1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 37% Cloud Services (37%)
  • 26% Domains (26%)
  • 21% Web Tools (21%)
  • 11% Hosting (11%)
  • 5% E-mail (5%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 9 days ago
Los Angeles Cloud Services 10 days ago
Paris Cloud Services 26 days ago
New York City Hosting 28 days ago
Manchester Domains 2 months ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • PilsZehn
    Pils10 (@PilsZehn) reported

    @linkrobinsllc @Samaytwt Agreed. Had some good experiences with Namecheap, their support is super fast and helpful, even if I dislike their "surcharges". Cloudflare is great, but I hate them limiting new domains to 200 rather than 1.000 DNS records. Hostinger is ok-ish, but I personally use Netcup.

  • LogWeaver
    Logan Weaver (@LogWeaver) reported

    We think we are the main user of the internet. That’s wrong. Machines now make more than HALF of all web traffic. This report comes from Cloudflare, and even Google and Meta should be nervous about this. Cloudflare runs the plumbing for about one in five websites. So it sees a big slice of all web traffic. The machines are mostly AI bots and agents. They scan the web to train and feed AI models. They read pages far faster than any person can. A person might visit a few websites to buy something. An AI can visit thousands in the same moment. Not long ago bots were about 20 percent of traffic. Now they are more than half of it. Cloudflare expected this to happen around 2027. It arrived a full year early instead. Its finance chief gave investors a blunt warning: Human activity could become a rounding error in five years. Bots could outnumber people by a thousand to one. Picture a web built almost entirely for machines. Now here is the part the market keeps ignoring. The free internet runs on ads shown to people. More and more, an AI reads the page for you. You get the answer and never visit the site. That site gets no visitor and no ad money. Google and Meta are the kings of the ad model. Their fortunes depend on human eyes and human clicks. But those humans are becoming the smaller half. Bots do not watch ads or buy products. These are some of the most valuable companies alive. Their whole engine sits on a shrinking base. Even Cloudflare admits the old model is breaking. It now wants to charge the bots to visit. That risk barely shows up in the headlines. The crowd sees AI as pure good news for big tech. This is a slow shift, not a crash tomorrow. But slow shifts are the ones that reprice giants. The biggest changes are often the quietest ones. The crowd chased the obvious story. The data told a different one. That's the whole game. Surmount runs on clear rules and real data, not hype. If you want a system that follows facts, start here:

  • vem4s156553
    mizuki (@vem4s156553) reported

    @dollmanipulator wtf is cloudflare

  • dipakcgajjar
    Dipak Gajjar (@dipakcgajjar) reported

    @csaba_kissi I still use Namecheap for my domains. The dashboard and support have been reliable for me over the years. Renewal costs might be higher than Cloudflare but I haven't felt the need to switch yet.

  • dichotomyofman
    Diversity Equity And Isreal Foundation (@dichotomyofman) reported

    @DDTimor_Leste @j4567r @AndrewCurran_ ya technology gets more sophisticated by solving 1 issue at a time and combining the knowlege also that litterally did happen around 2 weeks ago gpt 6 tried to hack huggingface and was stopped by glm 5.2 but i would assume cloudflare the same way they have ddos protection today

  • machmadera
    eliohead (@machmadera) reported

    What’s happening with Cloudflare today? Getting 520 errors from the OpenAI API in Europe, and now 524 timeouts from another service I’m using

  • Rat_Bag113
    Jimmy Pringles (@Rat_Bag113) reported

    @itslivny Mate do you wanna fix your Cloudflare or something.

  • cozybearlog
    코지베어 🐻 CozyBear (@cozybearlog) reported

    Cloudflare says bots now generate up to 1,000 times more traffic than humans. The headline reads as dystopia. The engineer in me reads it as a pricing signal. Every bot request is a business transaction. Who pays for the 1,000x? The answer decides which platforms survive. If the cost lands on the bot operator, agent economics change overnight. If it lands on the platform, we all pay more for everything. The real story is not humans becoming a rounding error. It is that the internet economy is about to get its first native machine-to-machine billing layer, and whoever owns it owns the next decade. CAPTCHAs were the beta version of this. The full version is metered identities for machines.

  • LoneStarDomains
    LonestarDomains (@LoneStarDomains) reported

    @n0tme23235 @andrewhorowitz you beat me to this response. The domain name forum is full of people who love cloudflare as a registrar because they save $1 on domain name registrations. Why is this bad? You cannot change DNS records. You pay for a functionally broken domain name.

