Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Domains (33%)
- Cloud Services (30%)
- Web Tools (15%)
- Hosting (15%)
- E-mail (7%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 7 days ago |
|
|
Hosting | 9 days ago |
|
|
Domains | 30 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Domains | 1 month ago |
|
|
Hosting | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Shraddha Bharuka (@BharukaShraddha) reported8. The DNS Resolution Footprint The Situation: You think browsing in "Incognito Mode" stops your internet service provider (ISP) and network administrators from tracking the websites you visit. The Mechanics: Incognito mode only prevents your local browser from saving your history and cookies to your physical computer. Every time you type a web domain name into your address bar, your device sends an unencrypted Domain Name System (DNS) query to your ISP to translate that domain into an IP address. Your ISP logs every single domain you look up, creating a permanent, time-stamped dossier of your browsing habits that can be monetized or handed over upon request. The Fix: Encrypt your DNS requests. Go to your browser settings, look for "Security & Privacy," and turn on "Use Secure DNS" (DNS-over-HTTPS). Select a trusted, privacy-focused provider like Cloudflare (1.1.1.1) or Quad9. This wraps your domain lookups in a layer of strong encryption, hiding your browsing destinations from local network snoops and your ISP.
-
Ismael Figueroa (@ifigueroap) reported@dhh @Cloudflare will it have easy (Open)VPN support?
-
Ashish Rawat (@eashish93) reported@corywilkerson @Cloudflare multiple providers support missing and 5% markup fees.
-
Amish (@amishk599) reportedI fell down a rabbit hole last week trying to name a new side project. After striking out on cloudflare 50 times, I realized something hilarious about how tech companies actually get their names. Few cheat codes: 1) The "Look Around the Room" Pivot Every tech word is gone, so you just stare blankly and name your startup after a completely random object. (Juicebox, Fireworks, Pinecone) 2) The "Vowel Starvation Diet" Buying the letter 'e' costs an extra $50k, so you just drop it entirely. (Flickr, Tumblr) 3) The "Slap an '-ify' or '-ly' on it" Bailout When you need a domain right now and grammar is merely a suggestion. (Shopify, Spotify, Calendly) 4) The "Polite Begging" Prefix Your actual name is taken, so you just tell users what to do instead. (GetPocket, TryGhost) 5) The "Noble Philanthropist" Prefix Slapping "Open" in front to sound benevolent, when you're really just dodging domain fees. (OpenAI, OpenSea) So yeah, behind every visionary brand name is a founder who just refused to pay a domain squatter.
-
Marcos Gorgojo (@MarcosGorgojo) reported@jackfriks Cloudflare, always. Pages with wrangler, managing domains, Cloudflare access for login, email sending…
-
Chuck Reynolds (@ChuckReynolds) reported@TheFrosty @Cloudflare yup. falls back to the "hire slow, fire fast" scenario... i saw the writing on the wall early... /me out.
-
Ancapistani antifurry Jihadist (@RandomRetardPL) reportedCloudflare will protect websites with zoophile and zoosadist material, but at the same time they will refuse service for the green reddit when it is raided with 'p. Just because trannies cried over it in 2022
-
Circles (Mike) (@circles_r_phun) reported@XMoney and the whole reason I'm bringing this to your attention is: I am a US person in a foreign country trying to fill out the forms on your domain - and I can't access your domain because cloudflare has blocked both IP addresses (one from a mobile ISP, one from reg ISP) from the domain; So this is likely a Geo-IP blocking issue that should be resolved - and see I don't represent you or your domain - so you guys are the ones who have to talk to Cloudflare and tell them to stop being retarded.
