HTTP status codes
A complete reference of HTTP status codes from 1xx to 5xx, with a short explanation for every code and notes on how Google treats the ones that matter for SEO.
Every HTTP response starts with a three-digit status code. The first digit tells you the class of the response: 1xx informational, 2xx success, 3xx redirection, 4xx client error and 5xx server error. The meaning of each code is defined in RFC 9110 and a few additional RFCs; this list covers all codes from RFC 9110 plus the extension codes you will actually run into.
Clients that don't recognise a code treat it like the x00 code of its class, so an unknown 499 is handled like 400. The reason phrase (e.g. "Not Found") is only informational and is not sent at all in HTTP/2 and HTTP/3.
Want to know which status code a URL returns? Paste it into the redirect checker to see the code of every hop, including redirects, headers and the final response.
1xx Informational
Interim responses that tell the client the request was received and processing continues. A final response always follows.
- 100
-
100 Continue
The server has received the request headers and the client may send the body. It's the answer to a request with
Expect: 100-continue, which lets a client check whether a large upload will be accepted before sending it. - 101
-
101 Switching Protocols
The server agrees to switch to the protocol the client asked for in the
Upgradeheader. The most common case is the handshake that opens a WebSocket connection. - 102
-
102 Processing
A WebDAV code (RFC 2518) telling the client that the server is still working on a long-running request, so it shouldn't time out. It was dropped from the WebDAV spec in RFC 4918 and is rarely used today.
- 103
-
103 Early Hints
Sent before the final response with
Linkheaders, so the browser can start preloading stylesheets or preconnecting to other origins while the server is still building the page (RFC 8297). Modern browsers and CDNs such as Cloudflare support it.
2xx Success
The request was received, understood and accepted.
- 200
-
200 OK
The request succeeded. For a
GETthe response body contains the requested resource; this is the code every normal, indexable page should return.SEO: Google passes the content of a 200 page on to indexing. A 200 is not a guarantee of indexing, though: if the page looks empty or like an error page, Google may classify it as a soft 404.
- 201
-
201 Created
The request created a new resource, typically after a
POSTorPUTto an API. TheLocationheader usually points to the new resource. - 202
-
202 Accepted
The request was accepted for processing, but processing hasn't finished yet and may still fail. Used for asynchronous jobs such as queued exports.
- 203
-
203 Non-Authoritative Information
The request succeeded, but a transforming proxy modified the payload from the origin server's 200 response.
- 204
-
204 No Content
The request succeeded and there is intentionally no response body. Common for API calls such as
DELETEor for saving a form without leaving the page.SEO: Google has nothing to index on a 204. Search Console may report such URLs as soft 404s.
- 205
-
205 Reset Content
The request succeeded and the client should reset the document view, for example clear the form that was just submitted. No body is sent.
- 206
-
206 Partial Content
The server returns only part of the resource because the client sent a
Rangeheader. Used for resuming downloads and seeking in video and audio files. - 207
-
207 Multi-Status
A WebDAV code (RFC 4918): the body is an XML document containing separate status codes for several resources or operations.
- 208
-
208 Already Reported
Used inside a WebDAV 207 response (RFC 5842) to avoid listing the same bound resource repeatedly.
- 226
-
226 IM Used
The server returns the result of instance manipulations applied to the resource, such as a delta instead of the full document (RFC 3229). Hardly ever seen in practice.
3xx Redirection
The client has to take further action, usually follow the URL in the Location header, to complete the request.
- 300
-
300 Multiple Choices
The resource has several representations (for example different languages or formats) and the client or user should pick one. Browsers don't handle this consistently, so it's rarely used.
- 301
-
301 Moved Permanently
The resource has permanently moved to the URL in the
Locationheader. Clients may change aPOSTinto aGETwhen following it. The classic choice for domain moves, HTTPS migrations and changed URLs, see 301 vs. 302.SEO: Passes PageRank and is a strong signal that the target URL should become canonical. Google gradually replaces the old URL with the new one in its index.
- 302
-
302 Found
The resource is temporarily available at a different URL; clients should keep using the original URL. Like with 301, browsers usually switch
POSTtoGET.SEO: Also passes PageRank, but is only a weak canonicalization signal: Google usually keeps the original URL in the index.
- 303
-
303 See Other
The client should fetch a different URL with
GET. Typically sent after a formPOSTto send the user to a confirmation page (Post/Redirect/Get pattern), which prevents duplicate submissions on reload.SEO: Treated by Google like a temporary redirect: passes PageRank, weak canonicalization signal.
- 304
-
304 Not Modified
The answer to a conditional request with
If-None-MatchorIf-Modified-Since: the resource hasn't changed, so the client can use its cached copy. The response has no body.SEO: Tells Googlebot the content is unchanged since the last crawl. Google may recalculate signals for the URL, but otherwise it has no effect on indexing. Correct ETag/Last-Modified support saves crawl resources on large sites.