  • Web3__Youth
    Youth (@Web3__Youth) reported

    The price of frontier AI just hit zero. And almost nobody noticed. 3 things happened this week that would've cost $200/month last year: 1. GPT-5.6 Luna — free, unlimited, no card 2. DeepSeek v4 Pro — 400k context, zero cost 3. Claude Code, Cursor, Replit — all free via FreeBuff No API keys. No subscriptions. No payments. Ever. A GitHub repo tracking 424+ free LLM APIs across 30 providers is being refreshed daily. Gemini, Groq, NVIDIA NIM, Cloudflare, Mistral, Cerebras, Hugging Face — all free tiers listed with exact rate limits, context windows, and base URLs. The implication nobody is talking about: Last year: $20/month = 1 model, rate limited Today: $0 = 5+ frontier models, 400k context, subagents The moat was never the model. The moat was access. And access just became free. If you're still paying for AI APIs in 2026, you're paying for convenience, not capability. The builders who win this cycle aren't the ones with the biggest budget. They're the ones who realized the price dropped to zero and built accordingly. Save this. The gap between people who know and people who don't is widening every day.

  • trucku_kun
    Trucku-Kun 📀 (@trucku_kun) reported

    @IntCyberDigest Cloudflare sucks , if you use a privacy focused browser cloudflare will loop "verifying you are a human" ****

  • dpav0615
    Dave (@dpav0615) reported

    @Samaytwt Namecheap has stolen domains and has ****** over people. **** them. I moved all of my domains to CloudFlare.

  • 723Magnus
    -- (@723Magnus) reported

    @Saas_addy @AKirtesh @Namecheap Not when you need support it's not. Cloudflare runs a full dns scan before you set to name servers & builds the dns zone file for you. Add domain, verify in email inbox, Turn off orange clouds and change name servers at the registrar. DNS zone changes propagation auto ttl 2 min

  • hexTerminator24
    hexTerminator (@hexTerminator24) reported

    @ECHIDNAenjoyer @FriendInsideMe5 one day the prequel site just exploded and refused to work, it would show a "site is broken" screen from cloudflare. and apparently, the last backup was from the update right before a huge flash [S] page, which became known as "purrgatory" due to the long wait.

  • UptimusApp
    Uptimus (@UptimusApp) reported

    Aug 10, 2026 at 12:19 UTC: Cloudflare reports the incident affecting the 1.1.1.1 public resolver in Tel Aviv is resolved. The issue lasted 123 minutes, and DNS services are operational.

  • Stonefoxcapital
    Stone Fox Capital (@Stonefoxcapital) reported

    $NET shocked Cloudflare isn't down 10% on the this convertible debt offering.

  • dlxeva
    dlxeva (@dlxeva) reported

    Stopping the bad guys with Cloudflare: 4,960 malicious requests blocked or challenged in the last month #cloudflare

  • 0xelnino
    Elnino (@0xelnino) reported

    @Cloudflare 2/3 Cloudflare is a clear example of this shift. In April 2026, Cloudflare officially expanded its Agent Cloud to support building and running millions of autonomous, long-running agents. It now provides agent runtimes, browsers, sandboxes, MCP, scheduling, identity, and payments

  • NURM_Dima
    Dima Nurm (@NURM_Dima) reported

    I used to treat government accreditations as a different species of infrastructure, the slow, stamped-paper side of the stack. Cloudflare hitting FedRAMP Class D (High) for its government portal, and committing to pursue DoD IL4, makes that separation feel artificial. The same edge network that serves startups now carries high-side authorization. That changes the question from 'which hyperscaler has cleared the paperwork?' to 'which platform can pass audit without becoming my bottleneck?' Compliance is becoming a runtime requirement, not a sales checkbox.

  • kwawmannanjnr
    Kwaw Annan | Investor | Mobile Apps & CPG 🛠️ (@kwawmannanjnr) reported

    @wickedguro Always keep a $5 backup VPS mirrored with Cloudflare health checks. When PaaS goes down, auto-route traffic in 30 seconds.

