1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Is Cloudflare down?

Service-wide status: Cloudflare

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

Cloudflare signals over the past 24 hours. The dashed line is the service-wide baseline used to detect unusual activity.

  • Service-wide signals
  • Service-wide baseline

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 62% Cloud Services (62%)
  • 31% Hosting (31%)
  • 8% E-mail (8%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Tlajomulco de Zúñiga Cloud Services 7 days ago
Asnières-sur-Seine Cloud Services 11 days ago
New York City E-mail 15 days ago
Township of Evan Hosting 15 days ago
Ahmedabad Cloud Services 21 days ago
Le Puy-en-Velay Cloud Services 22 days ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • SelenkaOnChain
    Selenka (@SelenkaOnChain) reported

    Netnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."

  • kristianfreeman
    Kristian Freeman (@kristianfreeman) reported

    Day one support for Cloudflare!

  • OmegaNekoSimp
    Α Ω Programmer (@OmegaNekoSimp) reported

    @sneedistan Cloudflare proetects terorrist oeganizations and will badically threaten to destroy your company if you don't pay them more money. They are a disgusting company. **** them. Also the Linux Kernel uses this.

  • nuvorlane
    Nuvorlane (@nuvorlane) reported

    From today, a Workers Free D1 account that crosses 5 million rows read or 100,000 rows written gets errors until 00:00 UTC. Binding API and REST both stop. Stored data stays. Cloudflare emails you when you hit the wall. The read string is: Your account has exceeded D1's free tier daily row read limit. Upgrade to a paid plan or wait until tomorrow (midnight UTC) to continue. Writes get the matching write-limit string. SELECT * FROM users on a 5,000-row table costs 5,000 rows read even if you keep ten. Filter on an unindexed column and D1 still scans to pick the subset. Check meta.rows_read on the query, add indexes, or move to Workers Paid (25 billion reads / 50 million writes included per month).

  • las_nish
    lasan (@las_nish) reported

    Comparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.

  • EnzInnocent
    Innocent Bigega (@EnzInnocent) reported

    Stopping the bad guys with Cloudflare: 17,256 malicious requests blocked or challenged in the last month #cloudflare

  • gabrielrockson_
    Gabriel | Algo Trading (@gabrielrockson_) reported

    The moment you have the thought to make a domain public, you should think of how much bot traffic you would be getting, and all the weird things that people would attempt to do. Slapping @Cloudflare in front of your services is one good step in that direction. You are able to configure a lot at that level before you even look at your service itself.

  • neolaj
    Jeremiah K (@neolaj) reported

    @dotgil #169 was the promotion to Cloudflare PR (production), so it was awaiting my old school manual review. I'll login and check the changes against the PR log. - Coder agent unit tests and opens the PR to integration branch. - Integration agent does integration testing and merges the PR - Deployment to production is strictly manual and waits for me to review before the deploy.

  • WesRoth
    Wes Roth (@WesRoth) reported

    Cursor cloud agents can now run on infrastructure you manage, including machine pools that automatically scale with demand. Self-Hosted Machines let agents execute inside your network with access to internal services, source control, custom hardware like GPUs and Macs, and existing build infrastructure, while inference, planning, and the agent loop remain in Cursor’s cloud. Cursor also supports AWS Lambda, Cloudflare, Coder, Daytona, E2B, Modal, Namespace, and Vercel. Cursor says cloud agents now create more than 60% of the pull requests it merges internally.

  • besodemieterd
    Guillermo Zaandam 🇨🇦🇳🇱 (@besodemieterd) reported

    @Cloudflare Your CSP rules and WAF rules aren't working again and again. Please fix this

  • SignalForge_AI
    SignalForge AI (@SignalForge_AI) reported

    Cloudflare 503 killed my EA silently. Orders never reached MT5. Fix: 30-min news filter pause + retry queue. Trade-off: misses NFP entries, but zero ghost orders. How many silent failures did your bridge survive before you added the retry loop?

  • danieldmai
    CerooDan (@danieldmai) reported

    Whats going on ? Gmail not working properly rn, websites not loading properly. Don't see errors on cloudflare or AWS.

  • Klehmann79
    Karsten Lehmann (@Klehmann79) reported

    Hey @Cloudflare I accidentally ordered a pro account (1 year) for the wrong domain and all I get in your support portal are standard docs. How can I submit a case? There‘s no way to get to a form, even as paying customer.

  • SoccerGuyUS
    SoccerGuy (@SoccerGuyUS) reported

    @levelsio @Cloudflare Namecheap is awful. Anyone looking for a better Google Domains (since they rug pulled) alternative: Porkbun.

  • davideoks
    David Oks (@davideoks) reported

    @inoutremer @CharlieTyson1 this type of thing is solved by hosting on e.g. Cloudflare. pieces going modestly viral like Wilson's or Oyler's did shouldn't crash a modern web site! presumably they just have terrible IT. (but a quite wonderfully designed website IMO)

  • pcppup
    Megumi, Internet Angel 🏳️‍⚧️ (@pcppup) reported

    @NightlyArii i think you are not catching my sarcasm :) i do not know how much you know about cybersec, but a static page would require Cloudflare, Github, or my Computer to get hacked, which is just crazy. You're just criticizing AI because you can. It's good for some things, bad at others.

