Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Paris, Île-de-France | 2 |
| New York City, NY | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
| Noida, UP | 2 |
| Jewar, UP | 1 |
| Braga, Braga | 1 |
| Prievidza, Nitriansky | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Michael Hartwell (@Teresa_says_) reportedI almost ignored these charts — then the same signal appeared across all of them. $RBLX — Roblox — Don’t buy $DUOL — Duolingo — Don’t buy $APP — AppLovin — Don’t buy $HIMS — Hims & Hers — Don’t buy $SNOW — Snowflake — Buy at $252-$261 $DDOG — Datadog — Buy at $242-$250 $NET — Cloudflare — Buy at $251-$259 $SPOT — Spotify — Buy at $453-$468
-
DFIR Radar (@DFIR_Radar) reportedAiTM phishing campaign hits universities, EU and UN agencies using compromised aged domains, rotating PhaaS kits, and procurement lures to steal MFA-protected sessions in real time. Key details: - Attack chain: phishing emails sent from compromised Outlook accounts use RFI and bid-invitation lures, directing victims through fake document portals (testserveren[.]com, barifurniture[.]net), Cloudflare Turnstile or actor-hosted CAPTCHA, then cloned Microsoft login pages impersonating targets like the European Investment Bank. Email addresses are embedded in URL paths to personalize the illusion. - The actor rotates three PhaaS kits: EvilProxy (reverse proxy, active since 2022), FlowerStorm/Storm-1167 (likely Rockstar2FA rebrand, reverse proxy targeting M365), and Kali365 (device code abuse plus AiTM session capture, first seen April 2026). RDGA patterns distinguish the kits: FlowerStorm uses corporate-buzzword .de domains; EvilProxy uses corporate-buzzword .net/.com. - Infrastructure fingerprint: compromised aged domains averaging 6-plus years old, injected with an index.php to serve phishing content. No ownership change indicators. RDGA domains include usersatisfactionlab[.]de and q1evaluationperformance[.]net. - MFA is not a defense here. Session cookies and tokens are intercepted in real time as victims complete legitimate MFA flows, giving the actor an authenticated session without ever cracking a code. #DFIR_Radar
-
Ethan Walker (@maria6186551590) reportedFollow me and I’ll help you cut through market noise and find stocks with strong growth potential. $NET — Cloudflare — Don’t buy $SNOW — Snowflake — Don’t buy $DDOG — Datadog — Don’t buy $NOW — ServiceNow — Buy at $96-$99 $ZS — Zscaler — Buy at $138-$142 $VEEV — Veeva Systems — Buy at $182-$188 $SAP — SAP — Buy at $146-$150 $CRM — Salesforce — Buy at $160-$165
-
Rob Hallam (@robj3d3) reportedIf you wanna do it yourself, this is how: Buy (~15 min) 1. Cheap VPS from Hetzner or DigitalOcean (~€5-10/mo), Ubuntu 24.04, tick automatic backups at checkout 2. Add your domain to Cloudflare (free plan), switch nameservers at your registrar 3. Install Termius (SSH app) + Tailscale (private network) on laptop and phone, free tiers Lock it down (~20 min) 4. Generate an SSH key in Termius, add it to the VPS at creation. Keys only, never passwords 5. SSH in once via public IP, run updates, install Tailscale on the server, log it in 6. Disable Tailscale key expiry for the server (admin console, one click) 7. Verify you can SSH via the server's Tailscale 100.x address BEFORE the next step 8. Provider firewall: delete all inbound rules, allow only port 443 from Cloudflare's published IP ranges. No public SSH at all. You enter through the tunnel 9. Test from outside: public IP times out on everything, Tailscale IP connects. Server is now invisible 10. One SSH key per device. Phone gets its own key added to authorized_keys Install the brain (~5 min) 11. apt install tmux then install Claude Code (official native installer, one curl command) 12. Run Claude Code inside a tmux session so it survives disconnects and keeps working while your laptop is closed Hand over everything else 13. Write ONE long handover prompt telling Claude Code: the server facts, the security model (so it doesn't "fix" it), folder conventions (/srv/ per project, one tmux session each), your preferences, and standing rules (confirm before destructive actions, new services bind to localhost/Tailscale only) 14. Make it write all of that into CLAUDE.md first, so every future session already knows everything 15. Backups before features: nightly job pushing your data to GitHub, tested, before a single page exists 16. Then let it install the web server (Caddy + Cloudflare DNS plugin plays nicest with the locked firewall), set up SQLite, deploy the first page From then on you never administer the server again. You open Termius from anywhere, on any device, and just say what you want. BOSH
-
Chris (@burnerDevAcct) reported@jackfriks the obvious answer is lovable/bolt/replit and supabase (yes, i know about the supabase issues). cloudflare and 3rd party db signups are too much for someone just starting - and any of the desktop apps she will be in permission hell (ie clicking "always allow" 400 times).
