Skip to content

HTTP status codes

A complete reference of HTTP status codes from 1xx to 5xx, with a short explanation for every code and notes on how Google treats the ones that matter for SEO.

Every HTTP response starts with a three-digit status code. The first digit tells you the class of the response: 1xx informational, 2xx success, 3xx redirection, 4xx client error and 5xx server error. The meaning of each code is defined in RFC 9110 and a few additional RFCs; this list covers all codes from RFC 9110 plus the extension codes you will actually run into.

Clients that don't recognise a code treat it like the x00 code of its class, so an unknown 499 is handled like 400. The reason phrase (e.g. "Not Found") is only informational and is not sent at all in HTTP/2 and HTTP/3.

Want to know which status code a URL returns? Paste it into the redirect checker to see the code of every hop, including redirects, headers and the final response.

1xx Informational

Interim responses that tell the client the request was received and processing continues. A final response always follows.

100

100 Continue

The server has received the request headers and the client may send the body. It's the answer to a request with Expect: 100-continue, which lets a client check whether a large upload will be accepted before sending it.

101

101 Switching Protocols

The server agrees to switch to the protocol the client asked for in the Upgrade header. The most common case is the handshake that opens a WebSocket connection.

102

102 Processing

A WebDAV code (RFC 2518) telling the client that the server is still working on a long-running request, so it shouldn't time out. It was dropped from the WebDAV spec in RFC 4918 and is rarely used today.

103

103 Early Hints

Sent before the final response with Link headers, so the browser can start preloading stylesheets or preconnecting to other origins while the server is still building the page (RFC 8297). Modern browsers and CDNs such as Cloudflare support it.

2xx Success

The request was received, understood and accepted.

200

200 OK

The request succeeded. For a GET the response body contains the requested resource; this is the code every normal, indexable page should return.

SEO: Google passes the content of a 200 page on to indexing. A 200 is not a guarantee of indexing, though: if the page looks empty or like an error page, Google may classify it as a soft 404.

201

201 Created

The request created a new resource, typically after a POST or PUT to an API. The Location header usually points to the new resource.

202

202 Accepted

The request was accepted for processing, but processing hasn't finished yet and may still fail. Used for asynchronous jobs such as queued exports.

203

203 Non-Authoritative Information

The request succeeded, but a transforming proxy modified the payload from the origin server's 200 response.

204

204 No Content

The request succeeded and there is intentionally no response body. Common for API calls such as DELETE or for saving a form without leaving the page.

SEO: Google has nothing to index on a 204. Search Console may report such URLs as soft 404s.

205

205 Reset Content

The request succeeded and the client should reset the document view, for example clear the form that was just submitted. No body is sent.

206

206 Partial Content

The server returns only part of the resource because the client sent a Range header. Used for resuming downloads and seeking in video and audio files.

207

207 Multi-Status

A WebDAV code (RFC 4918): the body is an XML document containing separate status codes for several resources or operations.

208

208 Already Reported

Used inside a WebDAV 207 response (RFC 5842) to avoid listing the same bound resource repeatedly.

226

226 IM Used

The server returns the result of instance manipulations applied to the resource, such as a delta instead of the full document (RFC 3229). Hardly ever seen in practice.

3xx Redirection

The client has to take further action, usually follow the URL in the Location header, to complete the request.

300

300 Multiple Choices

The resource has several representations (for example different languages or formats) and the client or user should pick one. Browsers don't handle this consistently, so it's rarely used.

301

301 Moved Permanently

The resource has permanently moved to the URL in the Location header. Clients may change a POST into a GET when following it. The classic choice for domain moves, HTTPS migrations and changed URLs, see 301 vs. 302.

SEO: Passes PageRank and is a strong signal that the target URL should become canonical. Google gradually replaces the old URL with the new one in its index.

302

302 Found

The resource is temporarily available at a different URL; clients should keep using the original URL. Like with 301, browsers usually switch POST to GET.

SEO: Also passes PageRank, but is only a weak canonicalization signal: Google usually keeps the original URL in the index.

303

303 See Other

The client should fetch a different URL with GET. Typically sent after a form POST to send the user to a confirmation page (Post/Redirect/Get pattern), which prevents duplicate submissions on reload.

SEO: Treated by Google like a temporary redirect: passes PageRank, weak canonicalization signal.

304

304 Not Modified

The answer to a conditional request with If-None-Match or If-Modified-Since: the resource hasn't changed, so the client can use its cached copy. The response has no body.

SEO: Tells Googlebot the content is unchanged since the last crawl. Google may recalculate signals for the URL, but otherwise it has no effect on indexing. Correct ETag/Last-Modified support saves crawl resources on large sites.

