Cloudflare Outage Map
The map below depicts the most recent cities worldwide where Cloudflare users have reported problems and outages. If you are having an issue with Cloudflare, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
Cloudflare users affected:
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Tlajomulco de Zúñiga, JAL | 1 |
| Asnières-sur-Seine, Île-de-France | 1 |
| New York City, NY | 3 |
| Township of Evan, KS | 1 |
| Ahmedabad, GJ | 1 |
| Le Puy-en-Velay, Auvergne-Rhône-Alpes | 1 |
| Ann Arbor, MI | 1 |
| Palermo, Sicily | 1 |
| Los Angeles, CA | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
Michael Bruno (@brubarian) reported@RockyCapital18 @TMTLongShort Yes - but it's more of a framework because some rx/diligence are on the private side. But big blue arrow: 1. What are the top three pieces of information that I want to have? 2. What role/function would use this data to solve their own problem? e.g., A DoW analyst wants to know where to buy widgets for a Humvee; how would he try to find the answer? Or a gas station owner wants to know how many Poland Spring bottles to order based on expected highway traffic because of the Sturgis motorcycle rally. 3. Which US institutions/think tanks/policy/others have the raw data? (too many to list) 4. Download CSVs, databases, etc. to desktop to isolate it, Claude from hallucinating or pulling information from the internet. (You may have to get a cloudflare/suprabase/*** to help facilitate accelerated use.) 5. Instruct Claude to clean the data sets (this used to be what data scientists spent most of their time on; NaN, void answers, separating street addresses from state, etc.) 6. In clear, concise, simple language, ask Claude to take XYZ categories of data and produce a snapshot to serve a "product manager at company XYZ" or a "credit risk manager at Bank ABC", etc. 7. Adjust and iterate. Force Claude to produce "Tufte" data visualizations. If Claude is left to run linear/logistic regressions, it becomes a science project instead of a problem-solving or illuminating exercise. 8. Force Claude to explore. e.g., take an analogy, "You are a surgeon; this data set is akin to human nervous system, if you were performing surgery, which node, if removed would destroy the utility of the system"? Random questions like this. Analogically map it in unique ways. Claude RL underbelly does nicely here. And as a guiding principle, I'd suggest focusing on being creative. The best definition I've seen is from Bruner: "Creativity is a way of figuring out what you already know in order to go beyond what you currently think."
-
Anthony Lambert (@AnthonyTBM) reported@jb_ma @sb_chadi Yes, but I've never had CloudFlare request a terminal command sequence. I think most people will be immediately on guard if that occurred after clicking their human status?
-
Selenka (@SelenkaOnChain) reportedNetnet Capital team is flexing metrics and talking about successful launch of Subway Runner... Meanwhile, 2 vibecoders literally drained their entire mechanic and became the #1 and #2 top holders. Here is the breakdown directly from one of the guys who farmed them: 🧵👇 "First decent cook of the bull run (if we’re even in one). Spent the last few months trying to get good at on-chain analytics, so hadn't been actively cooking. Two nights ago, I'm watching the feed and notice everyone sending $10 clips to this CA: 0x8154e35166f21305adac82f95b54de8acd44d23a. Instantly smelled pure degen activity. Hit up the group chat, did some digging - turns out it’s a Subway Surfers / Chrome dino style runner game by NetNet. Their shitcoin was sitting at a $90M cap at the time, so I figured if their token is holding that kind of valuation, there’s definitely meat on the bone. Normally, their games are pure casino trash: deposit cash, pray to RNGesus, or get rekt. But why not test it? Played a run manually and noticed that at the end of each game there was a draw. Checked their TG and reverse-engineered the contract - turns out there’s an N% chance to win an NFT from their collection. Their previous official collection had crazy volume and peaked