↑ ↓ select, Enter open, Esc close

HTTP Status Codes

What a status code means, what usually causes it on the server and what it means for Google. Type a code or a keyword into the filter field.

Filter status codes

39 codes

Check the status code of a URL
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/page/

1xx: Informational

Interim responses. They rarely show up in logs and do not matter for SEO.

CodeMeaningTypical cause on the serverSEO impact
100Continue
The server has received the headers, the client may send the body.
The client sends Expect: 100-continue, for example curl with large uploads.None.
101Switching Protocols
Protocol switch, typically to WebSocket.
WebSocket connection. Behind nginx this needs proxy_set_header Upgrade and Connection.None.
103Early Hints
Early hints about resources, before the actual response is ready.
Server or CDN sends Link: rel=preload early.Indirectly positive: can speed up loading and thus improve LCP.

2xx: Success

The request was processed successfully.

CodeMeaningTypical cause on the serverSEO impact
200OK
All good, the response contains the content.
The normal case.The page can be indexed. Watch out for error pages served with 200: Google treats them as soft 404s.
201Created
A resource was created.
REST APIs after a POST, such as the WordPress REST API.None, affects APIs only.
204No Content
Success without content.
APIs, tracking endpoints, admin-ajax.php in some cases.None. As a response to a normal page, 204 would be wrong.
206Partial Content
Only part of the file is delivered.
Range requests for videos, resumable downloads.None.

3xx: Redirection

The content lives elsewhere. For SEO the most important group after 4xx.

CodeMeaningTypical cause on the serverSEO impact
301Moved Permanently
Moved permanently, the new address is in the Location header.
HTTPS and www redirects, changed URLs, domain moves.The standard for moves. Signals pass to the target, Google indexes the new URL. Avoid chains.
302Found
Temporarily located elsewhere.
Temporary redirects, login redirects, many default CMS rules.The old URL stays in the index. Use 301 for permanent moves, otherwise the switch takes longer.
303See Other
Fetch the result from another address with GET.
Redirect after a form submission (Post/Redirect/Get).Hardly relevant, treated like a temporary redirect.
304Not Modified
Content unchanged, the client uses its cache.
Response to If-Modified-Since or If-None-Match.Positive: saves crawl budget and bandwidth. Requires correct Last-Modified or ETag headers.
307Temporary Redirect
Like 302, but the method (such as POST) is preserved.
Temporary redirect, also generated internally by the browser for HSTS.Like 302: the old URL stays in the index.
308Permanent Redirect
Like 301, but the method is preserved.
Permanent redirect, common with APIs and some frameworks.Equivalent to 301 for Google.

4xx: Client errors

The request could not be fulfilled, usually because of a wrong URL or missing permission.

CodeMeaningTypical cause on the serverSEO impact
400Bad Request
The request is malformed.
Broken headers, cookies too large (nginx: Request Header Or Cookie Too Large), plain HTTP on an HTTPS port.The page is not indexed. With many 400s, check the logs.
401Unauthorized
Authentication required.
HTTP basic auth, password-protected directory in Plesk, API without a token.The page is not indexed. Exactly right for staging environments.
403Forbidden
Access denied, even with authentication.
Wrong file permissions or owner, missing index file with directory listing turned off, ModSecurity, a deny rule, Fail2ban.Like 404, not indexed. If Googlebot gets a 403, check the firewall and bot protection.
404Not Found
There is nothing at this address.
Deleted or renamed page, typo in a link, missing rewrite rule (WordPress permalinks).Normal and harmless for the rest of the site. The URL drops out of the index after a while. Redirect important old URLs with 301.
405Method Not Allowed
The method is not allowed for this address.
POST to a static file, blocked methods, misconfigured API.None, as long as normal GET requests work.
408Request Timeout
The client took too long.
Slow connection, keepalive connections closed by the server.A few are normal. Many of them point to network or load problems.
410Gone
Permanently removed, will not come back.
Deliberately deleted content, for example spam pages after a hack.Google removes the URL somewhat faster than with a 404. Ideal for getting rid of spam URLs after a hack.
413Content Too Large
The uploaded file is too large.
nginx client_max_body_size (default 1 MB), PHP upload_max_filesize and post_max_size.None, affects uploads only.
414URI Too Long
The URL is too long.
Endlessly growing query strings caused by faulty redirects or filters.Often a sign of a redirect loop that keeps appending parameters.
429Too Many Requests
Too many requests in a short time.
Rate limiting in nginx (limit_req), WAF, CDN, API limits.Googlebot slows down crawling. A persistent 429 for Googlebot can lead to deindexing.
451Unavailable For Legal Reasons
Blocked for legal reasons.
Geoblocking or an official takedown.Treated like an error, the page is not indexed.

5xx: Server errors

The server could not answer a valid request. Critical for SEO if they persist.

