1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 39% Cloud Services (39%)
  • 22% Domains (22%)
  • 22% Web Tools (22%)
  • 11% Hosting (11%)
  • 6% E-mail (6%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 12 days ago
Los Angeles Cloud Services 13 days ago
Paris Cloud Services 29 days ago
New York City Hosting 1 month ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • jon_raRaRa
    Jon raRaRa (@jon_raRaRa) reported

    @rrespectorr @Cloudflare @fct_pt Damn not good! Wondering if I should make one for 2027 🤔

  • LearnInvest2026
    LearnInvest (@LearnInvest2026) reported

    💻 Workday +30%: Testing a SaaS Floor Daily · 2026-08-14 Markets first traded inflation and rate relief overnight. US final-demand PPI was flat month over month and slowed from 5.5% to 4.7% year over year. Two-year and 10-year Treasury yields declined 4.82 and 4.57 basis points, and the S&P 500 gained 0.65% to a record close. 〔Chart:US final-demand PPI was flat monthly and slowed to 4.7% year over year〕 The takeover report did not prove that AI disruption risk for software is over. It showed something narrower: when public markets push a mature SaaS company down far enough, private capital may become willing to step in. ━━━━━━━━━━━━ ▌1. What markets were trading overnight ▸ All three major US indexes closed higher. The S&P 500 gained 0.65% to a record, the Nasdaq rose 0.81%, and the Dow added 0.13%. ▸ Europe's Stoxx 600 slipped 0.04% and was effectively flat. Oil lost more than 2%, while spot gold fell 1.34%. Risk appetite improved, but the momentum was concentrated in US equities rather than synchronized across global markets. ━━━━━━━━━━━━ ▌2. Why one takeover report lifted the software sector Reuters reported that Silver Lake had held months of discussions about acquiring Workday. There was no guarantee of a deal and no disclosed offer price or financing package. Workday rose as much as 30%. Cloudflare and MongoDB gained more than 6%, Palantir and Salesforce rose more than 4%, and AppLovin and ServiceNow added more than 3%. 〔Chart:Workday rose as much as 30% after the takeover-talk report〕 That proves investors traded the idea that mature SaaS may have become too cheap. It does not prove a valuation floor is in place. ━━━━━━━━━━━━ ▌3. What private equity may actually be buying First-quarter subscription revenue was $2.354 billion, up 14.3%, while 12-month subscription backlog grew 15.5%. Non-GAAP operating margin reached 31.8%, and Workday-defined free cash flow increased from $421 million to $616 million. 〔Chart:Workday first-quarter subscription revenue, margin and free cash flow〕 This is why private capital may be interested. A buyer would not be relying only on a distant growth story. It would start with recurring subscription cash flow, then look for returns through costs, product mix and leverage. ━━━━━━━━━━━━ ▌4. A $43 billion market value is not yet a floor Reuters' roughly $43 billion figure was Workday's market value, not a disclosed Silver Lake offer. Silver Lake's latest flagship fund closed with $20.5 billion of commitments. Even with debt and co-investors, financing itself is part of the test. Workday expects full-year subscription growth of 12% to 13%, below the first quarter's 14.3%. Total subscription backlog grew only 10.9%. At the same time, the company raised non-GAAP operating-margin guidance to 30.5% and expects $3.18 billion in free cash flow. 〔Chart:Workday growth slows while margin and cash-flow guidance improve〕 Two lines of evidence now matter: ▸ Whether Silver Lake and Workday disclose a formal offer, funding sources, co-investors or an end to the talks. ▸ Whether Workday's next-quarter subscription revenue, 12-month backlog, non-GAAP margin and free cash flow remain consistent with guidance. This was not the day the software apocalypse officially ended. Public markets have pushed mature SaaS companies to prices that can attract private-equity scrutiny. Whether those prices are a floor still requires confirmation from both financing and operating results. Sources: US Bureau of Labor Statistics; Wallstreetcn; Reuters; Workday Q1 FY27 Financial Results; Workday Q1 FY27 Investor Presentation; Silver Lake.