- 305
-
305 Use Proxy
Deprecated. It told the client to access the resource through a proxy, which was a security risk, so browsers ignore it.
- 306
-
306 (Unused)
Formerly "Switch Proxy" in an early draft. The code is reserved and no longer used.
- 307
-
307 Temporary Redirect
A temporary redirect like 302, but the client must repeat the request with the same method and body. Browsers also show an internal 307 when HSTS forces the switch from HTTP to HTTPS. Details in 307 vs. 308.
SEO: Treated by Google like a 302: passes PageRank, weak canonicalization signal.
- 308
-
308 Permanent Redirect
A permanent redirect like 301, but the method and body must not change, so a
POSTstays aPOST. Well suited for APIs and form endpoints (originally defined in RFC 7538).SEO: Treated by Google like a 301: passes PageRank and is a strong canonicalization signal.
4xx Client Error
The request contains an error or can't be fulfilled, for example because the resource doesn't exist or access is denied.
- 400
-
400 Bad Request
The server can't process the request because of a client error, such as malformed syntax, an invalid header or a cookie that is too large.
- 401
-
401 Unauthorized
The request requires authentication and none or invalid credentials were sent. The server must include a
WWW-Authenticateheader describing how to authenticate.SEO: Content behind a 401 is not indexed. Don't use 401 or 403 to throttle Googlebot, use 429 or 503 instead.
- 402
-
402 Payment Required
Reserved for future use. Some APIs and services use it for exhausted quotas or unpaid accounts, but there is no standardised meaning.
- 403
-
403 Forbidden
The server understood the request but refuses to fulfil it. Unlike 401, logging in usually doesn't help, for example because of missing permissions, an IP block or a firewall rule.
SEO: If Googlebot gets a 403, the page is not indexed and indexed URLs are removed over time. Check that your firewall or bot protection isn't blocking Googlebot by accident.
- 404
-
404 Not Found
The server can't find a resource at this URL. It doesn't say whether the absence is temporary or permanent. The most common error on the web, often caused by broken links or missing redirects after a relaunch.
SEO: Google doesn't index 404 URLs and drops already indexed ones over time; crawl frequency decreases gradually. 404s don't hurt the rest of your site, but redirect URLs that have backlinks or traffic to a relevant new page.
- 405
-
405 Method Not Allowed
The resource exists but doesn't support the request method, for example a
POSTto a static page. The response must include anAllowheader listing the supported methods. - 406
-
406 Not Acceptable
The server has no representation that matches the client's
Acceptheaders (content type, language, encoding). Some security modules also misuse it to block requests. - 407
-
407 Proxy Authentication Required
Like 401, but the client has to authenticate with a proxy. The proxy sends a
Proxy-Authenticateheader. - 408
-
408 Request Timeout
The server didn't receive the complete request within the time it was willing to wait and closes the connection. The client may repeat the request.
- 409
-
409 Conflict
The request conflicts with the current state of the resource, for example an edit based on an outdated version or an attempt to create something that already exists.
- 410
-
410 Gone
The resource was deliberately removed and won't come back, and there is no forwarding address. More explicit than 404 for content you have deleted on purpose.
SEO: Google treats 410 like 404 (all 4xx codes except 429 are handled the same): the URL isn't indexed and drops out of the index over time. The benefit of 410 is mainly that it states your intent clearly.
- 411
-
411 Length Required
The server refuses the request because it has no
Content-Lengthheader. - 412
-
412 Precondition Failed
A condition in the request headers, such as
If-MatchorIf-Unmodified-Since, evaluated to false. Used to prevent overwriting changes made by someone else. - 413
-
413 Content Too Large
The request body is larger than the server is willing to process, typically an upload that exceeds a limit like nginx's
client_max_body_size. Formerly called "Payload Too Large". - 414
-
414 URI Too Long
The URL is longer than the server accepts. This often shows up with faulty redirect rules that append parameters on every hop until the URL becomes too long.
- 415
-
415 Unsupported Media Type
The server doesn't support the format of the request body, for example XML sent to an API that only accepts JSON. Check the
Content-Typeheader. - 416
-
416 Range Not Satisfiable
The byte range in the
Rangeheader lies outside the resource, for example beyond the end of the file. - 417
-
417 Expectation Failed
The server can't meet the requirement in the
Expectheader, usuallyExpect: 100-continue. - 418
-
418 (Unused)
Known as "I'm a teapot" from the April Fools' RFC 2324 (Hyper Text Coffee Pot Control Protocol). RFC 9110 reserves the code because it is widely implemented as a joke, so it can't be assigned otherwise.
- 421
-
421 Misdirected Request
The request reached a server that can't produce a response for this host. Happens with HTTP/2 connection reuse when a TLS certificate covers several domains that are served by different servers.
- 422
-
422 Unprocessable Content
The request is syntactically correct but semantically invalid, for example a JSON body that fails validation. Very common in REST APIs; formerly "Unprocessable Entity" from WebDAV.
