Cloudflare status: hosting issues and outage reports
Problems detected
Users are reporting problems related to: cloud services, hosting and domains.
Cloudflare is a company that provides DDoS mitigation, content delivery network (CDN) services, security and distributed DNS services. Cloudflare's services sit between the visitor and the Cloudflare user's hosting provider, acting as a reverse proxy for websites.
Problems in the last 24 hours
The graph below depicts the number of Cloudflare reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
August 25: Problems at Cloudflare
Cloudflare is having issues since 03:20 PM AEST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Cloudflare users through our website.
- Cloud Services (46%)
- Hosting (23%)
- Domains (15%)
- E-mail (8%)
- Web Tools (8%)
Live Outage Map
The most recent Cloudflare outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Hosting | 4 days ago |
|
|
Cloud Services | 23 days ago |
|
|
Cloud Services | 24 days ago |
|
|
Cloud Services | 1 month ago |
|
|
Hosting | 1 month ago |
|
|
Domains | 2 months ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Cloudflare Issues Reports
Latest outage, problems and issue reports in social media:
-
ericosiu (@ericosiu) reportedCloudflare scanned roughly 200,000 high-traffic domains for agent readiness. Only 3.9% passed its Markdown content-negotiation check. Emerging capability-discovery standards were nearly absent. Cloudflare also says fewer than half of the HTML requests it observes now come from humans. That machine traffic includes crawlers, monitoring systems, automation, malicious bots, and AI systems, so it would be sloppy to call all of it agent traffic. The direction still matters. More research, comparison, and purchasing will happen through software acting for a person. That software needs a very different buyer path than the one most companies have built. I call this Agent-Led Growth. Agent-Led Growth means making your company easy for an agent to discover, understand, call, buy from within rules, and verify. Here is what each part looks like in practice. 1. Make the company discoverable Publish one canonical description of the product, who it serves, what job it completes, what it costs, and where the source documentation lives. Keep those facts consistent across your website, documentation, marketplaces, integration directories, and public profiles. If five pages give five different answers, the agent has to guess which one is current. Machine-readable Markdown can reduce that friction. Cloudflare now tests for it inside its Agent Readiness diagnostics. A polished homepage designed for humans can still be a mess for software trying to extract exact product facts. 2. Make the offer understandable An outside agent should be able to answer seven questions without hallucinating: What does the product do? Who is it for? What inputs does it need? What output does it return? What does it cost? What permissions does it require? What evidence supports the claims? This is where clear use cases, current pricing, technical documentation, limitations, and primary proof become part of distribution. 3. Make one valuable job callable Reading about a product is different from completing work with it. Give the agent one bounded action through an API, MCP tool, or another structured interface. For an SEO product, that job might be: analyze this domain and return three sourced opportunities for review. The tool should define its inputs, output schema, authentication, errors, retries, and stop conditions. The agent should not have to imitate a person clicking through six browser screens every time it needs the same result. MCP is becoming useful here because it gives models a shared way to access tools and data. The MCP Apps extension can also render forms, dashboards, and visualizations inside supported clients. Support still varies, so publishing an MCP server does not automatically create distribution or reliable usage. 4. Let the agent buy within rules Two emerging protocols show where agent commerce is heading. Google launched the Universal Commerce Protocol, co-developed with Shopify, Etsy, Wayfair, Target, Walmart, and others. UCP coordinates parts of the shopping journey, including discovery, checkout, and post-purchase support. Coinbase introduced x402, which embeds stablecoin payment instructions into HTTP so software can pay for APIs or digital resources programmatically. They solve different pieces of the transaction. The operating controls still have to come from the business. Give the agent an approved vendor list, spending limit, expiry, purpose, approval threshold, and stop rule. A $49 purchase from an approved vendor might proceed automatically. A $4,900 purchase from a new vendor should require human approval. Unknown terms or an unrestricted wallet should stop the transaction. 5. Return a receipt a human can defend A server response that says 200 OK tells you almost nothing about whether the business job succeeded. A useful agent receipt should include the request ID, timestamp, vendor identity, inputs, source links, approved amount, actual amount, permission, output, errors, retry state, and measurable result. That receipt matters for trust. It also gives the agent evidence it can bring back to the human who delegated the work. Listings, successful calls, integrations, citations, and clean receipts may eventually influence which products agents select and recommend. No universal ranking formula has been established, so I would treat those as signals to test rather than guaranteed ranking factors. The fastest way to start is an outside-agent audit. Pick one product and one valuable buyer job. Ask an outside agent to: Find the correct product. Explain the offer, pricing, proof, and limitations. Complete one bounded action. Attempt a purchase inside preset rules. Return an auditable receipt. Score each step as blocked, possible with manual rescue, or clear and verifiable. The first failed step becomes the next Agent-Led Growth project for marketing, product, and engineering. If an outside agent tried to buy from your company today, where would it get stuck?
