Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (45%)
- Cloud Services (28%)
- Hosting (17%)
- Web Tools (6%)
- E-mail (4%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 2 days ago |
|
|
Domains | 4 days ago |
|
|
Web Tools | 5 days ago |
|
|
Web Tools | 5 days ago |
|
|
Domains | 8 days ago |
|
|
11 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Mussadiq wani (@MussadiqWani) reportedHey @abhijeet_dipke the petition section on Cockroach Janta Party’s site is frustrating. Cloudflare keeps asking me to prove I’m human again and again just to sign. Most users are in India, but this setup isn’t tuned and people leave midway. Hosting it closer to India would help
-
Michael hochstat (@HochstatMichael) reportedCloudflare just made one of the clearest “AI + layoffs” statements we’ve seen from a public company. Despite reporting a strong Q1 2026 (revenue up 34% YoY to $639.8M), Cloudflare cut ~20% of its workforce (~1,100 employees). In a WSJ op-ed, CEO Matthew Prince explained why. His framework (inspired by Peter Drucker) splits roles into: - Builders (engineers, product) - Sellers (sales) - Measurers (ops, HR, finance, compliance, analytics, middle management) The key idea: AI disproportionately replaces “measurers.” Agentic AI can now: - Expand manager span of control - Automate financial close and reporting - Enable continuous risk monitoring - Reduce compliance and audit overhead Most layoffs targeted this category. Prince called out how unusual this is: A company growing 30%+ cutting 20% of its workforce may be a preview of what AI-driven operating models look like. Market reaction was mixed: The stock dropped ~20% initially despite the earnings beat, suggesting investors are still parsing whether this is efficiency-driven upside or a signal of slowing growth. At the same time, Cloudflare is still hiring: - Plans for ~1,111 interns in 2026 - ~1M applications reportedly received - Continued hiring in AI-related roles So this isn’t “shrink the company”—it’s “reshape the workforce.” The open question: If AI meaningfully boosts productivity, do companies reinvest in growth—or lean into margin expansion? Cloudflare is one of the first large-scale test cases. ***
-
Amir Fadhel (@DrAmir0078) reportedCloudflare is down, seriously scary! #cloudflare
-
FootiememeTV (@FootiememeTv) reported@inference_labs inference changes the economics of AI. But once outputs start driving real systems, verification becomes the bottleneck. Cloudflare leaning into AI reviews at scale is another signal that the next infrastructure layer won’t just generate intelligence it’ll prove it.
-
udevadm (@udevadm) reported@_JohnHammond @OepnAI Fell for this and got really pissed off because the cloudflare captcha was saying it didn't support linux
-
woner (@mywoner) reportedCloudflare is down again. Well, it's my leisure time for now
-
Sumanth (@insumanth_) reported@Cloudflare is having some issues. I have trouble logging in and using it
-
Jonathan (@jonnyMarshal) reported@Cloudflare I can’t login to my dashboard for over 30mins now!
-
Sir FAFO (@HowToQuotePro) reportedSuper chuffed with what my CRM is turning into and how many pro subs it's allowing me to drop. When companies like AWS, Github, CloudFlare etc keep getting hacked, it's time to stop lining their pockets and lock it down yourself. Big is not safe anymore.
-
Tiresias (@iamTiresias) reported@heygurisingh The fact that the real IP leaks in a dozen places companies forget to clean up is the real lesson here. Putting Cloudflare in front of your site does nothing if your old DNS records or SPF entries still point straight to the origin. What's the most common leak point? Feels like historical DNS records would catch most people - they set up Cloudflare but never think about what was exposed before they turned it on.
-
El Guapo (@Checkm3out) reported@dok2001 @threepointone @zebassembly I desperately need help - your ANC cloudflare center is constantly having issues and traffic is not being rerouted - we updated to Argo and it will won’t route . All other regions work. This has been ongoing for at least a week now! Plz plz
-
Ruben Herz (@aethroc) reportedAnthropic acquired Stainless — the SDK and MCP platform that OpenAI, Google, and Cloudflare all depended on. Hosted products shut down. Competitors now rebuild from scratch. Control over the AI dev tooling stack just shifted hard. #Anthropic #MCP #AIDev
-
⚙️ Zubair H (@localsysadmn) reportedHow to use Cloudflare as a free security layer for WordPress without breaking anything: 1. Move your DNS to Cloudflare (free plan is enough) 2. Set SSL/TLS to Full (Strict) if you have a cert on the server. If not, Flexible is fine temporarily. 3. Enable "Under Attack Mode" only during active bot traffic. Keep it off normally. 4. Create a WAF rule: block requests where URI contains /wp-login.php AND IP reputation is high threat. 5. Enable Cloudflare Bot Fight Mode (free). 6. Cache static assets: Browser TTL 1 year for CSS, JS, images. 7. If using WooCommerce: add a cache bypass rule for cart, checkout, and my-account pages. This single setup has reduced bot traffic on client sites by 60 to 80%. Takes about 30 minutes to configure correctly. Questions? Drop them below.
