Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| New York City, NY | 3 |
| Los Angeles, CA | 1 |
| Paris, Île-de-France | 1 |
| Manchester, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Waffl3x ❤️🩹 🩹 👁🗨 (@Waffl3x) reported@LinusMixson I'm currently of the mind that it doesn't have to be anonymous as it isn't meant to contend with something like TOR. However 2 hosts operating in the walled garden shouldn't being able to correlate that a user on both of their platforms is the same person. There are some strategies I've heard brainstormed to mitigate non-anonymity but it isn't the problem I want to solve right now. (Not that it isn't important mind you.) And I'm 100% sure that hosts on the network should not be able to boot people out of the walled garden. I don't intend to give more power to large sites, more take the burden of moderation off small ones. Of course if a user is violating rules of the walled garden (sharing an identity with other people, running unannounced scrapers) that would be grounds for losing access. I wouldn't want to impose how moderation of a particular host must be done, if they want to ban for particular opinions that's their own (bad) choice. It can't be opinionated on things outside its 'jurisdiction' lest hosts and users won't have incentive to use it. Hosts should also be allowed to accept connections from outside the walled garden, provided they don't forward those connections into it arbitrarily, or perform arbitrary lookups on their behalf. That would defeat a lot of the utility. This is probably essential to obtain a userbase, it would fracture the web. Right now non-normies are forced to use platforms that normies are on. If the walled garden required hosts reject all connections from outside of it, it would just be immediately killed and non-normies would never have the opportunity to join. Hosts could still choose whether they support external connections or not, arbitrarily turning it on and off depending on what's happening. Sudden DDOS attack? Just turn off the unprivileged portal. Obviously Cloudflare already does a lot of this so there isn't a huge inventive. But it should be trivial from a technical perspective. Hosts that don't care to cater to normies and would rather sacrifice quantity for quality would likely opt to operate totally within the walled garden. Part of my goal is to bring communities that have slipped off the open web into their own smaller walled gardens, back into the open. Forums for example are a big example. Touching on non-anonymity again, part of my thoughts on it are that outside of using a VPN we are already effectively not anonymous. Governments can subpoena it in the snap of a finger. I'm hoping this design would still allow one to connect to the walled garden using a VPN, but they would still need a 'personalized' id which would need to be turned over. If they did everything right, all that would reveal about them is their VPN connection and the vouch chain for the identity. Speaking of that, I'm pretty strongly of the opinion the right mechanism for this is vouches. The reason is that if an individual vouches for too many bad actors, they can lose vouch privileges, and everyone they vouched for retroactively needs new vouches to access the garden. This would ripple down, and up, the chain. The principle here is that you can't just vouch for anyone because it reflects back on you. I intend for people to think about who they vouch for, whether they trust them to follow the rules or not. I initially played with this idea as a way of preventing cheating in online games. I'm sure some of the design reflects that. It should be obvious, while it isn't anonymous, it wouldn't require government ID to participate. Online games also made it clear that doesn't work anyway, in Korea elderly people just sell their ID to kids, they make a new account and start cheating again. It isn't infallible but it increases the cost of making sock puppet accounts greatly. That should ultimately be the goal, increase the cost of turnover. Long winded post, I'll probably do a real write up on it in the future that isn't all over the place and is a bit more concise. If you want to reach out to discuss it on a synchronous medium I would be interested
-
CapyToolkit (@CapyToolkit) reported@h_meow_meow @TeeDevh Actually these cause 2 separate issues. Crawler Hints with Cloudflare caching made thousands of unnecessary URLs to be submitted via IndexNow. Bot Fight mode was blocking legitimate Bingbot and OpenAI IPs (not detecting them as Verified).
-
Reina Cruz 🥼🧤🇨🇺 (@rea1ReinaCruz) reported@Cloudflare Please, fix human verification
-
SafeBrowz (@SafeBrowz) reported8/ We hit Cancel to see where it fell back to. whitelistportal[.]com/callback That domain is the attacker's. Registered 1 August 2026. Under 3 weeks old. Registrant redacted, St. Kitts & Nevis, sitting behind Cloudflare. Then we requested the root of it.
