On 18 November 2025 Cloudflare suffered a global failure that returned error pages for a large share of the sites it fronts. The cause was an oversized internal configuration file generated by a change to a database permissions query, which crashed the proxy process that handles traffic. Because Cloudflare sits in front of a very large slice of the internet, the blast radius was enormous.
Who this hit
Anyone whose website, API, VPN endpoint or SaaS supplier uses Cloudflare — which, for UK small businesses, is most of them. Sites hosted perfectly well on healthy servers were unreachable because the layer in front of them was down.
The uncomfortable lesson
Content delivery networks and DDoS protection genuinely improve availability nearly all of the time. The trade-off is that when they fail, they fail everywhere at once, and there is nothing your hosting provider can do. That is a reasonable trade — but it should be a decision you've made deliberately, not one you discover during an outage.
Practical steps
- Keep a status page bookmark for the services in front of your website, not just your host.
- Make sure your email doesn't depend on the same provider as your website, so you can still tell customers what's happening.
- If you sell online, know how to take an order by phone.
- Ask whoever manages your DNS how quickly they could route around a failed edge provider. For most small sites the honest answer is 'not quickly', and that's fine as long as you know.