Cloudflare status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (55%)
- Hosting (27%)
- Domains (18%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Cloud Services | 32 minutes ago |
|
|
Cloud Services | 2 days ago |
|
|
Hosting | 2 days ago |
|
|
Hosting | 11 days ago |
|
|
Cloud Services | 30 days ago |
|
|
Cloud Services | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Smail (@Smailancer) reported@levelsio @Cloudflare Why you don't fix the strict mode in cloudflare that bans tons of people who trying to reach the website?
-
Rue Mohr🇨🇦 (@RueNahcMohr) reported@vccccnv I have never had this issue on a site that did not use cloudflare.
-
Nathan Pierce (@norsegaud) reported@levelsio @Cloudflare Same, switched 5ish months ago and will never go back to namecheap!
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Fix human verification
-
Kamil Fabian (@KamilFabian) reported@RueNahcMohr @lmilsfsd @Cloudflare just cler the cache. Problem is at your "receiver" ;)
-
Inauthentic behavioralist (@SenZJo) reported@RueNahcMohr i have the same problem because i use a vpn.., i restart my vpn and im in.. i hate cloudflare sites wanting to know my location so they can serve me ads that will be blocked anyways..
-
Tang Vu (@tangvu_dev) reportedI compared Cloudflare Workers and Vercel Edge Functions, two production platforms built on V8 isolates, using a latency-sensitive crypto analytics service. The workload fetched prices and computed OHLC + VWAP over 24 kline periods.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
jacky (@jjacky) reportedive moved entirely off cc to devin, but losing localhost sucks but.. turns out i can still get it devin's vm tunnels its dev server to a URL using @Cloudflare quick tunnel it gives me the url and i get a live UI of the wip code dont even need to commit or deploy incredible
-
「Hi-Tech Lo-Life」 (@HiTechLoLife1) reported@GrimmiVT Fake cloudflare captcha... well **** I think a lot of people are gonna fall for it.
-
iyda (@notiyda) reported@dean_walsh1 @theo @janaka_a Ah actually cray you just reminded me normal ISP's normally do not have proper peering to IX or cloudflare magic transit either or Lumen or anything proper so most people if you were hosting a game server would have **** ping lmao
-
Kala (@kalapowered) reportedon 15 September Cloudflare starts blocking AI agents by default on any new site that shows ads. not scrapers, the agents shopping for a person who's waiting. search bots stay in, training bots stay out, and "verified" stops meaning "allowed" so the web is getting a bouncer, and the guest list for the paying lane is kept by Visa and Mastercard: an agent gets through with a key registered at the card network and a tag that says it's here to pay. fine by us, it's how every other door on the internet ended up. we're just enjoying that step one of buying anything online as a robot is a wristband 🙃
-
Deyder Cintron (@deydercintron) reported@levelsio @Cloudflare Full API surface that lets you register and manage without handoffs is the real unlock. Anything that forces a browser click or support ticket re-introduces the bottleneck.
-
Noah (@itsnoahd) reported@jjacky @Cloudflare Oh hmmm that's probably an issue for me haha
-
FLOW intern (@flow_interno) reported@anonchain cloudflare decides which anon gets rich now and it has never let me through
-
Frankie Ramirez (@frankiedevs) reported@zachwills Oh I gotta see if that made it through. The default twilio voice setup was crap so I spun up a Cloudflare worker to allow it to use the Grok Voice API to sound a bit more natural.
-
David Haddad (@daveying99) reported@levelsio @Cloudflare Easy decision. Only thing I would like more is domain favoriting (considering buying) and more tld support (namecheap has more and godaddy much more)
-
nora 🇨🇦 (@zunxra) reported@JakeLandauTO Not that weird if they use cloudflare or a similar service, which I both imagine and hope they do.
-
Akash.eth🌊 (@sheikhakash69) reported@0xBlue Cloudflare moving first is a big signal. Domain depth will decide winners.
-
dodeka.AVI 🔆 (@greenyphatom) reported@ignaseeo "But that's BAD! It's being controlled by bad people and stuff! And they're using it to spread and normalize bad things! I know I'm talking about Bluesky here, the social network that I and my friends use, but that also applies to Cloudflare too!!"
-
James Martinez (@realjamesmtz) reported@mrfundman @Cloudflare Damn too rich for me.
-
Ric Orna (@ric_orna) reported@yongfook Or you gotta be doing something that actually has a moat still. Eg a network of sensors and API. Nobody is gonna vibe code physical stuff. Or something so big and boring a lift that nobody would want to and couldn’t in short order anyway. Vibe code your Cloudflare competitor.
-
Sharax (@Sharax) reportedThere's an issue with @Cloudflare Warp that I feel needs to be addressed. For example, I'm sometimes in Toronto, but it connects me to the Montreal network. That means two different provinces and two different sets of regulations, which causes issues when accessing certain websites and services. @eastdakota
-
saint (@thetronchguy) reportedaws, cloudflare, google, meta literally all have such ******* hostile ui it’s genuinely physically ******* painful to have to go spelunking thru the cave of mysteries just to get any ******* thing done no reason why having to use these dashboards genuinely leaves me wanting to fight someone EVERY single time man like how does it benefit you that your users would rather eat a ******* tire than use your **** dashboard??
-
Sommy (@GAkpugo) reported@AirtelNigeria You network has been bad since morning. I cant access some websites at all. Also my airtel sims do not specifically o}en cloudflare.
