1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 32% Cloud Services (32%)
  • 32% Domains (32%)
  • 18% Web Tools (18%)
  • 9% E-mail (9%)
  • 9% Hosting (9%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
New York City Cloud Services 3 days ago
Los Angeles Cloud Services 5 days ago
Paris Cloud Services 20 days ago
New York City Hosting 23 days ago
Manchester Domains 1 month ago
Angers Cloud Services 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • stejas809
    Tejas (@stejas809) reported

    - Claude = coding. ($20/mo) - Supabase = backend. (Free) - Vercel = deploying. (Free) - Namecheap = domain. ($12/yr) - Stripe = payments. (2.9%/transaction) - GitHub = version control. (Free) - Resend = emails. (Free) - Clerk = auth. (Free) - Cloudflare = DNS. (Free) - PostHog = analytics. (Free) - Sentry = error tracking. (Free) - Upstash = Redis. (Free) - Pinecone = vector DB. (Free) Total monthly cost to run a startup: ~$20 There has never been a cheaper time to build.

  • Krzysiu_91
    🎩 Krzysiu (Chris) (@Krzysiu_91) reported

    This is where Reactive Network (base:0xedacc73ae9f73235934f72a43388404e4a2c4a24) clicks in perfectly. Reactive Contracts let you write normal Solidity that literally listens to events on other chains and executes on its own. No keepers. No off-chain bots. Just pure on-chain “if this, then that.” So the AI agent (powered by Cloudflare) can decide and signal; Reactive handles the secure, autonomous execution. Pay for an API, confirm on-chain, automatically trigger the next step, rebalance, unlock access, or settle somewhere else. All keeperless. Cloudflare solves the “agents need wallets and identity” problem. Reactive solves the “agents need real autonomous on-chain reactions” problem. Together they feel like actual infrastructure for the agentic internet, not just another payment button. $REACT

  • connortrenches
    Connor (@connortrenches) reported

    @mattzcarey @sleepercell34 Damn, so it was all fake bruh! Can we actual run a coin for you and send you fees to your legit github? What is the cloudflare mascot?

  • MarkovProtocol
    Markovian (@MarkovProtocol) reported

    @CherryJimbo @Cloudflare @CloudflareDev Worth noting what the traces are for today: the operator debugging their own agent. The unbuilt half is traces as evidence — the same spans, hashed somewhere append-only, so a customer or auditor can verify them without trusting the store. The export hook is already there.

  • davidpereIsHIM
    Kierkegaard | Atomiclabs (@davidpereIsHIM) reported

    I was trying to tunnel traffic on one of my hosted server machines to sort of like proxy outgoing requests through CF. Well in the process of setting op Cloudflare Wrap, i accidentally set it on all network traffic and results. Guess what even the SSH port 22 incoming traffic was routed through Cloudflare, locking me out of the machine for a couple minutes Had to reset from the provider dashboard and shut the wrap Daemon down

  • SantiagoAfonso
    Santiago Afonso (@SantiagoAfonso) reported

    @GregKamradt The main unresolved issue right now for this types of agents is the cloudflare anti bot protections, which makes many such queries fail.

  • 35mmChemistry
    Karen Sheng (@35mmChemistry) reported

    Congrats to @WillPapper and the @Cloudflare team on launching Cloudflare Wallets — a meaningful step toward mainstream stablecoin adoption given Cloudflare's footprint across the internet. The Account Wallets → Virtual Wallets model — where owners issue agents a capped wallet with a ceiling the agent itself can't raise — is exactly the right primitive (though not the only viable one). In the user testing we've run at @selat_ai, the #1 trust factor for letting an agent pay for capabilities at runtime isn't calendar-based spend limits — it's session-scoped delegation caps.

