1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 33% Domains (33%)
  • 29% Cloud Services (29%)
  • 17% Web Tools (17%)
  • 13% Hosting (13%)
  • 8% E-mail (8%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Paris Cloud Services 11 days ago
New York City Hosting 13 days ago
Manchester Domains 1 month ago
Angers Cloud Services 1 month ago
London Domains 2 months ago
Noida Hosting 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • iamTRA
    Rohan (@iamTRA) reported

    I killed my Wix/Webflow subscriptions this week. ~$40/mo from old acquisitions. Bloated af. Replaced with $0/mo Cloudflare pages - built end-to-end by agent. Faster pages rank higher on Google Maps. Cloudflare docs are complex, never bothered to read. No need to in 2026.

  • txmedai
    Colin Son (@txmedai) reported

    @ptremblay Yes Cloudflare is very good. And free tier is amazingly generous. Isnt quiet idiot proof (why do I have independent turnon AI gateway or R2 or all these individual features) but at least there’s not a million layers of IAM. GCP and AWS are fine

  • raehanbobby
    Bobby Umar | Keynote Speaker 🇨🇦 (@raehanbobby) reported

    Tried so hard to contact @Cloudflare & @CloudflareHelp for some support. But it kept directing me to a website. How do I talk to a person? I have charges I don't understand, for an account I don't know about. So either I talk to you, or cancel you getting paid. #custserv #fail

  • TechRemarker
    TechRemarker (@TechRemarker) reported

    @CloudflareHelp Does any one know how to contact @Cloudflare support? As detailed in this thread. CF had a bug where they charged me twice for the domain registration. Site contact options just show help docs. No response from CF Help here. Anyone know how I can reach them?

  • magicnaptime
    the Sleeping Wizard (@magicnaptime) reported

    Damn guys maybe try dialing it up to 2:2:2:2 for Pete's sake @CloudflareDev @Cloudflare

  • PrajwalTomar_
    Prajwal Tomar (@PrajwalTomar_) reported

    Vibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked. (full breakdown in my article below)

  • DFIR_Radar
    DFIR Radar (@DFIR_Radar) reported

    Chaos ransomware's msaRAT routes C2 entirely through Chrome or Edge via Chrome DevTools Protocol, making attacker traffic invisible on the wire. The RAT process never touches the network directly. - msaRAT is a Rust-based RAT attributed to the Chaos ransomware group. Initial access delivers update_ms.msi via curl over HTTP on port 443, bypassing port-based firewall rules. The MSI impersonates a Windows update and loads the RAT DLL directly into memory, leaving no obvious on-disk payload to catch. - C2 is split across two legitimate services: Cloudflare Workers at is-01-ast.ols-img-12.workers[.]dev handles SDP signaling to establish a WebRTC channel, then drops out entirely. All subsequent commands flow over a WebRTC DataChannel relayed through Twilio, so the attacker's real server IP never appears in traffic. - The RAT binds only to 127.0.0[.]1. All external traffic originates from the browser process itself, launched headless with remote debugging enabled. CSP is bypassed via a CDP command and JavaScript injected into the browser handles every network operation. What a defender sees is a browser making HTTPS calls to Cloudflare and WebRTC to Twilio, both normal. - Talos found msaRAT deployed between initial access and the Chaos encryptor, confirming it serves pre-encryption reconnaissance. Double encryption: DTLS from WebRTC plus ChaCha-Poly1305 over an ECDH-derived key means stripping DTLS still yields ciphertext. #DFIR_Radar

  • DuaneC6
    Duane C (@DuaneC6) reported

    @CryptoCyberia The internet was never a system of tubes, it has always been 500 micro-services pointed at each other like loaded firearms. People on remote, nearly-uncontacted islands know when Cloudflare goes down, and now it goes down all the ******* TIME.

  • vinvan
    Vincent van der Meulen (@vinvan) reported

    could anyone at @Cloudflare help @mainframe get access to artifacts? working on something very cool (hopefully!) and artifacts would be *perfect*

  • swisscheese4299
    swisscheese (@swisscheese4299) reported

    @OpenAI image generation is still throwing intermittent 520 errors through cloudflare.

