Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (29%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 11 days ago |
|
|
Hosting | 14 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
T_T🏴☠️XMREscrow (@xmrescrow) reportedThings people usually have to take on faith, that you can check here: Our node relays every transaction through Tor, so payouts do not enter the network from a clearnet address tied to this service. We do not store IP addresses. Anti-abuse uses a keyed HMAC that cannot be reversed. Web-server error logs can hold an address transiently and are deleted within two days - it is on our legal page because saying "we log nothing" would be a lie. No accounts, no email, no KYC. An escrow is two private links and a PIN each. The onion carries no third-party code at all. The clearnet is Cloudflare-fronted for DDoS and we say so
-
Grant Mucha (@grantmucha) reportedOrdering $50,000 in server hardware today and reflecting on a post I read earlier that asked, "Why is it so difficult to build a genuinely good X, Y, or Z, and why do so many products remain 'good enough' for half a decade without ever becoming great?" The answer, in most cases, is not capability. It is priorities. One company pushes X, another pushes Y, and another pushes Z, all because each benefits the seller. I see **** like this every day, it's not what's best for the owner, but rather what's best for the seller. In my experience, greed and ego explain a large percentage of mediocre products and services. Companies CAN build something better, take starlink, starship, building quality is a decision. Most prioritize profit first, investors second, and customers last. Take hosting. I do not need to: > Invest in quality servers > Pay 40k per month for Cloudflare Enterprise > License LiteSpeed Enterprise > Include real WordPress management > Promise zero technical debt > Maintain 90 days of redundant backups I could operate with a fraction of that investment and significantly increase my companies profit. I choose not to because I know exactly how this industry operates. I know companies still running production servers from 2013 on outdated kernels. Can they upgrade? Absolutely. Will they? No. Most people are not aware that Cloudflare Enterprise is modular. Contracts are assembled like Lego blocks. One company may technically offer "Cloudflare Enterprise" with a single component, another may have a handful, and others may have more than 100 enterprise features and configurations enabled. All of them advertise the same label, yet they are not remotely the same product. Now consider the customer's side. Within 48 hours, I can move a business owner into what is effectively a top 1% WordPress hosting environment, complete with real WordPress management, for $1,490 per year or about $124 per month. Consider for a moment that some companies charge $200/mo or more for WordPress management alone, and let that sink in for a minute. No technical burden. No infrastructure management. All existing technical debt resolved. Full WordPress management. No worrying about backups, performance, security, updates. etc. Owners focus on business, and for $124/mo, this is a joke to the vast majority making money, every day, 365 days a year. Circling back to mindset, I believe the people who fail to see it are often operating from the same greed-and-ego framework. They have to sell X, so they recommend it to everyone relentlessly, whether it's right or not. And the why is simple! It comes down to what you choose to prioritize, the decisions you make, and whether you are willing to put quality ahead of profit. More importantly, it is whether you are willing to put the customer ahead of yourself and your business, and prioritize a genuine win-win relationship. At which point, I believe there is no limit in business.
-
JeromeTheDJ (@JeromeTheDeejay) reportedCloudflare verification pmo so bad let me click through links stop slowing me down *****
-
Panat (@ptaranat) reported@LevJampolsky @Teknium you're better off implementing a simple version of this. give each trust tier its own hermes profile with toolsets stripped in config (platform_toolsets, agent.disabled_toolsets). then you expose only the api_server, and let ur own app authenticate the user and broker ever call. hermes' shared API key reads every session on the instance so it never accepts a session ID from a client. you'll want to map the user to the session in a DB and translate server side. and also put a Cloudflare Tunnel + Access service token in front so the agent host doesn't open any inbound ports. something like this took me one afternoon.
-
na na (@make_dope_stuff) reported@cloudflare i'd love to buy a domain right now... but it keeps asking me to "refresh the page to try again" thought I'd go to /support and of course that's also "refresh the page to try again"
-
Colin Son (@txmedai) reported@ptremblay Yes Cloudflare is very good. And free tier is amazingly generous. Isnt quiet idiot proof (why do I have independent turnon AI gateway or R2 or all these individual features) but at least there’s not a million layers of IAM. GCP and AWS are fine
-
brendan (@brendonovich) reported@thdxr i've never used cloudflare until alchemy existed, i'm scared of wrangler configs
-
Dr. Gonzo (@N3DrGonzo) reported@AnisDrawn PSN goes down more often than CloudFlare. And CloudFlare has an outage QUOTA. But yes, please tell me how an all digital ecosystem for a console is a good thing.
-
Informer |-/ (@_Nformer) reportedI love how half the comments are just people who get salty when Cloudflare goes down and the other half are mad about Cloudflare having a monoply.
