1. Home
  2. Companies
  3. Cloudflare
Cloudflare

Cloudflare status: hosting issues and outage reports

No problems detected

If you are having issues, please submit a report below.

Full Outage Map

Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.

Problems in the last 24 hours

The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

At the moment, we haven't detected any problems at Cloudflare. Are you experiencing issues or an outage? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by Cloudflare users through our website.

  • 33% Domains (33%)
  • 30% Cloud Services (30%)
  • 15% Web Tools (15%)
  • 15% Hosting (15%)
  • 7% E-mail (7%)

Live Outage Map

The most recent Cloudflare outage reports came from the following cities:

CityProblem TypeReport Time
Paris Cloud Services 9 days ago
New York City Hosting 11 days ago
Manchester Domains 1 month ago
Angers Cloud Services 1 month ago
London Domains 1 month ago
Noida Hosting 2 months ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

Cloudflare Issues Reports

Latest outage, problems and issue reports in social media:

  • aarondelasy
    Aaron Delasy (@aarondelasy) reported

    @jackfriks jack, here's my suggestion: if you want to be able to prompt from your phone, then I suggest using voice input apps like wispr flow, becuase typing on phone is super slow I wouldn't go as deep as actually coding from your phone because the screen is smalkk using Claude dispatch is a **** show because it's too limited, so the only real way ... a legal way is ... claude for web it basically runs your project in cloud vm spun up by Anthropic. the only pre-req is to create a setup script OR use session-start hook server specs are 4 vCPUs, 16 GB of RAM, 30 GB of disk space the flow then becomes like this: you start the session, claude sets up your VM, then you prompt, Claude does everything for you and it pushes its branch to GitHub you review the diff on GitHub, leave inline comments and send a message to address your feedback this way you can paste images in a nice chat, still be able to review the code Claude produces and steer it you can use something like ngrok or cloudflare tunnels to create preview links to test the new changes

  • TechRemarker
    TechRemarker (@TechRemarker) reported

    @CloudflareHelp Does any one know how to contact @Cloudflare support? As detailed in this thread. CF had a bug where they charged me twice for the domain registration. Site contact options just show help docs. No response from CF Help here. Anyone know how I can reach them?

  • eayetsi
    Ekow Nyame Ayetsi (@eayetsi) reported

    @Cloudflare @Cloudflare The link is broken

  • synoet
    teo (@synoet) reported

    @CherryJimbo @Cloudflare great site, wish it existed a year ago when I picked up durable objects. one more thing on DOs: the system clock is frozen except across I/O, so you can't get consistent timing or traces inside an object, making debugging perf issues basically impossible

  • ummo__
    H (@ummo__) reported

    @HumbertoLunaTi2 @allmusic @allmusic Same problem. Fix the Cloudflare error, please.

  • GraemeVIP
    Graeme (@GraemeVIP) reported

    @IntCyberDigest They still allow accessible options for people who can't do it. Google Captcha V2 was terrible for disabled people and the visually impaired. V3 solved that. This is unnecessary. You can beat bots with a honeypot field and Cloudflare, you don't even need Captcha V3.

  • itsjeffan
    Jeff An (@itsjeffan) reported

    @raunakdoesdev @Cloudflare your first mistake was paying for gcp support

  • siraustin
    Austin S. Lin (@siraustin) reported

    @prd_008 dear lord no… Sites is a fine name for what it is (it’s cloudflare pages and workers abstracted). one big issue is that you get different levels of github access from within chatgpt app depending on whether you have chat (no access to private repos), work (access to existing repos), or remote selected (full github access to create and manipulate repos).

  • Crypto_peet
    Cryptopeet (@Crypto_peet) reported

    solana:HmTi3CQfKfXWbn1tNoiAxH7GzMV7L3tDAmPWabZEBAGS own hardware is coming next week also people fudded because the network has some issues due to cloudflare problems some said also why no daily buybacks all i hear is monkeys talking anyway, solana:HmTi3CQfKfXWbn1tNoiAxH7GzMV7L3tDAmPWabZEBAGS own hardware is catalyst for next leg up hope you all locked in!