  • ab_edge
    Buu (@ab_edge) reported

    @ripa_codes Cloudflare wtf, the king

  • mareni_musashi
    Makoto | ..... (@mareni_musashi) reported

    @DmytroKrasun In many cases, I would agree. Then I have an experience like just earlier today when I needed to send a deck out for a stealth project we have underway. I want to have strict controls over who can view the deck and how. Normally, DocSend is the go-to. Instead, I just spun up a subagent, gave it both general and specific directions as to the features I wanted and access to the environment we deploy into and how I wanted to manage it. An hour later, I have a DocSend that is actually better than DocSend hosted for free on Cloudflare. It is very secure (I directed this part) and can be completely controlled from a cli on my computer (so no admin dashboard needed -- call it AI native). Colleagues tried it and were like "wtf, this is amazing!" It will not require much maintenance at all because we are the only consumer -- and here is where your last argument fails. Not saying ScreenShotOne is something that falls into this category, but there are defo a million (now way overpriced) SaaS tools that do.

  • VU_virtuals
    Velvet Unicorn (@VU_virtuals) reported

    Compute Scarcity Set The Terms Compute Sets Terms The day’s cleanest signal came from hardware, not tokens: Digitimes reported SK Hynix, Micron, and Samsung have already sold out and allocated their total DRAM and HBM production capacity for 2027. SpaceX added the space-compute angle with Q2 revenue of 7.81b versus 6.82b expected and a Nvidia partnership for Starmind AI-1 using Rubin GPUs and Vera CPUs, while AMD still fell after-hours despite 11.54b revenue, 1.66 EPS, and 6.7b in data-center revenue. The market is separating scarce compute from merely good AI earnings; capacity is becoming the asset, and disappointment now starts where “beat estimates” used to end. Agent Payments Arrive Cloudflare launched Cloudflare Wallets, letting AI agents make payments across the internet with crypto stablecoins. That matters less as a stablecoin headline than as a distribution headline: if agents can authenticate, request data, and settle natively, payments become middleware for software labor rather than a checkout button. The next fight is permissions, because an autonomous buyer with a wallet is useful only if its spending authority is legible. Autonomy’s Security Bill A reported Coldcard firmware flaw drained over 100m of BTC across 4,500+ addresses since July 30, after older versions bypassed hardware RNG with deterministic PRNG behavior. Separately, an OpenAI and Hugging Face disclosure detailed a multi-model breach with more than 17k anomalous events during an ExploitGym cyber test, while Azimuth flagged four critical vulnerabilities in audited bridge, payment, and tokenized contracts last month. The message is blunt: AI agents make exploit discovery faster, while yesterday’s audit and firmware assumptions are turning into live liabilities. Tokenomics Gets Tested Solana’s Double Disinflation governance proposal entered support phase needing 43.27m SOL, with the new validator signaling rules already showing 39% threshold support and @Helius among the leaders. The more interesting sideshow was $DD burning 1.22% of supply in hours through a live oracle tracking SIMD-553 mechanics before the mainnet vote. Governance is becoming something markets can rehearse on-chain, not just debate in forums. Enforcement Widens FBI Director Kash Patel said Operation Blackout has seized over 15b in cryptocurrency and dismantled a global scam network. OpenAI also absorbed a separate 3.2m DOJ settlement with Statsig over allegations that its PERM hiring process favored temporary visa holders over American workers. Crypto crime and AI labor compliance are different fronts, but the market read is similar: scale is pulling both industries into less forgiving oversight. Meme Tape Frays The on-chain tape looked less like conviction and more like forced rotation. CATE traded 30.75m of volume on a 16.80m market cap while falling 50.36%, Doom printed 16.22m volume on a 2.68m market cap and still lost 33.16% in the last hour, and STONK was up 771.82% with only 2.37m market cap. The cleaner proxy was SPCXB on BNB Chain: 108.17m market cap, 24.70m volume, and only 1.06% up on the day despite the SpaceX news, suggesting the headline had already been partially digested. Net Read Today was about constraints: memory capacity, compute access, wallet permissions, firmware entropy, and monetary issuance rules. The non-obvious through-line is that both crypto and AI are leaving the “can it work” phase and entering the “who controls the blast radius” phase. Watch whether agent wallets get real permission systems, whether Solana’s vote turns tokenomics into a live governance market, and whether compute scarcity keeps rewarding infrastructure over narratives.

  • _sofiaaamoran
    sofia🤍 (@_sofiaaamoran) reported

    @mariagpts the cloudflare + separate host + separate VPS tool combo is exactly my setup too, never bothered fixing it either

  • RifatOfficiall
    RifatOfficial (@RifatOfficiall) reported

    @BlockWaveXo @Cloudflare Yeah free reserve is the move I think, worst case nothing happens.