-
Kamran Khan (@itskamrankhan) reported@Jordenbs @Taniyatweets_ Jorden, the problem comes when you renew it, GoDaddy will charge hefty fee....you might have got the deal better at initial stages....they will show their colour when you renew,,, My domain still in Cloudflare, Cloudflare has flat pricing they don't charge like GoDaddy...
-
Julian Goldie SEO (@JulianGoldieSEO) reportedHermes agent just added 44 new one-click app connections, and there's a setting that stops them from slowing your agent down. Cloudflare, Datadog, Metabase, GitLab, Railway, Deep Wiki, and plenty more in the catalog. Before this, you found the server yourself, read its docs, and hand-edited a config file. One typo and nothing connected. Now you open the catalog, hit enter on the app you want, and it handles the key or the login for you. You never touch a config file. But here's the setting most people miss. Every tool you connect sends its instructions to your model on every single turn. Connect enough apps and your context is full before you've asked anything. Cloudflare alone exposes around 3,300 tools. Just the names come to roughly 32,000 tokens. The fix is called Tool Search. Instead of loading every tool description, Hermes swaps them for three tiny helpers. One finds the right tool. One loads its details. One runs it. Your agent only pulls what it needs, when it needs it. That's why you can add 44 connections and not wreck your setup. Two more things: Every connector is off by default, and Hermes hands you a checklist of what each one can do. Reading issues, yes. Deleting things, no. And you can point the terminal at a Docker container instead of your own machine if that makes you nervous. Want the SOP? DM me. 💬
-
Corey J. Gallon (@CoreyGallon) reportedI'm stoked to recap my own talk from @aiDotEngineer World's Fair! The premise of "The Dark Arts of Web Automation: Teaching Agents to Use Websites Like Humans" fits on one slide: a CDP-driven browser is indistinguishable from one driven by a human, because the agent's clicks and keystrokes travel the same path inside Chrome that yours do. I provide a repeatable method for making agents actually operate the web, ending with a fully automated reCAPTCHA v2 solve with no human in the loop. To make your agent appear human to websites, you need the following things. - A CLI, not an MCP server. An Arize AI study found both hit ~83% task success, but the same task took MCP 71 round trips and eight minutes against seven turns and under a minute for the CLI. Anthropic have reported the CLI can be up to 75x cheaper in tokens. - Drive the browser through the Chrome DevTools Protocol. It's the same protocol behind the panel that opens when you hit F12. 57 domains now, but you only need the handful that give your agent digital senses: DOM and accessibility tree and screenshots to see, network and console to hear, clicks and keystrokes to act. - Sense, act, verify, repeat. Verification has to come through a different channel than the one you acted on. If you clicked something, don't ask the click whether it worked, check the network or the screen. - The "meatbag ladder". Rung one is a synthetic JavaScript click, free and instant and the right default. Rung two is a real click through CDP's input domain, which Chrome stamps trusted. Rung three is human motion and vision. Climb only as high as the page forces you. - Trusted versus untrusted is why your click does nothing. A synthetic click on a defended add-to-cart button fails silently, no error, and the page just drops it. The trusted one goes straight through. - Cloudflare Turnstile hides its checkbox behind a closed shadow root inside a cross-origin iframe with another shadow root inside that. So stop trying to grab the element. Ask where the iframe sits, do the math, fire a trusted click at that position on the glass. - Slider captchas are won by how you move. They sample the mouse into a trail of points, so the drag eases in, curves, deliberately overshoots and settles back. - Split the work: deterministic solver, agent operator. Code does the clicking, iframe piercing, screenshotting and rearming; the agent only looks at the grid and picks tiles. reCAPTCHA rounds expire, and an agent that round trips a model on every click burns the clock and loses. - Explore by hand, then write the path down. As code, as an agent skill, often both. Figure it out once, do it forever. It was delightful to speak at this conference, and to meet and talk with so many other AI Engineers working on cool projects! I look forward to the next AIE event. I'm working through the published talks from AI Engineer World's Fair sharing summaries and takeaways. Follow for more!
-
MANU MI (@manumish) reportedJust in case… - Is there a hardware KILL switch - Is Cloudflare and Crowdstrike and all truly ready to help.
-
Tommy Geoco 🇺🇸 (@designertom) reportedcontext: grok bot runs in the cloud out of the box, which is great, but the whole point of registering a computer is letting agents run things on YOUR machine. i have a mac mini as the home base for my whole OpenClaw (and others) agent stack: my Obsidian knowledge vault, my capture scripts, QMD and sub-surface UIs for slices of workflows connected to crons, all of it lives there. grok's agents are supposed to reach into that box and run stuff. the bug: from the iOS app, every one of those commands dies with "couldn't bind the command for review." i checked the mini's side and grok's own exec daemon was connected the whole time but the command never even left the app. same commands run fine from desktop. so it's the mobile approval surface that's broken, not the computer link. and there's no allowlist or auto-approve at all. every command needs a review card that mobile can't show. which means all agent → your-own-computer automation is dead from my phone ended up standing up my own authed relay on the mini + a cloudflare tunnel just to route around the approval layer. it works, but come on. what i want: 1. per-computer command allowlist so trusted scripts skip review 2. fix the review card on mobile 3. when it fails, give the agent a real error instead of a silent retry loop