Cloudflare incident

Email Security delivery impacted by Spamhaus listing

Major Resolved View vendor source →

Cloudflare experienced a major incident on August 12, 2026 affecting Email Security (Area1) and Email Security (Zero Trust), lasting 2h 19m. The incident has been resolved; the full update timeline is below.

Started
Aug 12, 2026, 03:04 PM UTC
Resolved
Aug 12, 2026, 05:23 PM UTC
Duration
2h 19m
Detected by Pingoru
Aug 12, 2026, 03:04 PM UTC

Affected components

Email Security (Area1)Email Security (Zero Trust)

Update timeline

  1. investigating Aug 12, 2026, 03:04 PM UTC

    We are currently investigating an issue where customers that use Spamhaus for additional filtering of email downstream from the Cloudflare Email Security service are rejecting emails from IPs in the 134.195.26.0/23 block. This IP block should be allowed for all customer downstream systems to avoid treating the Email Security service as an originator of mail. We recommend all Cloudflare Email Security customers disable Spamhaus filtering in downstream systems.

  2. investigating Aug 12, 2026, 03:07 PM UTC

    We are continuing to investigate this issue.

  3. investigating Aug 12, 2026, 04:30 PM UTC

    We are continuing to investigate this issue. Customers using O365 will be impacted only if they have not completed the required setup. Please check your setup and ensure the connector includes all egress IPs: https://developers.cloudflare.com/cloudflare-one/email-security/setup/pre-delivery-deployment/prerequisites/m365-email-security-mx/#2-configure-enhanced-filtering

  4. monitoring Aug 12, 2026, 04:48 PM UTC

    All IPs previously listed by Spamhaus are now clean. Monitoring the propagation of that change to downstream systems.

  5. resolved Aug 12, 2026, 05:23 PM UTC

    This incident is now resolved.