-
james (@f82james) reported@opencode @Cloudflare nah bruh **** still doesnt work
-
oh 🔴 (@ohdeez144) reported@Gamingtronium Cloudflare devs trying to make their service not ****
-
Genesis Rhapsodos (@GacktRhapsodos) reported@BrodieOnLinux Data breaches are almost always 3rd party related and across multiple platforms. Locally stored physically written down passwords do not save you from data breaches from 3rd party partners Like when AWS/Cloudflare go down.
-
⚡BeefButterBTC⚡ AKA - Big Pleb (@BeefButterBTC) reported@BitcoinFinally @fold_app Try again, looks like Cloudflare issue
-
Mike in’ Software (@mikeinsoftware) reported@soham_nayak04 @marclou How can an analytics service break after 470 users? And why note have a local one on your server + use cloudflare webstats
-
ABG (@_abgweb3_) reported9/ If this scales, the subscription model we know today could change. Instead of paying $20 every month, users could have agents pay for exactly how much data or service they actually consume. The AI economy could move from subscriptions to pay per use. But the market is still very early. Cloudflare is still developing its products. Mastercard is in early access. MoonPay hasnt disclosed usage figures. And part of Coinbase’s volume may come from testing and incentives. There is no mass adoption yet.
-
Ud (@Ud_84) reportedCloudflare blocks or challenges bad requests from hitting my website. #cloudflare
-
donmagicjuan (@donmagicjuan) reported@technolochap @sickdotdev A lot of high-level enterprise work vibe codes as well, and we only notice when AWS/Google Cloud/Cloudflare goes down for a few hours. These cheeky lot only pick on the presentations that don't speed run their own manual UX testing.
-
Kenton Varda (@KentonVarda) reported@m0hilll @thdxr @arnvbnsl Reusing isolates keeps costs down and lets us bill for CPU time only instead of total request duration. Vercel built Fluid Compute to accomplish the same thing -- explicitly getting away from Lambda's inefficient one-instance-per-request model. That said, we (Cloudflare) have some cool (though long-term) stuff in the works to make it possible for every request to have its own isolate, without blowing up memory usage... deep V8 changes involved.
-
aginaut (@aginaut) reportedAWS AgentCore Payments: The Rails Are Opening. The Junction Is Not Settled. On 18 August, AWS made an odd move for a platform widening its role in agent payments: it declined to choose a payment rail. AgentCore Payments moved from preview to general availability with MPP beside x402 and, according to AWS, one developer integration across both. AWS imposes no extra charge for its Payments APIs. Wallet providers still charge; Gateway, Policy and CloudWatch still meter usage. If AWS were competing primarily for the rail, supporting two rivals without an API fee would be a peculiar opening move. The mismatch deepens at the other side of the transaction: AWS WAF can already challenge an AI agent for an x402 payment through Coinbase before admitting it to content. MPP and Stripe support were still described as forthcoming. For an allocator, protocol adoption is therefore the wrong scoreboard. If the rail is becoming plural and inexpensive to integrate through AWS, which part of the transaction is AWS trying to make indispensable? The missing fee makes the bundle the live hypothesis AWS is not alone in making payment rails interchangeable. Cloudflare supports x402 and MPP. Visa and Mastercard are building protocol-agnostic or multi-rail agent-payment capabilities. The Linux Foundation’s x402 Foundation brings cloud, payment and technology companies into the same standards effort. This demonstrates protocol plurality and standards activity—not adoption or power. That may shift the source of scarcity. As payment syntax becomes easier to support, a potentially scarcer task is coordinating the records around it: identity, authority, counterparty, budget, policy, execution and evidence. AgentCore already places several of those functions near one another. Payments now sits beside identity, Gateway discovery, bounded sessions, Policy pathways and observability. WAF separately approaches seller admission. These are not one integrated marketplace, and AWS does not control the entire transaction. They do, however, give AWS an early option on the environment in which agentic economic action is governed. The Platform Envelopment hypothesis Thomas Eisenmann, Geoffrey Parker and Marshall Van Alstyne call this platform envelopment: a platform enters an adjacent market by bundling a new function that shares users and technical components with its existing services. The bundle changes the contest. A standalone payment service must now compete with payments embedded where agents are identified, authorised, routed and observed. That is the strategic possibility in AgentCore: protocol-agnostic support could let AWS coordinate several payment systems inside one governed environment while making its surrounding services more useful together. Yet bundling alone is not platform