hard, so my degen senses started tingling: this was a hidden gem. Literally 15 minutes later, they pause the game. Perfect timing - gave us room to prep. By that point, I had already captured the WSS traffic and requests. Their game logic was using a basic commit-reveal scheme: courseCommit = keccak256(serverSecret) seed = keccak256(serverSecret ++ playerSalt ++ runId) Meaning: right at game start, the server literally sent us the secret, allowing us to compute the seed and reconstruct the entire track in advance. The game loop: 3 lanes, 30 coins, 3600 ticks to finish (60 seconds). You dodge obstacles while longing/shorting NVDA. 3 hits = you lose the full $10. Complete a flawless run = you collect all coins to refund your stake and it only burns ~$0.20 in fees, giving you an almost free roll at the NFT lottery. In the era of AI and vibecoding, this was child's play. My boy XXX and I started spinning up bots in parallel. Ended up deploying his script since he coded it faster. We simulated runs, got a 100% win rate, set up a websocket listener for when the contract unpauses, and went to bed. Woke up at 6 AM, and literally 30 seconds later the game goes live. We spun up the bots - 5 minutes in, we already bagged our first NFT. Then came the scaling phase. At first, the team didn't give a single **** - no Cloudflare, no rate limiting, not even a basic 429. We ran 10 wallets simultaneously. After a few hours, they finally threw in a primitive 429, and that was it. No bot protection, no captcha, nothing. They didn’t even enforce single-session checks per wallet, so we were running multiple concurrent instances on the exact same address (literally impossible to do manually). The bots printed flawlessly. At one point, our load was crashing live games for actual manual players, forcing the team to repeatedly pause the game to fix lag. Every time they brought it back up, we resumed blasting. Total mint size was 1,060 NFTs. We scooped over 20% of the entire supply. Then came the funny part: the collection had zero secondary volume. Time for a little social engineering. We hopped into their TG playing dumb, gently nudging the admins: 'Hey guys, might want to tweet that the game is live and apply for OpenSea verification!' The final tally: * Total capital spent on fees/burns: ~$1,700 * Total NFTs pulled: ~50–60 pieces (friends got a similar bag) * PnL: Dumped most of the floor tier into bids today at $200–$300 a pop, still holding some. Nothing crazy for a real bull run, but an easy 5-figure profit for a couple of hours of vibecoding."
-
Cassiel (@Cassiel1137) reported@SportingNest @Cloudflare Quite spectacularly a scam. Luckily anyone who might fall for it (cough... everyone has their off days fella... cough) wouldn't have the first clue how to do any of that ****.
-
Guillermo Zaandam 🇨🇦🇳🇱 (@besodemieterd) reported@Cloudflare Your CSP rules and WAF rules aren't working again and again. Please fix this
-
Witch Cult Translations (@WCTranslations) reportedWe're aware our site is experiencing increased load times again. This is due to increased traffic following the episode and issues with our Cloudflare integration. Unfortunately, we can't do much right now to improve load times, so please be patient and try not to spam refresh.
-
Brendan Ryan (@BrendanRyanM) reported@mntruell @petergyang @bot Also having an issue getting past bot blockers, e.g. cloudflare prompts to press a button and prove you’re human. Even pressing the button manually via virtual machine does not clear the gate
-
volkanolmez (@volkanolmez) reported@xDestin0 That's almost always a local proxy or antivirus doing SSL inspection — the cert itself is valid (Google Trust Services via Cloudflare). Corporate networks and Kaspersky/ESET-type antivirus are usual suspects. Any chance you're on a work network? 🙏
-
VaultCord (@VaultCord) reported@imdevPU23 @acolombiadev @Cloudflare Website is hella slow.
-
Dr. Internets (@Dr_Internets) reported@spacebruce @alynokioku Hello, I am Albanian cloudflare. Due to poor technology, I need you to paste this totally real command into your admin command prompt. Very real, trust.