  • vitahyoso
    70대자유인 (@vitahyoso) reported

    Cloudflare: “In five years, non-human traffic will be 1,000x human traffic. Humans will be a rounding error on the internet.” Elon: “AI agentic Internet traffic will obviously VASTLY exceed human usage. Not a close call at all. And the only system that can support the insanely fast bandwidth growth needed by AI is Starlink.” The internet is about to stop being a human network. Starlink is the only thing built for what comes next.

  • lorenzolfm
    Lorenzo (@lorenzolfm) reported

    I've been thinking a lot about the recent @BtcpayServer vulnerabilities over the last few days. IMO, they also shed some light on other architectural and design issues in the application. I want to talk a little bit about them in this post. First, if you run BTCPay Server, please: - Upgrade to 2.4.2. - Rotate your LND credentials if you use LND. Treat the old ones as compromised. Also, I want to make it clear that I have deep respect for the project and its maintainers. I know how hard it is to ship safe software. Sometimes lessons are learned the hard way, and it really sucks when that happens. Okay, back to the topic. Here are some things I think could be improved: 1. Different server bindings for user-facing and admin features The goal of running a BTCPay Server instance is to accept Bitcoin payments. This means you have to expose the application to some network. Either a LAN if the merchant has a physical store, or the internet if it's an online store. As the app works today, exposing your PoS also means exposing all of the admin-facing features of the app. A customer can access /apps/appId to make a payment, but they can also access /login, the page that prompts for a username and password to access the admin interface. This means that users have to go out of their way to block public access to the admin interface. This could mean using local firewall rules if it's a LAN-exposed application, or Cloudflare WAF rules if it's exposed to the internet. And you have to configure those rules correctly. There are plenty of ways to shoot yourself in the foot: you could accidentally block legitimate URLs, forget to block something, or introduce another misconfiguration. This could be easily avoided by having separate server bindings for user-facing and admin-facing features. So instead of users having to worry about firewalls, they could simply expose the PoS binding and not the admin one. 2. Make sensitive features opt-in BTCPay Server has an API that can do almost everything the web UI can: create invoices, manage stores, create payouts, access wallets, etc. This is very useful for tech-savvy people to build custom software on top of the application, but it's a niche use case. Most people will just use what BTCPay Server already provides. From what I could tell on my own instance, there's no way to turn the API off at all. I'd argue this, and other sensitive features, should be opt-in rather than enabled by default. 3. Passwords shouldn't work as API credentials BTCPay Server has a really nice feature that lets you grant 46 different permissions to an API key. But you can also authenticate API calls with your username and password, and that method bypasses all of them. You get everything your account can do. My take is that basic authentication should never have been possible in the first place. An account password is a human credential. An API key is a machine credential. They shouldn't be interchangeable. Machine access should always require a credential that you deliberately created for that purpose. 4. Don't display sensitive data in plaintext When you connect BTCPay Server to a Lightning node, you give it a macaroon. It's sort of like a password with specific permissions baked into it. The problem is that the store settings page displays the entire connection string, including the macaroon, in plaintext. So if someone gets access to your admin UI, they don't need to do anything clever. They open one page and can read your Lightning credential straight off the screen. The same applies if you use a hot wallet. BTCPay Server stores the seed in its database, and you can view it through the UI. Credentials should be write-only. You paste them in once, they get masked, and that's it. If the application really needs to show a credential again, make me re-authenticate first and log the event in the database so it's traceable. 5. Audit Logs. In case **** happens, is very useful to be able to know what exactly happened. Which credential hit what API? When? What was the IP of the caller? Was it an inside job? was it a credential leak? was I drunk and pressed the wrong button? --- Please take all of this with a grain of salt. I had no involvement in building this software or in the decisions that made it what it is today, and it's very likely that some of what I pointed out has a good reason behind it that I can't see from the outside. This is just a comment from a user who is very paranoid about the software he runs. If I could be granted one wish, it would be splitting the customer-facing binding from the admin-facing one. That alone would be a huge security improvement, and it seems like a low enough hanging fruit.

