1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 37% Cloud Services (37%)
  • 26% Domains (26%)
  • 21% Web Tools (21%)
  • 11% Hosting (11%)
  • 5% E-mail (5%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 10 days ago
Los Angeles Cloud Services 11 days ago
Paris Cloud Services 27 days ago
New York City Hosting 29 days ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • junaid_1460
    /home/junaid (@junaid_1460) reported

    I am finally paid @Cloudflare customer, I will pay 5 dollars now. Someday I will pay 5k.

  • _Edeb
    Edeb (@_Edeb) reported

    @Majora__Z @p_e_t_e_r_s_e_n Cloudflare’s Sept 15 change is bigger than it looks. They’re flipping the default: AI training crawlers get blocked on any page that shows ads, and multi-purpose bots like Googlebot (which still does both search indexing and training data collection in one) get caught in the same net unless the site owner manually opts out. That means a huge chunk of the web — especially free-tier and new sites on Cloudflare — could suddenly stop letting Google crawl them. Implications in plain terms: Google’s index starts going blind on large parts of the internet. Search results get thinner, older, and more reliant on whatever they already have cached or on AI summaries that never send traffic back. Publishers finally get real leverage. They can protect their content from being vacuumed up to train models that compete with them, without (in theory) fully disappearing from search — but only if they carefully configure the settings. Most won’t. A lot of smaller sites will just let the default ride and vanish from Google. Users will notice it slowly: more “no good results,” more AI answers that feel hollow, more content locked behind logins or paywalls because free crawling no longer makes economic sense. The open web’s old deal is dying. For thirty years the bargain was “crawl everything for free and send traffic back.” That deal is broken. Cloudflare is forcing the next phase: either separate your crawlers cleanly, pay for access, or get locked out. It’s not the end of the internet. It’s the end of the free-for-all version of it.

  • BaigengXIV
    Soggy (@BaigengXIV) reported

    @iyici_ @wikimapper The us courts determined Google to be a monopoly, then instead of breaking it up said "**** it, Google is too big. We'll do nothing instead". I think Google would be fine to buy cloudflare lol

  • dump_tcp
    tcpdump (@dump_tcp) reported

    @ashleypeacock still a issue for ddos attacks #cloudflare charges for requests so if request limit is reached then the website will display a error saying it's plan ran out of limits or requests

  • OlvidateTWT
    Benjamín Ortiz (@OlvidateTWT) reported

    @charlietlamb namecheap = poor godaddy = uncle vercel = poser cloudflare = tech people

  • BigwetRealism
    h index enjoyer (@BigwetRealism) reported

    getting real tired of hitting cloudflare issues on @biorxivpreprint even tho I'm not a bot!!!!

  • dummdidumm_
    Simon H (@dummdidumm_) reported

    @tnkuehne We ditched using the environment API to its fullest for now, because it adds too much complexity and maintenance for appeasing essentially one runtime (Cloudflare). But we'll still have much better support for it with deep dev time integration, just through another way. PR soon.

  • pepeller
    Pedro Pellerini (@pepeller) reported

    @synopsi @Cloudflare As bad as AWS? Have you ever used AWS??

  • TherealUDP
    Udit (@TherealUDP) reported

    I'm cryin dude saw a classmate flexing on story his kali linux with four terminals open using hping3 flood on a cloudflare hosted game server bragging he can down any game server/wifi he wants

  • techdreamergc
    Lucas Gray-Joy (@techdreamergc) reported

    @HedgieMarkets I think it's an incentive problem. Cloudflare profits from bot traffic. Proof-of-personhood could create a verified human layer, but nobody running the pipes has reason to build it.

  • inababi
    Salina Mendoza (@inababi) reported

    @burcs But also…..can you please fix the papercut where you implement auth for the first time…a user signs up with Cloudflare access but emails are scanned. So you can never get in because one time code is used by email scanners. Its been such a nightmare & only got around it 1x

  • Jamie1Coutts
    Jamie Coutts CMT (@Jamie1Coutts) reported

    Things have been quiet. x402 daily settlement volume is down 93% year to date after the Q4 2025 testing wave died off. Reality check on the "agentic economy is here" narrative. But the recent Cloudflare just made it a lot more real. On 1 July they launched Monetization Gateway, letting any customer charge for a page, API, dataset, or MCP tool, priced at the edge and settled in stablecoins via x402, with Cloudflare handling metering and settlement itself. It's the expansion of their old Pay Per Crawl feature, which only charged AI bots, to charging any caller, human or agent. Agentic activity should start ticking meaningfully higher alongside increased harness usage in Q4.

