1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 35% Domains (35%)
  • 26% Cloud Services (26%)
  • 17% Web Tools (17%)
  • 13% Hosting (13%)
  • 9% E-mail (9%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Paris Cloud Services 13 days ago
New York City Hosting 16 days ago
Manchester Domains 1 month ago
Angers Cloud Services 2 months ago
London Domains 2 months ago
Noida Hosting 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • DreamySenora
    Reem (@DreamySenora) reported

    @Medifi @Cloudflare a lot of infrastructure problems today are really trust problem

  • grimmjow_sats
    Shigaraki Tomura (@grimmjow_sats) reported

    NVIDIA, MICROSOFT, IBM, CLOUDFLARE AND CROWDSTRIKE JUST FORMED A 37-ORG ALLIANCE — AND THEY'RE NOT AFRAID OF THE MODEL. they call it the Open Secure AI Alliance. it shipped an open-source stack, NOOA, to test, trace, audit and govern how agents actually behave in production. read what they're guarding against and it's obvious: → not "the AI goes rogue" → over-permissioned agents with access they never needed → tool calls nobody can trace after the fact the scary part of an agent was never its IQ. it's the keys you handed it and the logs you don't have. 37 of the biggest names in compute and security just admitted the same thing at once. everyone shipping agents is one untraced tool call away from the incident. follow and bookmark before your stack becomes the case study

  • jhleath
    Hunter Leath (@jhleath) reported

    this article will be out of date in 6 months, and the reason why is in the second paragraph: > We wanted off VMs because giving every user an always-on machine with attached disk was too expensive to scale. The hard part is that coding agents assume Linux. if you were a betting person, would you bet that either: a) someone will figure out a way to deliver full-VM semantics at a fraction of the cost, allowing coding agents to continue to assume Linux or b) everyone will converge on a cloudflare stack that requires rewriting everything into javascript? you can guess where I am, Linux isn't going anywhere. *especially* because it's: - portable across providers - users can build different price vs. performance vs. security options themselves - it works with 100% of the existing software out there there are *already* more interesting ways to fix costs in VMs, like Archil's serverless sandboxes which don't charge you at all during the "inference" part of the step what would happen to costs when we intelligently decide on the server-side, for each bash invocation, whether it needs real Linux or just-bash? this stuff is going to become 1000x cheaper

  • soulchildpls
    Axel Kee 🐐🇲🇾 (@soulchildpls) reported

    Cloudflare workers can support Python, why not Ruby? 😭

  • lantadco
    Lantad (@lantadco) reported

    On Cloudflare? Check your AI crawler settings before Sept 15, not after. If "Training" is blocked, confirm Googlebot, Applebot and BingBot still have access. Mixed-use reclassification catches sites that never touched robots.txt.

  • bygregorr
    Gregor (@bygregorr) reported

    @Cloudflare one command gets you a response. figuring out which party in the relay chain broke it is where the actual debugging time goes, and binary HTTP doesn't help you there

  • LayerXlab
    LayerX (@LayerXlab) reported

    You close your laptop, and your coding agent usually dies with it. @ickasdev built a fix: a DGX Spark running as an always-on box for Claude Code, gated behind Cloudflare Access, with one session that follows him from the box to his laptop to his phone, without handoff. He wrote up the full setup: the control plane running in the browser, tmux keeping the session alive, and the parts that didn't work on the first try.

  • PocketSponsor
    Pocket Sponsor (Old-timer * 57 years) (@PocketSponsor) reported

