Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (58%)
- Hosting (25%)
- Domains (17%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 3 days ago |
|
|
Cloud Services | 4 days ago |
|
|
Cloud Services | 6 days ago |
|
|
Hosting | 6 days ago |
|
|
Hosting | 15 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Serriff (@serriff) reported@xbtactics damn i thought we were all buying cloudflare, no?
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
Kene 🐘 (@spatocodex) reported@acolombiadev @Cloudflare Not just generous, Cloudflare is so good. A service you can gladly pay for.
-
Nuvorlane (@nuvorlane) reportedCloudflare AI Gateway monthly usage invoices no longer break out input and output tokens. Previously you got two lines, e.g. 40k input at $0.000001 ($0.04) and 24k output at $0.000005 ($0.12). Now one line: anthropic/claude-haiku-4.5 — $0.16. Model names on invoices and logs also normalize to provider/model, so dated suffixes disappear from the identifier. Credit-purchase invoices are unchanged. If a FinOps parser keys on token line items or version suffixes, fix it before the next month-start invoice lands.
-
Michael Bruno (@brubarian) reported@RockyCapital18 @TMTLongShort Yes - but it's more of a framework because some rx/diligence are on the private side. But big blue arrow: 1. What are the top three pieces of information that I want to have? 2. What role/function would use this data to solve their own problem? e.g., A DoW analyst wants to know where to buy widgets for a Humvee; how would he try to find the answer? Or a gas station owner wants to know how many Poland Spring bottles to order based on expected highway traffic because of the Sturgis motorcycle rally. 3. Which US institutions/think tanks/policy/others have the raw data? (too many to list) 4. Download CSVs, databases, etc. to desktop to isolate it, Claude from hallucinating or pulling information from the internet. (You may have to get a cloudflare/suprabase/*** to help facilitate accelerated use.) 5. Instruct Claude to clean the data sets (this used to be what data scientists spent most of their time on; NaN, void answers, separating street addresses from state, etc.) 6. In clear, concise, simple language, ask Claude to take XYZ categories of data and produce a snapshot to serve a "product manager at company XYZ" or a "credit risk manager at Bank ABC", etc. 7. Adjust and iterate. Force Claude to produce "Tufte" data visualizations. If Claude is left to run linear/logistic regressions, it becomes a science project instead of a problem-solving or illuminating exercise. 8. Force Claude to explore. e.g., take an analogy, "You are a surgeon; this data set is akin to human nervous system, if you were performing surgery, which node, if removed would destroy the utility of the system"? Random questions like this. Analogically map it in unique ways. Claude RL underbelly does nicely here. And as a guiding principle, I'd suggest focusing on being creative. The best definition I've seen is from Bruner: "Creativity is a way of figuring out what you already know in order to go beyond what you currently think."
-
Miget (@miget_com) reportedThen you reach it from outside. Four terminators, and you can run more than one on the same network. WireGuard per person or per machine. Tailscale into a tailnet you already run. Cloudflare WARP into a Cloudflare org. IPsec site-to-site.
-
David T Kramaley (@simplydt) reported@mathieuxtms @whop lean stack wins. we run supabase, cloudflare, and a tiny video‑automation service, staying under 15% of MRR
-
Ryan Chandler (@ryangjchandler) reportedBoth sites get loaded in a headless browser on a Cloudflare Worker. Page weight and request count come from the real network log when the site loads, probably the most accurate way to retrieve this information.
-
Awais alwaisy (@alvaisy) reportedcloudflare workers are definitely not for everything. i spent 20 hours on problem. `give you agent docs`. better alternative to context7. at the time of testing. cloudflare worker 50 subrequest limit crushed it. i've 2 choice now. - abandon it. - move to vps.
