Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (35%)
- Cloud Services (27%)
- Web Tools (15%)
- Hosting (15%)
- E-mail (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 10 days ago |
|
|
Hosting | 12 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 1 month ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Erik ≋ 🇺🇸 Fight for Digital Rights 🇺🇸 (@ErikInCt_) reported@PorkPoncho PlayStation can't control when AWS ***** up. Come on bro, you're smarter than this. There's no switch that says, "Bypass AWS if AWS has issues." My site goes down if Cloudflare has issues, somethings you can't control.
-
Aiden (@WallisDev) reported@thdxr mostly terraform and a custom deploy pipeline that just pushes code directly to the workers. Config changes land through terraform updates It sucks. this stuff and: * No workload identity federation * Their permissions story is simple - too simple hold Cloudflare back for me
-
DFIR Radar (@DFIR_Radar) reportedChaos ransomware's msaRAT routes all C2 traffic through Chrome DevTools Protocol and WebRTC, making the RAT process itself invisible to network monitors while burying attacker comms inside legitimate browser activity. Key findings: - Delivered via curl.exe over plain HTTP on port 443 (bypassing port-only firewall rules) as update_ms.msi to C:\programdata\, which drops lib.dll directly into memory via a custom MSI action. The RAT exports a single function, RUN, and impersonates a Windows update in installer metadata. - msaRAT launches Chrome or Edge in headless mode via CreateProcessW, injects JavaScript through CDP Runtime.evaluate after bypassing CSP, and signals the C2 through Cloudflare Workers endpoint is-01-ast.ols-img-12.workers[.]dev. Twilio TURN (global.turn.twilio[.]com) relays all subsequent WebRTC DataChannel traffic, intentionally omitting ICE candidates so no P2P path forms and the attacker's real IP never appears in traffic. - All network activity from the RAT process is limited to 127.0.0[.]1. External comms appear as browser-originated WebRTC, double-encrypted with ChaCha-Poly1305 over DTLS. The C2 IP 172.86.126[.]18 appears only in the initial MSI download. - Hunt for headless browser processes (HeadlessChrome User-Agent) making WebRTC connections, MSI files writing DLLs to ProgramData, and curl.exe dropping installers. ClamAV sig Win.Downloader.ChaosRaas-10060321-0 and Snort rules SID 66839-66841 (v2), 301587 (v3) cover this. #DFIR_Radar
-
Santosh Yadav (@SantoshYadavDev) reported@apvarun @astrodotbuild @Cloudflare Definitely and I get why pages support is as removed, but I wish the migration experience was seamless too
-
Dr. Xi Zeng (@xiz25) reported@dhh @Cloudflare Putting speedtest and DNS choice in the same panel is the detail: diagnosis and action live together. Most network UIs show status, then make users hunt elsewhere for control. Which metric actually changed your behavior after using it?
-
Sidi jeddou (@sidi_jeddou_dev) reportedPlease stop using Opus 4.8 for your serious production apps. I built something with @DrizzleORM, @Cloudflare D1 and @expo I asked Opus to add status to one of my schemas, and it used plain text instead of Enum for type safety with database CHECK constraint, since there will be only: -active -pending -suspended This is actually a bad sign that this model just generates slop
-
Polarbear · App Growth Breakdowns (@polarbeargrowth) reportedPublic app, private admin, zero custom auth code. Cloudflare Access locks /admin/* behind Google login while the rest stays open. • Bake it into IaC so agents build the UI and protect it in one pass • No auth logic to maintain Vibecoded tools ship safe by default. h/t @thdxr
-
pdp (@pdp) reportedBoth cloudflare and vercel AI gateways do very little when it comes to gemini models - i.e. you need extra plumbing to get it right. But never mind. We fixed it. I think the CBK AI gateway is the only one out there that provides consistent behaviour across all models.
-
avyonette (@avyonette) reported@IntCyberDigest I already get captchas everywhere, even when not using a VPN (**** Cloudflare) At this point I'm just going to stop using the internet entirely
-
Fayi (@fayimora) reported@pidotdev Possible issue for UK/London users: model catalog requests are timing out. I VPN'd to another country and they worked immediately. Perhaps a Cloudflare edge hiccup?