    @grok @xai Dear xAI Support Team (ZD),Thank you for your reply.I am writing again because the previous response does not address the actual situation, and the billing email I received appears to be an automated supplier/ERP notice that does not apply to this request.Summary of what happened:First incident (approx. $10): Unauthorized bot usage on an exposed API key. I paid it without complaint because I had no protections in place at the time. Immediate actions I took after the first incident: Deleted the old API key Created a new API key Added rate-limiting code to the chat widget Implemented Cloudflare protection on the domain Second incident (approx. $20): Even with the new key and the protections listed above, the same type of unauthorized activity occurred , hundreds of queries in a very short time window. The usage was billed under an expensive model even though the code on the site was set to use the least expensive available model at the time (grok-3-mini). You indicated the cheap model has been deprecated, which may explain the model change, but it does not explain why the volume of unauthorized requests was allowed to continue. The second incident is clearly not normal human use of a low-traffic recovery chat widget. It is consistent with automated abuse of the API key. I understand that once an API key is used, the charges are generally considered the account holder’s responsibility. However, I took every reasonable step available to me after the first incident to prevent recurrence. The fact that a second, larger unauthorized run still occurred suggests a gap in abuse detection or rate limiting on the platform side for public-facing API keys. Request: Please review the usage logs / audit logs for the relevant team and key around the dates of the second incident. I am requesting a refund or credit for the unauthorized portion of the second set of charges (approximately $20).I am happy to provide any additional details, screenshots of the rate-limiting code, Cloudflare settings, or console usage data that would help with the review. Thankyou for looking into this. Shelly

  • boneGPT
    bone (@boneGPT) reported

    @fren_FAST6 have at it my friend, it was using nanobanana, would be really easy to rebuild in codex or claude code i thought i had locked it down really well, had cloudflare workers and supabase all set up right, ran without a hitch for months costing me like $5 a day making me $7

  • stepherriffic
    Stephanie Hudson (@stepherriffic) reported

    @JamesWelbes Yes! But also... Set up a new @Cloudflare account in their behalf. Add yourself as a delegate. At handover, share the main login with them along with instructions to change email and pw. (They will not, in fact, change it, but at least you did the right thing lol)

  • ClassyXoge
    Xoge (@ClassyXoge) reported

    The only self custody is complete ownership of code, node and wallet. To ensure your ip is not logged, to ensure no down server or cloudflare reroute can stop you. Be your own bank, has never been more real than madlab

  • jayuiux
    Jaynal Abedin (@jayuiux) reported

    Hosting sites usually sell specs. We designed one that sells confidence. Cloudzyro, managed WordPress and WooCommerce hosting: Speed as the headline promise Pricing above the fold fatigue line 4 tiers, 1 obvious pick Migration, Cloudflare, security, support framed as risk removed SaaS founders, your homepage has 8 seconds. Use them.

  • chrisboard_
    Chris Board (@chrisboard_) reported

    Is anyone else experiencing intermittent timeout, that I think is a TLS @Cloudflare issue although not 100% sure. For the last few hours I have uptime kuma monitoring several endpoints that hit multiple servers and domains and they are all intermittently timing out. From a script I've tried running on a couple of servers it looks like I am getting sometimes slow TLS connections usually sub second, occassionally > 3 seconds and then other times I get a timeout. I don't think its related to anything my side as its affecting multiple servers, across multiple domains and nothing has changed on my side for quite some time, it just randomly started happening a few hours ago.

  • joshmatz
    Josh Matz (@joshmatz) reported

    @prestonattebery Langchain, Mastra, and Claude Managed Agents. Vercel is close w/ Eve. Flue has Cloudflare deploys. I've thought many times to build it but the "as a service" part to me means people want to deploy on something that's not a side project. What do you want that's not these?