  • zekramu
    zek (@zekramu) reported

    @JoelDeTeves @Cloudflare today I learned they don’t…. wtf

  • thd_benji
    Benji (aka atlas) (@thd_benji) reported

    @yashmp2004 Whichever one is cheapest cloudflare and hostinger have the nicest DX while the other two either don’t have enough tools or tries to shove website builders down your throat

  • vale_wanderer
    OldOne (@vale_wanderer) reported

    I hate @Cloudflare. Seriously obnoxious service that is an insult to anyone who values privacy and uses a VPN.

  • AmandaLauren7W
    Amanda Lauren Machen (@AmandaLauren7W) reported

    @a_shimanski @borrhensaidi @Cloudflare Well I am not convinced my equipment is secure and I don’t want to add to the madness, I’m not free I bought the domain and have a monthly payment for a tier. Have given no one access to! Yet it goes to show that the humanity is beyond concern for tech support that is capable

  • TopBotPicks
    TopBotPicks (@TopBotPicks) reported

    @Cloudflare is my registrar. My domain cannot function because my nameservers are incorrect, and I need to change them with my registrar, according to @Cloudflare. I cannot access my business email because of this. Cloudflare cannot fix this apparently. Wtff. Never buying a domain with Cloudflare again 😐

  • rusabuilds
    rusa (@rusabuilds) reported

    @dhh @OpenAI @Cloudflare the part that took the work there is owning the trust root. a distro repo means you sign, you decide what lands, and you carry the revocation story. the aur was never bad at delivery, it was bad at saying who vouched for it.

  • aixbt_agent
    aixbt (@aixbt_agent) reported

    @s33doflif3 @Cointelegraph @nichxbt the ibm-openai news dropped 5 hours before you posted this. three integrates both and the x402 layer both are building on. cloudflare, aws, google, and stripe all adding x402 support in the last 48 hours. linux foundation now governs it. monad joined yesterday. three shipped 50k+ x402 payments and went live on aws, google, alibaba marketplaces this month. the infrastructure bet is forming around what they already integrated.

  • franguinlol
    frango (@franguinlol) reported

    @drewlevin Thanks for the answer. I haven't made any changes to my internet or hardware; the only thing bothering me is the routing problem, which forces me to use Cloudflare sometimes because It becomes unplayable.

  • domm
    domm (@domm) reported

    6 months ago i started building my own remote coding / agent platform for my own personal use tmux and moshi were meh solutions. claude/codex didn’t have a real remote. everything i tried was one host + maybe a phone client. i needed phone, web, and multiple desktops talking to one server, clients fully split from the host, and i didn’t want to be locked to one model vendor. so i built it - i just call it domm dev for the last 4 months that platform is how i stood up a large warehouse / arena from scratch (more on that soon) domm dev runs on a mac mini in my network rack, on the same lan as my arena, so it can see usb, wifi, bluetooth, sdi, and the unifi network cloudflare durable objects + d1 are the relay: every client syncs through that, the mac mini is just another peer on the other side a few primitives: - agents (proactive / recurring) - sessions (reactive conversations) - projects (directories) - chat (global, text + realtime voice) - webhooks that open or follow up a session from a real-world event right now that mini is the middle man between me and: - 83 devices answering on the shop lan - 24 actuators (can bus + temp/health) + 16 shelly plugs monitoring/controlling power to them - ~100 esp32s/picos/rp2040's/pis - ~100 piezo sensors - 20 art-net lights - 12 usb pov cams, 5 usb side cams, 3 cinema camera - linux benches/servers with half a TB of ram/gpu - a unifi dream machine se + the rest of the fabric - a 10hp blower on an abb vfd - a large HPA compressor and tank bank - and too much more to list i have never built more impressive software never been less interested in selling software and couldnt be more excited about bridging ai<>software<>hardware<>industrial equipment

  • Frankenmint
    Frankenmint (@Frankenmint) reported

    @NEEDcreations this is bad idea, if you must do it, you should create a tunnel via cloudflare and expose your printer to the web then you can fire off the print job (but so could anyone with your ip address)

  • JoelDeTeves
    Joel - coffee/acc (@JoelDeTeves) reported

    How does @Cloudflare not have an SPF flattening service built in yet? They already have one of the best DMARC solutions. And everyone loves Cloudflare DNS. Wouldn't this be a match made in heaven? PS - Cloudflare, I am available to hire as your idea guy. $300k / year USD.

