Cloudflare Access had a 41 minute spell on 29 September 2026 where one time pin emails largely failed to arrive. If your product relies on Access OTP logins, that was Cloudflare's fault, not yours.
Started
20:11 UTC
Duration
Lasted 41m
Source
IsDown
Next time
Cloudflare is degraded. Is your product working?
An incident on their side does not always mean an outage on yours, and the only way to know is to already be watching your own endpoints. Set that up in under a minute and you will be notified the next time your own site is affected. And there will be a next time.
50 monitors for your own websites. No card.
Affected components: Cloudflare Sites and Services, Access
What happened?
Cloudflare's status page logged one incident on 29 September 2026, starting at 20:11 UTC and lasting 41 minutes. It was filed under Access, affecting Cloudflare Sites and Services as well as Access itself. The title Cloudflare gave it was "OTP Deliverability Errors", and the single update posted says a high percentage of Access One Time Pin emails were failing to send. The same update specifies that all other authentication methods were working normally, so this was narrow in scope: anyone relying on a different login method through Access would not have noticed anything. Cloudflare filed only that one update, marked "investigating", and nothing further appears on the record, including no resolution notice. No user reports were filed during the window on our side. There is no post-mortem and no stated cause, so why the OTP emails failed to send is not on the record. For context, Cloudflare's own 90 day history shows 195 incidents with a median duration of 1 hour 47 minutes, so this one ran shorter than Cloudflare's typical fix time, at least as far as the visible record goes.
Learning
UptimeRobot's own probes, which check Cloudflare's api-control, dns-1111 and edge-data components from EU and NA regions every 60 seconds, stayed at 100% uptime across the 24 hour, 7 day and 30 day windows, and this incident was not registered against it. That is not a contradiction. The probes test whether Cloudflare's edge and control plane respond, not whether a specific downstream mail delivery path for one time pin codes is working. An OTP email failing to send is a narrow functional fault inside Access, not a reachability problem, so a check that measures uptime of the edge will correctly read green while a login flow that depends on that email quietly breaks. If your product sits behind Cloudflare Access and uses OTP as a login method, your own monitoring of your endpoints would show your service as up, because from your side nothing changed, the failure sat entirely inside Cloudflare's mail delivery for Access. That is the general shape to watch for: your side green, a specific feature inside the provider's stack broken, and no overlap between the two until someone connects the symptom to the vendor's status page. Your monitoring covers your half, UptimeRobot now watches the provider's half too, so next time you know which side broke without guessing.