-
Matt Schober (@migratewithmatt) reportedStopping the bad guys with Cloudflare: 2,176 malicious requests blocked or challenged in the last month #cloudflare
-
Trishool | SN23 (@trishoolai) reportedAI is at the same inflection point web security hit twenty years ago. The attacks are real, the damage is mounting, and the industry is starting to realise that shipping without a safety layer isn't a risk worth taking. Cloudflare didn't create that shift in web security. It became one of the companies that defined it. We believe the same thing is happening in AI right now. AI agents have deleted production databases, exposed sensitive customer data, and taken actions their creators never intended. As AI systems do more and touch more, the cost of getting safety wrong keeps growing. The internet eventually stopped expecting every company to build its own security infrastructure because the problem outgrew what individual teams could manage. Shared infrastructure became the better answer. AI safety is heading in the same direction. That's the future we're building toward with HaloGuard on Bittensor. Production-ready, peer-reviewed, open weights, and built to protect AI systems across 46 languages, backed by a decentralised network that gets stronger every week. AI safety isn't a problem that gets solved once. It's infrastructure that has to keep learning as the threat landscape evolves. That is what we are building on Bittensor.
-
The_Conservative_Commenter (@_The_Commenter_) reported@dhh @Cloudflare can confirm that it is very nice. when I first updated to quatro, the icon would not update depending on if the wifi was on or not, but the issue seems to have fixed itself
-
Sumanth (@Sumanth_077) reportedTurn any website into agent-ready data! Loop engineering is about designing systems that run agents autonomously. Instead of prompting your agent manually each turn, you write a loop that finds the work, hands it to the agent, checks what came back, and decides what happens next. Your job is to design the loop once and walk away. But loops that need live information from the web hit a real constraint. JS-heavy pages return empty content. Anti-bot systems return challenge pages. Login walls block access entirely. When the model gets weak context back, it still responds - just less accurately. Anakin is building the source-access layer underneath agents. URL Scraper turns any URL into clean Markdown, HTML, or structured content immediately usable by an LLM. Built for scale across 200M+ active websites globally, including a large chunk of Cloudflare and Akamai-protected pages. Authenticated sessions handle content behind login walls. Wire handles workflow-heavy sites. Login flows, navigation, form submission, report exports - all accessible through a stable API. Define the workflow once and Wire keeps it working as websites change. Key capabilities: • Clean Markdown, HTML, or structured output from 200M+ active websites • Built for difficult pages including Cloudflare and Akamai-protected sources • Authenticated sessions for content behind login walls • Wire for login flows, navigation, form submission, and export-based access • Useful for AI agents, RAG systems, finance intelligence, and vertical AI workflows I've shared the link in the replies!
-
hai (@haikukoten) reportedStopping the bad guys with Cloudflare: 375 malicious requests blocked or challenged in the last month #cloudflare
-
Leon Morris (@LeonMorris) reported@shihou22 Yeah, I think it's down. I'm getting a CloudFlare error.
-
Austin S. Lin (@siraustin) reported@prd_008 dear lord no… Sites is a fine name for what it is (it’s cloudflare pages and workers abstracted). one big issue is that you get different levels of github access from within chatgpt app depending on whether you have chat (no access to private repos), work (access to existing repos), or remote selected (full github access to create and manipulate repos).
-
Jason · The Orbital Forge🧬🤖 (@occupymars___) reported@JoeWinton @XFreeze Already working towards that my Os linux is almost an AI node with no desktop only a dashboard scroll my network access is anywhere phone tablet p.c using cloudflare it works
-
the Sleeping Wizard (@magicnaptime) reportedDamn guys maybe try dialing it up to 2:2:2:2 for Pete's sake @CloudflareDev @Cloudflare
-
Vikas(Vik) Malpani| AI for US Real Estate (@vikasmalpani) reported@dhh @ashirsc @Cloudflare We run the same loop for closing exceptions. An agent catches the missing doc or mismatched figure, drafts the write-up with the evidence, and files it for a human to clear. The win isn't fewer errors, it's that every exception arrives already triaged.
-
Camaleón Raro (@camale0nrar0) reported@simonw the deployment abstraction is nice until you need custom background workers or cron triggers outside their sandbox. had to drop down to direct cloudflare wrangler configs+ *** hooks because the managed UI hid too much logging when mutations failed silently. how are you handling state persistence when workers scale?
-
syxncwtww (@syxncwtw) reportedDoes anyone know if cloudflare is down ??
-
Ara T. Howard (@drawohara) reportedtoday, with the help of 3 agents, I managed to create a cloudflare API token JFC
-
VictualBro (@Victual_Bro) reportedYour daily reminder that @Cloudflare is a wart on the *** of the internet. Not bad enough I have to deal with it here daily, but now it's blocked my email server. Yaayyyyy.