power. If users can bypass AgentCore, carry identity and evidence elsewhere, or multi-home without friction, this is integration—not durable envelopment. Follow the right, not just the payment An autonomous transaction rarely specifies every relevant contingency in advance. It still needs answers to ordinary institutional questions: Who approved the spend? Was the recipient valid? What was delivered? Which record proves it? Who can revoke authority or remedy failure? This is why payment begins to cluster with identity, policy, audit, reputation and recourse. The payment message moves value. The surrounding records make the action acceptable to the next institution. One diagnostic keeps the layers separate: RAIL → JUNCTION → RIGHT Rail: What became interchangeable? Junction: Which operating records must still be reconciled? Right: Whose record will the next institution accept? Today, those rights remain divided. The enterprise principal funds, mandates and revokes. Application code must validate the recipient. AgentCore can constrain amount and time, route through supported protocols and preserve operational evidence. Wallet providers sign. Merchants price and deliver. Financial networks and payment providers retain settlement, fraud and dispute functions. A payment proof therefore establishes neither satisfactory delivery nor a universal right to refund or remedy. Portable-record systems form a counter-architecture. AP2 under FIDO stewardship and W3C Verifiable Credentials target portable mandates or identity evidence. On Ethereum, draft ERC-8004 and ERC-8183—with Virtuals ACP implementing the latter direction—target identity, reputation, validation and escrow. This is documented standards and implementation activity, not evidence of broad adoption or transferred power. Open rails cut both ways Modularity is the counterforce to envelopment. Open interfaces can commoditise the rails beneath AWS, increasing the value of AgentCore. They can also commoditise AgentCore if customers can move their identities, mandates, policies, wallets, reputation and audit history intact. The practical test is not whether an interface is called open. It is whether substitution works: Can an enterprise multi-home cheaply? Can another cloud or network recognise the same mandate? Who controls schema changes, revocation and the evidence required after failure? Until those answers settle, AWS holds a candidate position—not the junction itself. Three futures from the same move The current evidence supports an option space rather than one forecast. 1. Managed-junction consolidation. If AgentCore Payments drives attachment to AWS identity, policy, discovery and observability—and operating state becomes expensive to move—value could concentrate around managed control planes and their security, compliance and monitoring complements. 2. Federated recognition. If portable mandates, credentials, reputation and escrow records gain acceptance across clouds, wallets and marketplaces, value could move towards cross-platform identity, verification, translation and assurance rather than one platform owner. 3. Institutional retention. If enterprise procurement and treasury continue to hold spending authority while Visa, Mastercard, Stripe and other financial actors retain acceptance, fraud, settlement and remedy, cloud payments would remain useful orchestration while the authoritative economic record stayed with enterprise and financial institutions. These futures can coexist. Low-value machine purchases may favour managed automation, while consequential enterprise actions remain institutionally governed. The receipts that decide the path Watch four things: Attachment: Does Payments increase use or retention across AgentCore? Recognition: Which counterparties accept the session, policy and audit records produced or held around AgentCore? Portability: Can those records move across clouds, wallets, networks and marketplaces without material loss? Economics and remedy: Where do switching costs, adjacent revenue, disputes and paid-but-no-service outcomes accumulate? Protocol adoption alone is not enough to underwrite power. At minimum, Payments must produce attachment plus either non-portable operating state or measurable adjacent economics. The allocator’s question is not which payment protocol wins. It is whose record the next institution accepts, whether that record can leave—and which future becomes investable as those answers emerge. AWS has taken an option on power. Power has not yet transferred. Notes : Platform Envelopment follows Eisenmann, Parker and Van Alstyne. The supporting logic draws on transaction-cost and incomplete-contract research associated with Coase, Williamson and the Grossman–Hart–Moore tradition; the countercase draws on Baldwin and Clark’s modularity work and Ghazawneh and Henfridsson’s boundary-resource research. RAIL → JUNCTION → RIGHT and its application here are Aginaut syntheses. Product and standards claims remain bounded by the first-party materials available on 22 August 2026.