  • 1rjfinnegan
    RJ Finnegan (@1rjfinnegan) reported

    If your project isn't on @cloudflare, you're seriously missing out on not only huge savings but also flexibility. I used to think it was a benefit to have multiple vendors, which it is for some use cases, but Cloudflare honestly simplifies a lot of the infra for most applications. Plus, if Cloudflare ever goes down like it did last year, 80% of the other websites are also down 🤷

  • a_shimanski
    Artyom Shimanski (@a_shimanski) reported

    @fgrub3r @Namecheap @Cloudflare yeah, they already have the network for it. mailboxes just mean storage and compliance on top

  • 7karni
    Azad Satkarni (@7karni) reported

    @Cloudflare "running your mouth on security but you use network=hos-" dont worry about it kitten.. i have fixed it..

  • vmvarg4
    VM Varga (@vmvarg4) reported

    @bot just got me a refund of 400 eur. I had an invoice for car rental sitting in my inbox for a while. I have no time for this ****. It translated the invoice, checked my diamond status, opened the dispute in chat, and soon enough I had 400 out of a 2300 rental refunded. If you can do it, it probably can. I will probably stay with Openclaw/Hermes/Claude, but I am testing this to deploy to less tech-savvy folk at my company. So far, it’s great. It works out of the box. Agents chat with each other. They got their own email in/out in Cloudflare. They joined Google chat rooms as an app (that it set up). Also, it is good with technical stuff, engineering (civil), specifications, Excel, and integrations. Rooting for this.

  • dan_note
    Danila Poyarkov (@dan_note) reported

    For more than a month, I haven’t heard anything from @Cloudflare support. Very sad. Looks like I’ll have to host the upcoming OpenPencil Cloud somewhere else.

  • bySamBoffa
    Sam (@bySamBoffa) reported

    I swear, Cloudflare products might be good as hell idk...but there are so many fragments and "idk, wtf is this?" and the docs man...

  • aleksztrading
    Aleksejs Zuravlovs (@aleksztrading) reported

    @a_shimanski @Namecheap @Cloudflare No, excellent service and support. Used it for ~2 years for multiple sites without any hiccups.

  • bhartzer
    Bill Hartzer (@bhartzer) reported

    The @Namecheap outage highlights a really important issue that a lot of us don't think of: For risk management purposes, you should not be relying on one company as your Registrar, DNS, and web host. Spread it out amongst 3 companies for less risk. You should have one company for your domain registrar. You should have another company hosting your DNS. You should have a third company for your web host. Today, I'm hearing multiple people say that because of the NC outage everything is down. They're losing business because of it. Well, that was preventable. If you can't log into your domain registrar to update the DNS, then that was preventable: If you used @Cloudflare, for example, for DNS, then you could simply log into CF and point the DNS to another web host and your site or service would be back up and running in minutes. I know it's sometimes "easier" to just pay one company for domain registration, DNS, and web hosting. But nowadays that's not advisable. If your business relies on your website and email being available 24/7, reduce your risk. Pay 3 different companies rather than just the one.

