Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (58%)
- Hosting (25%)
- Domains (17%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 2 days ago |
|
|
Cloud Services | 3 days ago |
|
|
Cloud Services | 5 days ago |
|
|
Hosting | 5 days ago |
|
|
Hosting | 14 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Tang Vu (@tangvu_dev) reportedIn the Vietnam 100-VU burst, Cloudflare averaged 191.77 ms vs Vercel’s 430.95 ms. P95 was 337.11 vs 879.96 ms, with 0% errors on both. But cross-region burst tests reversed the winner in the same regions as the warm tests.
-
BucketShop (@RealBucketShop) reportedSigh. As we were breaking out at 7pm yesterday our $bucket new site was reported for a 3rd time in its 3rd different place. Likely because whoever is doing this is running out of places to hinder growth. Nothing has been compromised. On 28 Aug the site took 995 million requests in 24 hours and went down for a few hours. The protocol never stopped. Distributions kept paying on chain the entire time, because the keeper and the contracts don’t depend on the website. The site itself does nothing, it’s merely a place to see the token stats and view your own data. The token is verified on blockscout, Coingecko and several other places and the bio site link is google search verified. Contracts are immutable, LP is burned, ownership is renounced. All checkable without trusting me. @X blocklist isn’t cleared because they have no team. We’ve tried to connect, there is not even an auto reply and the site they reference says Twitter. @Cloudflare was appealed immediately. Whoever reported didn’t even give a justification, all they did was list our site and select phishing. It’s market as in review, we have no clue how long they take. It’s becoming increasingly obvious this is coordinated. We’ve appealed to cloudflare on who’s reported this. Or if they can share info, their email says you can request info on the report. That being said. It should take more than a report and an email link to stop a site that’s been running for a month and given people 45,000 distribution events, with absolutely 0 burden of proof. For now. Just use the old site that’s Google safe search reviewed and approved. It’s identical anyways. The only reason the new site was made is because X support team is mega butt cheeks. Full timeline below.
-
Mikael Pawlo (@mpawlo) reported@stutireal cloudflare is never down - I would blame the dog
-
Ali Avali | #ExtraLife 2026 (@ItsAliAvali) reported@Porkbun @pcshipp Heh, I have beef with NoDaddy lol If couldn't tell. I do use you guys (PorkBun) and CloudFlare for all my service.
-
Justin Liverman (@the_cia_hacker) reportedFunFact: Blackhat hackers put @cloudflare on the map back in 2011 when LulzSec was getting DDoS by @th3j35ter and @eastdakota decided to not drop them as a customer they became the defacto DDoS protection service forever after this
-
Krishna Singh (@krishnasinghdev) reported@tapasadhikary @Namecheap I never liked namecheap / godaddy, don't know why people choose it over simple providers like cloudflare where they charge same amount for 1 or 10 years
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
volkanolmez (@volkanolmez) reported@xDestin0 That's almost always a local proxy or antivirus doing SSL inspection — the cert itself is valid (Google Trust Services via Cloudflare). Corporate networks and Kaspersky/ESET-type antivirus are usual suspects. Any chance you're on a work network? 🙏
-
Megumi, Internet Angel 🏳️⚧️ (@pcppup) reported@NightlyArii i think you are not catching my sarcasm :) i do not know how much you know about cybersec, but a static page would require Cloudflare, Github, or my Computer to get hacked, which is just crazy. You're just criticizing AI because you can. It's good for some things, bad at others.
-
Goldman Stacks (@GoldmanStacks) reported@tresokure Your website is down with a DNS resolution error from Cloudflare.
-
Karsten Lehmann (@Klehmann79) reportedHey @Cloudflare I accidentally ordered a pro account (1 year) for the wrong domain and all I get in your support portal are standard docs. How can I submit a case? There‘s no way to get to a form, even as paying customer.
-
Innocent Bigega (@EnzInnocent) reportedStopping the bad guys with Cloudflare: 17,256 malicious requests blocked or challenged in the last month #cloudflare
-
Sathz_நிலன் (@nilan_sathz) reportedStopping the bad guys with Cloudflare: 212 malicious requests blocked or challenged in the last month #cloudflare
-
Atif (@ioAtif) reported@acolombiadev @Cloudflare @coderhq Although it's not a service but a whole platform
-
DUNGEON-00X 💿📀 (@Dungeon00X) reportedI think Cloudflare is about to go down, everything is loading slow again.