- 423
-
423 Locked
A WebDAV code (RFC 4918): the resource is locked, for example because another user is editing it.
- 424
-
424 Failed Dependency
A WebDAV code (RFC 4918): the request failed because a previous request it depends on failed.
- 425
-
425 Too Early
The server won't process a request sent as TLS 1.3 early data (0-RTT) because it could be replayed (RFC 8470). The client should retry after the handshake is complete.
- 426
-
426 Upgrade Required
The server refuses to handle the request with the current protocol and names the required one in the
Upgradeheader, for example a newer TLS or HTTP version. - 428
-
428 Precondition Required
The server requires a conditional request such as
If-Matchto prevent lost updates (RFC 6585). - 429
-
429 Too Many Requests
The client sent too many requests in a given time (rate limiting, RFC 6585). A
Retry-Afterheader can say how long to wait before trying again.SEO: Unlike other 4xx codes, Google treats 429 like a server error: Googlebot slows down crawling. Indexed URLs stay in the index for a while but are dropped if the errors persist.
- 431
-
431 Request Header Fields Too Large
A single header or all headers together are too large (RFC 6585). A frequent cause is too many or oversized cookies; deleting cookies for the domain usually fixes it.
- 451
-
451 Unavailable For Legal Reasons
The resource can't be served for legal reasons, for example because of a court order or geoblocking required by law (RFC 7725). The number is a reference to Ray Bradbury's "Fahrenheit 451".
5xx Server Error
The server failed to fulfil an apparently valid request.
- 500
-
500 Internal Server Error
A generic error: something went wrong on the server and no more specific code fits. Typical causes are PHP fatal errors, invalid
.htaccessdirectives or failing database connections. The server's error log tells you more.SEO: Googlebot temporarily slows down crawling on 5xx errors. Indexed URLs are kept at first but removed if the errors persist, so fix server errors quickly.
- 501
-
501 Not Implemented
The server doesn't support the functionality required for the request, typically an unknown request method.
- 502
-
502 Bad Gateway
A gateway or reverse proxy (for example nginx or a CDN) received an invalid response from the upstream server, such as a crashed PHP-FPM or Node.js process.
SEO: Handled like other 5xx errors: crawling slows down, and URLs are dropped from the index if the problem lasts.
- 503
-
503 Service Unavailable
The server is temporarily unable to handle the request, because of overload or maintenance. A
Retry-Afterheader can say when to try again. The correct code for planned maintenance windows.SEO: The recommended code for short maintenance: Google slows down crawling but keeps indexed pages for the time being. If the 503 persists for a longer time, URLs start dropping out of the index.
- 504
-
504 Gateway Timeout
A gateway or proxy didn't get a response from the upstream server in time, for example because a script runs longer than the proxy timeout.
- 505
-
505 HTTP Version Not Supported
The server doesn't support the major HTTP version used in the request.
- 506
-
506 Variant Also Negotiates
A configuration error in transparent content negotiation (RFC 2295): the chosen variant is itself set up to negotiate, creating a loop.
- 507
-
507 Insufficient Storage
A WebDAV code (RFC 4918): the server can't store the data needed to complete the request, for example because the disk or quota is full.
- 508
-
508 Loop Detected
A WebDAV code (RFC 5842): the server detected an infinite loop while processing the request. Some hosts also use it when an account exceeds its resource limits.
- 510
-
510 Not Extended
The request needs further extensions for the server to fulfil it (RFC 2774). The underlying extension framework is historic and the code is practically unused.
- 511
-
511 Network Authentication Required
The client must authenticate to get network access (RFC 6585). Sent by captive portals in hotel or airport Wi-Fi, not by the website you're trying to reach.
Frequently asked questions
- Which status code for a deleted page, 404 or 410?
Both work. If there's a suitable replacement page, use a 301 redirect instead so visitors and link signals end up there. If the content is gone for good without a replacement,
410 Gonestates that most clearly;404 Not Foundis fine too. Google treats both as "not found" and removes the URL from the index over time. Don't redirect all deleted pages to the homepage: Google usually treats that as a soft 404 anyway.- What is a soft 404?
A soft 404 is a URL that returns
200 OKalthough the page is effectively missing, for example an empty search results page, a "product not found" template or a redirect of many unrelated URLs to the homepage. Google detects these pages, reports them in Search Console and doesn't index them. The fix is to return a real404or410, or to redirect to a genuinely equivalent page.- Which redirect code should I use: 301, 302, 307 or 308?
For permanent moves use
301, or308if the request method must be preserved (APIs, form endpoints). For temporary redirects use302, or307to preserve the method. All of them pass PageRank, but only 301 and 308 are a strong signal for Google to index the target URL. Details in 301 vs. 302 and 307 vs. 308.- How can I check which status code a URL returns?
Enter the URL in the redirect checker. It shows the status code of every hop, the response headers and the final destination, so you can spot unwanted 302s, errors at the end of a chain or redirect chains that should be shortened. In the browser you can also open the developer tools and look at the Network tab.