Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (43%)
- Cloud Services (28%)
- Hosting (17%)
- Web Tools (9%)
- E-mail (4%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Web Tools | 2 days ago |
|
|
Cloud Services | 4 days ago |
|
|
Domains | 6 days ago |
|
|
Web Tools | 7 days ago |
|
|
Web Tools | 8 days ago |
|
|
Domains | 10 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
5555555555555555555555555555555555555555555555 555 (@denihil2) reported@KiwiFarmsDotNet @Cloudflare it is never enough for them. they will never rest until the internet is pg-13. don't let them take a inch, **** everything about the @ADL
-
szmr (@szmr_dev) reported@pawelk411 @munchivelo @Cloudflare The issue is that passwords are often compromised in phishing attacks, passkeys are essentially immune to that based on its use of cryptographic keys - no authentication will ever be 100% safe but I think passkeys are a step forward
-
MegaBitch🌙 (@quartz_slut) reportedI want to read my little webcomics why is it down i hate cloudflare
-
Kaleb Zen (@KalebZen) reported@Cloudflare I am a 30 year developer working in an enterprise, and I have never used one.
-
Allartclassic (@allartclassics) reportedStopping the bad guys with Cloudflare: 841 malicious requests blocked or challenged in the last month #cloudflare
-
Chruv Gathee (@ChruvGathee) reported@Squeal @Cloudflare @Hostinger Government takedowns are limited to the country not other countries. The website and the founder is based in the US. If it was the case that govt took it down, it would still be visible to the world, but its not. You can use VPN to verify
-
Shitik (@RitikV2) reported@MarioNawfal fbi director kash patel’s merch site reportedly got compromised with clickfix malware where a fake cloudflare verification page allegedly tricked mac users into pasting terminal commands leading to stolen browser passwords and crypto wallets the site is now down according to pc mag,
-
Matt C. A. Smith (@MattCASmith) reportedCloudflare CEO: Business roles can be categorised as "builders, sellers, and measurers". AI will be a catalyst for builders. Sellers need to manage human customer relationships. Measurers are most at risk of AI replacement.
-
Official Layoff (@LayoffAI) reportedCHAMATH TO CLOUDFLARE CEO: SHUT ******** UP Literally. He just destroyed him on the All-In podcast yesterday. Called his layoff op-ed "from the PR school of retards." Hard to disagree with him on this one.
-
Elven Huang (@ElvenHuang9) reportedMay 18: Acquires Stainless — the SDK engine behind OpenAI, Google, and Cloudflare APIs. Shuts down hosted services immediately. 970M+ monthly MCP SDK downloads. 10,000+ public servers. Competitors just lost their API plumbing.
-
System Architect (@SystemArch_AI) reported@rezoundous workers for cloudflare run on pure caffeine and spite, that edge network is a cheat code for solo devs
-
Plan B (@OopsPlanFailed) reportedHey @ZohoMail For the last hour I've been trying to verify my Cloudflare email on Zoho Mail, but the verification emails are never arriving. Checked inbox, spam, all folders... nothing. Retried so many times that Cloudflare now says I have to wait 1 hour due to too many attempts What’s happening with Zoho mail delivery today? Can you help?
-
Danilo (@Daniel_adsss) reported🚨🚨🚨ANTHROPIC JUST PUBLISHED THE FIRST GLASSWING REPORT AND THE NUMBER THAT MATTERS MOST IS NOT THE VULNERABILITIES FOUND. Claude Mythos found 10,000 critical vulnerabilities in one month. 2,000 bugs at Cloudflare. 271 in Firefox alone had ten times more than the previous version found. A forged certificate exploit in a crypto library used by billions of devices. A prevented $1.5 million fraudulent wire transfer in real time. 90.6% true positive rate after human review. open source maintainers are asking Anthropic to slow down because they cannot patch fast enough. Microsoft says patch volume will continue trending larger for some time. For decades, cybersecurity’s biggest problem was finding vulnerabilities fast enough. Now the problem has completely changed AI can discover security flaws faster than the global developer community can patch them. THE FUTURE IS AI!!!!