  • eayetsi
    Ekow Nyame Ayetsi (@eayetsi) reported

    @Cloudflare @Cloudflare The page is broken

  • dev_ita_chi
    Dev Itachi (@dev_ita_chi) reported

    @honour_can_code Bro i just discovered cloudflare for my startup, I'm never going back.

  • occupymars___
    Jason · The Orbital Forge🧬🤖 (@occupymars___) reported

    @JoeWinton @XFreeze Already working towards that my Os linux is almost an AI node with no desktop only a dashboard scroll my network access is anywhere phone tablet p.c using cloudflare it works

  • BarbogDaFinka
    Barbog Da Big Finka (@BarbogDaFinka) reported

    In my endeavour to see just how little I can do, I started a new project. Sol has worked diligently to shill CloudFlare to me, opening a oauth sign in to CloudFlare, and eventually haulted work till I swiped my credit card. It has now successfully deployed a game behind a domain. The game is horrible, but I'm impressed it did all this in about 5 hours.

  • voltreaver
    Volt ✚.🏳️‍🌈 (@voltreaver) reported

    it feels like adolf hitler made cloudflare warp to be the most unusable **** ever why does it keep disconnecting randomly

  • polarbeargrowth
    Polarbear · App Growth Breakdowns (@polarbeargrowth) reported

    Public app, private admin, zero custom auth code. Cloudflare Access locks /admin/* behind Google login while the rest stays open. • Bake it into IaC so agents build the UI and protect it in one pass • No auth logic to maintain Vibecoded tools ship safe by default. h/t @thdxr

  • DFIR_Radar
    DFIR Radar (@DFIR_Radar) reported

    Chaos ransomware's msaRAT routes C2 entirely through Chrome or Edge via Chrome DevTools Protocol, making attacker traffic invisible on the wire. The RAT process never touches the network directly. - msaRAT is a Rust-based RAT attributed to the Chaos ransomware group. Initial access delivers update_ms.msi via curl over HTTP on port 443, bypassing port-based firewall rules. The MSI impersonates a Windows update and loads the RAT DLL directly into memory, leaving no obvious on-disk payload to catch. - C2 is split across two legitimate services: Cloudflare Workers at is-01-ast.ols-img-12.workers[.]dev handles SDP signaling to establish a WebRTC channel, then drops out entirely. All subsequent commands flow over a WebRTC DataChannel relayed through Twilio, so the attacker's real server IP never appears in traffic. - The RAT binds only to 127.0.0[.]1. All external traffic originates from the browser process itself, launched headless with remote debugging enabled. CSP is bypassed via a CDP command and JavaScript injected into the browser handles every network operation. What a defender sees is a browser making HTTPS calls to Cloudflare and WebRTC to Twilio, both normal. - Talos found msaRAT deployed between initial access and the Chaos encryptor, confirming it serves pre-encryption reconnaissance. Double encryption: DTLS from WebRTC plus ChaCha-Poly1305 over an ECDH-derived key means stripping DTLS still yields ciphertext. #DFIR_Radar

  • Swgtct
    Sam (@Swgtct) reported

    @ODEONHelp some bizzare reason I have been cloudflare blocked on app and website any ideas or can I just never go to odeon again ?

  • stuxnet_vt
    Stuxnet (@stuxnet_vt) reported

    Riot literally spends millions, *millions* on infrastructure to mitigate the variability and inconsistency that comes with large scale networking. We benchmark and test things ruthlessly (as @dok2001 knows given Riot is a customer of CloudFlare). Hell, I’ve literally spent the last six years of my *life* building tooling to help test these things and it’s still nowhere near enough.