  • RealBucketShop
    BucketShop (@RealBucketShop) reported

    Sigh. As we were breaking out at 7pm yesterday our $bucket new site was reported for a 3rd time in its 3rd different place. Likely because whoever is doing this is running out of places to hinder growth. Nothing has been compromised. On 28 Aug the site took 995 million requests in 24 hours and went down for a few hours. The protocol never stopped. Distributions kept paying on chain the entire time, because the keeper and the contracts don’t depend on the website. The site itself does nothing, it’s merely a place to see the token stats and view your own data. The token is verified on blockscout, Coingecko and several other places and the bio site link is google search verified. Contracts are immutable, LP is burned, ownership is renounced. All checkable without trusting me. @X blocklist isn’t cleared because they have no team. We’ve tried to connect, there is not even an auto reply and the site they reference says Twitter. @Cloudflare was appealed immediately. Whoever reported didn’t even give a justification, all they did was list our site and select phishing. It’s market as in review, we have no clue how long they take. It’s becoming increasingly obvious this is coordinated. We’ve appealed to cloudflare on who’s reported this. Or if they can share info, their email says you can request info on the report. That being said. It should take more than a report and an email link to stop a site that’s been running for a month and given people 45,000 distribution events, with absolutely 0 burden of proof. For now. Just use the old site that’s Google safe search reviewed and approved. It’s identical anyways. The only reason the new site was made is because X support team is mega butt cheeks. Full timeline below.

  • LubosKolouch
    Lubos Kolouch (@LubosKolouch) reported

    Think twice before you paste: if a website's "Cloudflare CAPTCHA" asks you to open Windows Terminal and run a command, it's a trap. This is TerminalFix, a malware campaign Microsoft detailed in late August 2026. Pasting the code installs malware, exposes your accounts, and opens a backdoor to your network. Real CAPTCHAs only ask you to click images or checkboxes. Never open Terminal or PowerShell just because a website told you to. If you see these instructions, close the tab immediately to avoid a full corporate breach.

  • bmwhocking
    Ben Hocking (@bmwhocking) reported

    @rustie5555 There are a lot of round robin API calls for content. Works fine if you are close to their US data-centre. Sucks for us. They are using Cloudflare, I don’t believe they are processing at Cloudflare’s edge, just caching content. They need better & faster timeline building.

  • junebnunny_
    junebnunny (@junebnunny_) reported

    @SportingNest @Cloudflare This is a click fix attack. Do not run the code. Do not do ctrl V. Do not do Windows plus R. You will lose all of your data. You will get scammed. Your bitcoins will be taken.

  • the_cia_hacker
    Justin Liverman (@the_cia_hacker) reported

    FunFact: Blackhat hackers put @cloudflare on the map back in 2011 when LulzSec was getting DDoS by @th3j35ter and @eastdakota decided to not drop them as a customer they became the defacto DDoS protection service forever after this

  • PadraigOraghail
    Patrick Ryall (@PadraigOraghail) reported

    The learning is never ending. Mostly it is platforms, in this case using Cloudflare as the auth gate. I had never used cloudflare for more than DNS. Now I have three sites running on it, for free, which is mad. Workers, Zero Trust, DNS, connected to ***. It's all rather slick.

  • theOGstud
    💊🧠 (@theOGstud) reported

    @leviackermanft Novel works fine ... I've also played an anime .. problem comes with the manga. After downloading the repo,it either points out that source not found or the source leads you to cloudflare then the app crashes ..

  • junebnunny_
    junebnunny (@junebnunny_) reported

    @Gion_the_critic @SportingNest @Cloudflare It's just the type of thing you've just got to come across and you don't really find them that often, because when a campaign is up, it's up for a few hours and then taken down very quickly, because it's quite obviously malware.

  • _theCyberDoctor
    Henry C | DevSecOps (@_theCyberDoctor) reported

    4/ The part I'm proudest of isn't the happy path. It's what happens when the web fights back. CrunchBase threw a Cloudflare captcha → agent refused to bypass it, wrote down why, moved on. LinkedIn threw a sign-in popup → agent closed it and read what was visible. Chrome crashed → agent reloaded.

  • GoldmanStacks
    Goldman Stacks (@GoldmanStacks) reported

    @tresokure Your website is down with a DNS resolution error from Cloudflare.

  • Gion_the_critic
    R.Gion (Any/All) (@Gion_the_critic) reported

    @junebnunny_ @SportingNest @Cloudflare I figure it's not legit, but I wanted to know where it was from since I've never seen this particular scam.

  • acolombiadev
    Andrea (@acolombiadev) reported

    Name one underrated/generous free tier service. I’ll start: @Cloudflare

  • sprki999
    ticktechh (@sprki999) reported

    @OmegaNekoSimp @NoboKik Does cloudflare use PoW? Never noticed a temperature spike from those and the ryzen in my thinkpad likes to spike 15 degrees just from looking at it

  • jeffinator06
    Jeffinator (@jeffinator06) reported

    ive been STUCK in cloudflare HELL for the past 2 WEEKS. this is the 2nd time ive been caught up in some mass-wide bullshit. holy **** dude reddit is so so awful i dont want to go back

Cloudflare detected incident history

These records describe service-wide increases in reported problems. They do not confirm an outage at every address. Recorded end times describe our detection window, not a provider-confirmed repair.

  • Detected:
    Detection ended: (11 minutes)
  • Detected:
    Detection ended: (1 minutes)
  • Detected:
    Detection ended: (56 minutes)
  • Detected:
    No end recorded. This alone does not establish the current status.
  • Detected:
    Detection ended: (8 minutes)
  • Detected:
    No end recorded. This alone does not establish the current status.

What to do if Cloudflare is not working

Compare your issue with the local reports and map. Note the affected service and when the problem began before contacting Cloudflare; report your own experience using the report button above.

How to interpret these reports

Direct reports are submitted by visitors. Locations may be estimated from their connection or supplied by the reporter. A low local count does not establish that service is working; the service-wide status and local report totals describe different areas. How our outage detection works