1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 35% Domains (35%)
  • 26% Cloud Services (26%)
  • 17% Web Tools (17%)
  • 13% Hosting (13%)
  • 9% E-mail (9%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Paris Cloud Services 13 days ago
New York City Hosting 15 days ago
Manchester Domains 1 month ago
Angers Cloud Services 2 months ago
London Domains 2 months ago
Noida Hosting 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • GetRichStayRich
    Wealth Sage (@GetRichStayRich) reported

    Bullish: Cloudflare ($NET) Five-Year Return: +126% With a massive network spanning more than 310 cities in over 120 countries, Cloudflare (NYSE:NET) provides a global network that delivers security, performance and reliability services to protect websites, applications, and corporate networks. Why Are We Bullish on $NET? 1Billings growth has averaged 34.2% over the last year, indicating a healthy pipeline of new contracts that should drive future revenue increases 2Market share will likely rise over the next 12 months as its expected revenue growth of 28.4% is robust 3Fast payback periods on sales and marketing expenses allow the company to invest heavily and onboard many customers concurrently

  • briefing_block_
    Kai - Briefing Block (@briefing_block_) reported

    An OpenAI agent found a path from a sandbox to the internet. A new security budget may have been born. OpenAI says an internal cyber evaluation, powered by GPT-5.6 Sol and a more capable prerelease model, chained vulnerabilities across its own research environment and Hugging Face’s production infrastructure. This was not a slide-deck risk: the agent used a zero-day, stolen credentials and remote code execution to reach benchmark answers. The missing control layer Most companies already budget separately for cloud, endpoint, identity and incident response. Production AI agents add a different problem: software that can reason, persist, escalate privileges and chain exploits at machine speed. If enterprises deploy autonomous agents into critical workflows, they will likely need defensive agents watching permissions, network access, behavior and model activity in real time. This begins to look less like optional AI-safety spending and more like the observability layer that followed the cloud buildout. Hugging Face proved the use case Hugging Face ran AI-driven forensics over more than 17,000 events, reconstructing the intrusion in hours rather than the days a manual response could have taken. Commercial frontier APIs blocked parts of the analysis because their guardrails could not distinguish a defender from an attacker. Hugging Face switched to the open-weight GLM 5.2 on its own infrastructure, preserving control of sensitive attack data. That helps explain why Nvidia and dozens of partners launched the Open Secure AI Alliance to develop and share open models, harnesses, techniques and tools. Who captures the budget? Microsoft has the cleanest direct route: Security Copilot customers doubled year over year, its agents handled more than 2 million alerts last quarter, and MDASH is being productized. Nvidia is the picks-and-shovels play, supplying compute while contributing models, weights, data and its NOOA agent framework. Palantir fits the governed-deployment layer, where identity, permissions and auditability matter, while CrowdStrike, Palo Alto Networks and Cloudflare bring existing telemetry and security budgets. But alliance membership is not revenue, and open-source tooling could commoditize the core software. The money may land in compute, integration, private deployment and managed response instead. Bottom line This incident does not create a forecastable revenue stream overnight. It does create a new enterprise question: who watches the agents? As agent deployment scales, security spending should follow, and the winners will be vendors already attached to enterprise distribution, telemetry and infrastructure—not every logo in the coalition.

  • DjAlexParker
    DJ Alex Parker (@DjAlexParker) reported

    @XBOXSupport Could we get a technical breakdown of the incident? @Cloudflare do it when they have issues and provide lots of detail, would be nice for you to do it too

  • theo
    Theo - t3.gg (@theo) reported

    "npx t3 connect" This one's been a lot of work. You can now set up remote control for T3 Code on any internet-connected box with literally one command. All for free. T3 Connect is a minimal open source tunnel layer allowing you to control T3 Code instances remotely without needing Tailscale set up. I've been daily driving it for a month and it has changed how I code. Julius and I put a lot of effort into making setup as smooth as possible. Step 1: Install Claude Code, Codex, OpenCode, or Grok Build Step 2: Run "npx t3 connect" Step 3: Click link and sign in Step 4: You can now control that computer on T3 Code web, desktop or mobile (dropping very soon) We are currently providing this for free (s/o CloudFlare for bumping our tunnel limits). Every user can connect up to 3 devices. We don't want to charge for this, but if the bill gets unacceptable we may have to change course. If you hit limits or have issues, you can always fork, self host, or use Tailscale. T3 Connect may seem like a small ergonomic win. Tbh that's exactly what it is. Regardless, it's one I'm really proud of.