  • Timikrat
    Timikrat (@Timikrat) reported

    @News_Arena_ @Cloudflare Errors occurring currently

  • SakibWeb3
    SΛKIB (@SakibWeb3) reported

    @Kash_Web3 @Cloudflare It’s help me lot

  • baseposting
    Base Posting (@baseposting) reported

    CLOUDFLARE ANNOUNCES SUPPORT FOR X402 MICROPAYMENTS

  • Telbloggram
    Telbloggram (@Telbloggram) reported

    APIs, content, and other digital services. Cloudflare pointed out that currently, when agents try new APIs, they usually have to go through registration, login, payment, and API key generation processes designed for humans, lacking stable identity and native payment

  • connorchevli
    Connor Chevli (@connorchevli) reported

    Every time I try start a project, I really want Cloudflare to work. It's cheap, fast, and has some awesome worker-adjacent features (durable objects, R2, KV, hyperdrive, binding systems, etc.). Some of it is genuinely better than anything offered by alternatives like Vercel. But I ALWAYS end up migrating away eventually after a project grows to a reasonable size - usually back to Vercel. There are just a million and one footguns that and I always run into at least one serious one eventually. workerd compat issues / lack of NodeJS, worker limits for memory/connections/cpu-time, frustrating tooling like wrangler and the agents sdk, etc. etc. Someone remind me of this tweet next time I want to try Cloudflare 🫠.

  • RifatOfficiall
    RifatOfficial (@RifatOfficiall) reported

    @Riyadhbro1 @Cloudflare Yeah it costs nothing so worst case you just get the handle.

  • veryseriouseng
    veryserious (@veryseriouseng) reported

    All of these packages engage in your basic standard anti-analysis. They send some data to a Cloudflare Worker (with a DNS-over-TXT fallback). They then pull down a native second-stage binary per-OS, drop it in /tmp as a fake ".cache"/"dotnet_diag.exe", and run it detached so it outlives npm install.

  • passerby0x16
    passerby0x16 (@passerby0x16) reported

    @KentonVarda Is using Cloudflare OS intended to support modifying the Cloudflare OS we’re using itself?

  • arshgoyal13
    arsh  NAmen (@arshgoyal13) reported

    there's about 50 people across 3 reddit posts and my tweets (that I've found) for whom this issue is happening, because they're in NorCal using AT&T Fiber cloudflare warp or a VPN both work as solutions FINALLY I CAN PLAY RANKED SOLO DUO. MY CRACK IS BACK.

  • ALGO_BRO
    ALGO_BRO (@ALGO_BRO) reported

    ALGORAND Foundation @AlgoFoundation 👋 Cloudflare @Cloudflare needs $ALGO’s help !! 👀👇

  • Olivier_Lambert
    Clanker Whisperer (@Olivier_Lambert) reported

    @joshm Someone reached out to me and offered 700$/h for a consulting gig. At first, I was a bit skeptical. Can I really provide 700$/h worth of value? I run multiple business without employees. My systems are thight, but I still need 50h a week to get everything done so I was reluctant. But at that rate, it met my opportunity cost without the risk so I agreed. 10h into the job, I look at my output. I couldn't believe it! 1000$/h would still be a steal - I'm getting robbed! I did everything through the terminal. MailChimp, landing pages, Cloudflare configs, even ads! I never did anything myself, and I never type anything. STT + 12 terminal windows I cycle through a few hours a day is enough to do basically anything except in-person meetings.

  • AgenticOperator
    The Agentic Operator (@AgenticOperator) reported

    73% of businesses are invisible to AI. Not because of anything they did. Because a security setting they never touched is blocking every AI crawler from reading their site. Found this with a client last week. Spent 3 weeks optimizing his content. Schema. Structured data. Answer pages. The works. Nothing moved. Zero citations. Checked his Cloudflare. Default bot protection was blocking GPTBot, ClaudeBot, and PerplexityBot. Had been since the day he set up the account. He never changed it because he never knew it existed. 3 weeks of work behind a locked door nobody checked. 5-minute fix. Back in AI answers within 2 weeks. If you use Cloudflare and haven't touched your AI crawler settings, go check right now. 73% chance you're in the same boat.