-
lasan (@las_nish) reportedComparisons of Free Trial Abuse Prevention Services If you're running a SaaS with a free trial or focusing on PLG, authentication and abuse prevention are not the same problem. - WorkOS: If you're already using WorkOS, WorkOS Radar is probably the first thing I'd look at. For a WorkOS stack, WorkOS AuthKit + Radar makes the most sense. You don't need to bolt another authentication system onto your app just to get abuse signals. - Auth0, Supabase Auth, Better Auth: These are primarily identity/authentication platforms. Integrating only these can't prevent free trial abuse. - Custom: Like the previous options, you need a custom way to prevent free trial abuse. Most free trial abuse methods involve disposable emails, Google dot variations, Google/Gmail domain variations, and plus addressing. That's why even when you block bots via Cloudflare Turnstile or CAPTCHA, you can still get these abusers. The industry standards: - Block free trial abuse using lists hosted on GitHub: This is a pain in the ***. If you don't want to pay money, you can use a service that offers a generous free tier. - WorkOS Radar: This is mainly used at the enterprise level. They focus more on WorkOS-related integrations rather than integrations with other providers. - ZeroBounce, NeverBounce, MillionVerifier, DeBounce: These are mainly used to clean/validate emails. There are 100s of alternatives, and most are similar with minor differences. They all have disposable email checking APIs. - UserCheck: This is also an email validation API, but they focus on blocking fake email addresses. It's better than a basic email verification API. - Autheona: This is in the same category as WorkOS Radar and UserCheck, but with more features. It also focuses on fake user detection and is growing with a real user base. Now, pricing: - WorkOS Radar: First 1,000 checks free, then $100 per 50 checks. No application-specific logic changes. Easy to integrate and manage. - ZeroBounce: 100 free validations in the free tier, then pay-as-you-go, starting at 2,000 for $39, and so on. - NeverBounce: No free trial or use case, $8 per 1,000 checks. - UserCheck: 1,000 API requests per month in the free plan. The rule-based engine is not included in the free plan, and you can get up to 1 request per second. - Autheona: 3,000 checks per month, with the rule-based policy engine included. Standard API request rate limitations apply, similar to paid plans. Now, use cases: - WorkOS Radar: Block disposable emails, plus addressing, and Google dot variations. - ZeroBounce, NeverBounce, etc.: Block disposable emails. - UserCheck: Block disposable emails, plus addressing, and Google dot variations; detect public emails; email suggestions; syntax validation; role detection. - Autheona: Everything included in UserCheck, plus business/free/government email identification, deliverability checks, fraud patterns, punycode and mixed-script checks, VPN detection, and bot detection (not necessary if you already use CAPTCHA, Cloudflare, etc.). Final decision from me: - Use WorkOS Radar if you're already in the WorkOS ecosystem. It's harder to integrate with other auth providers. - Use ZeroBounce-like APIs if you need basic disposable email checks. They're not as good if you need a better free tier. - Use UserCheck if you only need email-related validation and want to stay within the free plan. - Use Autheona if you need the most generous free tier available with a custom policy engine. All services take a maximum of a few hours to integrate and test. Both UserCheck and Autheona have a similar approach: integrate once and never touch the code again.
-
manny shaw (@MannyShaw) reported@0xAdesola 1.1.1.1 does not block malware or phishing. For that, use 1.1.1.2. DNS generally cannot unblock geographically restricted streaming services. That normally requires an authorised VPN or Smart DNS service. It cannot increase your broadband speed. It may make the beginning of website loading slightly quicker if your ISP’s DNS is slow. AdGuard DNS blocks many domain-based advertisements, but not every advertisement. It usually cannot reliably block YouTube, Instagram or advertisements served from the same domain as the content. Parental DNS is useful but not foolproof. VPNs, encrypted DNS, mobile data and some apps can bypass router-level filtering. How to change DNS on your router While connected to your home Wi-Fi, open a browser. Enter one of these common router addresses: 192.168.1.1 192.168.0.1 192.168.29.1 192.168.100.1 The correct address is often printed underneath the router as Router IP, Gateway or Web GUI. Sign in using the router’s administrator username and password. This is not necessarily your Wi-Fi password. Check the router label or your ISP’s documentation. Before changing anything, take a photograph or screenshot of the existing settings. Look for a menu called: Internet or WAN Network DHCP Server LAN Settings DNS Settings Disable Automatic DNS, Obtain DNS automatically, or DNS from ISP. Enter your chosen pair. For general family protection, I suggest: Primary DNS: 1.1.1.3 Secondary DNS: 1.0.0.3 For advertisement blocking instead: Primary DNS: 94.140.14.14 Secondary DNS: 94.140.15.15 Do not mix servers from different providers; otherwise filtering may become inconsistent. Tap Save/Apply and restart the router. Disconnect and reconnect your devices to Wi-Fi, or restart them. Cloudflare confirms that router-level configuration normally applies the DNS setting across connected devices.
-
bored knees (@boredknees) reported@punekarnews Fix your cloudflare settings. The site blocks normal users too.
-
Krishna Singh (@krishnasinghdev) reported@tapasadhikary @Namecheap I never liked namecheap / godaddy, don't know why people choose it over simple providers like cloudflare where they charge same amount for 1 or 10 years
-
Declan | Rust Developer (@buildWithDeclan) reported@acolombiadev @Cloudflare Thats why i am loyal to them. They provided services when i was poor. All my platforms are in cloudflare