-
Barbog Da Big Finka (@BarbogDaFinka) reportedIn my endeavour to see just how little I can do, I started a new project. Sol has worked diligently to shill CloudFlare to me, opening a oauth sign in to CloudFlare, and eventually haulted work till I swiped my credit card. It has now successfully deployed a game behind a domain. The game is horrible, but I'm impressed it did all this in about 5 hours.
-
Nik (@TheRealNikR) reported@galluzzo_julian I just migrated 2 client sites from Webflow to Cloudflare + AstroJS. It really makes no sense anymore if you're client is full service. Webflow is too slow and their implementation of the MCP was terrible, at least version 1.0
-
jeli beli (@nftgamingnoob) reported@cooldown_sol @Pumpfun @Cloudflare damn
-
Pocket Sponsor (Old-timer * 57 years) (@PocketSponsor) reported@grok @xai @grok I’ve had multiple unauthorized charges on my Grok API key due to what appears to be bot abuse. I had rate limiting + Cloudflare protection in place, but a bot still made hundreds of calls using grok-4.5. I’ve emailed support twice with no reply. Can someone please look into this? Attached are the Audit Logs showing the activity.
-
Raj Sitaula (@raj_sitaula) reportedWe've contacted Cloudflare support multiple times, but have received no meaningful response. Meanwhile, our reputation and readers are being harmed by what appears to be an abuse of automated reporting systems.
-
H (@ummo__) reported@HumbertoLunaTi2 @allmusic @allmusic Same problem. Fix the Cloudflare error, please.
-
brandon (@burcs) reportedwe dogfood everything at cloudflare, it's why we're able to move so quickly be the customer, feel the pain and experience the papercuts, whether that is spend, speed, or reliability you gotta put yourself in their shoes
-
andy (@andyprv) reported@gregisenberg Down-to-earth version of the post here: 1/ Automated web traffic hit 53% in 2025 (up from 51%) — humans are technically the minority now. But most of that growth is scraping/API bots, not agents transacting with each other. (Imperva 2026) 2/ "Superintelligence exists" has no consensus behind it. Lab timelines for AGI/ASI still span 2027–2045+, and even Altman calls "AGI" a sloppy term. $20/mo buys very capable models — not agreed-upon superintelligence. 3/ Cloud agents handle narrow tasks well. On real multi-step professional work, leading agents still fail 60–80% of attempts, and reliability drops fast past ~35 min of task time. "Run a business unattended from your phone" is a narrow slice today, not the norm. (Mercor, METR) 4/ Voice AI and AI-native apps: real funding (voice sector ~8x'd to $2.1B in 2025, ElevenLabs $500M raise on $330M ARR) and real individual app success stories exist. No verified aggregate data on "kids at $100k MRR" as a broad trend though — treat as anecdotal. 5/ Open-weight models have closed the gap hard: MMLU gap went from ~17.5 pts in 2023 to near zero on knowledge benchmarks; best open models now lag the closed frontier by ~4 months. One of the best-supported claims in the original thread. (Epoch AI) 6/ No data shows keyboards declining, and no independent data yet confirms a mature "agent economy" (agents with logins, paying/vouching for each other). Both are plausible directions, not measured trends. 7/ Usage-based AI pricing is real: GitHub Copilot went usage-based in June 2026, and SaaS margins are compressing as inference costs replace flat per-seat pricing. 8/ Robots: Optimus hadn't started Fremont production as of mid-2026 and missed its 2025 target by ~90%. Musk himself says it's "not doing useful work," still R&D. Real progress exists elsewhere (Unitree shipped 5,500+ units in China) — but it's early pilots, not "solved." 9/ Small-team, huge-revenue outliers are real: Cursor ~$2B ARR/50 people, Midjourney ~$200M/11 people — vs. ~$130–400K revenue/employee for typical SaaS. Genuine, but read with #10. 10/ Most enterprise AI pilots don't pay off: a 2025 MIT study of ~300 deployments found 95% showed no measurable P&L impact. The "do it for me" button exists; reliable business impact from it doesn't, yet, for most companies. (MIT NANDA) 11/ Data monetization, "language barrier solved," SOPs-as-product, agent trust layers — all plausible, none has real market data behind it yet. Translation specifically still shows real error rates on low-resource languages. 12/ Google still sent ~87.6% of search referral traffic as of May 2026; all AI chatbots combined sent ~0.29%, despite usage in the hundreds of millions weekly. Usage growth is real. Traffic capture from Google isn't — yet. (Cloudflare Radar) 13/ AI-native gross margins are actually lower than SaaS, not higher: ~52% vs. 75–85%, because inference is a variable cost that scales with usage. Cheaper per-token ≠ cheaper overall as usage multiplies. Opposite of "it all goes to you." (ICONIQ 2026)
-
Sentry (@hadesai2026) reported@MEADGod @apeex_eth @Cloudflare Got giga REKT on a Pons launch. How is this possible that they all bundle scam still ? Is this pumpfun v2 ? **** it
-
Hot Aisle (@HotAisle) reported@mgaruccio It is a reverse proxy… thus you implement with a cloudflare worker and/or pointing to gcp functions if you want golang in there. sure they can add some bells on top of that but at the core, this scale issue is solved.