305

305 Use Proxy

Deprecated. It told the client to access the resource through a proxy, which was a security risk, so browsers ignore it.

306

306 (Unused)

Formerly "Switch Proxy" in an early draft. The code is reserved and no longer used.

307

307 Temporary Redirect

A temporary redirect like 302, but the client must repeat the request with the same method and body. Browsers also show an internal 307 when HSTS forces the switch from HTTP to HTTPS. Details in 307 vs. 308.

SEO: Treated by Google like a 302: passes PageRank, weak canonicalization signal.

308

308 Permanent Redirect

A permanent redirect like 301, but the method and body must not change, so a POST stays a POST. Well suited for APIs and form endpoints (originally defined in RFC 7538).

SEO: Treated by Google like a 301: passes PageRank and is a strong canonicalization signal.

4xx Client Error

The request contains an error or can't be fulfilled, for example because the resource doesn't exist or access is denied.

400

400 Bad Request

The server can't process the request because of a client error, such as malformed syntax, an invalid header or a cookie that is too large.

401

401 Unauthorized

The request requires authentication and none or invalid credentials were sent. The server must include a WWW-Authenticate header describing how to authenticate.

SEO: Content behind a 401 is not indexed. Don't use 401 or 403 to throttle Googlebot, use 429 or 503 instead.

402

402 Payment Required

Reserved for future use. Some APIs and services use it for exhausted quotas or unpaid accounts, but there is no standardised meaning.

403

403 Forbidden

The server understood the request but refuses to fulfil it. Unlike 401, logging in usually doesn't help, for example because of missing permissions, an IP block or a firewall rule.

SEO: If Googlebot gets a 403, the page is not indexed and indexed URLs are removed over time. Check that your firewall or bot protection isn't blocking Googlebot by accident.

404

404 Not Found

The server can't find a resource at this URL. It doesn't say whether the absence is temporary or permanent. The most common error on the web, often caused by broken links or missing redirects after a relaunch.

SEO: Google doesn't index 404 URLs and drops already indexed ones over time; crawl frequency decreases gradually. 404s don't hurt the rest of your site, but redirect URLs that have backlinks or traffic to a relevant new page.

405

405 Method Not Allowed

The resource exists but doesn't support the request method, for example a POST to a static page. The response must include an Allow header listing the supported methods.

406

406 Not Acceptable

The server has no representation that matches the client's Accept headers (content type, language, encoding). Some security modules also misuse it to block requests.

407

407 Proxy Authentication Required

Like 401, but the client has to authenticate with a proxy. The proxy sends a Proxy-Authenticate header.

408

408 Request Timeout

The server didn't receive the complete request within the time it was willing to wait and closes the connection. The client may repeat the request.

409

409 Conflict

The request conflicts with the current state of the resource, for example an edit based on an outdated version or an attempt to create something that already exists.

410

410 Gone

The resource was deliberately removed and won't come back, and there is no forwarding address. More explicit than 404 for content you have deleted on purpose.

SEO: Google treats 410 like 404 (all 4xx codes except 429 are handled the same): the URL isn't indexed and drops out of the index over time. The benefit of 410 is mainly that it states your intent clearly.

411

411 Length Required

The server refuses the request because it has no Content-Length header.

412

412 Precondition Failed

A condition in the request headers, such as If-Match or If-Unmodified-Since, evaluated to false. Used to prevent overwriting changes made by someone else.

413

413 Content Too Large

The request body is larger than the server is willing to process, typically an upload that exceeds a limit like nginx's client_max_body_size. Formerly called "Payload Too Large".

414

414 URI Too Long

The URL is longer than the server accepts. This often shows up with faulty redirect rules that append parameters on every hop until the URL becomes too long.

415

415 Unsupported Media Type

The server doesn't support the format of the request body, for example XML sent to an API that only accepts JSON. Check the Content-Type header.

416

416 Range Not Satisfiable

The byte range in the Range header lies outside the resource, for example beyond the end of the file.

417

417 Expectation Failed

The server can't meet the requirement in the Expect header, usually Expect: 100-continue.

418

418 (Unused)

Known as "I'm a teapot" from the April Fools' RFC 2324 (Hyper Text Coffee Pot Control Protocol). RFC 9110 reserves the code because it is widely implemented as a joke, so it can't be assigned otherwise.

421

421 Misdirected Request

The request reached a server that can't produce a response for this host. Happens with HTTP/2 connection reuse when a TLS certificate covers several domains that are served by different servers.

422

422 Unprocessable Content

The request is syntactically correct but semantically invalid, for example a JSON body that fails validation. Very common in REST APIs; formerly "Unprocessable Entity" from WebDAV.

423

423 Locked

A WebDAV code (RFC 4918): the resource is locked, for example because another user is editing it.

