stackwitness

Blog

When the edge returns 1016, the origin is still down

Microsoft Copilot's website returned Cloudflare Error 1016 from 22:25 UTC on 9 September 2026 until 00:05 UTC on 10 September. How to read an edge error page without declaring the CDN down, or the product up.

The chat box never loads. The page is a Cloudflare Error 1016. Support is already asking if Cloudflare is down. That question is too coarse. You need the hostname that failed, and what 1016 actually means.

A recent case: copilot.microsoft.com, 9 to 10 September 2026

On 9 September 2026 at 22:25 UTC, copilot.microsoft.com stopped serving the Copilot chat UI. Users got a Cloudflare Error 1016 page instead. Access returned at 00:05 UTC on 10 September, about an hour and 40 minutes. The Register reported that window and the error page. isinternetup.com's 10 September digest matched those clocks and put Downdetector's peak near 4,200 reports.

At 00:18 UTC, Microsoft 365 Status posted that they had investigated reports of an issue affecting access to Microsoft Copilot on the web, identified the source, and took mitigation actions to restore access, with further details at status.cloud.microsoft. The Register separately reported Microsoft's diagnosis as an affected network flow, closed with a configuration fix that restored copilot.microsoft.com.

We do not invent StackWitness probe outcomes for that window. StackWitness does not currently publish a Microsoft Copilot truth page. The lesson below is how to read the error page you already have.

What 1016 actually means

Cloudflare's own docs call Error 1016 an origin DNS error: the edge cannot resolve the origin web server's IP address. Typical causes are a missing A record, a CNAME that does not resolve, or an unresolvable load-balancer origin hostname. The edge still answered. It answered with an error page that says it could not find where to send the request. That is not a report that Cloudflare's network is dark. It is also not proof the product is up because someone got an HTTP response.

A user report captured on IsDown's Microsoft Copilot page quoted the text: Cloudflare is currently unable to resolve your requested domain (copilot.microsoft.com). That sentence is the unit. Name the hostname.

Why the logo on the error page fools people

The page wears Cloudflare's wordmark. On-call pages the CDN. Someone opens cloudflarestatus.com, or pings a Cloudflare host, and reports that Cloudflare is answering, so the product must be fine. Or they do the opposite: they tell customers Cloudflare is having a global incident because the error page says Cloudflare.

Neither move names copilot.microsoft.com. A probe of Cloudflare's own host, and a reading of Cloudflare's vendor status page, answer questions about Cloudflare. They do not tell you whether a customer origin behind Cloudflare resolved.

On 10 September 2026 at 15:25 UTC, hours after Copilot's website recovered, the StackWitness Cloudflare truth page showed host reachability as reachable and vendor self-report as degraded. That split is a Cloudflare-host signal. See /status/cloudflare, and the index at /status. Reachable means the host we probe answered. It is not a certificate that every hostname on the Cloudflare network found its origin.

Two Copilot incidents, not one

At around the same time, The Register reported that the Microsoft 365 Copilot team ran a resilience test that hid Copilot Chat's suggested-prompt pills after a bot response. Microsoft halted the drill. That is a different surface, a different failure mode, and a different customer sentence. A banner that says Copilot is down mixes a website that returned 1016 with a chat UI that lost suggestion chips. Support cannot triage that.

Copy you can adapt

The weak version, which could be pasted onto any incident:

We are aware some users may be experiencing issues with Copilot. A third-party CDN is investigating. All other systems remain operational. We apologize for any inconvenience.

That paragraph costs 100 minutes of the wrong vendor. On-call opens Cloudflare's status page. Customers refresh. Nobody writes down that copilot.microsoft.com returned 1016, so the postmortem has a CDN anecdote and no hostname. The suggestion-pill drill gets folded into the same incident and never gets its own clock.

The version that names the hostname and the code:

As of 22:25 UTC, copilot.microsoft.com is returning Cloudflare Error 1016 (origin DNS error: the edge cannot resolve the origin). The Copilot web UI is not loading. This is not a report that Cloudflare's own network is down. A separate Microsoft 365 Copilot Chat drill is affecting suggestion pills; that is a different incident. We will update when copilot.microsoft.com serves the chat UI again, not when a CDN status page turns green.

A reader who was not on the bridge can check that against the error page, against Microsoft's public update, and against Cloudflare's published meaning of 1016. The weak paragraph cannot be checked, so it cannot be trusted an hour later.

What not to do

Operator checklist

  1. Read the error code on the page (1016), not only the logo.
  2. Name the hostname (copilot.microsoft.com), not only the CDN.
  3. Look up what the code means. 1016 is origin DNS, not origin TCP, not a Worker exception, not a 5xx from the app.
  4. Check the product hostname, not the CDN vendor homepage.
  5. Keep concurrent feature incidents on a separate line, with their own clock.
  6. Write the customer update so a reader can check it against the error page and the vendor's public statement.

StackWitness measures host reachability and reads vendor self-reports so teams can attribute faster. An edge error page is still an outage for anyone who needed that origin. Name the hostname that did not resolve.

We measure reachability and read vendor self-reports. We never invent calm green or issue a compliance verdict.

Start free See live dependency truth