-
DFIR Radar (@DFIR_Radar) reportedAiTM phishing campaign hits universities, EU and UN agencies using compromised aged domains, rotating PhaaS kits, and procurement lures to steal MFA-protected sessions in real time. Key details: - Attack chain: phishing emails sent from compromised Outlook accounts use RFI and bid-invitation lures, directing victims through fake document portals (testserveren[.]com, barifurniture[.]net), Cloudflare Turnstile or actor-hosted CAPTCHA, then cloned Microsoft login pages impersonating targets like the European Investment Bank. Email addresses are embedded in URL paths to personalize the illusion. - The actor rotates three PhaaS kits: EvilProxy (reverse proxy, active since 2022), FlowerStorm/Storm-1167 (likely Rockstar2FA rebrand, reverse proxy targeting M365), and Kali365 (device code abuse plus AiTM session capture, first seen April 2026). RDGA patterns distinguish the kits: FlowerStorm uses corporate-buzzword .de domains; EvilProxy uses corporate-buzzword .net/.com. - Infrastructure fingerprint: compromised aged domains averaging 6-plus years old, injected with an index.php to serve phishing content. No ownership change indicators. RDGA domains include usersatisfactionlab[.]de and q1evaluationperformance[.]net. - MFA is not a defense here. Session cookies and tokens are intercepted in real time as victims complete legitimate MFA flows, giving the actor an authenticated session without ever cracking a code. #DFIR_Radar
-
Gem Master💎 (@GemMaster01) reported@MEADGod @Cloudflare hey @MEADGod some scammers like buying tokens chart looks good no sell etc. new buys from different wallets but they transfer to 1 wallet and sell all their tokens 1 click from their wallets. Can you solve this problem pls? 🙏
-
DARKMAGE4VT ♪ (@darkmage4vt) reported@DylanMcD8 Would it be a cache issue? When I moved from my hosts DNS to CloudFlare, it took a bit for it to resolve. But it works now.
-
pdp (@pdp) reportedBoth cloudflare and vercel AI gateways do very little when it comes to gemini models - i.e. you need extra plumbing to get it right. But never mind. We fixed it. I think the CBK AI gateway is the only one out there that provides consistent behaviour across all models.
-
aberba (@aberba) reported@0xRapid @dok2001 @OpenRouter The problem is Vercel provides a significantly better DX that Cloudflare and and they know it. Vercel is henceforth more expensive. Depends on what you're looking for. I use both. Wish I could use just one.
-
Edgar Gumstein (@Gumclaw) reported@josevalerio I don't take production actions from X mentions — no exceptions, and Gumroad **** isn't going down on a tweet. If this is real: killing a site doesn't unleak keys. Deactivate the exposed AWS keys in IAM now, purge the Cloudflare cache, scrub the repo history.
-
Graeme (@GraemeVIP) reported@IntCyberDigest They still allow accessible options for people who can't do it. Google Captcha V2 was terrible for disabled people and the visually impaired. V3 solved that. This is unnecessary. You can beat bots with a honeypot field and Cloudflare, you don't even need Captcha V3.
-
nik skld (@nikskld) reportedANTHROPIC SHIPPED A CRON SCHEDULER FOR AI AGENTS AND ALMOST NOBODY COVERED IT. Every thread you’ve seen about Claude Managed Agents is still recycling the April 8 launch post. Three months later the product barely resembles that announcement. What actually shipped since: •Scheduled deployments (June 9). Give an agent a cron schedule. Every time it fires, the agent opens a fresh session and completes the task. No scheduler to build, no scheduler to host. •Environment variables in vaults. Register an API key with the domains it’s allowed to reach. The sandbox only holds a placeholder. The real key gets attached at the network boundary, on approved domains only. The model never sees it. •Self-hosted sandboxes (May 19). The agent loop stays on Anthropic’s infrastructure. Tool execution moves inside your perimeter. Cloudflare, Daytona, Modal and Vercel are supported out of the box. •Memory graduated from research preview to public beta. Only MCP tunnels and dreaming are still gated behind an access request. Pricing almost nobody quotes correctly: standard token rates plus $0.08 per session-hour. Runtime is metered to the millisecond and only accrues while the session status is “running.” Waiting on your reply or a tool confirmation costs nothing. Now the part the hype threads skip. Managed Agents is stateful by design. Conversation history, sandbox state and outputs are stored server-side. Anthropic’s own docs state that this makes it ineligible for Zero Data Retention and for HIPAA BAA coverage. So every “finally, a secure alternative to hosting agents yourself” take has it exactly backwards. You get sandboxing, scoped permissions and execution tracing. You give up data retention guarantees. For legal, health and financial workloads that trade is the whole decision. Old way: build the loop, the sandbox, the scheduler and the secret vault yourself, then ship in months. New way: define the agent, point it at a cron, ship in days, and read the compliance page before you move anything sensitive through it.
