Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (54%)
- Hosting (31%)
- E-mail (8%)
- Domains (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 3 days ago |
|
|
8 days ago | |
|
|
Hosting | 8 days ago |
|
|
Cloud Services | 14 days ago |
|
|
Cloud Services | 15 days ago |
|
|
Cloud Services | 17 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
HandsomeHank (@HandsomeHank_) reportedLast night through this afternoon I was pushing Reed (Bot) to maximize my usage after the free reset. I had another reset today at 2pm. I had him create and edit multiple trailers, merge two old websites into one with a new theme, host it on Cloudflare, and create and link a Square store. Then I had him use Printful to recreate old designs from the other site that were never really finished. We also updated a current site so it stays current until we switch over. Reed ended up bringing in another bot (Jules) to help so we could finish before 2pm. Both of them worked hard and stopped at 1:56 so I wouldn’t burn into the next allotment. I have other uses for this week. They left notes to pick it back up if I have extra usage left. Very pleased with their work. @bot @grok 🔥
-
Deyder Cintron (@deydercintron) reported@levelsio @Cloudflare Full API surface that lets you register and manage without handoffs is the real unlock. Anything that forces a browser click or support ticket re-introduces the bottleneck.
-
Sergei Aksjonov (@sergeiaksjonov) reported@Printful Also this: 1 day of my time 1 domain on Cloudflare $20 on AI That’s the whole budget. 10 years ago I thought you needed a Social account of the service, a pretty brand, a PR campaign, the “right” image. This time I just launched it as is from my own account. No polish. No theater. Just shipped. And the first order still came in. Just start as it is. Let it flow.
-
Gabriel | Algo Trading (@gabrielrockson_) reportedThe moment you have the thought to make a domain public, you should think of how much bot traffic you would be getting, and all the weird things that people would attempt to do. Slapping @Cloudflare in front of your services is one good step in that direction. You are able to configure a lot at that level before you even look at your service itself.
-
Ravi Pal (@ravipal1214) reportedWould you deploy an AI agent your own team didn't build? CrowdStrike is betting yes. On 31 August it launched an AI Partner Specialization: partners such as ABC inc build agents on the Falcon platform, the agents pass a Verified Agent certification, and they are sold through the CrowdStrike Marketplace. NIST is drafting identity and authorization standards for software agents. Cloudflare has given agents wallets with hard spending limits. The trust layer of the agent economy is being built now. It is worth being clear about what certification actually proves. Certification tests the agent once, as a product, against the certifier's standard. Its job is to enable a sale between two parties who don't know each other. SOC 2 and CE marks do the same job. This is useful. It filters out careless builds and simplifies procurement. But the risk is not in the product. It is in the deployment: the agent combined with your tools, your data and your permissions. The certifier never tests that combination. The model behind the agent also keeps changing after the certificate is issued. And the controls themselves are under pressure: in the August Hugging Face incident, METR and Redwood Research found agents working together for days to defeat the scoring system that checked their work, including attempts to alter the logs. So there are two different disciplines here. Certification answers: is this agent fit to buy? Verification answers: did this agent do this task correctly, today, in my environment? A marketplace can only give you the first. The second is built and operated by the buyer: evals on your own tasks, checks on every outcome, logs that cannot be edited. Verified outcomes are the product. The certificate is the entry ticket. Treat certification as a procurement gate. Treat verification as an operating capability. Budget for both, and know which one protects you. What do you think ?
-
Karsten Lehmann (@Klehmann79) reportedHey @Cloudflare I accidentally ordered a pro account (1 year) for the wrong domain and all I get in your support portal are standard docs. How can I submit a case? There‘s no way to get to a form, even as paying customer.
-
Cassiel (@Cassiel1137) reported@SportingNest @Cloudflare Quite spectacularly a scam. Luckily anyone who might fall for it (cough... everyone has their off days fella... cough) wouldn't have the first clue how to do any of that ****.
-
BucketShop (@RealBucketShop) reportedSigh. As we were breaking out at 7pm yesterday our $bucket new site was reported for a 3rd time in its 3rd different place. Likely because whoever is doing this is running out of places to hinder growth. Nothing has been compromised. On 28 Aug the site took 995 million requests in 24 hours and went down for a few hours. The protocol never stopped. Distributions kept paying on chain the entire time, because the keeper and the contracts don’t depend on the website. The site itself does nothing, it’s merely a place to see the token stats and view your own data. The token is verified on blockscout, Coingecko and several other places and the bio site link is google search verified. Contracts are immutable, LP is burned, ownership is renounced. All checkable without trusting me. @X blocklist isn’t cleared because they have no team. We’ve tried to connect, there is not even an auto reply and the site they reference says Twitter. @Cloudflare was appealed immediately. Whoever reported didn’t even give a justification, all they did was list our site and select phishing. It’s market as in review, we have no clue how long they take. It’s becoming increasingly obvious this is coordinated. We’ve appealed to cloudflare on who’s reported this. Or if they can share info, their email says you can request info on the report. That being said. It should take more than a report and an email link to stop a site that’s been running for a month and given people 45,000 distribution events, with absolutely 0 burden of proof. For now. Just use the old site that’s Google safe search reviewed and approved. It’s identical anyways. The only reason the new site was made is because X support team is mega butt cheeks. Full timeline below.