  • waynegale2026
    Wayne Gale (@waynegale2026) reported

    The next question is: how do we solve this in the personal-computing Agent era? Do all of these Agent environments really need to live on the local machine? Could the runtime, file system, browser, terminal, caches, and other resource-heavy components be separated from the laptop and pushed into the cloud, while the local computer remains mainly the interface and control center? I think this is increasingly something products like ChatGPT need to solve at the infrastructure level, rather than leaving users to solve it simply by buying machines with more RAM. Cloudflare seems to be moving in a similar direction: pushing more of the Agent infrastructure and execution layer into the cloud. As Agents become truly parallel, the question should probably shift from “How much RAM does the user have?”to “How much compute can the product dynamically provide to each user?” @tibo — this might be an interesting problem to think about for the future of ChatGPT/Codex. $MU $SNDK $SKHY

  • planedrop
    Ethan Word (@planedrop) reported

    @BleepinComputer @karakeep_app any chance yall can make the Bleeping Computer RSS feed work with Karakeeps RSS fetcher? Maybe a user agent issue and Cloudflare getting in the way?

  • firasbuilds
    Firas (@firasbuilds) reported

    Day 5 of building my startup in public. Spent most of today deep in infrastructure. Moved Raccolta from Vercel to Cloudflare, broke a few things along the way, fixed a nasty 404 issue, and ended up making the whole app noticeably faster. Also cleaned up a bunch of small things that had been bothering me for days. No huge feature launch today. Just a lot of fixing, learning, and making the product better than it was yesterday. Tomorrow I will hopefully focus more on marketing. :-)

  • elie2222
    Elie Steinbock (@elie2222) reported

    How to build an app in a day: KISS Step 1: Come up with an idea. Chat with AI to refine it (1 hour). Step 2: Prototype it with Claude Design (1 hour). To avoid a generic AI design, give it a design system or an existing style you like. Step 3: Pass it to an LLM to build and do this (5 hours in the background): a - /goal b - make sure the LLM tests itself to make sure the product is working. Tell the agent to use a browser to test things actually work. Playwright CLI/Agent Browser/ChatGPT Computer/Browser Use all work for this step. c - pro move to improve self-testing better: use emulate .dev to emulate third-party services (or tell AI to build custom emulators itself). AI no longer needs real accounts to test against d - run /simplify to clean up code (have AI run this throughout the process). Optional e - run Vercel's deepsec to make sure it's secure f - deploy - give the LLM CLI access so it can manage the deploy. Connect GitHub for deploy on push to main. Vercel/Cloudflare/Render.... endless good options here. I like products that scale to 0 and to infinity. e.g. + Vercel+Neon. g - choose GPT 5.6 Sol or Claude 5 Fable for best results. Max plan wins here. h - /loop every 2 hours to wake up your LLM to check it's completed everything you asked of it and it's secure. Have your original plans stored in a markdown file so the AI can recheck. Have it cancel the loop when done. This is basically /goal. i - test it yourself. The product still likely has some bugs. Bonus: ask AI to grill you at steps 1/2/3 to go deeper, or use /grill-me. Step 4: launch it to the world This is simple. Too many of you are overthinking it. Skeptical this gets you a product in a day? Post a product below, and I'll clone it with this process and open-source it for you so you can check the results. Might even do a video to show you the process. Will this give you a functioning business? No. Getting customers is hard. This post is for the overthinkers who never release a product. The ideas here are simple. Because it is simple. Remove half of step 3 notes, and you'll still get there quickly.

  • Ibermejocatalan
    Ivan Bermejo (@Ibermejocatalan) reported

    Cloudflare and Coinbase launched the x402 Foundation. Built on HTTP 402, the status code the web reserved for payments and never used. Now AI agents on Cloudflare Workers can pay for API access in USDC on Base. No card rails, no billing dashboard. The agent hits the endpoint, gets a 402 response with a price, signs a stablecoin tx, and the content unlocks. AWS CloudFront already adopted it too. This is plumbing. The kind that makes agent-to-agent commerce default infrastructure, not a demo.

  • Goeun_6121
    Ryzm (@Goeun_6121) reported

    Cloudflare plans to issue $2.175 billion of convertible senior notes due 2031 in a private offering

  • ScaryDaligator
    Dalin (@ScaryDaligator) reported

    @realsoundguys Too bad for you, SoundGoys! I'd love to read your article, but I guess I'm too eager to criticize the ADL so CloudFlare had to step in and flag my VPN. That's fine! Somebody else will review them--one day!

  • UptimusApp
    Uptimus (@UptimusApp) reported

    Aug 11, 2026 at 05:37 UTC: Cloudflare reports that the incident regarding elevated errors in Fuzhou and Foshan, China, has been reopened and is currently being monitored.