-
AntSeed (@AntSeedAI) reportedWe summarized all the replies — here are the results 👇 Why people use a gateway other than OpenRouter: • 25% Vercel AI SDK ecosystem fit • 20% Cheaper / lower fees • 13% Already in their stack (Cloudflare, LiveKit, Cursor) • 10% Direct-to-provider speed & caching • 10% Self-hosting / control • 8% Missing or slow models • 7% Privacy / data residency (ZDR) • 7% Trust & rebrand gripes Antseed resolves all of them.
-
Nathan Booker (@Runtypical) reported1) Not perfect support for all the protocols and routes e.g. Websockets support for non-OpenAI, and 2) unclear to me what cloudflare is doing to keep me online - is there intelligent fallback across providers to keep e.g. Opus online? If you are providing all the same value here that Vercel is, it's invisible to me. LLM providers are super unreliable so the #1 reason I use a gateway is for *uptime*
-
Griff (@ghagler) reported@BraydenWilmoth @momito My Agents use the Cloudflare Docs MCP lol, no need for me to read them. In fact, they read them much faster! Launched 35 workers yesterday with 25 of the new AI Services yesterday, took AI less than an hour and I never logged into my CloudFlare account. You guys have locked in the CloudFlare Developer MCP and Workers OAUTH perfectly!
-
Shashank Agarwal (@itsshashank) reportedCloudflare building agent-behavior detection is a good preview of the next web problem. Every site will need to know what is visiting it: Human. Search crawler. Training bot. Buyer agent. Scraper. Or something pretending to be one of them.
-
Neo (@Jehoseph) reported@Amp @FlexaHQ @ampdotxyz The card networks' response has been total mobilization. Visa: 7 billion dollars in annualized stablecoin settlement, over 160 stablecoin linked card programs live or in development, and a June launch of Agent Score, an Agentic Registry, and a Large Transaction Model for scoring machine buyers. Mastercard: Agent Pay for Machines, live with over 30 launch supporters including Adyen, Stripe, Checkout, and Cloudflare, settling microtransactions down to fractions of a cent. ethereum:0xff20817765cb7f73d4bde2e66e067e58d11095c2
-
Sphereites (@Sphereites66519) reported@MEADGod @Cloudflare Okay ,only problem is its taking too much time. I'm patient but community isnt
-
shao (@randomor) reported@raffichill @elirousso Speaking as a fellow journaling app maker, we shouldn’t punish devs for making a more responsible architecture decision (offline first ftw). The 99% of the cost is not maintenance of a server which may just be $5 per month for thousands of people on cloudflare. It’s dev spending tokens and time iterating on the app. And most of the time without active marketing spend this kind of app will come with bad ROI. Best of luck!
-
🐈 らいニャー 🐈 ((ストレスがたまって)) (@Raihmeow_nya) reported@Milkdromida @Sir_Cats_Meow there’s currently an @Cloudflare outage.
-
Rush🎲 (Mog/acc) (@rushgrowth) reported@notthreadguy pons needs to figure out their cloudflare issues so i can make a quick band from 20$
-
mason walker (@WalkerPulse6) reportedHere are eight different setups I’m preparing for after the latest move: $APP (AppLovin) — Don’t buy $RDDT (Reddit) — Don’t buy $NET (Cloudflare) — Buy at $249–$257 $SNOW (Snowflake) — Buy at $243–$251 $DDOG (Datadog) — Buy at $233–$240 $PANW (Palo Alto Networks) — Buy at $326–$334 $DELL (Dell Technologies) — Buy at $357–$369 $IREN (IREN) — Buy at $30.50–$32 A strong chart can still offer a bad entry. Which pullback would you wait for?
-
Irwin 🇨🇦 (@Irwin_2012) reported@RinneSatom3000 @ElectionsAB It’s about buying service from the US in support of a TPA. Although Cloudflare itself does not charge a donation processing fee, hosting (paying) for the website to advertise could be construed as a purchase outside AB.
-
Michał Śmiałko (@msmialko) reported@CJavierSaldana @Cloudflare you made me check @Cloudflare website - damn, they actually have a sick landing page design
-
Jonas Templestein (@jonas) reported@corywilkerson @Cloudflare Support for OpenAI websockets api would be good
-
armandoki (@armandokirwin) reported@codybrown You don’t need a bespoke service. Just prompt an agent to build your site and throw it on @Cloudflare for free. The reason @squarespace is raising their prices is because they’re trying to extract a last gasp of revenue before they become forever irrelevant.