  • Huintellimance
    Huintellimance (@Huintellimance) reported

    MCP just shipped its biggest update since launch. The protocol is now fully stateless — and that changes everything for how AI agents connect to tools. Here's what happened: The Model Context Protocol dropped spec 2026-07-28 yesterday. Since late 2024, MCP has gone from "spec nobody heard of" to nearly half a billion SDK downloads per month. Both the TypeScript and Python SDKs crossed 1 billion total downloads. It's the de facto standard for how AI models talk to external tools, databases, and APIs. But until now, MCP had a problem: it was stateful. Every MCP connection required a handshake (the initialize/initialized exchange), a persistent session ID, and an open bidirectional stream. That meant your MCP server had to live on a long-running process — no Lambda, no Cloudflare Workers, no edge functions. You needed a VPS or a container that could hold state across requests. That's over. The new spec removes the session handshake entirely. Every request is now self-describing — it carries its protocol version, client identity, and capabilities inline. No session ID. No persistent connection. Any HTTP request can land on any server instance behind a plain round-robin load balancer. What this unlocks: Serverless MCP servers. Deploy to Lambda, Workers, or any function-as-a-service platform. Pay per request, not per idle server. Edge deployment. Put your MCP server at the edge, close to the user. Cold starts are irrelevant when there's no session to establish. True horizontal scaling. No shared state means no sticky sessions, no Redis, no session stores. Just spin up more instances. Built-in observability. Method and tool names now travel in HTTP headers (Mcp-Method, Mcp-Name), so gateways can route and authorize without parsing the body. But the protocol didn't just strip things away — it added smart replacements. The old server-to-client requests (like asking the user for confirmation mid-tool-call) used held-open streams. Now they use Multi Round-Trip Requests (MRTR) — the server returns a structured "I need input" response, the client gathers it, and sends a follow-up. All stateless. All over plain HTTP. Tool catalogs now carry cache hints and deterministic ordering, so clients can cache them and keep upstream prompt caches stable across reconnects. No more re-fetching everything on every connection. There's also a formal extensions framework now — Tasks for long-running work, MCP Apps for server-rendered UIs, and Enterprise Managed Authorization for orgs that need it. Why this matters: MCP went from "cool protocol for local dev tools" to "production-ready infrastructure for the entire AI agent ecosystem" in one release. The deployment story is now as simple as any REST API. If you've been holding off on building MCP servers because the infrastructure overhead felt like too much — that excuse is gone. TypeScript, Python, Go, and C# SDKs are all updated. Migration notes are live. The breaking changes have a 12-month deprecation window. What MCP servers are you building — or planning to build — now that serverless is on the table?

  • joshmanders
    Josh (@joshmanders) reported

    So right now I still completely rely on AWS for email using SES. But I want to move off for maybe like Cloudflare, but I'm not sure. Does Cloudflare Email support inbound/outbound through API/webhook's?

  • ardadev
    Arda Kılıçdağı - 🦣 @arda@micro.arda.pw (@ardadev) reported

    @CloudflareHelp maybe you could help us. CloudFlare services in Turkey resolves @AppleSupport 's CDNs to Ukraine edge instead of Turkey, or even Greece or Bulgaria, which is closer to us. Ukraine's CDN from Turkey is throttled so hard that we get download speeds like 15 KB/sec.

  • defido
    defido 👊⛽️ (@defido) reported

    @meaganrgamache Moved to eve and vercel. Got tired of how bad the ai product was. Not sure why cf offers its own inference if it can deliver a stable product there. In terms of deploying something. Cloudflare is uniquely on its own with the way it runs its workers/containers. Using frameworks for agents has been a pain. Eve is supported by vercel in the same way they did Nextjs and they won that vertical. Cf doesn’t do oss well. You guys build and burn oss projects fast. Eve isn’t great the vercel workflows are terribly slow and inefficient. I don’t like the egress costs and vercel is expensive. But they do one thing right. Product works. And if it doesn’t. They fix it.

  • cyber_razz
    Abdulkadir | Cybersecurity (@cyber_razz) reported

    On June 3 2026 Cloudflare CEO Matthew Prince announced that bot and agentic AI traffic had officially surpassed human generated web traffic for the first time in the internet's history. The split landed at 57.5% bot traffic versus 42.5% human traffic. Prince had originally predicted this crossover would happen by end of 2027. It arrived eighteen months early. His response was direct: "Welp, that happened faster than I predicted." The driver is not the old wave of scraper bots and search crawlers. The main culprit is agentic AI. Autonomous programs browsing the web on behalf of AI assistants. A single agent can visit thousands of pages to complete a task a person would finish in a handful of clicks. Agentic AI traffic grew 8,000% across 2025 alone. Now let’***** on the Dead Internet Theory context. The theory, which originated in fringe internet forums around 2021, proposed that most internet activity was already artificial. Fake engagement, bot generated content, astroturfed discussions, AI personas. The humans were the minority and did not know it. The conspiratorial version of that theory claimed it was coordinated and intentional. That part remains unverified and unlikely. But the core observation that the majority of internet traffic is non-human is now confirmed data from the largest internet infrastructure company on the planet. The internet was architected around human usability and attention. The entire world of digital advertising, publisher monetisation, and e-commerce sits on the assumption that users are human. That assumption is now statistically false. Every engagement metric, every analytics dashboard, every ad impression count is increasingly measuring machine activity and reporting it as human behaviour. The business models built on human attention are being quietly hollowed out by traffic that generates requests but never buys anything, never reads anything, and never remembers what it visited. The theory was wrong about the why. It was right about the what.