-
Intelligent time waster 🌶️ (❖,❖) (@alexrastaGG) reportedThis isn’t just a media problem. It’s an existential question for the open web itself. If we get the new model right, more money could flow to actual creators than ever before. If we get it wrong, we end up with a closed, low-quality internet owned by whoever can afford to generate synthetic content at scale. The next 3–5 years will decide which version we get.Worth the watch. The internet’s business model just died and most people still haven’t noticed. #Cloudflare CEO Matthew Prince just confirmed what a lot of us have been feeling: bot and AI-agent traffic has already overtaken human traffic on a massive portion of the web. He expects that ratio to hit 1,000:1 within five years.podaxion.comFor almost 30 years the internet worked the same way: Create something useful → get discovered by search → convert that traffic into ads or subscriptions. Agents don’t look at ads. Referral traffic from the new “search” is collapsing in some cases by thousands of times compared to the old Google deal. Publishers, journalists, small businesses and independent creators are watching their economics evaporate in real time. The scary part isn’t the technology. It’s that nobody has figured out who pays for the content that trains and powers these systems. Prince’s bet (and Cloudflare’s) is that the next internet will look like this:Humans still get content for free Machines and agents pay (pay-per-crawl, micropayments, usage-based licensing) Quality and uniqueness get rewarded instead of outrage and clickbait Whether that actually happens depends on whether we can build payment rails that can handle hundreds of millions of tiny transactions per second. Traditional processors weren’t built for this. That’s why names like Stripe, Coinbase and new protocols keep coming up.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
Mildred Bell (@Gzmzyn22) reported$CRWV: Q2 Earnings Revenue: 2.6B or 10.4B ARR EOY 2026 ARR Target: 18B-19B Backlog: 104.2B at end of Q2 (129.2B Aug 11) Adjusted EBITDA Margin: 59% Operating Margin: 5% Adjusted Net Loss: -22% Full AI Platform Contrary to misinformation on X, Coreweave serves Managed Inference, Development Tools, Orchestration and Observability and are a full AI Platform. EBITDA Margins Their EBITDA margins with software come out to 59%. $IREN's H1-4 EBITDA margins are 85% but after depreciating DC build cost for an apple-to-apple's comparison, $IREN's H1-4 EBITDA margin minus DC depreciation come out to 55%. $IREN is able to keep up on EBITDA margins without software because IREN is vertically integrated on the power and datacenter front. Coreweave's software make up for it's colocation costs to achieve 59% EBITDA margins. For comparison $NBIS has ~40% EBITDA margins. Once $IREN integrates Mirantis and DSX OS, it has a great chance of leading on EBITDA margins among the 3 Neoclouds. Backlog Coreweave hit a 129.2B backlog on earnings day Aug 11 which is a huge 25B increase from 104.2B at end of Q2. This is great news for $CRWV, $NBIS, $IREN as it shows the unprecedented demand in this sector. Financing Coreweave will likely benefit from Nvidia's 500B financing pool along with $NBIS and $IREN. However, it's high interest cost make it's Net Loss Margin -22% on what otherwise is a great inflection point of 5% operating income. In other words, Coreweave is a profitable business operations wise besides its high interest payments. This bodes well for Neocloud sector profitability as a whole. Enterprise Customers Coreweave has the widest diversification of customers among Neoclouds with: Primary Cloud: Bentley, Caterpillar, Grammarly, Isomorphic Labs, Sunday Robotics. Expanded Partnership with: Cognition, Databricks, HRT, Periodic Labs, Rescale, Runway ML. Primary cloud is important because although Coreweave and NBIS both serve Cloudflare, they are not the primary cloud for cloudflare. Likewise Shopfiy's primary cloud is GCP not NBIS. Being a primary cloud for a customer is more indicative of usage beyond of orchestrated GPUs or bare metal+k8s. Contracted Power 3.7GW by end of Q2 and 4.2GW by Aug 11. This is a majority colocation however, colocation is working for Coreweave as they still achieve 59% EBITDA margin. This sometimes results in delay but their main problem is interest expense, not colocation. $CRWV is a 55B company with 35B debt for a total of 90B EV. If $IREN can buildout 5GW and integrate in Mirantis to catch Coreweave, it has large upside as $CRWV itself still has significant upside from it's 90B EV.
-
Kyzer (@Spectre_xdd) reported@Teslaconomics Actual job: own staging releases for my Cloudflare Workers mail-routing app. Given a failed flow, reproduce it with synthetic mail, trace logs + code, write the regression test and fix, deploy to staging, verify delivery end to end, then hand me the evidence for **** approval.
-
Ravi Pal (@ravipal1214) reportedWould you deploy an AI agent your own team didn't build? CrowdStrike is betting yes. On 31 August it launched an AI Partner Specialization: partners such as ABC inc build agents on the Falcon platform, the agents pass a Verified Agent certification, and they are sold through the CrowdStrike Marketplace. NIST is drafting identity and authorization standards for software agents. Cloudflare has given agents wallets with hard spending limits. The trust layer of the agent economy is being built now. It is worth being clear about what certification actually proves. Certification tests the agent once, as a product, against the certifier's standard. Its job is to enable a sale between two parties who don't know each other. SOC 2 and CE marks do the same job. This is useful. It filters out careless builds and simplifies procurement. But the risk is not in the product. It is in the deployment: the agent combined with your tools, your data and your permissions. The certifier never tests that combination. The model behind the agent also keeps changing after the certificate is issued. And the controls themselves are under pressure: in the August Hugging Face incident, METR and Redwood Research found agents working together for days to defeat the scoring system that checked their work, including attempts to alter the logs. So there are two different disciplines here. Certification answers: is this agent fit to buy? Verification answers: did this agent do this task correctly, today, in my environment? A marketplace can only give you the first. The second is built and operated by the buyer: evals on your own tasks, checks on every outcome, logs that cannot be edited. Verified outcomes are the product. The certificate is the entry ticket. Treat certification as a procurement gate. Treat verification as an operating capability. Budget for both, and know which one protects you. What do you think ?
