Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (29%)
- Web Tools (17%)
- Hosting (13%)
- E-mail (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 11 days ago |
|
|
Hosting | 14 days ago |
|
|
Domains | 1 month ago |
|
|
Cloud Services | 2 months ago |
|
|
Domains | 2 months ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Abdul Rauf (@armujahid) reported@karachism @argamingpk1 Will check. My setup is -> pihole (custom block list, dns cache) -> dnscrypt -> cloudflare zero dns. But yeah, noticed random issues on vanilla network without any custom setup.
-
RedPocatto (@RedPocatto) reported@PirateSoftware strange - microsoft teams had australia wide problems too today - amazon or cloudflare problem i wonder?
-
Michael Timbs (@michael_timbs) reported@thdxr Hahahahha. Improbable. One of the many reasons there’s very serious applications deployed on Cloudflare. Primitives are just wrong with terrible APIs the entire way down
-
David Frosdick (@DavidFrosdick) reportedCloudflare Email then sends the customer a link to a watch page. They can react, or reply, and that comes back into D1 against the original order. Whole loop, no third-party service in the middle.
-
VICTOR (@victoris_x) reported@TheRealAdamG I tried it with Crunchyroll but Cloudflare verification stopped me from login.
-
Leo (@0xGKBRK) reported@FuckKoroks It’s not like Cloudflare puts itself in the middle by hacking the website. The person running the website wants to use Cloudflare. If you’re gonna complain to someone, complain to the website that subjects you to that crap. Or vote with your wallet and go to a normal website.
-
adas🧦🌹 (@adastroworld) reported@thsottiaux just does a cloudflare auth "human check" loop when trying to sign in from the browser lol
-
Informer |-/ (@_Nformer) reportedI love how half the comments are just people who get salty when Cloudflare goes down and the other half are mad about Cloudflare having a monoply.
-
Alvin (@Alvin1492840) reportedFix 2: He changed the DNS server from their ISP's to Cloudflare's. He asked if they knew what DNS was. They didn't. Nobody does. DNS stands for Domain Name System. Every time you type a website name into a browser or open an app that connects to the internet, the DNS server translates that name into an IP address the numerical location of the actual server. It's the phone book of the internet. Your device asks the DNS "where is Netflix?" and the DNS responds with the address. By default, every router uses the DNS server provided by the ISP. The ISP's DNS works. It resolves the requests. But ISP DNS servers are notoriously slow, overloaded, and sometimes unreliable. Every web request passes through them, and every millisecond of delay compounds across every page load, every app refresh, every stream buffer. He opened the router's WAN settings and changed the DNS from "Automatic" to manual. He typed in two addresses: 1.1.1.1 and 1.0.0.1 Cloudflare's public DNS servers. Cloudflare operates one of the fastest DNS networks in the world. Google's public DNS 8.8.8.8 is another popular alternative. Both are free. Both are faster than virtually every ISP's default. The change applies to every device on the network simultaneously. Every phone, every laptop, every tablet, every smart TV, every game console all now routing DNS requests through a faster server without any individual device needing to be touched. Web pages started loading noticeably snappier. Not because the bandwidth increased the speed test wouldn't show a difference but because the time between typing a URL and the first byte of data arriving dropped by 30–50 milliseconds on every single request. Multiply that across thousands of requests per day across 23 devices and the cumulative effect is a WiFi network that feels materially faster.
-
Bryan Jones (@bdkjones) reportedExplaining an Outage 101: @Cloudflare: "John uploaded a bad config file at 08:24:47.252 UTC. It flipped bit 0x00007FF6E4D316D0 in datacenter 49 and brought down the whole Internet. This is unacceptable. We know you count on us. John has been shot." @Apple: "Some users may have been affected by a service 'problem'. Pray we do not affect you further."
-
Josh (@joshmanders) reported@leodev So if I am understanding this correctly, using Cloudflare email is $21.45 for 50k emails? Honestly that's acceptable to me. Especially if they have good inbox placement and reliability. AWS is saturated with spammers and ****. I'll pay a premium to guarantee my stuff hits inboxes.
-
Volt ✚.🏳️🌈 (@voltreaver) reportedit feels like adolf hitler made cloudflare warp to be the most unusable **** ever why does it keep disconnecting randomly
-
Gregor (@bygregorr) reported@Cloudflare one command gets you a response. figuring out which party in the relay chain broke it is where the actual debugging time goes, and binary HTTP doesn't help you there
-
Rian (@Rian_Visser) reported@ItsKamranK You must use Cloudflare's nameservers for any domain registered or transferred through Cloudflare Registrar. No support for IDNs. No thank you, I do not have these restrictions and limitations with @Namecheap and will happily pay the increased fee to have control over my domain.
-
Eidzoku (@evi77ain) reportedApparently Codex Desktop 26.721.4979.0 can self-destruct just from using its built-in browser. Very agentic.💀 At first I thought Cloudflare was the cause. Nope. Perplexity reproduced the exact same failure, and it's already mentioned in one of the related issues. The actual chain is: webpage loads → Chromium GPU crashes (`101457950`) → Windows blocks the bundled `vk_swiftshader.dll` fallback for not meeting Microsoft signing requirements → GPU relaunch fails (`18`) → Codex dies.