  • nikskld
    nik skld (@nikskld) reported

    ANTHROPIC SHIPPED A CRON SCHEDULER FOR AI AGENTS AND ALMOST NOBODY COVERED IT. Every thread you’ve seen about Claude Managed Agents is still recycling the April 8 launch post. Three months later the product barely resembles that announcement. What actually shipped since: •Scheduled deployments (June 9). Give an agent a cron schedule. Every time it fires, the agent opens a fresh session and completes the task. No scheduler to build, no scheduler to host. •Environment variables in vaults. Register an API key with the domains it’s allowed to reach. The sandbox only holds a placeholder. The real key gets attached at the network boundary, on approved domains only. The model never sees it. •Self-hosted sandboxes (May 19). The agent loop stays on Anthropic’s infrastructure. Tool execution moves inside your perimeter. Cloudflare, Daytona, Modal and Vercel are supported out of the box. •Memory graduated from research preview to public beta. Only MCP tunnels and dreaming are still gated behind an access request. Pricing almost nobody quotes correctly: standard token rates plus $0.08 per session-hour. Runtime is metered to the millisecond and only accrues while the session status is “running.” Waiting on your reply or a tool confirmation costs nothing. Now the part the hype threads skip. Managed Agents is stateful by design. Conversation history, sandbox state and outputs are stored server-side. Anthropic’s own docs state that this makes it ineligible for Zero Data Retention and for HIPAA BAA coverage. So every “finally, a secure alternative to hosting agents yourself” take has it exactly backwards. You get sandboxing, scoped permissions and execution tracing. You give up data retention guarantees. For legal, health and financial workloads that trade is the whole decision. Old way: build the loop, the sandbox, the scheduler and the secret vault yourself, then ship in months. New way: define the agent, point it at a cron, ship in days, and read the compliance page before you move anything sensitive through it.

  • Galkon
    Joshua Lipson (@Galkon) reported

    @dok2001 @Cloudflare @BraydenWilmoth still an issue btw. feels like CF can handle deleting a worker w/ over 100 deployments. instead it offloads the responsibility to me to use the API and paginate deletions in batches for ages to not hit rate limits

  • ArtChicken4
    Art Chicken 🐓 (@ArtChicken4) reported

    From Jovan Hutton Pulitzer's Telegram- - For tech nerds understanding the PCAP fraud: The mechanism works, and every input is public. Rosters of US election officials are published (state SoS directories, EAC, NASS, commercial lists). Take each office's email domain → MX lookup → resolve the mail host to an IP → geolocate it. You now hold a table of "jurisdiction → IP → city/lat/lng" covering every election jurisdiction in the country, built entirely from DNS, without ever sending a packet to an election office. That table would look authoritative and survive spot-checking — the IPs are real, the org names are real, the geography is real. It would also be probatively empty, because an MX record identifies who handles that office's email. It says nothing about vote systems. The signature of an MX-derived list would be hundreds of jurisdictions collapsing onto a handful of shared mail-provider IPs — Microsoft 365 (*.mail.protection.outlook.com), Google Workspace, Barracuda, Proofpoint — because that's who most county governments use. What your file actually shows I tested it. The target roster is a complete enumeration of election jurisdictions, and the counts are exact: State Rows Actual jurisdiction count Massachusetts 351 351 municipalities Connecticut 169 169 towns Texas 254 254 counties Georgia 159 159 counties Virginia 133 95 counties + 38 independent cities Kentucky 120 120 counties North Carolina 100 100 counties Iowa 99 99 counties One row per jurisdiction, zero duplicates in any state. Real network traffic doesn't distribute itself one-event-per-administrative-unit. This is a roster walk. But the IPs are coarser than your MX hypothesis. Eleven states collapse to a single IP for every jurisdiction: 490 Maine town clerks        -> 13.32.25.126     (AWS CloudFront edge) 351 Massachusetts clerks     -> 45.60.195.2      (Imperva/Incapsula WAF) 246 Vermont town clerks      -> 45.60.45.214     (Imperva/Incapsula WAF) 237 New Hampshire clerks     -> 199.192.7.129 169 Connecticut town clerks  -> 199.107.32.42 160 Texas election admins    -> 98.129.145.194   (Rackspace) Plus 104.17.x / 104.18.x (Cloudflare) across 189 more rows. Those aren't mail servers — they're CDN and WAF edge addresses, the public front door of a state's website. A CloudFront edge IP is shared by thousands of unrelated customers; it isn't "Maine's election system," and you can't route vote data to it, because it terminates HTTPS for public web content and nothing else. So the lookup behind this file was one resolution per state's public web presence, cloned across every jurisdiction in that state. An MX-per-office build would have been more sophisticated than what was actually done here. And 253 rows have TargetIP = literally * — a failed lookup, no address at all. Those rows still carry 70,448 flipped votes. Votes attributed to an intrusion against an IP that does not exist. Bottom line Your instinct is right about the class of technique: a public roster plus DNS resolution manufactures a nationally-complete, real-looking IP table with no access to anything. That's the general answer to "could this manufacture data" — yes, trivially, and it's undetectable if you only check whether the IPs are real. The detection method is the reverse question: not "is this IP real?" but "what does this IP actually serve?" Real intrusion data resolves to the specific host attacked. Manufactured data resolves to whatever the jurisdiction's public name happens to point at — a CDN, a WAF, a mail gateway, a hosting provider. That's what's here: 490 distinct Maine towns, all pointing at one Amazon CDN address.

