years, but it was just last quarter that I opened a Cloudflare account because of this issue. I insisted on using Cloudflare's free email routing cause it’s only accessible with VPN
-
Jiten Bansal (@bansal_io) reportedI’m building a SaaS where customers will use their own custom domains. Can anyone familiar with Cloudflare for SaaS clarify this for me? The pricing page says $0.10 per additional hostname. Is that $0.10 per hostname per month, or a one-time charge? Any confirmation from someone who has actually used Cloudflare for SaaS billing would be really helpful. It’ll help me choose the right stack for my SaaS. @CloudflareDev @threepointone
-
Cory Wilkerson (@corywilkerson) reportedLove it when I see execs book focus time. For real. I see more of it here at Cloudflare than I have at other places and see it as a bullish indicator that **** is getting done. I suppose what I see of the internal culture here supports my interpretation of that time -- at other bigcos I'd prob read it differently -- but here you know it's go-time.