-
Matt Schober (@migratewithmatt) reportedStopping the bad guys with Cloudflare: 2,176 malicious requests blocked or challenged in the last month #cloudflare
-
PaulSD (@paulsd_95) reported@thte857 @FuckKoroks You'd be mad too if your work relies on something online and that critical work got blocked because Cloudflare went down for hours. Wouldn't be surprised if lives were ruined or lost because of it.
-
Jason Fleagle (@jjfleagle) reported@Cloudflare This is the kind of tooling that turns a privacy protocol into an operable system. The next useful artifact is a redacted debug receipt showing each hop, encapsulation step, draft version, timing, and failure boundary so teams can reproduce errors without exposing the request.
-
Santosh Yadav (@SantoshYadavDev) reported@thdxr I never got comfortable using wrangler, I think I dont like it. otherwise cloudflare has a great DX
-
Blue Pastel (@CoyotlCompany) reportedStopping the bad guys with Cloudflare: 376 malicious requests blocked or challenged in the last month #cloudflare
-
Milk Road AI (@MilkRoadAI) reportedNvidia just launched a security alliance with over 30 companies and OpenAI and Anthropic didn't join the party. The Open Secure AI Alliance brings together Nvidia, Microsoft, Cisco, Salesforce, Palantir, IBM, Cloudflare, CrowdStrike, Hugging Face and dozens of others to build open source cybersecurity tools specifically for AI agents. The actual trigger for this was a real incident. When Hugging Face got hit with a security breach, its closed AI security tools couldn't tell the difference between the attacker and the defenders trying to investigate so those tools blocked the forensic analysis Hugging Face needed to actually contain the intrusion. Hugging Face had to switch to an open weight Chinese model, GLM 5.2, running on its own infrastructure, to analyze more than 17,000 actions and shut down the breach. That's the case study Nvidia is using to argue closed AI security tools have a structural blind spot. If a defender can't inspect and modify the model doing the defending, they're stuck waiting on the vendor during the exact moment speed matters most. The alliance's core argument is that AI agent security depends on the entire stack like identity, permissions, guardrails, logs not just whether the underlying model's weights are open or closed. Each founding member is contributing a specific piece. Nvidia is open sourcing models and a new agent harness framework called NOOA, Hugging Face is contributing its Safetensors format to prevent remote code execution, Microsoft built a multi model bug hunting scanner, and HPE is contributing zero trust identity standards. Now, why aren't OpenAI or Anthropic in this. This entire initiative is built around open weight models and open tooling as the foundation of AI security, and OpenAI and Anthropic's core business model depends on the opposite, keeping their frontier models closed and proprietary. But to be fair there's also a competitive angle worth naming. Nvidia sells chips to everyone, so it has no downside to championing an open ecosystem where more companies build and compete on top of open models, since Nvidia gets paid on compute regardless of who wins. OpenAI and Anthropic, by contrast, are trying to build durable moats around their specific models and joining an alliance that treats open weights as inherently safer would undercut the entire pitch they make to enterprise customers about why they should pay a premium for a closed, controlled system.
-
Ayush Chugh (@aayushchugh) reportedA few days ago, our login API experienced a DDoS attack. This triggered a high volume of SMS notifications, resulting in unexpected operational costs. Although we had IP-based rate limiting in place, the attack was highly coordinated, utilizing rotating IP addresses and phone numbers to bypass our initial defenses. To mitigate the immediate financial impact, we temporarily disabled our notification micro-service. We have since implemented a frontend CAPTCHA to verify requests before they reach the server. Additionally, we are configuring advanced Cloudflare rules to better protect our infrastructure against future incidents.
-
Chinmay Purav (@chinmay_purav) reportedHey @Cloudflare , Please bring in support for .IN TLD domains!
-
Anjula Dwivedi (@HeyAnjula) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked.
-
Anita Thompson (she/her) (@ltniita) reported@Cloudflare #Cloudflare It's ironic that I can't use your Contact page to connect with you because the "Verify..." captcha not working for me is the problem I need help with.
-
Rishi Raj Jain (@rishi_raj_jain_) reported@SantoshYadavDev @astrodotbuild @Cloudflare CF Pages are basically replaced with Worker. Lmk if you need any help!