-
Former Child (@abdvlkadr) reported@santos__vito Why did you guys host on Vercel? Never do that lmaooo! Just set up a Cloudflare worker and host for free.
-
Welldone (@welldone_tech) reportedCloudflare shipped WriteGuard for MCP servers: agents can read data, write operations need an explicit gate. Unrestricted tool access is the actual production risk with agents - not that the model is wrong, but that a prompt injection or a hallucination reaches a database that never should have been writable in the first place. Read/write separation for agents isn't a Cloudflare feature. It's the same principle behind every gate we put in our own process - a senior approves the spec before code exists, a different model reviews it, an engineer deploys manually. The tool doesn't get more trust than the person watching it.
-
EMELEC emeleXista (@emelectv) reportedStopping the bad guys with Cloudflare: 1,745 malicious requests blocked or challenged in the last month #cloudflare
-
Aaron Makelky (@theaaron) reported@nickvasiles just point them at a private github repo or cloudflare artifact where your skills live installing them natively across different agents is a waste of time and they never stay synced to the system of record version
-
Grant Hermes (@GrantHermes) reportedMedian's domain was registered on August 10th using private Cloudflare servers. Its registrants' names are masked with a data replacement service. It's not registered in any state or federal database as an official entity. 2/
-
matt rothenberg (@mattrothenberg) reported@itsnoahd @Cloudflare Will fix! Send me a DM plz, wanna ask a few questions
-
Melek Turkoglu - Ekrem İmamoğlu’nu Serbest Bırakın (@AvukatMeleknur) reported@Dynadot 🚨 Active phishing & brand-spoofing domain reported to Case ID: ddcn:9Cr7A6QO7i7u7t:ddcn The site mimics exposes a broken/failed "INVALID" license seal, and targets users via @Cloudflare proxy (104.21.31.33). #Infosec #Phishing #OSINT
-
Phillip Shoemaker (@pbsIdentity) reportedIndia just ordered hundreds of Google Firebase accounts shut down after authorities found scammers using the platform to impersonate major banks. At least 57 Firebase-hosted websites and databases were targeted for takedown this month alone. Some mimicked banks. Others distributed malicious Android apps. Some were designed to steal financial information from phones. Here's what I find interesting. Firebase isn't some shady hosting company operating out of a basement. It's Google infrastructure. That's exactly why criminals want it. We've spent years teaching people to look for obvious signs of scams. Weird domain. Broken English. Sketchy hosting. Browser warning. No HTTPS. But increasingly the attacker doesn't need to build suspicious-looking infrastructure. They borrow legitimate infrastructure. Google. Microsoft. Cloudflare. GitHub. Dropbox. Whatever gives the attack credibility and reliability. Now imagine the average person inspecting the link. They recognize Google. The connection is encrypted. The page loads perfectly. The certificate is valid. Everything their brain has been trained to interpret as: SAFE may technically be true. Except the person controlling the page is a criminal. That's an important distinction. HTTPS proves your connection to the website is encrypted. It does not prove the person operating the website is honest. A Google URL proves Google is providing infrastructure. It doesn't necessarily prove Google created the content you're looking at. The little padlock was never a morality detector. We just accidentally trained an entire generation to treat it like one. India says scammers have increasingly shifted toward Firebase because its legitimate development tools and database functionality make it useful infrastructure for fraudulent sites and apps.
-
Jared James (@jaredjames_) reported@RichHickson @brieanna_jade @maeve_social Ahh, looks like DMARC never got published in Cloudflare. My bad. Good catch man. TY, I owe you.
-
TheDataBunny (Darth Bunny) (@thedatabunny) reportedWhat would you do if cloudflare and AWS was down for a week?
-
Seun (@seunoyebode) reportedFor many years, I couldn’t watch prime video on tv. Starlink solved it. Apparently the issue is the same issue that causes homepages of sites like vercel, cloudflare etc inaccessible directly when you’re using MTN or Airtel etc Now Starlink is stressing me out also. It just won’t play prime video movies