Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Paris, Île-de-France | 1 |
| New York City, NY | 1 |
| Manchester, England | 1 |
| Angers, Pays de la Loire | 1 |
| London, England | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Dr. Gonzo (@N3DrGonzo) reported@AnisDrawn PSN goes down more often than CloudFlare. And CloudFlare has an outage QUOTA. But yes, please tell me how an all digital ecosystem for a console is a good thing.
-
Name Groove (@Name__Groove) reported@SpaceshipStatus Site appears down to me - cloudflare errors
-
Polymarket Alpha (@Polymarketalpha) reported🚨 JUST IN: Bots now generate more web traffic than humans. According to Cloudflare, bots accounted for 57.5% of global web page requests in June 2026, while human traffic fell to 42.5%. This marks a historic turning point for the internet. AI crawlers, automated systems and intelligent agents are no longer a minor part of the web—they are becoming its dominant users. Cloudflare’s CEO had previously predicted that bot traffic would not surpass human traffic until 2027. Instead, the milestone arrived a year early. The internet is rapidly shifting from a network built primarily for humans to one increasingly accessed, indexed and operated by machines. Technological progress—or the beginning of a less human internet?
-
Art Chicken 🐓 (@ArtChicken4) reportedFrom Jovan Hutton Pulitzer's Telegram- - For tech nerds understanding the PCAP fraud: The mechanism works, and every input is public. Rosters of US election officials are published (state SoS directories, EAC, NASS, commercial lists). Take each office's email domain → MX lookup → resolve the mail host to an IP → geolocate it. You now hold a table of "jurisdiction → IP → city/lat/lng" covering every election jurisdiction in the country, built entirely from DNS, without ever sending a packet to an election office. That table would look authoritative and survive spot-checking — the IPs are real, the org names are real, the geography is real. It would also be probatively empty, because an MX record identifies who handles that office's email. It says nothing about vote systems. The signature of an MX-derived list would be hundreds of jurisdictions collapsing onto a handful of shared mail-provider IPs — Microsoft 365 (*.mail.protection.outlook.com), Google Workspace, Barracuda, Proofpoint — because that's who most county governments use. What your file actually shows I tested it. The target roster is a complete enumeration of election jurisdictions, and the counts are exact: State Rows Actual jurisdiction count Massachusetts 351 351 municipalities Connecticut 169 169 towns Texas 254 254 counties Georgia 159 159 counties Virginia 133 95 counties + 38 independent cities Kentucky 120 120 counties North Carolina 100 100 counties Iowa 99 99 counties One row per jurisdiction, zero duplicates in any state. Real network traffic doesn't distribute itself one-event-per-administrative-unit. This is a roster walk. But the IPs are coarser than your MX hypothesis. Eleven states collapse to a single IP for every jurisdiction: 490 Maine town clerks -> 13.32.25.126 (AWS CloudFront edge) 351 Massachusetts clerks -> 45.60.195.2 (Imperva/Incapsula WAF) 246 Vermont town clerks -> 45.60.45.214 (Imperva/Incapsula WAF) 237 New Hampshire clerks -> 199.192.7.129 169 Connecticut town clerks -> 199.107.32.42 160 Texas election admins -> 98.129.145.194 (Rackspace) Plus 104.17.x / 104.18.x (Cloudflare) across 189 more rows. Those aren't mail servers — they're CDN and WAF edge addresses, the public front door of a state's website. A CloudFront edge IP is shared by thousands of unrelated customers; it isn't "Maine's election system," and you can't route vote data to it, because it terminates HTTPS for public web content and nothing else. So the lookup behind this file was one resolution per state's public web presence, cloned across every jurisdiction in that state. An MX-per-office build would have been more sophisticated than what was actually done here. And 253 rows have TargetIP = literally * — a failed lookup, no address at all. Those rows still carry 70,448 flipped votes. Votes attributed to an intrusion against an IP that does not exist. Bottom line Your instinct is right about the class of technique: a public roster plus DNS resolution manufactures a nationally-complete, real-looking IP table with no access to anything. That's the general answer to "could this manufacture data" — yes, trivially, and it's undetectable if you only check whether the IPs are real. The detection method is the reverse question: not "is this IP real?" but "what does this IP actually serve?" Real intrusion data resolves to the specific host attacked. Manufactured data resolves to whatever the jurisdiction's public name happens to point at — a CDN, a WAF, a mail gateway, a hosting provider. That's what's here: 490 distinct Maine towns, all pointing at one Amazon CDN address.
-
Flavio Amiel (@fba) reportedYet some very pro SEOs here say llms don’t matter. It does matter specially for SaaS in the building space. The strategy is: LLMs recommend you because is free to enter and easy of plug. You might or not upgrade at some point. I’m sticking with resend and cloudflare because if this. And I know the moment I need to upgrade I won’t even flinch. SaaS of the world: fix and keep your .md’s and llms.txt updated.
-
Grigori Karapetyan (@GregKara6) reported@59thProfile first of all, i think that also went over your head, my whole premise is that i have exhausted my ego and accepted llms into every part of my workflow. if i had an ego id be the other side of the argument. don't confuse me calling an llm a tool for some type of strength you have over me, that's cute and hilarious. also i don't know what's wrong with you, but my memory of our interaction is completely different, i remember mentoring you, putting you on the right track, validating your work, telling you good job, and also praising you in the cloudflare post and calling your sandbox implementations better than theirs, do you not remember that? do you not remember me teaching you about propper kernel isolation? do you not remember me putting you on the right track when you were trying to hand bake sandboxing by hand? do you not remember me telling you that if you take that approach you are making a weaker sandbox because you can never handle all the edge cases yourself? do you not remember me telling you to use microVMs instead? to me that was a positive interaction. very concerning my friend.