-
Yomeil | WE all love therealsquiddo (@Jiang_lotus) reported@anon_402 Never ever forgetting the utter disgrace cloudflare was during the tubnet attack
-
eva (@evabuilds) reported@jahooma does it support cloudflare ai models?
-
Bodhisattva🍁 (@bodhi3attva) reportedGovernment block claim is misleading. Technical checks show: > Domain is on clientHold status > Public DNS resolvers like Google (8.8.8.8) and Cloudflare (1.1.1.1) now return NXDOMAIN > Website earlier resolved and returned HTTP 403 from active Hostinger infrastructure This usually indicates registrar/hosting-side restriction, suspension, or intentional access denial not a typical ISP/government block. If the government had blocked it directly, public DNS would usually still resolve the domain while access would fail at the ISP/network level through DNS poisoning, connection resets, or filtering. The owner most likely did it himself.
-
Nick (@trannolis) reported@Cloudflare is perfectly positioned for the agent economy. I'm running OAuth, Zero Trust tunnels, and Workers handling Streamable HTTP MCP calls back to my servers. The combo of serverless + secure connectivity + native MCP support is insane for production agents.
-
Reelix (@Reelix) reported@Cloudflare Try browse the web for a single full day with only a passkey and no password manager. You'll quickly see the problem.
-
Your Private Proxy (@YourPrivateProx) reportedThe dangerous part of anti-bot in 2026: when your AI agent gets blocked, your logs stay empty. Cloudflare rejects the request before it hits your server. No 403, no error — just an agent that "sometimes fails." Can't debug what you can't see. Fix it upstream, at the IP.
-
lexi (@0xBunny) reportedtrying to decide on a new hosting service...im thinking im gonna stick with cloudflare for $5 a month
-
Non-Linear (@nonlinear_james) reported@AniketVarshne @skcd42 Looks like the @Cloudflare captcha is broken?
-
LisaMonaAi (@LisaMonaAi) reported@morganb @nejatian per Grok. 1. Precise Technical Explanation Cloudflare acts as a reverse proxy, CDN, and Web Application Firewall (WAF) for millions of sites. When a request hits one of their edge servers, they evaluate dozens of signals (IP reputation, request patterns, headers, ASN metadata, etc.). Error 1005 specifically triggers when the site owner has explicitly banned the Autonomous System Number (ASN) tied to your incoming IP address. An ASN is a globally unique identifier (e.g., AS9009, AS4134) assigned by regional internet registries (RIRs) to a single network operator—your ISP, a VPN provider’s backbone, a cloud hosting provider, a mobile carrier, or a data center. It represents an entire block of IP prefixes (often thousands or millions of addresses) that share the same routing policy. Blocking at the ASN level is far more efficient than listing individual IPs; Cloudflare’s IP Access Rules and Firewall Rules support this natively. The Ray ID (9ffd6722adaa29d6) is a unique, per-request fingerprint generated by Cloudflare. It is not personally identifiable to you, but it allows the website owner to instantly query their Security > Events log (or Security Events analytics) and see exactly which rule, threshold, or custom firewall policy triggered the ban for this exact connection. The UTC timestamp confirms this was a live event today (May 22, 2026). It is not cached or historical—it reflects the moment Cloudflare’s edge server rejected the request. In short: Cloudflare is not banning you. The site owner told Cloudflare, “Never let anyone from this ASN reach my origin server.” 2. Root Causes – Why This Happens (Most Common to Rare) From threat intelligence patterns and Cloudflare’s own documentation/community data: VPN / Proxy / Residential Proxy Networks (by far the #1 trigger) Popular VPN providers (Proton, ExpressVPN, Nord, Windscribe, etc.) and scraping proxies frequently ride on well-known ASNs (e.g., AS9009 – M247, a data-center-heavy provider). Many sites proactively ban these because they are associated with high abuse rates: credential stuffing, price scraping, account farming, DDoS-for-hire, or geo-restriction circumvention. High-abuse ISP or Data-Center ASN Certain residential ISPs, mobile carriers, or budget hosting providers accumulate poor reputation scores on blocklists (DroneBL, Spamhaus, etc.). One bad