-
Net-Updates by StabilityTest (@stabilitystatus) reportedCloudflare Service Disruption We have identified the cause of this issue and are implementing a fix. Status: Identified Impact: Minor Updated: 10:24 PM GMT+0000 Service status tracked by @stabilitytestio
-
ReinaCruz.☭⃠ (@realReynaCruz) reported@Cloudflare Please, fix human verification
-
CodeDR.AI (@codedrai) reported@xhluca Well done @xhluca - not a bad grade! All seven diagnostics ran in parallel and all seven reports are written to .code-dr/reports/. The repo scores well overall — two A's and five B's — and the striking thing is that nearly every B is caused by the same root cause rather than by messy code. ReportFileGrade Structure 01-structure.md A Security 02-security.md B Test health 03-testing.md B Deploy readiness 04-deployment.md B Code quality 05-quality.md B Performance 06-performance.md B Architecture diagrams 07-architecture-diagram.md A The one theme that explains most of the findings: there is no CI at all. There's no .github/ directory anywhere. Five of the six diagnostic agents independently flagged this, and it's why other problems have gone unnoticed — Ruff is configured but never runs, 325 pytest cases exist but nothing gates a push, 15 high-severity npm advisories have accumulated in the website toolchain, and all 14 released PyPI tags were published by hand with no provenance or attestation. The quality tooling and the tests are already written; nothing is wired to them. The core Python CLI is genuinely well-built. Zero runtime dependencies (stdlib only), an acyclic reader → portable timeline → writer pipeline, fully parameterized SQL, 0600/0700 file modes with O_NOFOLLOW and symlink rejection, atomic no-clobber writes, timeouts on every subprocess and SQLite call, real forward schema migrations, zero TODO markers across 157 commits, and 100% parameter type annotations. No secrets appear in the working tree or in any commit. Three concrete issues worth acting on beyond CI: src/.../catalog.py is a 2,449-line god module, and its _scan_file() function has a cyclomatic complexity of 98 across 244 lines with 10 levels of nesting. Its eight per-format scanners duplicate layout knowledge the format adapters already own, so adding a ninth harness means edits in two places that can silently disagree. About 30.5 MB of the 31.8 MB in website/public is referenced by nothing — demo GIFs and MP4s duplicated byte-for-byte from docs/assets, which is where the README actually serves them. The tracked repo is 66.6 MB and roughly 97% of that is this duplicated media. The suite can't be collected on Windows at all: tests/test_cursor_native.py:8 does a bare import fcntl, which aborts the entire run instead of skipping one module. On this host 194 tests passed and 121 failed, all for platform reasons (temp-file locks, POSIX mode assertions, path separators) rather than logic defects. A one-line pytest.importorskip fixes the abort. Two caveats on the numbers. Coverage came in at 71.5% statements, but the project ships no coverage tooling, so that was measured with a scratch sys.monitoring probe and is a hard lower bound — the 121 platform failures never reached their assertions, so real coverage on Linux is higher. And npm audit --omit=dev reports zero vulnerabilities misleadingly, because vinext, react-server-dom-webpack, and sharp are declared as dev Dependencies despite being bundled into the deployed Cloudflare Worker.
-
Javed (@jshai0) reported@itskalenai Ok. May need to check if all the network requests are secured instead of Also you can check backend logs like Cloudflare or aws whatever being used if there is any geo blocking firewall.
-
Stan Sadokov | NodeMaven (@StanSadokov) reportedcloudflare put a price on honest crawling, august 21 to keep crawling sites that said no to training, a crawler now has to disclose, url by url, which pages were made available for training that is a contract problem, and code does not fix it could you publish that list for your crawler?
-
Net-Updates by StabilityTest (@stabilitystatus) reportedCloudflare Service Disruption Cloudflare is investigating an issue which may result in latency increases for a subset of requests. Status: Investigating Impact: Minor Updated: 8:38 PM GMT+0000 Service status tracked by @stabilitytestio
-
Twilight Surfers (@TwilightSurfers) reported@liorsela Grok bot on lboarded about 10 domains I own to Cloudflare and set up email to one catch all email. Simultaneously another Grok bot set up smtp plugins on some leftover wp sites and configured contact forms and sent tests. Found errors in the number of processes online and the actual number of processes and argued about it the the CEO bot who's a real hard a**. He set up a copywriting bot to fix the discrepancy. The set up is legit and Grok just works.