-
Anjula Dwivedi (@HeyAnjula) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked.
-
Abdulkadir | Cybersecurity (@cyber_razz) reportedOn June 3 2026 Cloudflare CEO Matthew Prince announced that bot and agentic AI traffic had officially surpassed human generated web traffic for the first time in the internet's history. The split landed at 57.5% bot traffic versus 42.5% human traffic. Prince had originally predicted this crossover would happen by end of 2027. It arrived eighteen months early. His response was direct: "Welp, that happened faster than I predicted." The driver is not the old wave of scraper bots and search crawlers. The main culprit is agentic AI. Autonomous programs browsing the web on behalf of AI assistants. A single agent can visit thousands of pages to complete a task a person would finish in a handful of clicks. Agentic AI traffic grew 8,000% across 2025 alone. Now let’***** on the Dead Internet Theory context. The theory, which originated in fringe internet forums around 2021, proposed that most internet activity was already artificial. Fake engagement, bot generated content, astroturfed discussions, AI personas. The humans were the minority and did not know it. The conspiratorial version of that theory claimed it was coordinated and intentional. That part remains unverified and unlikely. But the core observation that the majority of internet traffic is non-human is now confirmed data from the largest internet infrastructure company on the planet. The internet was architected around human usability and attention. The entire world of digital advertising, publisher monetisation, and e-commerce sits on the assumption that users are human. That assumption is now statistically false. Every engagement metric, every analytics dashboard, every ad impression count is increasingly measuring machine activity and reporting it as human behaviour. The business models built on human attention are being quietly hollowed out by traffic that generates requests but never buys anything, never reads anything, and never remembers what it visited. The theory was wrong about the why. It was right about the what.
-
Janek Mann (@janekm) reported@doodlestein @yzhang390 But that's not really the issue... it's that e.g. Huggingface and Microsoft and Cloudflare and Fireworks can be easily stopped from hosting them with misguided regulation. Literally only harming US companies at the expense of Chinese ones, ultimately.
-
Prajwal Tomar (@PrajwalTomar_) reportedVibe coders are getting sued. People are shipping apps with real users and skipping the boring stuff that kills them. A 20+ year dev shared the pre-launch checklist every AI builder needs. I added what I learned after shipping 60+ apps at the agency. Don't skip this: 1. Protect yourself, not just your app. The moment you collect user data you're in legal territory (GDPR, CCPA). Have a privacy policy. Know where user data lives. 2. Row Level Security. Without RLS, anyone can open DevTools and read your entire database. Supabase → Auth → Policies. Zero policies means your app is naked. 5 min to fix. 3. Test the failure path, not just the happy path. Wrong password 5x. Reset for an email that doesn't exist. Verification link clicked twice. Signup with an existing email. Catches 80% of auth bugs. 4. Security baseline in 2 min. Prompt your AI: "Review my app as a security specialist and make sure I have strong security headers and a solid baseline security posture." 5. OWASP. Prompt: "Review my app against OWASP standards and highlight vulnerabilities." This is where SQL injection, XSS and auth bugs actually get caught. 6. Client-side validation is UX, not security. Attackers disable JS and hit your API directly. Validate again on the server. Every time. 7. AI code leaks data in 3 spots: .env values in the frontend, API responses returning too much, secrets in logs. Prompt: "Check my app for credential or sensitive data leaks in frontend or API routes." 8. API keys in the frontend means game over. If it's in the browser, assume it's already taken. Move it server-side or proxy it. 9. Rate limits before someone burns your API bill. Cap every endpoint hitting a paid API. I've watched a Supabase bill jump from $20 to $200 in a day. 10. CAPTCHA on public forms (Cloudflare Turnstile is free) plus CORS locked to your domain. 10 min, kills bot floods. 11. Error messages that don't leak. "User not found", not "SELECT * FROM users failed". Log full errors server-side, show users generic messages. Build fast. Just don't ship naked. (full breakdown in my article below)
-
The Godfather (@TheGodfath13541) reported$DOT just keeps ******* cooking bro. Usage is up + 100% of revenue of revenue going back into the towards $DOT token/buybacks (~11% total supply burned already). Bullish AF + they are targeting a 100B+ TAM (forward-looking), so ARR numbers/users (703 users today) will grow steadily imho. Dot is betting it becomes the Cloudflare/AWS layer for private AI inference.Building the same early rails that scaled other s-tier plays I hold, such as $reppo, $vvv, and $pod. These are the Gold Standard for solid tech product + tying value back into the token. Been in crypto since 2019, anon. Assymetric **** going on here if you ask me. -Godfather
-
chrißy (@chribdotnet) reportedi need to set up cloudflare today and honestly cloudflare scares ******** out of me if i could make my own cloudflare i surely would but i just learned about /POST last night all this **** is easier than i expected ngl but still hard
-
Konstantinos (@kostasbotonakis) reportedCloudflare support: Health checks, checking a static page on Cloudflare Pages show plenty of outages. It’s been now 2 weeks
-
VictualBro (@Victual_Bro) reportedYour daily reminder that @Cloudflare is a wart on the *** of the internet. Not bad enough I have to deal with it here daily, but now it's blocked my email server. Yaayyyyy.
-
Ray 🇺🇦🏳️🌈 (@uasneppy) reportedI’ll try to fix snepclub twitter embedded later today, sorry :( I didn’t know about the new updates and me having to have a burner account, plus deploying it on Cloudflare 💀