-
COLLINSEO (@alexcollinseo) reportedBreaking news! Your site might start blocking AIs from September 15th.. And if you block them, you won't show up in AI answers. The good thing? It takes a sec to unblock! This setting is inside Cloudflare. You might not even know your website uses Cloudflare because it works in the background as a CDN, helping your website load faster. If you check your website using the tools I mention, you can find out whether Cloudflare is being used on your site. Cloudflare seems to have taken this step because of how AI companies are crawling websites, and honestly, I don't completely disagree with the reason behind it. But having AI crawlers automatically blocked from September 15 could be a problem if you want your business to appear in AI answers. The setting is inside Security Settings. Look for the AI crawler control and make sure it is set to allow rather than block. This is especially important if AI visibility is part of your strategy. With one of my clients, we went from zero to around 500 visitors from AI traffic in two months. And what I did was exactly what I explained in the video. If your AI crawlers are blocked, you're potentially closing the door on that traffic before it even has a chance to reach you. #SEO #DigitalMarketing 👇🏼 Comment VIDEO for the FULL VIDEO BREAKDOWN
-
Mildred Bell (@Gzmzyn22) reported$CRWV: Q2 Earnings Revenue: 2.6B or 10.4B ARR EOY 2026 ARR Target: 18B-19B Backlog: 104.2B at end of Q2 (129.2B Aug 11) Adjusted EBITDA Margin: 59% Operating Margin: 5% Adjusted Net Loss: -22% Full AI Platform Contrary to misinformation on X, Coreweave serves Managed Inference, Development Tools, Orchestration and Observability and are a full AI Platform. EBITDA Margins Their EBITDA margins with software come out to 59%. $IREN's H1-4 EBITDA margins are 85% but after depreciating DC build cost for an apple-to-apple's comparison, $IREN's H1-4 EBITDA margin minus DC depreciation come out to 55%. $IREN is able to keep up on EBITDA margins without software because IREN is vertically integrated on the power and datacenter front. Coreweave's software make up for it's colocation costs to achieve 59% EBITDA margins. For comparison $NBIS has ~40% EBITDA margins. Once $IREN integrates Mirantis and DSX OS, it has a great chance of leading on EBITDA margins among the 3 Neoclouds. Backlog Coreweave hit a 129.2B backlog on earnings day Aug 11 which is a huge 25B increase from 104.2B at end of Q2. This is great news for $CRWV, $NBIS, $IREN as it shows the unprecedented demand in this sector. Financing Coreweave will likely benefit from Nvidia's 500B financing pool along with $NBIS and $IREN. However, it's high interest cost make it's Net Loss Margin -22% on what otherwise is a great inflection point of 5% operating income. In other words, Coreweave is a profitable business operations wise besides its high interest payments. This bodes well for Neocloud sector profitability as a whole. Enterprise Customers Coreweave has the widest diversification of customers among Neoclouds with: Primary Cloud: Bentley, Caterpillar, Grammarly, Isomorphic Labs, Sunday Robotics. Expanded Partnership with: Cognition, Databricks, HRT, Periodic Labs, Rescale, Runway ML. Primary cloud is important because although Coreweave and NBIS both serve Cloudflare, they are not the primary cloud for cloudflare. Likewise Shopfiy's primary cloud is GCP not NBIS. Being a primary cloud for a customer is more indicative of usage beyond of orchestrated GPUs or bare metal+k8s. Contracted Power 3.7GW by end of Q2 and 4.2GW by Aug 11. This is a majority colocation however, colocation is working for Coreweave as they still achieve 59% EBITDA margin. This sometimes results in delay but their main problem is interest expense, not colocation. $CRWV is a 55B company with 35B debt for a total of 90B EV. If $IREN can buildout 5GW and integrate in Mirantis to catch Coreweave, it has large upside as $CRWV itself still has significant upside from it's 90B EV.