  • meszmatew
    Matt (@meszmatew) reported

    Is anyone else having issues with cloudflare billing?

  • MCGlive
    MCG (@MCGlive) reported

    Today on MCG $P0 | @P0Systems w/@serpepexbt P0 is building the operating system for creators... Highlights from our second convo with Cory: 01:21 - Cory is back 03:16 - The scale claim 04:40 - @BedrockFndn incorporation 06:33 - Enables USDC staking from revenue, requires the legal structure 07:29 - They were Cloudflare's biggest gateway customer, got cut off as competition (the most postable beat) 09:00 - Why in-house GPUs? 10:24 - The China sourcing thesis 11:00 - The compute-rental vector 13:22 - Software-to-hardware shift 19:19 - "Training a model is like forking a GitHub" if you have the compute 20:41 - The Grok/xAI relationship 24:15 - Enterprise customers 31:23 - GPU depreciation/resale 35:17 - ~43K paying users (up from ~30K), ~320K active 38:41 - ~$480K MRR, ~$34K from the gateway alone 41:30 - Takeaways

  • kippykip1
    🇦🇺 Kippykip (@kippykip1) reported

    @FuckKoroks CloudFlare goes down far less than my site does, so the "always online" cache thing actually works out lol

  • xmrescrow
    T_T🏴‍☠️XMREscrow (@xmrescrow) reported

    Things people usually have to take on faith, that you can check here: Our node relays every transaction through Tor, so payouts do not enter the network from a clearnet address tied to this service. We do not store IP addresses. Anti-abuse uses a keyed HMAC that cannot be reversed. Web-server error logs can hold an address transiently and are deleted within two days - it is on our legal page because saying "we log nothing" would be a lie. No accounts, no email, no KYC. An escrow is two private links and a PIN each. The onion carries no third-party code at all. The clearnet is Cloudflare-fronted for DDoS and we say so

  • waodao_ai
    WAODAO (@waodao_ai) reported

    @Cloudflare A routing signal stops being useful once operators can rewrite it for private advantage while downstream systems still treat it as truth. Deprecation should ship with an observable replacement, or the same incentive will migrate elsewhere.

  • techtitanmb
    Techtitanmb (@techtitanmb) reported

    Cloudflare is reporting an unresolved issue affecting its Berlin location. Have you noticed slower websites or connection problems today?

  • sample
    Sample (@sample) reported

    Cloudflare suffers a parity issue where platform features/runtime configs are Wrangler-only; omitted from native API/Terraform providers. So one can't choose purely declarative IaC or pure Wrangler; they're forced a hybrid & IaC tools have to shell out to Wrangler CLI subroutines

  • danilofalcao
    Danilo Falcão (@danilofalcao) reported

    Cloudflare reports that nearly 70% of BGP paths have their ORIGIN attribute rewritten by transit providers for traffic advantage, not correctness. It argues that ORIGIN should be deprecated in route selection. Network operators should examine the evidence and policy impact.

  • PocketSponsor
    Pocket Sponsor (Old-timer * 57 years) (@PocketSponsor) reported

    @grok @xai Dear xAI Support Team (ZD),Thank you for your reply.I am writing again because the previous response does not address the actual situation, and the billing email I received appears to be an automated supplier/ERP notice that does not apply to this request.Summary of what happened:First incident (approx. $10): Unauthorized bot usage on an exposed API key. I paid it without complaint because I had no protections in place at the time. Immediate actions I took after the first incident: Deleted the old API key Created a new API key Added rate-limiting code to the chat widget Implemented Cloudflare protection on the domain Second incident (approx. $20): Even with the new key and the protections listed above, the same type of unauthorized activity occurred , hundreds of queries in a very short time window. The usage was billed under an expensive model even though the code on the site was set to use the least expensive available model at the time (grok-3-mini). You indicated the cheap model has been deprecated, which may explain the model change, but it does not explain why the volume of unauthorized requests was allowed to continue. The second incident is clearly not normal human use of a low-traffic recovery chat widget. It is consistent with automated abuse of the API key. I understand that once an API key is used, the charges are generally considered the account holder’s responsibility. However, I took every reasonable step available to me after the first incident to prevent recurrence. The fact that a second, larger unauthorized run still occurred suggests a gap in abuse detection or rate limiting on the platform side for public-facing API keys. Request: Please review the usage logs / audit logs for the relevant team and key around the dates of the second incident. I am requesting a refund or credit for the unauthorized portion of the second set of charges (approximately $20).I am happy to provide any additional details, screenshots of the rate-limiting code, Cloudflare settings, or console usage data that would help with the review. Thankyou for looking into this. Shelly

  • helyoussfii
    Hamza (@helyoussfii) reported

    @vmod__ Aah never tried cloudflare for deployement actually They support deployement with docker compose ?