424

424 Failed Dependency

A WebDAV code (RFC 4918): the request failed because a previous request it depends on failed.

425

425 Too Early

The server won't process a request sent as TLS 1.3 early data (0-RTT) because it could be replayed (RFC 8470). The client should retry after the handshake is complete.

426

426 Upgrade Required

The server refuses to handle the request with the current protocol and names the required one in the Upgrade header, for example a newer TLS or HTTP version.

428

428 Precondition Required

The server requires a conditional request such as If-Match to prevent lost updates (RFC 6585).

429

429 Too Many Requests

The client sent too many requests in a given time (rate limiting, RFC 6585). A Retry-After header can say how long to wait before trying again.

SEO: Unlike other 4xx codes, Google treats 429 like a server error: Googlebot slows down crawling. Indexed URLs stay in the index for a while but are dropped if the errors persist.

431

431 Request Header Fields Too Large

A single header or all headers together are too large (RFC 6585). A frequent cause is too many or oversized cookies; deleting cookies for the domain usually fixes it.

451

451 Unavailable For Legal Reasons

The resource can't be served for legal reasons, for example because of a court order or geoblocking required by law (RFC 7725). The number is a reference to Ray Bradbury's "Fahrenheit 451".

5xx Server Error

The server failed to fulfil an apparently valid request.

500

500 Internal Server Error

A generic error: something went wrong on the server and no more specific code fits. Typical causes are PHP fatal errors, invalid .htaccess directives or failing database connections. The server's error log tells you more.

SEO: Googlebot temporarily slows down crawling on 5xx errors. Indexed URLs are kept at first but removed if the errors persist, so fix server errors quickly.

501

501 Not Implemented

The server doesn't support the functionality required for the request, typically an unknown request method.

502

502 Bad Gateway

A gateway or reverse proxy (for example nginx or a CDN) received an invalid response from the upstream server, such as a crashed PHP-FPM or Node.js process.

SEO: Handled like other 5xx errors: crawling slows down, and URLs are dropped from the index if the problem lasts.

503

503 Service Unavailable

The server is temporarily unable to handle the request, because of overload or maintenance. A Retry-After header can say when to try again. The correct code for planned maintenance windows.

SEO: The recommended code for short maintenance: Google slows down crawling but keeps indexed pages for the time being. If the 503 persists for a longer time, URLs start dropping out of the index.

504

504 Gateway Timeout

A gateway or proxy didn't get a response from the upstream server in time, for example because a script runs longer than the proxy timeout.

505

505 HTTP Version Not Supported

The server doesn't support the major HTTP version used in the request.

506

506 Variant Also Negotiates

A configuration error in transparent content negotiation (RFC 2295): the chosen variant is itself set up to negotiate, creating a loop.

507

507 Insufficient Storage

A WebDAV code (RFC 4918): the server can't store the data needed to complete the request, for example because the disk or quota is full.

508

508 Loop Detected

A WebDAV code (RFC 5842): the server detected an infinite loop while processing the request. Some hosts also use it when an account exceeds its resource limits.

510

510 Not Extended

The request needs further extensions for the server to fulfil it (RFC 2774). The underlying extension framework is historic and the code is practically unused.

511

511 Network Authentication Required

The client must authenticate to get network access (RFC 6585). Sent by captive portals in hotel or airport Wi-Fi, not by the website you're trying to reach.

Frequently asked questions

Which status code for a deleted page, 404 or 410?

Both work. If there's a suitable replacement page, use a 301 redirect instead so visitors and link signals end up there. If the content is gone for good without a replacement, 410 Gone states that most clearly; 404 Not Found is fine too. Google treats both as "not found" and removes the URL from the index over time. Don't redirect all deleted pages to the homepage: Google usually treats that as a soft 404 anyway.

What is a soft 404?

A soft 404 is a URL that returns 200 OK although the page is effectively missing, for example an empty search results page, a "product not found" template or a redirect of many unrelated URLs to the homepage. Google detects these pages, reports them in Search Console and doesn't index them. The fix is to return a real 404 or 410, or to redirect to a genuinely equivalent page.

Which redirect code should I use: 301, 302, 307 or 308?

For permanent moves use 301, or 308 if the request method must be preserved (APIs, form endpoints). For temporary redirects use 302, or 307 to preserve the method. All of them pass PageRank, but only 301 and 308 are a strong signal for Google to index the target URL. Details in 301 vs. 302 and 307 vs. 308.

How can I check which status code a URL returns?

Enter the URL in the redirect checker. It shows the status code of every hop, the response headers and the final destination, so you can spot unwanted 302s, errors at the end of a chain or redirect chains that should be shortened. In the browser you can also open the developer tools and look at the Network tab.