  • introsp3ctor
    Mike Dupont (@introsp3ctor) reported

    @zekramu well you need to make your sessions portable and i assume you have more than one node. I think that cloudflare in front should help. but for zero downtime you will need more than one node. libp2p should help as well.

  • dwinity_eco
    Dwinity (@dwinity_eco) reported

    @signalapp @Cloudflare the math was never the weak part. the key directory was. every e2e messenger asks you to trust a server handing out keys, and apple shipped contact key verification in ios 17.2 for exactly that. verification you have to remember to do is verification nobody does.

  • planedrop
    Ethan Word (@planedrop) reported

    @BleepinComputer @karakeep_app any chance yall can make the Bleeping Computer RSS feed work with Karakeeps RSS fetcher? Maybe a user agent issue and Cloudflare getting in the way?

  • DracoMenda
    Dracomenda ⟐ (@DracoMenda) reported

    and with things like *** lab, static page containers, wireguard, and OpenWRT, you can do a lot of the same stuff Cloudflare does off an old laptop and a crap router out of your closet.

  • KentonVarda
    Kenton Varda (@KentonVarda) reported

    OK I did some very unscientific testing of Cloudflare OS using a variety of ~30B models running locally in ollama. My "benchmark" here was asking them each to write a collaborative whiteboard app. I found: Muse Glimmer, Gemma 4: These both basically work. Certainly not as well as frontier models but with a few rounds of feeding errors back into the agent they get the job done. Qwen 3.6, Nemotron 3.5 Lightning: These models seem to basically understand the assignment but go completely off the rails before they can get the job done. They keep failing tool calls, hallucinating APIs, and generally writing code that doesn't work. They are, uh, very fast though! Like 4x as fast as Muse and Gemma! Maybe useful for non-code tasks? idk. Are there others I should try? Note: If you are trying this, make sure you have bugfix PR #157.

  • suat_tw
    Suat Özkaya | AI & Mobile (@suat_tw) reported

    4/6 AAIF brings competing companies to the same table. OpenAI, Anthropic and Block co-founded it, with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. That is a meaningful signal: agent infrastructure is becoming too important to remain fragmented.

  • Arxonic
    Daniel (@Arxonic) reported

    @gregisenberg @Cloudflare 7/ Startup Idea #2: Agent Readiness Audit Sell "agent readiness" to businesses. Show the founder exactly what AI says about their company today. Most will be horrified. Fix their structured data, MCP endpoints, and payment rules.

  • aaliya_va
    Aaliya (@aaliya_va) reported

    Let me break out a news: your next audience may not be human. Cloudflare expected AI agents and bots to outnumber people online in 2027 but we know this happened much earlier. Radar data showed automated traffic had passed human traffic in HTML webpage requests as agents browse, fetch and act at scale. Now all this is going to change the content game. Your work no longer competes only for a human scroll. It may first be read, summarised and recommended by an AI system. That makes generic content riskier. If every AI founder says “AI is transforming work,” machines and people have little reason to remember them. The answer is not to write for bots rather It is to write with greater clarity. >name the customer, problem, workflow and proof >Share real observation instead of borrowed opinions >build a body of work that sounds like the founder and gives agents something accurate to understand That is the new content strategy. The future of content is not louder posting. It is sharper thinking, clearer positioning and a voice that cannot be generated from the same prompt as everyone else.