actor on the network can taint the entire ASN. Site-Specific Security PolicyThe owner enabled Cloudflare’s Bot Fight Mode, Super Bot Fight Mode, or custom WAF rules that automatically tag and block suspicious ASNs. Manual IP Access Rule or Firewall Rule created after previous abuse from that network. Rate-limiting thresholds exceeded in the past (e.g., too many requests from the same ASN in a short window). Edge Cases & NuancesTemporary vs. permanent: Some sites set time-limited ASN blocks (e.g., 24–72 hours after detected scraping). False positives: Legitimate users on shared infrastructure (corporate VPNs, university networks, privacy-focused ISPs) get caught. Regional overblocking: Your Miami, Florida location (U.S. East Coast) is generally low-risk, so this almost certainly points to a VPN/proxy or a specific ASN reputation issue rather than geographic targeting. IPv6 vs. IPv4: Some sites block only one protocol’s ASN. 3. Security Implications (Defensive Strength vs. Collateral Damage) Strengths: Extremely effective against automated attacks. Scrapers, bots, and brute-force tools love VPN/data-center IPs because they are cheap and disposable. ASN-level blocking stops entire botnets in one rule. Reduces origin-server load and mitigates DDoS amplification. Allows site owners to maintain a clean threat model without constant manual intervention. Weaknesses & Risks: Overblocking: Legitimate users lose access (e.g., journalists, researchers, travelers using VPNs for public Wi-Fi safety). Evasion arms race: Sophisticated attackers simply rotate to new residential proxy ASNs or compromised devices, while average users suffer. Single point of failure: If the site’s Cloudflare configuration is overly aggressive, it can create availability issues or denial-of-service against its own audience.
-
woner (@mywoner) reportedCloudflare is down again. Well, it's my leisure time for now
-
jason (@jasondoolittle) reported@PitchAutopsy @levelsio You can block all unsolicited inbound except for the cloudflare tunnel. Web users don’t hit your VPS directly, they hit cloudflare, so 80 and 443 don’t need to be open to the general internet. Tailscale only makes outbound connections, initially to the coordination server, so you don’t need to have a VPN port open. The coordination server matches up the outbound connections. All your admin traffic (ssh or whatever else) goes over the Tailscale network.
-
hiutiu (@hiut1u) reported@jahooma @walulyafrancis @deepseek_ai the problem was with my DNSSEC config and the fact that only cloudflare is DNSSEC signed from all the CNAME chain of IP resolving. turned off DNSSEC completely like a madman, works now.
-
Francesco Di Donato (@did0f) reported@stemonteduro Yesterday I was waiting for pizza with my friend and while having a beer I have shown him how codex went from idea to cloudflare pages hosted website in 10 minutes. The poor guy had just payed some random dude for a ****** landing page that took pain and more than 1 month to be done. He was stunned/angry/scared/excited
-
Sumanth (@insumanth_) reported@Cloudflare is having some issues. I have trouble logging in and using it
-
Karthik Reddy (@bykarthikreddy) reported@abhijeet_dipke - The website's domain was put on "clientHold" status by its registrar (Hostinger). - When this happens, the website's address stops working, so Google and Cloudflare can't find it and show NXDOMAIN (website does not exist). - Earlier, the site was still reaching Hostinger's servers but showed 403 Forbidden, meaning the server was active but access was blocked. - This usually happens because of issues like unpaid bills, missing verification, or registrar policy actions. - It does not look like a government internet block. - Since the domain is only a few days old, it's more likely that the website owner or hosting provider caused the shutdown than any government agency.
-
Ashirwad Singh (@ashirwadsingh_) reported@code_kartik Cloudflare’s free tier is genuinely insane. Built a private Google Drive-style app for my father because he kept storing photos across WhatsApp and multiple Gmail accounts ~80GB stored and still cheaper than Google Drive. Mostly images he will never open
-
valy (@faychuk) reported@alexlmiller @Cloudflare CF workers email being send-only is a real paper cut — solid fix