  • MilkRoadAI
    Milk Road AI (@MilkRoadAI) reported

    Open-source is dying and the companies that survive it are about to get very rich (Save this). That's the uncomfortable truth in Dylan Patel's take, American open source AI is basically dead. Meta has gone quiet on Llama, Mistral, once the loudest open source advocate in the West, shifted its flagship models to proprietary licensing while charging five to ten times more than comparable Chinese models for similar performance. So the only frontier level open models left are Chinese, Qwen, DeepSeek, Kimi, GLM and the labs building them barely profit from giving them away. The money instead flows downstream, to whoever hosts, serves and charges for access to those free weights. Qwen overtook Meta's Llama as the most downloaded model family on Hugging Face in 2026, and Chinese open models now out download American ones globally by a wide margin. Kimi K3 was ranked the top open source model in the world by LMArena. None of that revenue lands with the Chinese labs themselves but rather lands with the inference layer running on top. Inference is already the biggest chunk of the AI compute market, with cloud inference alone estimated near $50 billion in 2026 and growing around 60% a year, dwarfing training infrastructure spend. Token pricing has collapsed roughly a thousandfold over three years which sounds bad for margins until volume growth outpaces the price decline, keeping total inference revenue climbing. Mistral's own pivot away from open weights shows what happens when a lab tries to charge premium prices in a market Chinese competitors are commoditizing its newest model is losing on both cost and quality to rivals a fraction of the price. If Chinese labs eventually decide there's no financial reason to keep releasing frontier models for free, the open-source pipeline could dry up overnight. However, here are the publicly traded infrastructure plays positioned to benefit if open source continues to dominate. Nebius provides the same raw compute layer underneath inference demand, without needing to bet on any single model's survival. AMD is chasing that same inference chip opportunity with its MI series accelerators, positioning itself as the main alternative supplier once inference volume keeps compounding. Cloudflare (NET) benefits through its Workers AI platform, which increasingly serves as the delivery layer pushing open weight models out to edge devices and apps cheaply. Microsoft (MSFT), Amazon (AMZN), and Alphabet (GOOGL) all benefit as the hyperscalers whose cloud platforms host the bulk of enterprise inference workloads, collecting compute revenue no matter which model an enterprise ultimately runs. Milk Road Pro is tracking all the biggest beneficiaries of open source AI, if you want access to all our AI trades around this trend, you can come join us for just $1 using the link below!

  • driftinj
    Swamp Thing (@driftinj) reported

    @NateSilver538 It really blames anyone but itself. Oh that is definitely a Cloudflare problem. Gmail is definitely doing this incorrectly. Clearly, Supabase built their auth logs in correctly.

  • MartinMartinV_V
    Mārtiņš V. (@MartinMartinV_V) reported

    VPN Renegade, falsely accused of SQL injection by Cloudflare’s WAF, currently stuck in a primitive splitting mechanism. Debating whether my hatred of CAPTCHA should be covert or fully public. “Cloudflare Inc … NYQ: NET 262.15 USD +66.13 (33.74%)” @ChatoshiAi "Life is not a problem to be solved, but a reality to be experienced" Søren Aabye Kierkegaard parable comes into mind.

  • sidi_jeddou_dev
    Sidi jeddou (@sidi_jeddou_dev) reported

    Please stop using Opus 4.8 for your serious production apps. I built something with @DrizzleORM, @Cloudflare D1 and @expo I asked Opus to add status to one of my schemas, and it used plain text instead of Enum for type safety with database CHECK constraint, since there will be only: -active -pending -suspended This is actually a bad sign that this model just generates slop

  • ZettaGeek
    Josh Lambert (@ZettaGeek) reported

    @dhh @Cloudflare Will it display ipv6? I'm deep in the middle of rolling out IPv6 across my internet subscriber customers in Rural Alabama. My Omarchy SER9 was the first computer on the network to get a fully routable ipv6 address!! 😎

  • janekm
    Janek Mann (@janekm) reported

    @doodlestein @yzhang390 But that's not really the issue... it's that e.g. Huggingface and Microsoft and Cloudflare and Fireworks can be easily stopped from hosting them with misguided regulation. Literally only harming US companies at the expense of Chinese ones, ultimately.

  • haikukoten
    hai (@haikukoten) reported

    Stopping the bad guys with Cloudflare: 375 malicious requests blocked or challenged in the last month #cloudflare

  • RedPocatto
    RedPocatto (@RedPocatto) reported

    @PirateSoftware strange - microsoft teams had australia wide problems too today - amazon or cloudflare problem i wonder?

  • vladinator1000
    Vlady Veselinov (@vladinator1000) reported

    @thdxr What specifically can't you do with IaC? Maybe someone at Cloudflare can help? @dillon_mulroy do you know someone who works on Wrangler?

  • KnowTechGlobal
    KnowTechGlobal (@KnowTechGlobal) reported

    That difference changes architecture. If your app depends on slow upstreams, the platform that charges less for waiting can look cheaper even when the code is identical. The winner is not "Cloudflare" or "AWS" in the abstract. It is the workload shape.

  • kippykip1
    🇦🇺 Kippykip (@kippykip1) reported

    @FuckKoroks CloudFlare goes down far less than my site does, so the "always online" cache thing actually works out lol

  • xiz25
    Dr. Xi Zeng (@xiz25) reported

    @dhh @Cloudflare Putting speedtest and DNS choice in the same panel is the detail: diagnosis and action live together. Most network UIs show status, then make users hunt elsewhere for control. Which metric actually changed your behavior after using it?