-
Toolport (@toolportapp) reportedCloudflare's CTO, Dane Knecht, emailed their entire customer list about running every AI agent through MCP portals, with scoped tool access and a Code Mode they say cuts token costs ~93%. We build Toolport. This is our exact category. A few notes from the small end of the pond. 1. The announcement is two products wearing one trenchcoat. AI Gateway is a model-layer proxy. It routes your OpenAI/Anthropic calls and meters model spend, same lane as OpenRouter or LiteLLM. MCP portals are the tool layer, deciding which servers and tools each agent can touch. Different problems, different failure modes. If you're evaluating either one, don't let the bundle blur that line. 2. Their ~93% Code Mode number lands in the same range we've been measuring with lazy discovery for the past year. Loading dozens of tool schemas into context on every request was always the wrong default. It's nice that it's no longer just indie gateway builders saying so. 3. The structural difference. Their portals require being a Cloudflare customer and routing agent traffic through their edge. Toolport runs on your own machine and works with Claude Desktop, Cursor, and 25 other clients, with no vendor in the traffic path. When the traffic is your prompts, your credentials, and your tool outputs, where it flows is not a detail. 4. Scoped access is becoming table stakes. The harder question is whether the tool you approved yesterday is the same tool running today. Toolport pins tool integrity, quarantines drift, and scans for injection. A DLP scan on the wire doesn't catch a server that changed underneath you. Watching a giant walk into your category is a strange feeling. It's also the strongest signal yet that this layer needs to exist. We just think it should live on your machine, not in someone else's cloud.
-
Chris Board (@chrisboard_) reportedIs anyone else experiencing intermittent timeout, that I think is a TLS @Cloudflare issue although not 100% sure. For the last few hours I have uptime kuma monitoring several endpoints that hit multiple servers and domains and they are all intermittently timing out. From a script I've tried running on a couple of servers it looks like I am getting sometimes slow TLS connections usually sub second, occassionally > 3 seconds and then other times I get a timeout. I don't think its related to anything my side as its affecting multiple servers, across multiple domains and nothing has changed on my side for quite some time, it just randomly started happening a few hours ago.
-
swisscheese (@swisscheese4299) reported@OpenAI image generation is still throwing intermittent 520 errors through cloudflare.
-
Art Chicken 🐓 (@ArtChicken4) reportedFrom Jovan Hutton Pulitzer's Telegram- - For tech nerds understanding the PCAP fraud: The mechanism works, and every input is public. Rosters of US election officials are published (state SoS directories, EAC, NASS, commercial lists). Take each office's email domain → MX lookup → resolve the mail host to an IP → geolocate it. You now hold a table of "jurisdiction → IP → city/lat/lng" covering every election jurisdiction in the country, built entirely from DNS, without ever sending a packet to an election office. That table would look authoritative and survive spot-checking — the IPs are real, the org names are real, the geography is real. It would also be probatively empty, because an MX record identifies who handles that office's email. It says nothing about vote systems. The signature of an MX-derived list would be hundreds of jurisdictions collapsing onto a handful of shared mail-provider IPs — Microsoft 365 (*.mail.protection.outlook.com), Google Workspace, Barracuda, Proofpoint — because that's who most county governments use. What your file actually shows I tested it. The target roster is a complete enumeration of election jurisdictions, and the counts are exact: State Rows Actual jurisdiction count Massachusetts 351 351 municipalities Connecticut 169 169 towns Texas 254 254 counties Georgia 159 159 counties Virginia 133 95 counties + 38 independent cities Kentucky 120 120 counties North Carolina 100 100 counties Iowa 99 99 counties One row per jurisdiction, zero duplicates in any state. Real network traffic doesn't distribute itself one-event-per-administrative-unit. This is a roster walk. But the IPs are coarser than your MX hypothesis. Eleven states collapse to a single IP for every jurisdiction: 490 Maine town clerks -> 13.32.25.126 (AWS CloudFront edge) 351 Massachusetts clerks -> 45.60.195.2 (Imperva/Incapsula WAF) 246 Vermont town clerks -> 45.60.45.214 (Imperva/Incapsula WAF) 237 New Hampshire clerks -> 199.192.7.129 169 Connecticut town clerks -> 199.107.32.42 160 Texas election admins -> 98.129.145.194 (Rackspace) Plus 104.17.x / 104.18.x (Cloudflare) across 189 more rows. Those aren't mail servers — they're CDN and WAF edge addresses, the public front door of a state's website. A CloudFront edge IP is shared by thousands of unrelated customers; it isn't "Maine's election system," and you can't route vote data to it, because it terminates HTTPS for public web content and nothing else. So the lookup behind this file was one resolution per state's public web presence, cloned across every jurisdiction in that state. An MX-per-office build would have been more sophisticated than what was actually done here. And 253 rows have TargetIP = literally * — a failed lookup, no address at all. Those rows still carry 70,448 flipped votes. Votes attributed to an intrusion against an IP that does not exist. Bottom line Your instinct is right about the class of technique: a public roster plus DNS resolution manufactures a nationally-complete, real-looking IP table with no access to anything. That's the general answer to "could this manufacture data" — yes, trivially, and it's undetectable if you only check whether the IPs are real. The detection method is the reverse question: not "is this IP real?" but "what does this IP actually serve?" Real intrusion data resolves to the specific host attacked. Manufactured data resolves to whatever the jurisdiction's public name happens to point at — a CDN, a WAF, a mail gateway, a hosting provider. That's what's here: 490 distinct Maine towns, all pointing at one Amazon CDN address.