-
chrißy (@chribdotnet) reportedi need to set up cloudflare today and honestly cloudflare scares ******** out of me if i could make my own cloudflare i surely would but i just learned about /POST last night all this **** is easier than i expected ngl but still hard
-
Milk Road AI (@MilkRoadAI) reportedNvidia just launched a security alliance with over 30 companies and OpenAI and Anthropic didn't join the party. The Open Secure AI Alliance brings together Nvidia, Microsoft, Cisco, Salesforce, Palantir, IBM, Cloudflare, CrowdStrike, Hugging Face and dozens of others to build open source cybersecurity tools specifically for AI agents. The actual trigger for this was a real incident. When Hugging Face got hit with a security breach, its closed AI security tools couldn't tell the difference between the attacker and the defenders trying to investigate so those tools blocked the forensic analysis Hugging Face needed to actually contain the intrusion. Hugging Face had to switch to an open weight Chinese model, GLM 5.2, running on its own infrastructure, to analyze more than 17,000 actions and shut down the breach. That's the case study Nvidia is using to argue closed AI security tools have a structural blind spot. If a defender can't inspect and modify the model doing the defending, they're stuck waiting on the vendor during the exact moment speed matters most. The alliance's core argument is that AI agent security depends on the entire stack like identity, permissions, guardrails, logs not just whether the underlying model's weights are open or closed. Each founding member is contributing a specific piece. Nvidia is open sourcing models and a new agent harness framework called NOOA, Hugging Face is contributing its Safetensors format to prevent remote code execution, Microsoft built a multi model bug hunting scanner, and HPE is contributing zero trust identity standards. Now, why aren't OpenAI or Anthropic in this. This entire initiative is built around open weight models and open tooling as the foundation of AI security, and OpenAI and Anthropic's core business model depends on the opposite, keeping their frontier models closed and proprietary. But to be fair there's also a competitive angle worth naming. Nvidia sells chips to everyone, so it has no downside to championing an open ecosystem where more companies build and compete on top of open models, since Nvidia gets paid on compute regardless of who wins. OpenAI and Anthropic, by contrast, are trying to build durable moats around their specific models and joining an alliance that treats open weights as inherently safer would undercut the entire pitch they make to enterprise customers about why they should pay a premium for a closed, controlled system.
-
Jerry Combs (@PointBlueTech) reported@PH0ENIXSMITH @thdxr Exactly. I never have to do anything in CloudFlare myself.
-
Ayush Chugh (@aayushchugh) reportedA few days ago, our login API experienced a DDoS attack. This triggered a high volume of SMS notifications, resulting in unexpected operational costs. Although we had IP-based rate limiting in place, the attack was highly coordinated, utilizing rotating IP addresses and phone numbers to bypass our initial defenses. To mitigate the immediate financial impact, we temporarily disabled our notification micro-service. We have since implemented a frontend CAPTCHA to verify requests before they reach the server. Additionally, we are configuring advanced Cloudflare rules to better protect our infrastructure against future incidents.
-
Matt (@meszmatew) reportedIs anyone else having issues with cloudflare billing?
-
Mr. Code NJ (@perpetualtalk) reported@bunjavascript Will @Cloudflare fully support bun once released?
-
Janek Mann (@janekm) reported@doodlestein @yzhang390 But that's not really the issue... it's that e.g. Huggingface and Microsoft and Cloudflare and Fireworks can be easily stopped from hosting them with misguided regulation. Literally only harming US companies at the expense of Chinese ones, ultimately.
-
Lewis N Watson (@LewisNWatson) reportedreally appreciate what cloudflare do but the chokehold they have over the internet is net negative. msft have similar issues.
-
Anita Thompson (she/her) (@ltniita) reported@Cloudflare #Cloudflare It's ironic that I can't use your Contact page to connect with you because the "Verify..." captcha not working for me is the problem I need help with.
-
Leo (@0xGKBRK) reported@FuckKoroks It’s not like Cloudflare puts itself in the middle by hacking the website. The person running the website wants to use Cloudflare. If you’re gonna complain to someone, complain to the website that subjects you to that crap. Or vote with your wallet and go to a normal website.