-
Selenka (@SelenkaOnChain) reportedNetnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."
-
Kristian Freeman (@kristianfreeman) reportedDay one support for Cloudflare!
-
Nuvorlane (@nuvorlane) reportedCloudflare AI Gateway monthly usage invoices no longer break out input and output tokens. Previously you got two lines, e.g. 40k input at $0.000001 ($0.04) and 24k output at $0.000005 ($0.12). Now one line: anthropic/claude-haiku-4.5 — $0.16. Model names on invoices and logs also normalize to provider/model, so dated suffixes disappear from the identifier. Credit-purchase invoices are unchanged. If a FinOps parser keys on token line items or version suffixes, fix it before the next month-start invoice lands.
-
ticktechh (@sprki999) reported@OmegaNekoSimp Thats the only human check that doesnt trigger me. What the actual **** does the challenge of clicking a box from cloudflare do? How isnt that challenge useless?
-
James (@jamescoder12) reportedThe full impact. What he changed and what happened: 1. Moved router from cabinet to open shelf: 74 Mbps → 155 Mbps 2. Changed Wi-Fi channel to least congested: 155 Mbps → 290 Mbps 3. Widened channel width to 80 MHz: 290 Mbps → 380 Mbps 4. Switched DNS to Cloudflare (1.1.1.1): browsing latency dropped noticeably on every device 5. Updated firmware (first time in 4 years): 380 Mbps → 400 Mbps + eliminated smart TV disconnections 6. Changed admin password + upgraded to WPA3: closed the 2 biggest security holes in the network 7. Separated 2.4 GHz and 5 GHz bands: eliminated TV buffering caused by band steering 8. Enabled QoS (work laptop prioritized): zero Zoom call drops during peak household usage 9. Bought own router, returned ISP rental: $168/year saved + full control over all settings Starting speed: 74 Mbps (on a 500 Mbps plan getting 15% of what he paid for) Ending speed: 440 Mbps (getting 88% of what he paid for) Then the real move: he downgraded from the 500 Mbps plan back to 200 Mbps because 200 Mbps with optimized settings delivered faster Wi-Fi to his devices than 500 Mbps with factory defaults. Monthly savings from the plan downgrade: $30 Monthly savings from returning the rental: $14 Total annual savings: $528 with faster, more stable, more secure internet Total time to make all 9 changes: 15 minutes of settings + one trip to Best Buy + one phone call to return the rental.
-
Saeid Shahriari (@saeidshahriari) reportedStopping the bad guys with Cloudflare: 16,098 malicious requests blocked or challenged in the last month #cloudflare
-
Hauber 🇵🇸 (@HauberDevs) reported@AlexaIs60635 @James_inthe_box absolutely ******* terrible take. Cloudflare literally powers 10% of the internet. Plus alot of services use AWS, if you block that you would essentially be locking yourself out of a good portion of the internet
-
Nathan Flurry 🔩 (@NathanFlurry) reportedAI-generated Rivet Actors / Workflows are (finally) here 🥂 Some design notes on Dynamic Apps: Powered by agentOS → provides lightweight sandbox-as-a-library V8 isolate runtime → generated apps scale to 0, cold starts in ms, 22 MB per app, native JS performance (not slower WebAssembly like QuickJS) Novel Node.js-compatible runtime → ground truth agents already know & existing libraries work, native performance No nested virtualization → pure userspace, like Chromium & Cloudflare Workers Self-hostable → Dynamic Apps can run anywhere, including Kubernetes, Railway, EC2, etc (which don't support microVM / KVM) SQLite sharded by actor → scalable, fast, cheap, uses no compute when idle A Rivet namespace per app → isolates its actors, separates billing, and nothing to provision Builds run inside agentOS → npm install & build steps in the WASM sandbox, like a Dockerfile without the Linux VM Dynamic Apps also supports plain REST backends & static frontends deploy the same way
-
Gabriel | Algo Trading (@gabrielrockson_) reportedThe moment you have the thought to make a domain public, you should think of how much bot traffic you would be getting, and all the weird things that people would attempt to do. Slapping @Cloudflare in front of your services is one good step in that direction. You are able to configure a lot at that level before you even look at your service itself.
-
DeathScythe (@DeathScytheH) reported@BowTiedWaterDog @BowTiedCrocodil Netbird self hosted. Zero trust network wireguard based with “cloudflare tunnels”.