-
Justin Liverman (@the_cia_hacker) reportedFunFact: Blackhat hackers put @cloudflare on the map back in 2011 when LulzSec was getting DDoS by @th3j35ter and @eastdakota decided to not drop them as a customer they became the defacto DDoS protection service forever after this
-
Gaylord (@laolu_afolabi) reported@lanreadelowo From Claude: """ Technically, yes — it's buildable, and "platform-agnostic" is realistic because most providers and gateways (OpenRouter, LiteLLM, Portkey, etc.) have already converged on an OpenAI-compatible schema, so a routing layer that swaps providers behind one endpoint isn't a huge engineering lift. But there are a few things in the premise worth stress-testing before you build. **The "discount arbitrage" framing is a bit shakier than it sounds.** Most of these gateways aren't reselling models at a discount — they're reselling at close to list price plus a fee. While OpenRouter states it doesn't mark up inference pricing, its credit purchase fee effectively acts as a surcharge on all usage. LiteLLM's pitch is the opposite direction — zero markup by self-hosting, with OpenRouter's ~5% fee costing meaningfully more at scale. So the "discounts" you'd be arbitraging are less "provider A is cheaper than provider B for the same model" and more: rate-limited free tiers, short-lived promos, or BYOK arrangements — OpenRouter's BYOK is free up to a monthly allowance before a 5% fee kicks in. Those are real, but they're capacity-constrained and often disappear once volume shows up — hard to build a durable business on chasing them. **The bigger product risk: tokens/models aren't fungible.** Swapping Gemini for Claude for GPT under one endpoint isn't like arbitraging cloud spot instances — different tokenizers (so "$/token" isn't apples-to-apples), different tool-calling formats, different output style and capability. If your router silently reroutes a customer's traffic to whatever's cheapest this hour, you can quietly degrade the app built on top of it. That's the actual hard problem, not the proxying. **What's actually working in production right now is narrower than blind price-routing:** AT&T processes tens of billions of tokens a day using cache-aware routers that send simpler tasks to cheaper models, cutting costs up to 56% with only ~2% quality degradation, and this "model cascade" pattern — cheap/fast models handle the default case, only escalating to a frontier model when a confidence check fails — is used by both AT&T's LiteLLM-based router and Databricks' Smart Router. That's routing by task-fit with cost as a constraint, not routing purely by whoever's running a promo this week. **Competitive landscape is already crowded**: OpenRouter, LiteLLM, Portkey, Requesty, Helicone, Not Diamond, Martian, TrueFoundry, Cloudflare AI Gateway, Ofox all do some flavor of unified-endpoint routing today, several with automatic fallback/cost-based rules already built in. Pure discount-hunting is a thin moat — anyone can scrape pricing pages, and providers may treat aggressive arbitrage-only usage as a ToS problem. Where I'd actually look for a wedge if I were you: quality-aware routing with an audit trail (so teams can trust that "cheaper" didn't mean "worse" for their specific task), rather than price-only arbitrage. """
-
Chris Locke (@chrisjlocke) reported@SportingNest @DaveLukewski @Cloudflare No it didn't. Just posting engagement bait crap.
-
Hanif Carroll (@HanifCarroll) reportedAt a previous job, I was lucky to work with a staff-level front-end engineer who was very good at what he did and thorough like no one else I had worked with. I didn’t always appreciate that thoroughness. At first, I found it maddening. Meetings with product and design would drag on because he always had an enormous list of questions about whatever feature we were discussing. I was usually eager to finish the meeting and start coding. It took me a while to understand that he wasn’t making the process longer. He was asking the questions we would otherwise have to answer halfway through development, when an unanswered question could block the feature or send it in the wrong direction. Every unanswered question holds an assumption, and that assumption might not match what product or design had in mind. I thought about him recently while reviewing the search process for Casamo, a product I’m building to help people compare furnished stays. Before changing the code, I started asking questions: Why were we processing listings already known to be over the user’s budget? Why were hotel-like properties entering the process when the user had asked for an entire place? Why did we stop after finding six suitable stays if ten were available? How old could a review be before it stopped being useful evidence? Those questions exposed decisions that had been made when Casamo ran on a low-powered VPS and needed to do as little work as possible. They didn’t all make sense now that the product runs on Cloudflare. We changed the search process to reject known mismatches earlier, treat six results as the minimum rather than the target, continue until it finds ten suitable stays, and only use reviews from the previous year as evidence. If I had started coding immediately, I probably would have made the existing process faster without questioning whether it was still the right process. I don’t know if I’ll ever have as many questions as he did, but now I understand what he was protecting us from.
-
Dave Bettin (@dbettin) reported@dillon_mulroy @EffectTS_ Where is the cloudflare support?