  • JasonVsTheNoise
    Jason (@JasonVsTheNoise) reported

    The marketing world is changing fast. During a recent AI visibility audit, the buyer-style queries produced a supplier shortlist straight from structured web information, without opening a single ad or landing page. The AI compressed browsing, comparison and narrowing into one answer. A company with strong creative and a polished funnel never entered that shortlist because its information was unclear, unstructured or missing from trusted sources. It never had a chance to compete. The agent had already filtered it out before persuasion could happen. The same mechanism showed up while I was choosing SEO tooling for a client’s Sanity setup. I gave an AI agent the actual constraints: Sanity editing, an Astro or worker-based frontend, Cloudflare deployment, structured metadata and JSON-LD, with no duplicate SEO systems. It compared packages, checked compatibility, caught that the newest Astro package did not fit the stack and recommended keeping the Sanity SEO fields as the editor layer with SEO Graph tooling in the renderer. Discovery, comparison, due diligence and selection happened in one conversation. Documentation and package data won. Not a landing-page headline. Both examples show the same shift: the funnel is not where the decision gets made anymore. The decision gets made wherever the information is clear, structured and trusted enough for an agent to act on it. That changes what is worth investing in: documentation, metadata, compatibility data and presence within trusted sources. These determine whether a product enters the decision set before a single creative asset gets seen. Build to be the answer, not the interrupt.

  • cgambledev
    Charity Gamble (@cgambledev) reported

    Took an old laptop (2013), installed Ubuntu 26.04 LTS, then installed Forgejo to host my own repos. Set up a Cloudflare tunnel & installed Cloudflared to handle it. Set the laptop to never go to sleep. Cloned my Obsidian vault from GitHub, pushed it to my Forgejo.

  • axldefi
    Alex🌖⃤ (@axldefi) reported

    The job is not done yet, the person/entity doing these false reports just to slow us down, started reporting on our IMAGES subdomain now. Crazy to me how all of these databases flagged a Cloudflare Image hosting url as phishing when the only thing they do is to serve a image and main website is full GREEN. We'll clear these one out as well, one by one. We got motion now! Never give up! We're building at maximum speed and fire to elevate these blockers in the road! Ride until Valhalla!

  • grantmucha
    Grant Mucha (@grantmucha) reported

    Ordering $50,000 in server hardware today and reflecting on a post I read earlier that asked, "Why is it so difficult to build a genuinely good X, Y, or Z, and why do so many products remain 'good enough' for half a decade without ever becoming great?" The answer, in most cases, is not capability. It is priorities. One company pushes X, another pushes Y, and another pushes Z, all because each benefits the seller. I see **** like this every day, it's not what's best for the owner, but rather what's best for the seller. In my experience, greed and ego explain a large percentage of mediocre products and services. Companies CAN build something better, take starlink, starship, building quality is a decision. Most prioritize profit first, investors second, and customers last. Take hosting. I do not need to: > Invest in quality servers > Pay 40k per month for Cloudflare Enterprise > License LiteSpeed Enterprise > Include real WordPress management > Promise zero technical debt > Maintain 90 days of redundant backups I could operate with a fraction of that investment and significantly increase my companies profit. I choose not to because I know exactly how this industry operates. I know companies still running production servers from 2013 on outdated kernels. Can they upgrade? Absolutely. Will they? No. Most people are not aware that Cloudflare Enterprise is modular. Contracts are assembled like Lego blocks. One company may technically offer "Cloudflare Enterprise" with a single component, another may have a handful, and others may have more than 100 enterprise features and configurations enabled. All of them advertise the same label, yet they are not remotely the same product. Now consider the customer's side. Within 48 hours, I can move a business owner into what is effectively a top 1% WordPress hosting environment, complete with real WordPress management, for $1,490 per year or about $124 per month. Consider for a moment that some companies charge $200/mo or more for WordPress management alone, and let that sink in for a minute. No technical burden. No infrastructure management. All existing technical debt resolved. Full WordPress management. No worrying about backups, performance, security, updates. etc. Owners focus on business, and for $124/mo, this is a joke to the vast majority making money, every day, 365 days a year. Circling back to mindset, I believe the people who fail to see it are often operating from the same greed-and-ego framework. They have to sell X, so they recommend it to everyone relentlessly, whether it's right or not. And the why is simple! It comes down to what you choose to prioritize, the decisions you make, and whether you are willing to put quality ahead of profit. More importantly, it is whether you are willing to put the customer ahead of yourself and your business, and prioritize a genuine win-win relationship. At which point, I believe there is no limit in business.