-
sourcerer (@sourcerer19) reported@aboutberlin You could use cloudflare plus robots.txt to block all Llms and crawlers and then issue dmca notice to google for removal of all links. It would not be legally allowed to feed on your content If you catch them doing it which will happen you sue them and profit? I’m sorry bro.
-
Harshil (@harshil1712) reportedAll About Berlin has a been a really useful resource. The impact due to AI is horrible. We might start loosing useful resources like this, if things continue. The whole AI Content negotiation work from @Cloudflare starts making more sense! I have seen similar issues with other platforms :(
-
ً (@riscented) reportedi need to like make a another strawpage 4 someone and cloudflare is not working
-
John D. Fowler (@jdfowler0x) reported@Cloudflare Props to @claudeai #ClaudeCode for letting me know Cloudflare's API was down before I even had to go to the the internet. #CloudflareOutage
-
Steve the Stupid (@stevethestupid) reported@notnullptr @catgirlprostate @dm4uz3 Considering they were hammering the website from a single IP, Cloudflare could easily be like "**** you" for spamming the site, here's something to trip you up.
-
Preetham Kyanam ☣︎ (@pkyanam) reported@daytonaio So I believe my account is Tier 1 access and something about that from what I can tell is causing issues with my application and Daytona’s proxy URLs. I have to proxy my traffic again through Cloudflare worker for my application to work correctly
-
valy (@faychuk) reported@alexlmiller @Cloudflare CF workers email being send-only is a real paper cut — solid fix
-
Miu (ReisenMiu) 🇻🇳 (@RetroCoastFan) reportedholy ****. i srsly js realized it today no wonder i had to use cloudflare warp :/
-
Virgo (@VirgocuteUwU) reported@ao3Learning Hey, i can’t pass through the cloudflare gate in the app. Can you fix it pls?
-
purikku22. ron (@purikku22) reported@nun1aeth @0xSunflowerLand mine is on and off. its cloudflare issue, server maintenance here is Singapore.
-
LisaMonaAi (@LisaMonaAi) reported@morganb @nejatian per Grok. 1. Precise Technical Explanation Cloudflare acts as a reverse proxy, CDN, and Web Application Firewall (WAF) for millions of sites. When a request hits one of their edge servers, they evaluate dozens of signals (IP reputation, request patterns, headers, ASN metadata, etc.). Error 1005 specifically triggers when the site owner has explicitly banned the Autonomous System Number (ASN) tied to your incoming IP address. An ASN is a globally unique identifier (e.g., AS9009, AS4134) assigned by regional internet registries (RIRs) to a single network operator—your ISP, a VPN provider’s backbone, a cloud hosting provider, a mobile carrier, or a data center. It represents an entire block of IP prefixes (often thousands or millions of addresses) that share the same routing policy. Blocking at the ASN level is far more efficient than listing individual IPs; Cloudflare’s IP Access Rules and Firewall Rules support this natively. The Ray ID (9ffd6722adaa29d6) is a unique, per-request fingerprint generated by Cloudflare. It is not personally identifiable to you, but it allows the website owner to instantly query their Security > Events log (or Security Events analytics) and see exactly which rule, threshold, or custom firewall policy triggered the ban for this exact connection. The UTC timestamp confirms this was a live event today (May 22, 2026). It is not cached or historical—it reflects the moment Cloudflare’s edge server rejected the request. In short: Cloudflare is not banning you. The site owner told Cloudflare, “Never let anyone from this ASN reach my origin server.” 2. Root Causes – Why This Happens (Most Common to Rare) From threat intelligence patterns and Cloudflare’s own documentation/community data: VPN / Proxy / Residential Proxy Networks (by far the #1 trigger) Popular VPN providers (Proton, ExpressVPN, Nord, Windscribe, etc.) and scraping proxies frequently ride on well-known ASNs (e.g., AS9009 – M247, a data-center-heavy provider). Many sites proactively ban these because they are associated with high abuse rates: credential stuffing, price scraping, account farming, DDoS-for-hire, or geo-restriction circumvention. High-abuse ISP or Data-Center ASN Certain residential ISPs, mobile carriers, or budget hosting providers accumulate poor reputation scores on blocklists (DroneBL, Spamhaus, etc.). One bad actor on the network can taint the entire ASN. Site-Specific Security PolicyThe owner enabled Cloudflare’s Bot Fight Mode, Super Bot Fight Mode, or custom WAF rules that automatically tag and block suspicious ASNs. Manual IP Access Rule or Firewall Rule created after previous abuse from that network. Rate-limiting thresholds exceeded in the past (e.g., too many requests from the same ASN in a short window). Edge Cases & NuancesTemporary vs. permanent: Some sites set time-limited ASN blocks (e.g., 24–72 hours after detected scraping). False positives: Legitimate users on shared infrastructure (corporate VPNs, university networks, privacy-focused ISPs) get caught. Regional overblocking: Your Miami, Florida location (U.S. East Coast) is generally low-risk, so this almost certainly points to a VPN/proxy or a specific ASN reputation issue rather than geographic targeting. IPv6 vs. IPv4: Some sites block only one protocol’s ASN. 3. Security Implications (Defensive Strength vs. Collateral Damage) Strengths: Extremely effective against automated attacks. Scrapers, bots, and brute-force tools love VPN/data-center IPs because they are cheap and disposable. ASN-level blocking stops entire botnets in one rule. Reduces origin-server load and mitigates DDoS amplification. Allows site owners to maintain a clean threat model without constant manual intervention. Weaknesses & Risks: Overblocking: Legitimate users lose access (e.g., journalists, researchers, travelers using VPNs for public Wi-Fi safety). Evasion arms race: Sophisticated attackers simply rotate to new residential proxy ASNs or compromised devices, while average users suffer. Single point of failure: If the site’s Cloudflare configuration is overly aggressive, it can create availability issues or denial-of-service against its own audience.
-
rvivek (@rvivek) reportedWe received almost a million applicants for 1111 paid internships this summer. The interns we hired are extremely AI-native and we expect a majority of them will get full-time offers — @eastdakota, Cloudflare CEO. This is what an AI-first company transformation looks like. Anyone who says they are cutting down on engineering hiring because they are more productive or stopping new grad hiring because agents are automating the work is on a slow decline to irrelevance.
-
Colin Dougherty (@colindougherty) reportedAI isn't coming for builders or sellers. It's coming for "measurers." Cloudflare cut 20% of staff while posting record revenue and 30%+ growth, first out the door: middle managers, audit, marketing, finance ops. The CEO says this becomes the norm this year. The part he skips: fire all your fact-checkers and your data quietly goes bad. Be a builder. Be a seller. Or be the one catching the hallucinations.
-
Dark Web Informer (@DarkWebInformer) reported🚨 Multiple users are reporting that Kash Patel’s apparel site is serving a ClickFix-style malware lure. The page appears to mimic a Cloudflare verification check and instructs visitors to run platform-specific commands to “verify” access. Instead, those commands can execute malicious code. On macOS, the observed chain reportedly pulls down an infostealer designed to target Keychain data, browser-stored credentials, session tokens, and cryptocurrency wallet information.
-
Carlos Alberto (@carlosadcaraujo) reported@ritakozlov @Cloudflare Probably a stupid question but why aren't we doing direct bindings with Cloudflare AI gateway? Example openrouter already adds it's own latency issues, using AI gateway with it adds extra network hops that adds up in poor network environments. On the topic, dynamic routing with fallbacks is quite difficult to make reliable because I guess every model things and communicates differently.
-
Thatweb3guy (@MinBringham) reported@inference_labs Cloudflare pushing AI reviews at scale says a lot about where things are heading. Running inference is getting easier, but proving outputs can be trusted still feels like the harder problem. That gap is probably where a lot of important infrastructure gets built.
-
Ian Smith (@IanSmith_HSA) reported@lopp My concern is timing, resources and surprises. Timing: Google and Cloudflare have both said that a full migration to PQC needs to be completed by 2029. BIP361 stated 2030 but it should be 2028, inclusive. Resources: 3 quantum architectures are now capable of reusing qubits. PSIQuantum(2024), Oratomic (2026) and IonQ (claimed 2026) have demonstrated (or claimed) qubit reuse. The ability to execute while generating new qubits means that the number of physical qubits required is 10k, not 500k or 20 million. Oratomic currently has 6100, but each key break would take 3+ days. Also, the qubit reuse reintroduces a NISQ era measurement called "Quantum Volume" where the error rate is the main fundamental limit. Ancillary qubits can act as spare tires, correcting or avoiding errors. Surprises happen when secrets are kept. PSI Quantum has 4 working quantum computers but they did not reveal the size of any of them. The 4th quantum computer is dozens of solid steel fridges sunk into the floor, could be anywhere between 5k-200k qubits. Could be enough to break ECC256. They are apparently operating under govt contract and secrecy. Their timeline to create a 1 million qubit quantum computer is January 2028, so we have 6 months left to deploy PQC Bitcoin and then 1 year for migration.