Confirm what is failing, from outside the host
Request the production domain and one API route from a machine that isn't on the host. A 503 with DEPLOYMENT_PAUSED points to a spend or billing pause, a 'Site not available' page to a Netlify pause, and an HTML challenge where you expect JSON to a bot filter. Then check the host's status page, its Activity log and the account owner's inbox for a pause or billing email.
curl -sS -o /dev/null -w '%{http_code} %{content_type}\n' https://yourdomain.com/api/health
Clear the cause, then resume each project
Pay the failed invoice, raise the Vercel On-Demand Budget, or buy Netlify credits. On Vercel, raising the spend amount does not unpause anything. You must resume each project yourself, in the dashboard or through the REST API.
curl -X POST "https://api.vercel.com/v1/projects/$PROJECT_ID/unpause?teamId=$TEAM_ID" \
-H "Authorization: Bearer $VERCEL_TOKEN"
Escalate a wrong flag with evidence, and don't change plans while you wait
If the usage page contradicts the block, open a support ticket. Include the team or account ID, a screenshot of remaining usage, the exact error, the deploy ID and the time it started. Don't switch plans to test a theory. A new plan can move you to a different metering model with different limits.
Add billing alerts and a backup payment method
Add a second payment method and make sure billing emails go to an inbox someone reads. On Vercel Pro, set an On-Demand Budget: web and email notifications fire at 50%, 75% and 100%, and SMS at 100%. Then decide whether Pause Production Deployments should stay on. On Netlify Personal or Pro, turn on auto recharge if you would rather pay an extra charge than have your sites go offline.
Rate-limit crawlers before they spend your quota
robots.txt only asks crawlers to behave, and Google's documentation says it can't enforce crawler behavior. Add a WAF rate-limit rule on your expensive routes instead. On Vercel it's under Firewall, Configure, New Rule, Rate Limit, with a default of 100 requests per 60 seconds per IP and a 429 action. Hobby plans get one such rule per project.
Stop browser challenges on your API paths
Cloudflare Bot Fight Mode can't be skipped with WAF custom rules or Page Rules. If it challenges your API or mobile clients, turn it off for that zone. On Pro plans and above, you can instead use Super Bot Fight Mode with a WAF custom rule that applies the Skip action to your API path.
Make the account recoverable and monitor it from outside
Register both an authenticator app and a passkey, store the single-use recovery codes offline, and give a second person owner access. Run an external uptime check on the production domain that alerts a phone directly, not an inbox tied to the host. Keep DNS at a provider you can sign in to independently of the host, so you can repoint the domain if the host is unreachable.