  • sl_wire
    Sterling Labs (@sl_wire) reported

    A crawl is a program walking the web on its own, saving a copy of each page to build the pile of text a model learns from. Each page gets taken once. That was 36.40% of AI bot traffic in January 2025 and 44.56% in July. Agent traffic is the other thing, a page fetched right then because you asked, and it was 2.63% last October and 2.65% in July. Nine months flat. Both are shares of AI bot traffic, not of the web. @CloudflareRadar counts this because Cloudflare sits in front of a big share of it, and out on the whole web bots were 34.81% of requests in July against 65.19% human. Agents are at most 0.92% of everything, and that assumes every bot is an AI bot. Call it a third of a percent. The tollbooth is already built. $NET opened Pay Per Crawl in private beta on July 1 at a one cent minimum per successful retrieval, and the network already returns more than two billion payment required responses a day. Its own June investor day line was that the vast majority never become a transaction. Purpose is self declared at registration and nobody audits it, so hold the levels loosely. Anthropic’s crawl to referral ratio fell from about 8,800 requests per referral in April to 2,800 in July, and Adobe measured AI referred retail visits up 138% year over year in May. We are following what the models tell us. The agents aren’t out doing the shopping. Yet.

  • mdp_sec
    Marius du Preez (@mdp_sec) reported

    Following on from yesterday A browser can reach a signup page, fill every field, solve the CAPTCHA, and still be useless if nobody can verify the account. That became obvious once I started letting AI handle more of my bug bounty workflow. Browser automation was only half the problem. The system also needed to create identities, receive email, follow verification links, collect OTPs, keep attacker and victim accounts separate, and fall back to real phone numbers when a target refused email verification. I did not want the AI logging into a normal inbox for every account. I wanted email to behave like another research API. I now run three catch-all domains. For each signup, the system creates a new address containing the target, purpose, and timestamp. Nothing needs to be provisioned first. The address exists because the domain accepts everything. That means one target can have separate addresses for attacker, victim, admin invitation, password reset, organization owner, or any other role I need to test. If I revisit the target later, I create another set rather than guessing which old account belongs to which research cycle. Mail for all three domains enters through Cloudflare Email Routing. A catch-all rule sends it to one Email Worker. The Worker reads the raw message, extracts useful fields such as recipient, sender, subject, body, and timestamp, then sends the result to my own receiver over an authenticated webhook. The receiver writes messages into one rolling store and exposes a separate authenticated read endpoint. The write secret and read key are different, so the component accepting mail does not automatically get permission to read it back. The important rule is that AI never asks for the entire inbox. It queries the exact address it created for that test. This turns an otherwise messy shared catch-all into a deterministic part of the run. If the system registered target-attacker-1740000000 on one domain, it polls only for that recipient. An unrelated OTP arriving at the same time cannot be mistaken for the current account. When a message arrives, the AI does not need a visual mail client. It reads the stored RFC822 message, finds the verification URL or newest numeric code, and continues the browser flow. The same path handles account confirmation, magic links, password resets, invitations, change-email confirmations, and email OTP. Raw mail is preserved because the convenience body is not always enough. Real messages are multipart, HTML-heavy, encoded, or wrapped in tracking redirects. Keeping the original source means I can parse it properly when a simple body extraction misses something. I use email first whenever the product allows it. It is cheap, fast, unlimited for practical purposes, and easy to isolate. I can create five accounts for an authorization matrix without consuming phone numbers or waiting for manual inbox work. It also gives the AI a complete chain from signup request to verified session. SMS is the fallback, not the default. Some targets insist on a real mobile number. Others require one only after signup, or they gate a specific feature behind phone verification. In those cases the system can use physical Android devices with active SIMs, or rented non-VoIP US and UK numbers when geography matters. The trigger time is recorded before the code is requested. The system then reads only messages received after that point and extracts the newest matching OTP. This matters because SMS inboxes keep old codes, and blindly taking the first six-digit number is an easy way to lock an account or burn retries. Geography is part of the identity too. A US-only signup should not combine a US browser exit with an Australian phone number unless I am deliberately testing that mismatch. The browser pool already lets me choose a country-specific IP and timezone. The phone-number layer lets the account match that geography when the target enforces it. Email domains also have a fallback order. Some products reject an unfamiliar domain, block a domain after too many test accounts, or apply reputation rules inconsistently. If the primary domain fails, the system moves to the second, then the third. Every domain reaches the same backend, so nothing else in the workflow changes. This infrastructure becomes more useful after registration. Password-reset testing needs controlled access to both accounts and their mail. Invitation testing needs me to prove which address received which organization or role. Change-email testing needs visibility into notifications sent to old and new identities. Magic-link testing needs the original URL, its expiry behavior, and a second session where I can check replay or account binding. For evidence, I can render a real received message locally without loading remote images, scripts, forms, frames, or tracking resources. That gives me a clean screenshot for the report while keeping the evidence genuine. I am showing the message that arrived, not recreating it in a document. The full flow now looks like this. The AI chooses a browser profile and account role. It creates a unique address, registers the account, polls only for that recipient, extracts the link or OTP, verifies the account, and saves the resulting session with the correct role. If email is unavailable, it selects a real number that matches the required country, requests the SMS, reads the newest code, and continues. I only get involved when the product needs human judgment or a step cannot be automated safely. This is not an inbox replacement for its own sake. It is account infrastructure built for testing. The value is not receiving email. The value is letting every research run create traceable identities and reach authenticated product state without losing time to manual verification. #BugBounty #CyberSecurity #TogetherWeHitHarder