-
Abdulkadir | Cybersecurity (@cyber_razz) reportedOn June 3 2026 Cloudflare CEO Matthew Prince announced that bot and agentic AI traffic had officially surpassed human generated web traffic for the first time in the internet's history. The split landed at 57.5% bot traffic versus 42.5% human traffic. Prince had originally predicted this crossover would happen by end of 2027. It arrived eighteen months early. His response was direct: "Welp, that happened faster than I predicted." The driver is not the old wave of scraper bots and search crawlers. The main culprit is agentic AI. Autonomous programs browsing the web on behalf of AI assistants. A single agent can visit thousands of pages to complete a task a person would finish in a handful of clicks. Agentic AI traffic grew 8,000% across 2025 alone. Now let’***** on the Dead Internet Theory context. The theory, which originated in fringe internet forums around 2021, proposed that most internet activity was already artificial. Fake engagement, bot generated content, astroturfed discussions, AI personas. The humans were the minority and did not know it. The conspiratorial version of that theory claimed it was coordinated and intentional. That part remains unverified and unlikely. But the core observation that the majority of internet traffic is non-human is now confirmed data from the largest internet infrastructure company on the planet. The internet was architected around human usability and attention. The entire world of digital advertising, publisher monetisation, and e-commerce sits on the assumption that users are human. That assumption is now statistically false. Every engagement metric, every analytics dashboard, every ad impression count is increasingly measuring machine activity and reporting it as human behaviour. The business models built on human attention are being quietly hollowed out by traffic that generates requests but never buys anything, never reads anything, and never remembers what it visited. The theory was wrong about the why. It was right about the what.
-
Sam (@Swgtct) reported@ODEONHelp some bizzare reason I have been cloudflare blocked on app and website any ideas or can I just never go to odeon again ?
-
Marius (@MariusdeBeer) reported**2/** The idea: a Cloudflare-native SaaS boilerplate marketplace. Full plan — automated checkout, license keys, GitHub delivery, affiliate program, AI support bot, dynamic pricing. 9 backend modules. Looked like a real business on paper.
-
PaulSD (@paulsd_95) reported@thte857 @FuckKoroks You'd be mad too if your work relies on something online and that critical work got blocked because Cloudflare went down for hours. Wouldn't be surprised if lives were ruined or lost because of it.
-
Alvin (@Alvin1492840) reportedFix 2: He changed the DNS server from their ISP's to Cloudflare's. He asked if they knew what DNS was. They didn't. Nobody does. DNS stands for Domain Name System. Every time you type a website name into a browser or open an app that connects to the internet, the DNS server translates that name into an IP address the numerical location of the actual server. It's the phone book of the internet. Your device asks the DNS "where is Netflix?" and the DNS responds with the address. By default, every router uses the DNS server provided by the ISP. The ISP's DNS works. It resolves the requests. But ISP DNS servers are notoriously slow, overloaded, and sometimes unreliable. Every web request passes through them, and every millisecond of delay compounds across every page load, every app refresh, every stream buffer. He opened the router's WAN settings and changed the DNS from "Automatic" to manual. He typed in two addresses: 1.1.1.1 and 1.0.0.1 Cloudflare's public DNS servers. Cloudflare operates one of the fastest DNS networks in the world. Google's public DNS 8.8.8.8 is another popular alternative. Both are free. Both are faster than virtually every ISP's default. The change applies to every device on the network simultaneously. Every phone, every laptop, every tablet, every smart TV, every game console all now routing DNS requests through a faster server without any individual device needing to be touched. Web pages started loading noticeably snappier. Not because the bandwidth increased the speed test wouldn't show a difference but because the time between typing a URL and the first byte of data arriving dropped by 30–50 milliseconds on every single request. Multiply that across thousands of requests per day across 23 devices and the cumulative effect is a WiFi network that feels materially faster.
-
🇦🇺 Kippykip (@kippykip1) reported@FuckKoroks CloudFlare goes down far less than my site does, so the "always online" cache thing actually works out lol
-
hai (@haikukoten) reportedStopping the bad guys with Cloudflare: 375 malicious requests blocked or challenged in the last month #cloudflare
-
Sachi (@sachi_gkp) reported1/3 🚨 The AI security debate just changed. NVIDIA has launched the Open Secure AI Alliance with 35+ tech companies—including Microsoft, Hugging Face, CrowdStrike, IBM, Cisco and Cloudflare. The message is clear: security is becoming an ecosystem problem, not a model problem.
-
Matt Schober (@migratewithmatt) reportedStopping the bad guys with Cloudflare: 2,176 malicious requests blocked or challenged in the last month #cloudflare
-
Prajwal Tomar (@PrajwalTomar_) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked. (full breakdown in my article below)
-
NetAskari (@NetAskari) reportedBased on that info it quickly builds a list of over 600 python scripts and sh files starting a full chain of recon and exploit measures. It logs all its operations, success rates and outcomes. From SQL Injections, http smuggling, race condition probing, cloudflare bypass, WAF evasion, cache poisoning etc. Its attack angles are pretty wide. None of the scripts or methods seems particularly clever but if a 'fire and forget' solution is what you are looking for, than this is not too bad. 4/6