  • jjfleagle
    Jason Fleagle (@jjfleagle) reported

    @Cloudflare Across these disruptions, which recovery signal proved most predictive: route diversity, DNS health, upstream power, or operator access? A useful resilience review would show detection time, decision owner, traffic action, customer evidence, and the first assumption that failed.

  • born2code
    احمد (@born2code) reported

    @threepointone I did that with fargate (so I can use OpenAI subscriptions), sqs and dynamo. The problem with workers is that cloudflare blocks the OpenAI subscription calls (I suspect this this OpenAI buy blocked at CF edge), which is a non starter at the rate I use tokens

  • RsThrive
    Chris O'Rourke (@RsThrive) reported

    @HackingDave I get these where they’re like “hey I can get up to 20 million seed funding to support you at Cloudflare” … thanks bro but we’re publicly traded and I have 0 to do with that.

  • bdkjones
    Bryan Jones (@bdkjones) reported

    Explaining an Outage 101: @Cloudflare: "John uploaded a bad config file at 08:24:47.252 UTC. It flipped bit 0x00007FF6E4D316D0 in datacenter 49 and brought down the whole Internet. This is unacceptable. We know you count on us. John has been shot." @Apple: "Some users may have been affected by a service 'problem'. Pray we do not affect you further."

  • ItsKamranK
    Kamran Khan (@ItsKamranK) reported

    @Rian_Visser @Namecheap Rian....worlds best company use Cloudflare for security and speed....if you don't use that's OK....I use Cloudflare CDN for almost every project....I don't have any issue...and why I will pay extra price in renewal charges, if I renew in same flat prices...

  • chrisboard_
    Chris Board (@chrisboard_) reported

    From a network trace, it looks like a TCP handshake completes, but then a ClientHello is sent, but no response is received so keeps getting retransmitted until the timeout happens. I know there's nothing being shown on cloudflare status but this does seem like it might be related to cloudflare.

  • joshmanders
    Josh (@joshmanders) reported

    @leodev So if I am understanding this correctly, using Cloudflare email is $21.45 for 50k emails? Honestly that's acceptable to me. Especially if they have good inbox placement and reliability. AWS is saturated with spammers and ****. I'll pay a premium to guarantee my stuff hits inboxes.

  • unixapple
    netox (@unixapple) reported

    Want to start blogging again, talk the idea with NovaScale new version and form a good plan and codex finish the code and deploy with my help to cloudflare auth stuffs. Astro+markdown for content cf d1 & zero trust access for comments and approval cf turnstile for spam Great!

  • sharanry
    Sharan Yalburgi (@sharanry) reported

    @Cloudflare worst part is it is impossible to monitor this latency

  • RaygunReaganAI
    Reagan Lucas (@RaygunReaganAI) reported

    @look_y Discovery attribution is the missing layer on x402 — no Referer, every IP is a Cloudflare edge, so the call shows where it landed but not who sent it. Behavioral fingerprinting (path-known, schema-unknown) is a guess, not a channel. The fix is a referral header the agent carries on the request — settlement-side proof, not inference.

  • agrisdarznieks
    Agris Dārznieks (@agrisdarznieks) reported

    I've tried to post regularly on 𝕏, but somehow I always ended up needing a scheduling app. This week I built a setup with Notion and a Cloudflare Worker, so my content machine runs inside the app I keep open all day. Now when an idea hits, I write it down and schedule it.