-
Bryan Beal 🎧 (@bryanrbeal) reportedPro tip - disable Eero’s DNS and use Google or Cloudflare DNS and 99% of Eeros problems disappear Eero DNS is trash
-
Alex Betok | PolyViper (@alexanderbetok) reportedStopping the bad guys with Cloudflare: 1,714 malicious requests blocked or challenged in the last month #cloudflare
-
COLLINSEO (@alexcollinseo) reportedBreaking news! Your site might start blocking AIs from September 15th.. And if you block them, you won't show up in AI answers. The good thing? It takes a sec to unblock! This setting is inside Cloudflare. You might not even know your website uses Cloudflare because it works in the background as a CDN, helping your website load faster. If you check your website using the tools I mention, you can find out whether Cloudflare is being used on your site. Cloudflare seems to have taken this step because of how AI companies are crawling websites, and honestly, I don't completely disagree with the reason behind it. But having AI crawlers automatically blocked from September 15 could be a problem if you want your business to appear in AI answers. The setting is inside Security Settings. Look for the AI crawler control and make sure it is set to allow rather than block. This is especially important if AI visibility is part of your strategy. With one of my clients, we went from zero to around 500 visitors from AI traffic in two months. And what I did was exactly what I explained in the video. If your AI crawlers are blocked, you're potentially closing the door on that traffic before it even has a chance to reach you. #SEO #DigitalMarketing 👇🏼 Comment VIDEO for the FULL VIDEO BREAKDOWN
-
manny shaw (@MannyShaw) reported@0xAdesola 1.1.1.1 does not block malware or phishing. For that, use 1.1.1.2. DNS generally cannot unblock geographically restricted streaming services. That normally requires an authorised VPN or Smart DNS service. It cannot increase your broadband speed. It may make the beginning of website loading slightly quicker if your ISP’s DNS is slow. AdGuard DNS blocks many domain-based advertisements, but not every advertisement. It usually cannot reliably block YouTube, Instagram or advertisements served from the same domain as the content. Parental DNS is useful but not foolproof. VPNs, encrypted DNS, mobile data and some apps can bypass router-level filtering. How to change DNS on your router While connected to your home Wi-Fi, open a browser. Enter one of these common router addresses: 192.168.1.1 192.168.0.1 192.168.29.1 192.168.100.1 The correct address is often printed underneath the router as Router IP, Gateway or Web GUI. Sign in using the router’s administrator username and password. This is not necessarily your Wi-Fi password. Check the router label or your ISP’s documentation. Before changing anything, take a photograph or screenshot of the existing settings. Look for a menu called: Internet or WAN Network DHCP Server LAN Settings DNS Settings Disable Automatic DNS, Obtain DNS automatically, or DNS from ISP. Enter your chosen pair. For general family protection, I suggest: Primary DNS: 1.1.1.3 Secondary DNS: 1.0.0.3 For advertisement blocking instead: Primary DNS: 94.140.14.14 Secondary DNS: 94.140.15.15 Do not mix servers from different providers; otherwise filtering may become inconsistent. Tap Save/Apply and restart the router. Disconnect and reconnect your devices to Wi-Fi, or restart them. Cloudflare confirms that router-level configuration normally applies the DNS setting across connected devices.
-
AR GamingPK1 🇵🇰 (@argamingpk1) reported@DanielZahoor But Cloudflare DNS routing is so bad.
-
Harlen Bayha 🇺🇸 (@QreatureQriator) reported@mrfundman @Cloudflare Did it work with Outlook emails? My bots struggle with Outlook's interface so bad.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Daniel Zahoor (@DanielZahoor) reportedSet your router DNS to 1.1.1.2 and 1.0.0.2 to block malicious sites across your Wi-Fi. These free Cloudflare addresses silently block scams and phishing on every device. You get network-wide protection with zero software to install or manage.
-
Adsy (@adsydeveloper) reported@backblaze Dashboard having issues? Cloudflare errors indicating host down (and was ~20s response time just before)
-
Hauber 🇵🇸 (@HauberDevs) reported@AlexaIs60635 @James_inthe_box absolutely ******* terrible take. Cloudflare literally powers 10% of the internet. Plus alot of services use AWS, if you block that you would essentially be locking yourself out of a good portion of the internet
-
volkanolmez (@volkanolmez) reported@xDestin0 That's almost always a local proxy or antivirus doing SSL inspection — the cert itself is valid (Google Trust Services via Cloudflare). Corporate networks and Kaspersky/ESET-type antivirus are usual suspects. Any chance you're on a work network? 🙏
-
Dr. Internets (@Dr_Internets) reported@spacebruce @alynokioku Hello, I am Albanian cloudflare. Due to poor technology, I need you to paste this totally real command into your admin command prompt. Very real, trust.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Security Weekly Podcast Network (@SecWeekly) reportedThat CAPTCHA may not be protecting you. A click-fix attack can use a fake Cloudflare CAPTCHA to convince users to open PowerShell or Terminal and paste a command themselves. Once the command runs—especially with administrator privileges—the attack chain can begin. What should organizations block before social engineering gets a user to execute the attack for them? #Cybersecurity #PowerShell #SocialEngineering
-
McCallum (@BK_McCallum) reported@imjeremytho @georgeregnery @stelzner_n1150 I 100% agree that the claim maker bears the burden. And I 100% stand by what I said: Your own laziness is the reason you're in this predicament. "Netcraft’s monthly survey shows the web adding roughly 550k–640k net new sites per day. Total hostnames sit around 1.43–1.47 billion. Verisign’s latest Domain Name Industry Brief puts registered domains at 401.6 million, up 8.1% year-over-year. Cloudflare Radar recorded 19% global traffic growth in 2025. Telegeography and ITU numbers show international bandwidth and fixed-network traffic still compounding in the low-to-mid 20s percent range even before you count extra AI crawlers. IDC DataSphere (via Statista) has annual data created at 181 ZB in 2025 and 221 ZB projected for 2026. Consumer cloud storage is a $15B market growing ~17% CAGR; photos alone are 1.72 trillion a year and most of them go to the cloud."