  • cutetopop
    lacking branding (@cutetopop) reported

    I built it for work so I don’t think I can just host it but hey maybe I’ll ask the IT guys. I think I could make it a Cloudflare worker real easy and throw on the never used art site.

  • shu_pavel
    Pavel Shu (@shu_pavel) reported

    It’s surprising how many people in our industry aren’t even trying. To them, AI is just a threat. Maybe they’re right. If not today, then in a year any mechanic will be able to build whatever they need. No APIs. No Cloudflare. No databases. But damn, it’s exciting to finally stop pushing pixels and wrestling with state sync in yet another React “prototype” just because you don’t know backend. It feels like pure ******* creativity.

  • pcstyle53
    pcstyle (@pcstyle53) reported

    @stupidbitchdog @vercel i do use Cloudflare too, and i’ve got some projects hosted there. i’ve just never really hit Vercel’s free limits either, and for my frontend dev work Vercel still feels like the better fit: previews, DX, Next support, deploy flow, all that boring stuff that saves time. not anti-Cloudflare at all, just not fully convinced it replaces Vercel for that use case yet.

  • camale0nrar0
    Camaleón Raro (@camale0nrar0) reported

    @simonw the deployment abstraction is nice until you need custom background workers or cron triggers outside their sandbox. had to drop down to direct cloudflare wrangler configs+ *** hooks because the managed UI hid too much logging when mutations failed silently. how are you handling state persistence when workers scale?

  • graykevinb
    Kevin Gray (@graykevinb) reported

    There are a ton of open fall internships rn. You should go apply. Google jobs sucks. Check companies directly. Also checkout handshake. Cloudflare and Tesla are hiring fall interns. You should apply ASAP. I will as usual be skipping this round but if you want help with your resume lmk. I have a somewhat decent success with applicant tracking algorithm manipulation. If you need money some are even 40hrs a week and pay $50/hr

  • vladinator1000
    Vlady Veselinov (@vladinator1000) reported

    @thdxr What specifically can't you do with IaC? Maybe someone at Cloudflare can help? @dillon_mulroy do you know someone who works on Wrangler?

  • brendonovich
    brendan (@brendonovich) reported

    @thdxr i've never used cloudflare until alchemy existed, i'm scared of wrangler configs

  • stejas809
    Tejas (@stejas809) reported

    GitHub — version control (free) Claude — coding ($20/mo) Namecheap — domain ($12/yr) Cloudflare — DNS (free) Vercel — deploy (free) Clerk — auth (free) Supabase — backend + database (free) Upstash — Redis (free) Pinecone — vector DB (free) Resend — emails (free) Stripe — payments (2.9% per transaction) PostHog — analytics (free) Sentry — error tracking (free) Total cost to run a startup: ~$20/month No servers. No DevOps team. No funding required. Just an idea and WiFi. There has never been a cheaper time to build. 🚀 Today is the best time to bet on yourself and build the things ⭐

  • PocketSponsor
    Pocket Sponsor (Old-timer * 57 years) (@PocketSponsor) reported

    @grok @xai @grok I’ve had multiple unauthorized charges on my Grok API key due to what appears to be bot abuse. I had rate limiting + Cloudflare protection in place, but a bot still made hundreds of calls using grok-4.5. I’ve emailed support twice with no reply. Can someone please look into this? Attached are the Audit Logs showing the activity.