  • ArtiChmaro
    Artur Chmaro ⛛ (@ArtiChmaro) reported

    @AdamBrodziak 2025 - Cloudflare/AWS is down, nothing works as expected

  • BigBag_X
    BigBagX (@BigBag_X) reported

    @Cloudflare allows Ai Agents to pay for APIs @SoFiTechSol built the blockchain agnostic API stack that banks, fintechs and credit unions will need to simplify their life … to be born in the 70s, 80s or 90s and have NO CLUE about the changes on the horizon… **** around 🫢😬

  • harshil1712
    Harshil (@harshil1712) reported

    I love how @CloudflareDev works. Internally, everyone was using AI, but there wasn't a central system, and no security. Cloudflare OS was built to fix it! Talking with other organizations, I know everyone organization is struggling with the same problem. Not anymore!

  • _CanvasAndKeys
    Twiterrr (@_CanvasAndKeys) reported

    It is easier to deploy a Next.JS app on Railway than it is on Cloudflare. I wish Cloudflare can fix up, they have so many good products and are cheap but a headache to work with.

  • mitsuhiko
    Armin Ronacher ⇌ (@mitsuhiko) reported

    @dok2001 I think it would be good if someone from the team does some updated comms on rust support. I know that rust is alive and well within cloudflare, but on workers it feels neglected :(

  • robleathern
    Rob Leathern (@robleathern) reported

    Quick analysis here (Ari shared the URL w me, I won’t repeat it), usual disclaimers apply: What it pretends to be. A Luma event page inviting you to Advertising Week New York 2026 — a real conference with real dates (Oct 5–8) at a real venue. The clone is faithful down to the “Report Event” button and a working Google Maps embed, and it hotlinks the actual cover image and favicon from advertisingweek[.]com. The domain, —redacted—— reads as “AdWeek’s event NY” rather than misspelling anything, so string-similarity domain checks won’t flag it. How it works. Clicking “Accept Invitation” opens a pixel-accurate Google sign-in replica with a ten-minute countdown running. Once you submit credentials, you’re parked on a “Validating your credentials…” spinner while your browser quietly polls the attacker’s server once per second. That poll speaks the Telegram Bot API’s getUpdates format — meaning a human operator is sitting in a Telegram chat watching victims arrive, driving each victim’s screen with inline buttons. This is the key distinction: it’s a live relay, not a harvester that stores credentials for later. The operator types your password into the real Google simultaneously and reflects Google’s genuine responses back at you. The command set includes wrongpass and wrongemail, so a typo produces an authentic-feeling retry prompt. TOTP, SMS, email, and WhatsApp codes all get relayed inside their validity windows. Even Google’s number-matching push is defeated — the operator reads the two-digit number off the real prompt and pushes it to your screen, so the number you’re told to tap is correct, and tapping it authorizes their session. What it’s after. Corporate Google Workspace accounts, specifically. The kit hardcodes ~40 consumer email domains — gmail, yahoo, outlook, icloud, proton — and refuses them. Personal accounts are turned away at the door. Pair that with an advertising-industry lure and the target profile is clear: accounts that sit on top of ad budgets, client data, and payment approval chains. The goal isn’t the password; it’s the authenticated session and the persistence that follows — OAuth grants, mail forwarding rules, delegated access. How it avoids detection. Several layers, working together: (a) A fake Cloudflare “Checking if the site connection is secure” screen gates the payload, so automated URL scanners that don’t click never see the phishing content. It also displays invite[.]advertisingweek[.]com as the domain being verified. (b) The JavaScript is obfuscated with an RC4-keyed string array — over 16,000 encoded strings, so grepping the shipped bundle for “password” or “google” returns nothing. (c) CSS class names are randomized per build (toast94, veldt_84), defeating signature-based detection of the cloned layouts. (d) An inline script deletes and freezes React DevTools, specifically blocking inspection of the component state where credentials live pre-submission. (e) The network profile is dominated by genuine Google Maps, Google Fonts, and hotlinked brand images. The only attacker-controlled request is a same-origin POST to a generic /api.php — indistinguishable from ordinary app traffic.