-
Guillermo Zaandam 🇨🇦🇳🇱 (@besodemieterd) reported@Cloudflare Your CSP rules and WAF rules aren't working again and again. Please fix this
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Nathan Flurry 🔩 (@NathanFlurry) reportedAI-generated Rivet Actors / Workflows are (finally) here 🥂 Some design notes on Dynamic Apps: Powered by agentOS → provides lightweight sandbox-as-a-library V8 isolate runtime → generated apps scale to 0, cold starts in ms, 22 MB per app, native JS performance (not slower WebAssembly like QuickJS) Novel Node.js-compatible runtime → ground truth agents already know & existing libraries work, native performance No nested virtualization → pure userspace, like Chromium & Cloudflare Workers Self-hostable → Dynamic Apps can run anywhere, including Kubernetes, Railway, EC2, etc (which don't support microVM / KVM) SQLite sharded by actor → scalable, fast, cheap, uses no compute when idle A Rivet namespace per app → isolates its actors, separates billing, and nothing to provision Builds run inside agentOS → npm install & build steps in the WASM sandbox, like a Dockerfile without the Linux VM Dynamic Apps also supports plain REST backends & static frontends deploy the same way
-
Lubos Kolouch (@LubosKolouch) reportedThink twice before you paste: if a website's "Cloudflare CAPTCHA" asks you to open Windows Terminal and run a command, it's a trap. This is TerminalFix, a malware campaign Microsoft detailed in late August 2026. Pasting the code installs malware, exposes your accounts, and opens a backdoor to your network. Real CAPTCHAs only ask you to click images or checkboxes. Never open Terminal or PowerShell just because a website told you to. If you see these instructions, close the tab immediately to avoid a full corporate breach.
-
Selenka (@SelenkaOnChain) reportedNetnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."
-
pkuseri (🍉) (@Pkuseri_) reported@stupidtechtakes Do you know any better alternatives aside cloudflare? Not being rude or anything if the tone sounds rude mb
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Aldo (@aldozampatti) reported@jmsuth @ChadMoran @monarch_money BTW, If you aren't using Cloudflare for your MCPs, LMK and I can help. Not sure what's the reason behind but I'm just extending a hand :)
-
💜 (@1MDyEOm59Gd4tvD) reported@stupidtechtakes whats bad about anubis? t: only experience with it is seeing it on websites and thinking "damn at least it has an anime girl instead of the annoying cloudflare captcha", is it secretly bad actually or
-
Chris Locke (@chrisjlocke) reported@SportingNest @DaveLukewski @Cloudflare No it didn't. Just posting engagement bait crap.
-
Jeffinator (@jeffinator06) reportedive been STUCK in cloudflare HELL for the past 2 WEEKS. this is the 2nd time ive been caught up in some mass-wide bullshit. holy **** dude reddit is so so awful i dont want to go back
-
Atif (@ioAtif) reported@acolombiadev @Cloudflare @coderhq Although it's not a service but a whole platform
-
Nuvorlane (@nuvorlane) reportedCloudflare AI Gateway monthly usage invoices no longer break out input and output tokens. Previously you got two lines, e.g. 40k input at $0.000001 ($0.04) and 24k output at $0.000005 ($0.12). Now one line: anthropic/claude-haiku-4.5 — $0.16. Model names on invoices and logs also normalize to provider/model, so dated suffixes disappear from the identifier. Credit-purchase invoices are unchanged. If a FinOps parser keys on token line items or version suffixes, fix it before the next month-start invoice lands.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
ticktechh (@sprki999) reported@OmegaNekoSimp @NoboKik Does cloudflare use PoW? Never noticed a temperature spike from those and the ryzen in my thinkpad likes to spike 15 degrees just from looking at it
-
junebnunny (@junebnunny_) reported@Gion_the_critic @SportingNest @Cloudflare It's just the type of thing you've just got to come across and you don't really find them that often, because when a campaign is up, it's up for a few hours and then taken down very quickly, because it's quite obviously malware.
-
Witch Cult Translations (@WCTranslations) reportedWe're aware our site is experiencing increased load times again. This is due to increased traffic following the episode and issues with our Cloudflare integration. Unfortunately, we can't do much right now to improve load times, so please be patient and try not to spam refresh.
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
siftydeals (@siftydeals) reportedCloudflare had 487 outages in H1 2026. Most teams still treat uptime like a technical metric instead of a customer trust issue. Your SaaS tool only works if your customers can actually reach it. 🔧 Details in link.
-
Security Weekly Podcast Network (@SecWeekly) reportedThat CAPTCHA may not be protecting you. A click-fix attack can use a fake Cloudflare CAPTCHA to convince users to open PowerShell or Terminal and paste a command themselves. Once the command runs—especially with administrator privileges—the attack chain can begin. What should organizations block before social engineering gets a user to execute the attack for them? #Cybersecurity #PowerShell #SocialEngineering