  • harsh_biz
    Harsh (@harsh_biz) reported

    The deliverability meta going into Q4 2026 is different from what worked in Q1. If you're still building infrastructure the way you did at the start of the year, you're going to feel it next quarter. SURBL made a lot of noise this quarter. Cold email inboxes got flagged in batches, everyone scrambled, and the enforcement has already lost most of its teeth. But the fixes are still the right build. Not because SURBL is going to catch you. Because when you build this way, there's almost nothing left for any ESP to pattern-match against. SURBL won't be relevant soon from what I think. You're no longer defending against a specific list. You're removing the mechanical fingerprint that makes automated detection possible at all. Practically: Keep domains to 20 per registrar account, 50 at the absolute ceiling, spread across multiple accounts. Once your domains aren't clustered, there's no cluster to flag. Stop naming them [Company]aa, [Company]ab, [Company]ac. Branch out entirely instead. If the brand is Milbridge Capital, use Milbridge Advisory, MBCapital, MilbridgeGroup, or drop the brand pattern altogether and use unrelated professional-sounding names. Older domains with genuinely varied names get listed far less often, and that holds regardless of which blacklist happens to be active. Placement tests are dead. They were reliable in early 2025. They aren't now. You can score 100% inbox placement on a test and pull a 0% reply rate on the live campaign the next day. Replies are the only trustworthy signal left. Build your monitoring around reply rate at the sender-email level, excluding auto-replies, and pull inboxes when they drop below threshold. Masking beats redirects, and both beat nothing. Redirects have visibly hurt deliverability this year. Dead domains hurt too, because prospects check the domain and expect a real site. Build masking through Cloudflare Workers rather than paying a markup for it. One free Cloudflare account holds around 80 domains. Your lead source is now a deliverability factor. Cheapest leads reply the least on average, and low reply rates suppress sender reputation. That's not a relevance problem, it's an infrastructure problem. When a campaign starts dying, diagnose before you rebuild. If two or three campaigns trend down at once, it's the copy. Rotate it. If you rotate the copy well and nothing recovers, it's the inboxes. Fix the wrong one and you burn another month.

  • CoderLuii
    CoderLuii (@CoderLuii) reported

    @pcshipp cloudflare pages. static hosting is free, and having workers + d1 in the same place meant i never had to stand up a separate backend for the control plane

  • murdok_gg
    murdok (@murdok_gg) reported

    (would you believe that i only spend $70 on groceries per week, but i splurged by buying 2 domains for $25 for a year a piece?! omg its crazy that cloudflare can sell at cost from a reg that people like, customer service is interesting these days...)

  • truehannan
    Hannan (@truehannan) reported

    @corbin_braun I also got $10k credits last week. But im honest, you will never complete a small percentage of it in the year. The reason is that cloudflare products are soo cheap. Until u use workers ai models