  • SyahmiRafsan
    Syahmi Rafsanjani (@SyahmiRafsan) reported

    Hot take: if you’re already using Cloudflare but not Cloudflare Access, your security setup is only half-done. That 403 Forbidden screen isn’t a problem. That’s literally the point. Internal dashboards, staging sites and admin panels shouldn’t be public just because someone has the URL. You already use Cloudflare for DNS, CDN and WAF. Might as well put identity checks in front of the sensitive stuff too.

  • the_holyheights
    The Holyheights 🇰🇪 (@the_holyheights) reported

    People are launching apps to real users while skipping the unglamorous work that quietly sinks them. Here is the essential pre-launch checklist every AI builder should run through. Don’t skip these steps: 1. Protect yourself, not just your product. The second you start collecting user data, you’re operating under real legal requirements (GDPR, CCPA, etc.). Publish a privacy policy and know exactly where that data lives. 2. Enable Row Level Security. Without RLS, anyone can open DevTools and read your entire database. In Supabase, go to Auth → Policies. Zero policies = your app is completely exposed. Fix it in five minutes. 3. Test the failure paths, not just the happy path. Wrong password five times in a row. Password reset for an email that doesn’t exist. Verification link clicked twice. Signing up with an email that’s already registered. These catch roughly 80% of auth bugs. 4. Establish a security baseline in two minutes. Prompt your AI: “Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture.” 5. Check against OWASP. Prompt: “Review my app against OWASP standards and highlight vulnerabilities.” This is where SQL injection, XSS, and authentication flaws actually surface. 6. Client-side validation is UX, not security. Attackers simply disable JavaScript and hit your API directly. Always validate again on the server—every single time. 7. AI-generated code commonly leaks data in three places: .env values ending up in the frontend, API responses returning too much information, and secrets appearing in logs. Prompt: “Check my app for credential or sensitive data leaks in frontend or API routes.” 8. API keys in the frontend = game over. If it’s visible in the browser, assume it’s already compromised. Move it server-side or proxy the request. 9. Add rate limits before someone burns through your API budget. Cap every endpoint that hits a paid service. I’ve seen a Supabase bill jump from $20 to $200 in a single day. 10. Put CAPTCHA on public forms (Cloudflare Turnstile is free) and lock CORS to your own domain. Ten minutes of work that stops most bot floods. 11. Error messages that don’t leak information. Show “User not found,” not “SELECT * FROM users failed.” Log the full technical details server-side and give users only generic messages. Build fast. Just don’t ship unprotected.

  • jonas
    Jonas Templestein (@jonas) reported

    @thdxr (Not a serious application) Alchemy is v good but unfortunately cloudflare is investing heavily in wrangler for local dev and it sucks not being able to run apps locally So we made a little script that takes env config and secrets in and produces wrangler files and wrangler commands It works quite well for us now - but it does feel like we are building half of IaC because we need to sequence resource creation and tear down and deal with flaky control plane APIs etc

  • armujahid
    Abdul Rauf (@armujahid) reported

    @karachism @argamingpk1 Will check. My setup is -> pihole (custom block list, dns cache) -> dnscrypt -> cloudflare zero dns. But yeah, noticed random issues on vanilla network without any custom setup.

  • jjainschigg
    κυβερκογιότλ (@jjainschigg) reported

    @Prokofy You can do this really cheap: - $10/year approx. for domain name (Cloudflare) and DNS support - GitHub Pages for static website hosting - A *** repo for file storage (text and minimal images) - A static site generator and GitHub Actions workflows that rebuild your website when you commit new stuff (or you run the software on your desktop and push the built branch for hosting). But this is NOT a 'drag files to the FTP client' kind of experience. You have to build and test your website using the site generator's framework. And then you have to use *** or GitHub Desktop and the GitHub webUI to make tweaks. Or you can have a 'drag files to the FTP' experience by installing a few things on a Raspberry Pi you run at home, and getting traffic forwarded to it from Cloudflare. But you have to do that setup and update that server (or make it update itself, which is more setup). $3/month for a server-like thing with pre-installed nginx or Apache or whatever with a /var/www/html directory that you can copy files to easily, can presume is getting updated, and is sitting in someone's datacenter with good electricity is a pretty good deal.

  • alandotnet
    Alan (@alandotnet) reported

    It would be great if @Cloudflare Mesh had the equivalent of network ACLs like Tailscale

  • jasonkarns
    Jason Karns (@jasonkarns) reported

    @Cloudflare @Cloudflare so i go to set a password. and I can't set a password without providing an old password. WHICH I DON"T HAVE. **** YOU CLOWNS

  • DavidFrosdick
    David Frosdick (@DavidFrosdick) reported

    Cloudflare Email then sends the customer a link to a watch page. They can react, or reply, and that comes back into D1 against the original order. Whole loop, no third-party service in the middle.