-
Invader Zim (@spiralout112) reported@dhh @Cloudflare I did go down the dns benchmarking rabbit hole, and cloud flare definitely did win.
-
Art Chicken 🐓 (@ArtChicken4) reportedFrom Jovan Hutton Pulitzer's Telegram- - For tech nerds understanding the PCAP fraud: The mechanism works, and every input is public. Rosters of US election officials are published (state SoS directories, EAC, NASS, commercial lists). Take each office's email domain → MX lookup → resolve the mail host to an IP → geolocate it. You now hold a table of "jurisdiction → IP → city/lat/lng" covering every election jurisdiction in the country, built entirely from DNS, without ever sending a packet to an election office. That table would look authoritative and survive spot-checking — the IPs are real, the org names are real, the geography is real. It would also be probatively empty, because an MX record identifies who handles that office's email. It says nothing about vote systems. The signature of an MX-derived list would be hundreds of jurisdictions collapsing onto a handful of shared mail-provider IPs — Microsoft 365 (*.mail.protection.outlook.com), Google Workspace, Barracuda, Proofpoint — because that's who most county governments use. What your file actually shows I tested it. The target roster is a complete enumeration of election jurisdictions, and the counts are exact: State Rows Actual jurisdiction count Massachusetts 351 351 municipalities Connecticut 169 169 towns Texas 254 254 counties Georgia 159 159 counties Virginia 133 95 counties + 38 independent cities Kentucky 120 120 counties North Carolina 100 100 counties Iowa 99 99 counties One row per jurisdiction, zero duplicates in any state. Real network traffic doesn't distribute itself one-event-per-administrative-unit. This is a roster walk. But the IPs are coarser than your MX hypothesis. Eleven states collapse to a single IP for every jurisdiction: 490 Maine town clerks -> 13.32.25.126 (AWS CloudFront edge) 351 Massachusetts clerks -> 45.60.195.2 (Imperva/Incapsula WAF) 246 Vermont town clerks -> 45.60.45.214 (Imperva/Incapsula WAF) 237 New Hampshire clerks -> 199.192.7.129 169 Connecticut town clerks -> 199.107.32.42 160 Texas election admins -> 98.129.145.194 (Rackspace) Plus 104.17.x / 104.18.x (Cloudflare) across 189 more rows. Those aren't mail servers — they're CDN and WAF edge addresses, the public front door of a state's website. A CloudFront edge IP is shared by thousands of unrelated customers; it isn't "Maine's election system," and you can't route vote data to it, because it terminates HTTPS for public web content and nothing else. So the lookup behind this file was one resolution per state's public web presence, cloned across every jurisdiction in that state. An MX-per-office build would have been more sophisticated than what was actually done here. And 253 rows have TargetIP = literally * — a failed lookup, no address at all. Those rows still carry 70,448 flipped votes. Votes attributed to an intrusion against an IP that does not exist. Bottom line Your instinct is right about the class of technique: a public roster plus DNS resolution manufactures a nationally-complete, real-looking IP table with no access to anything. That's the general answer to "could this manufacture data" — yes, trivially, and it's undetectable if you only check whether the IPs are real. The detection method is the reverse question: not "is this IP real?" but "what does this IP actually serve?" Real intrusion data resolves to the specific host attacked. Manufactured data resolves to whatever the jurisdiction's public name happens to point at — a CDN, a WAF, a mail gateway, a hosting provider. That's what's here: 490 distinct Maine towns, all pointing at one Amazon CDN address.
-
Rishi Raj Jain (@rishi_raj_jain_) reported@SantoshYadavDev @astrodotbuild @Cloudflare CF Pages are basically replaced with Worker. Lmk if you need any help!
-
Vlady Veselinov (@vladinator1000) reported@thdxr What specifically can't you do with IaC? Maybe someone at Cloudflare can help? @dillon_mulroy do you know someone who works on Wrangler?
-
Josh Lambert (@ZettaGeek) reported@dhh @Cloudflare Will it display ipv6? I'm deep in the middle of rolling out IPv6 across my internet subscriber customers in Rural Alabama. My Omarchy SER9 was the first computer on the network to get a fully routable ipv6 address!! 😎
-
Vincas Stonys (@VincasStonys) reported@dhh @Cloudflare I can't help but see AI built UI here, even if it isn't (dunno). Claude ruined all caps for me