-
Divine Arc (@divinexyz777) reported@MotionOnHype Fix your cloudflare issue on your web dude
-
dvnox201 (@dvnox201) reported@adityadotdev why not have cloudflare? that would stop almost all of the issues you're facing
-
Ichigo | helius.dev (@0xIchigo) reported@heymike777 @Helius That's true for any API key in the industry if you only domain-lock Sorry, let me be more explicit (I'll update the docs accordingly to get rid of any confusion): - By default, WaaS uses your Secure RPC URL (no API key rides on RPC calls at all) - You can pass in your API key for faster prototyping - You have the option to move your key server-side (via our one-click Cloudflare proxy, or by importing the route handler exposed by the wallet kit), which you can then lock down to specific IPs/CIDRs Note that the API keys are only RPC credentials and not the same as wallet keys; they can't sign, move funds, or access any user's embedded wallet. That is gated to the user's own passkey/session and isolated in secure enclaves
-
behrooz evans (@BehEvans) reported@robinebers @Cloudflare Less crazier thing is you can't point your domain at a bucket or s service if dns is not in cloudflare
-
Rishabh (@crashedrishabh) reportedDay 21 Shipped the full download backend. Users never see a GitHub link. Everything on free tiers. Serving a 108 MB installer without egress costs or serverless timeouts. That's the problem. Stack: • Next.js 14 + Bun + TypeScript • Neon Postgres + Prisma 7 • Cloudflare R2 (free egress) + Workers (edge delivery) • GitHub Releases API as source of truth Flow: sync script polls releases → upserts metadata into Postgres → installer streams from R2 via Worker → download starts directly. No 302 to GitHub. Why not proxy through Next.js? 108 MB through a serverless function = timeout risk + bandwidth bill. R2 egress is $0. Workers free up to 100k req/day. Also: AtCoder ABC 472. Solved A–E. E was a banger. @atcoder #buildinpublic @Cloudflare @nextjs
-
Drew Ronsman (@drew_ronsman) reported@robinebers @Cloudflare @vercel Any major or deal breaking problem with cloudflare boils down to using cloud flare services without clouflare dns
-
Aung Myat Moe (@theaungmyatmoe) reported@thekitze I would rather use @Cloudflare artifact **** that ****
-
Pramod Gupta (@pramodhq) reportedDayravel is getting good traction at this early stage. Now it’s time to start adding more user-focused features. - Like destinations. - Bookmark destinations. - Newsletter. But first, I need authentication, and for that I need a reliable email service for transactions mail and bulk email services for newsletters. I’ll be choosing one from: - Cloudflare Email - Resend - Brevo - Amazon SES - Postmark
-
Anurag (@anurag_gharat) reportedSystem Design Essentials #19 What is a CDN? Imagine your website is hosted in Mumbai and a user from New York requests your website. The request has to physically travel across the network to reach your hosted server, and then the same for the response. This adds latency. The site will be faster to load up for the user in India but slower for anyone outside of India. CDN, which stands for Content Delivery Network, is a network of geographically distributed servers that cache and deliver your content from a location physically closer to the user instead of the request travelling back to the origin server. How does it work? The origin server is the actual server where all the real content lives Content gets cached on Edge Servers all across the world. Static content like CSS, JS, HTML, images gets cached on these edge servers and served through them. Every user request is routed to the nearest Edge server. In case of cache hit -> return immediately In case of a cache miss -> get from the origin server and create a copy on the edge server, and return the response CDNs are best suited for static or infrequently changing content — not real-time, highly dynamic data like a live bank balance. Common CDN providers: Cloudflare, Amazon CloudFront
-
Bash (@bashirbuilds) reportedCloudflare had another network incident today. The interesting part isn’t just that a provider had issues. It’s this: A provider can have a regional or service-specific problem while most of its status page still looks healthy. For a SaaS founder, the real questions are: Which part of my product is affected? Which customers are seeing it? And when has that workflow actually recovered? That’s the gap I keep thinking about while building Reeno. Provider status is context. Product impact is what matters.
-
Alexey Zukutoke (@Zukutoke) reported@opencode @Cloudflare Why I can’t use free model when my monthly quota is fully used? Please, fix it
-
/喜欢ボカロ音乐/能不能尽量少喝咖啡 (@sonnnnnnnnnnnna) reported@FhuDra @realNyarime Cloudflare, Google Cloud, AWS free tier all cannot provide legal service at China. Because the CDN registration needs them pass some specific gov verification.