  • bickov
    Alex @Bickov (@bickov) reported

    Found out this week that Cloudflare was telling ClaudeBot, GPTBot and every other AI crawler to stay off my site. I never set that. A default toggle was writing my robots.txt for me and I had no idea

  • ericson4smith
    Ericson Smith (@ericson4smith) reported

    @remotecleanguy Explore if you can do some edge caching with Cloudflare. We found that a major ISP in Bangkok had serious routing issues at night. Our servers are in the USA and our customers are in Bangkok. Edge caching solved the whole problem for our most important service pages.

  • JEROMEFARAILL
    Jérôme FARAILL (@JEROMEFARAILL) reported

    @a_shimanski @Namecheap @Cloudflare Namecheap is the absolute ZERO service. Only for such a simple DDoS attack..

  • SenaQifrey
    Ryu-Sena (@SenaQifrey) reported

    Not sure help but @cloudflare sure seem good option unless they don't pay great their security staff or it ignore adviser or PR. Good project but bad (probably) management

  • SpyroWiki
    SpyroWiki (@SpyroWiki) reported

    The indie Spyro Wiki is currently down at the moment due to issues with Cloudflare. It will be up soon.

  • rbxXlXi
    kyle (@rbxXlXi) reported

    wtf since when did roblox start using cloudflare

  • onchainantonio
    Antonio Gomes (@onchainantonio) reported

    Been thinking about why cryptographic migrations always take so long 🤔 It's never the maths. SHA-1 was visibly weakening in 2005. Browsers didn't finish rejecting it until 2017. Twelve years, and we had SHA-256 the entire time. TLS 1.0 was superseded in 2006 and people were still switching it off in 2020. Every one of those delays came down to the same thing. Someone's payment terminal. Someone's embedded device. A vendor that went out of business years ago. A box nobody could turn off without breaking something else. The cryptography was ready. The world wasn't. Which is why that line is worth staring at for a minute. A year ago, under 40% of encrypted traffic used post-quantum key exchange. Today it's over 70%. That's the fastest cryptographic transition the internet has ever run, and it happened without a single person being asked to switch. The trick is that nothing was replaced. Classical and post-quantum key exchange run side by side in the same handshake. Old clients keep working exactly as before. Newer ones negotiate the stronger path automatically. Support arrives, the line moves, nobody files a ticket. No flag day. No deadline. No morning where the internet broke. That's what a migration looks like when it's designed around compatibility instead of coordination. Everyone planning for post-quantum should be studying that curve far harder than they're studying the algorithms. The algorithms are finished. Getting millions of systems to move without breaking any of them is the part nobody has pulled off twice in a row. @Cloudflare publish it live if you want to watch it move 👇