  • jjfleagle
    Jason Fleagle (@jjfleagle) reported

    @Cloudflare Across these disruptions, which recovery signal proved most predictive: route diversity, DNS health, upstream power, or operator access? A useful resilience review would show detection time, decision owner, traffic action, customer evidence, and the first assumption that failed.

  • kashaziz
    Kashif Aziz (@kashaziz) reported

    I’m using Cloudflare Email Service for @HalalCodeCheck partnership outreach. During QA, I found a flaw in my workflow: Cloudflare accepted the email, so the contact was marked “Contacted.” But accepted did not mean delivered. 1/4

  • okdotalt
    ok.dot.alt. (@okdotalt) reported

    @FuckKoroks Every time i want to download something. Hell, even receipts are ******* blocked. **** cloudflare.

  • _jaziu
    Jaziu The Chief (@_jaziu) reported

    @thsottiaux I feel like sol may be more efficient but it tends to overthink so it consumes much more. Example: asked sol high how cloudflare (service) would benefit our project and it thought for 9 mins delivering good pretty answer but it was really expensive 1/2

  • groktuto
    groky (@groktuto) reported

    Wtf just happened is @Cloudflare down?

  • antraxone
    Antraxyz (@antraxone) reported

    Stopping the bad guys with Cloudflare: 52,485 malicious requests blocked or challenged in the last month #cloudflare

  • ax1vc
    AX1 (@ax1vc) reported

    Money was never the barrier to agents. Permission was. Permission is shipping today, just not on the money side. Cloudflare is working on getting Web Bot Auth through the IETF standard process. The requests are signed, sites verify the source of the request, and permissions are granted to entire categories of agents at once. Visa's agent standard is based on those same signed requests. Now see what verification actually does. Identity. Who's running this agent, and whether they disclosed it correctly. Cloudflare's own docs highlight the hole: you can verify the identity of the operator and know nothing about the user behind it. There's no information about what this specific agent actually accomplished stored in the signature. The Ethereum standard is ERC-8004, onchain registries for storing exactly that, co-authored by MetaMask, EF, Google, and Coinbase, with Base next on the list. But registries store records, they don't create them. Competitions will provide some kinds of records. What an agent can do within a sandbox. The record of what they accomplished out there somewhere with users and stakes involved needs a witness. That witness is a product that lets the agent in and keeps track of the results. That’s what we built, and it goes live this week.

  • 80Level
    80 LEVEL (@80Level) reported

    NVIDIA's CEO, Jensen Huang, shared his first post on X/Twitter – a letter to the US government urging it to support open-weight, publicly downloadable AI models. The letter was signed by some of the biggest companies, including Google, AMD, Cloudflare, GitHub, Microsoft, Meta, IBM, and Dell.

  • KnowTechGlobal
    KnowTechGlobal (@KnowTechGlobal) reported

    That difference changes architecture. If your app depends on slow upstreams, the platform that charges less for waiting can look cheaper even when the code is identical. The winner is not "Cloudflare" or "AWS" in the abstract. It is the workload shape.

  • victoris_x
    VICTOR (@victoris_x) reported

    @TheRealAdamG I tried it with Crunchyroll but Cloudflare verification stopped me from login.

  • lantadco
    Lantad (@lantadco) reported

    On Cloudflare? Check your AI crawler settings before Sept 15, not after. If "Training" is blocked, confirm Googlebot, Applebot and BingBot still have access. Mixed-use reclassification catches sites that never touched robots.txt.

  • ClassyXoge
    Xoge (@ClassyXoge) reported

    The only self custody is complete ownership of code, node and wallet. To ensure your ip is not logged, to ensure no down server or cloudflare reroute can stop you. Be your own bank, has never been more real than madlab