  • lorenzolfm
    Lorenzo (@lorenzolfm) reported

    I've been thinking a lot about the recent @BtcpayServer vulnerabilities over the last few days. IMO, they also shed some light on other architectural and design issues in the application. I want to talk a little bit about them in this post. First, if you run BTCPay Server, please: - Upgrade to 2.4.2. - Rotate your LND credentials if you use LND. Treat the old ones as compromised. Also, I want to make it clear that I have deep respect for the project and its maintainers. I know how hard it is to ship safe software. Sometimes lessons are learned the hard way, and it really sucks when that happens. Okay, back to the topic. Here are some things I think could be improved: 1. Different server bindings for user-facing and admin features The goal of running a BTCPay Server instance is to accept Bitcoin payments. This means you have to expose the application to some network. Either a LAN if the merchant has a physical store, or the internet if it's an online store. As the app works today, exposing your PoS also means exposing all of the admin-facing features of the app. A customer can access /apps/appId to make a payment, but they can also access /login, the page that prompts for a username and password to access the admin interface. This means that users have to go out of their way to block public access to the admin interface. This could mean using local firewall rules if it's a LAN-exposed application, or Cloudflare WAF rules if it's exposed to the internet. And you have to configure those rules correctly. There are plenty of ways to shoot yourself in the foot: you could accidentally block legitimate URLs, forget to block something, or introduce another misconfiguration. This could be easily avoided by having separate server bindings for user-facing and admin-facing features. So instead of users having to worry about firewalls, they could simply expose the PoS binding and not the admin one. 2. Make sensitive features opt-in BTCPay Server has an API that can do almost everything the web UI can: create invoices, manage stores, create payouts, access wallets, etc. This is very useful for tech-savvy people to build custom software on top of the application, but it's a niche use case. Most people will just use what BTCPay Server already provides. From what I could tell on my own instance, there's no way to turn the API off at all. I'd argue this, and other sensitive features, should be opt-in rather than enabled by default. 3. Passwords shouldn't work as API credentials BTCPay Server has a really nice feature that lets you grant 46 different permissions to an API key. But you can also authenticate API calls with your username and password, and that method bypasses all of them. You get everything your account can do. My take is that basic authentication should never have been possible in the first place. An account password is a human credential. An API key is a machine credential. They shouldn't be interchangeable. Machine access should always require a credential that you deliberately created for that purpose. 4. Don't display sensitive data in plaintext When you connect BTCPay Server to a Lightning node, you give it a macaroon. It's sort of like a password with specific permissions baked into it. The problem is that the store settings page displays the entire connection string, including the macaroon, in plaintext. So if someone gets access to your admin UI, they don't need to do anything clever. They open one page and can read your Lightning credential straight off the screen. The same applies if you use a hot wallet. BTCPay Server stores the seed in its database, and you can view it through the UI. Credentials should be write-only. You paste them in once, they get masked, and that's it. If the application really needs to show a credential again, make me re-authenticate first and log the event in the database so it's traceable. 5. Audit Logs. In case **** happens, is very useful to be able to know what exactly happened. Which credential hit what API? When? What was the IP of the caller? Was it an inside job? was it a credential leak? was I drunk and pressed the wrong button? --- Please take all of this with a grain of salt. I had no involvement in building this software or in the decisions that made it what it is today, and it's very likely that some of what I pointed out has a good reason behind it that I can't see from the outside. This is just a comment from a user who is very paranoid about the software he runs. If I could be granted one wish, it would be splitting the customer-facing binding from the admin-facing one. That alone would be a huge security improvement, and it seems like a low enough hanging fruit.

  • heyjumanji
    jumanji 𝕏 (@heyjumanji) reported

    Hi @CloudflareHelp @Cloudflare i lost mt access to my cloudflare account and also lost my 2fa codes can you please help me to get back my account.

  • Arxonic
    Daniel (@Arxonic) reported

    @gregisenberg @Cloudflare 9/ The Filter for Finding Ideas Ask yourself: • What decision is expensive? • What information is messy? • What changes often? • Who already pays for help? • What would an agent need to do the job better?

  • aiproductguy
    akshat (@aiproductguy) reported

    @CloudflareDev @CloudflareHelp @Cloudflare Please help!

  • nicklaunches
    Nick Launches (@nicklaunches) reported

    Cloudflare shipped a scoreboard for AI recommendations last week. It probes Claude and GPT with the questions your customers actually ask, Then reports how often you get cited, how early you land in the answer, And your share of voice against competitors. The gap it closes is the one nobody could see. An assistant recommends someone else, the customer never reaches your site, and nothing anywhere records the loss. Their readiness checklist is boring on purpose. robots.txt, a sitemap, AI crawler rules, clean Markdown for agents. Low bar. Almost nobody has cleared it 👀

  • aakashgupta
    Aakash Gupta (@aakashgupta) reported

    On September 15, Cloudflare will start cutting off Google traffic for millions of its smallest customers by default. And those customers won't leave. They've been begging for this. The story starts with AI Overviews. Google began answering questions directly at the top of search, using content scraped from recipe blogs, how-to sites, and product reviewers, then sending them a fraction of the clicks. One recipe blog called the arrangement a hostage situation. Sites are looking at their traffic charts and realizing the thing they were afraid to lose is already gone. So this was never the death of the internet. This is publishers going to war with Google, and Cloudflare, which sits in front of roughly 20% of the web, just became their army. Peel back a layer and Cloudflare's move gets smarter. They aren't technically blocking Google at all. The new rule blocks any crawler that does both search indexing and AI training in one bot. Googlebot is exactly that bot, one front door for both jobs, which is why nobody could ever block the AI half without losing the search half. Cloudflare's message to Google is simple. Split the bot. Keep search separate and we'll allow it by default. Keep the bundle and our network treats you like a scraper. Which makes this a $107B company dictating terms to a $4.2T one. Cloudflare is 1/40th of Google's size, betting that controlling the pipes beats owning the index. Now we find out if David can make Goliath blink.