CodeMeaningTypical cause on the serverSEO impact
500Internal Server Error
Generic error on the server.
PHP fatal error, syntax error in the .htaccess, faulty plugin, wrong permissions with CGI.Harmless for a short time. If the error lasts for days, Google drops the pages from the index.
501Not Implemented
The server does not know the method.
Unknown HTTP method, old software.Rarely relevant.
502Bad Gateway
The upstream server returned an invalid response.
nginx cannot reach PHP-FPM or Apache: service crashed, wrong socket, process killed for lack of memory.Like 500. Googlebot reduces crawling, if it persists, deindexing is a risk.
503Service Unavailable
Temporarily unavailable.
Maintenance mode (WordPress .maintenance), overload, no free PHP-FPM workers.The right code for maintenance, ideally with a Retry-After header. Google then waits. No longer than one or two days.
504Gateway Timeout
The upstream server took too long to answer.
Slow PHP scripts or database queries, proxy_read_timeout or fastcgi_read_timeout too short.Like 500. Also a clear sign of poor response times.
508Loop Detected / Resource Limit
Officially: infinite loop detected. On LiteSpeed with CloudLinux: the account resource limit was reached.
Process or memory limits (LVE) exceeded, infinite loops with WebDAV.Like 500. On shared hosting a sign that the plan is too small.

nginx and Cloudflare special codes

These codes are not part of any standard, but they show up in logs and error pages all the time.

CodeMeaningTypical cause on the serverSEO impact
444No Response (nginx)
nginx closes the connection without a response.
Set deliberately with return 444;, for example for requests without a matching host or for bot defense.Never use it for normal pages. Well suited for junk requests.
499Client Closed Request (nginx)
The client closed the connection before nginx could respond.
The visitor gives up because the page is too slow, a load balancer with a short timeout, monitoring.Only appears in the log. Many 499s mean: the site responds too slowly.
520Web Server Returned an Unknown Error (Cloudflare)
The origin server sent an empty or unexpected response.
PHP or web server crash, headers too large, connection reset by the server.Like 500.
521Web Server Is Down (Cloudflare)
Cloudflare cannot reach the origin server.
Web server stopped, firewall or Fail2ban blocks Cloudflare IPs.Like 500, the site is unreachable for everyone.
522Connection Timed Out (Cloudflare)
Establishing the connection to the origin server takes too long.
Server overloaded, firewall drops packets, wrong IP in the DNS at Cloudflare.Like 500.
523Origin Is Unreachable (Cloudflare)
The origin server is unreachable.
Wrong DNS record, routing problem, server offline.Like 500.
524A Timeout Occurred (Cloudflare)
The connection is up, but the server does not respond within 100 seconds.
Long-running PHP scripts, exports, imports, slow database.Like 504. Better handle long tasks with cron or a queue.
525SSL Handshake Failed (Cloudflare)
The TLS connection to the origin server failed.
No certificate or the wrong one on the server, no shared ciphers.Like 500.
526Invalid SSL Certificate (Cloudflare)
The certificate on the origin server is invalid.
Expired or self-signed certificate in "Full (strict)" mode.Like 500. Renew the certificate, for example with Let’s Encrypt in Plesk.

And yes, there is also 418 I'm a teapot. The code comes from an April Fools' RFC from 1998 and is returned by some servers as a joke or for bot defense. It has nothing to do with real errors.

Check status codes with curl

The browser only reveals the status code in its developer tools and caches redirects. With curl you get the server's unvarnished response. Only the headers, including the status line:

curl -sI https://example.com/page/

A whole list of URLs at once, for example after a site move (one URL per line in urls.txt):

while read -r u; do
  printf '%s %s\n' "$(curl -s -o /dev/null -w '%{http_code}' "$u")" "$u"
done < urls.txt

An analysis of the access log shows which codes your server actually delivers. The path applies to Plesk, column 9 to the usual combined log format:

awk '{print $9}' /var/www/vhosts/example.com/logs/access_ssl_log | sort | uniq -c | sort -rn

404 or 410?

Both say "does not exist". 404 leaves open whether the page will come back, 410 explicitly says it is gone for good. Google treats both similarly, but usually removes 410 URLs from the index a bit faster. For normal deleted pages, 404 is perfectly fine. 410 is worth it when many unwanted URLs need to disappear quickly, typically after a hack that injected spam pages. If an old page has a successor with matching content, a 301 redirect is better than either.

Soft 404: error page with status 200

A soft 404 is a page that says "not found" but is delivered with status 200. Google detects such pages and reports them in Search Console. Common causes: custom error pages included via a redirect instead of ErrorDocument, empty category or search pages, and blanket redirects of all old URLs to the home page. Use curl to check that a non-existent URL really returns 404.

Announce maintenance properly: 503 with Retry-After

During maintenance the server should return 503 Service Unavailable, not 200 with a notice and not 404. The Retry-After header tells search engines when to try again (in seconds or as a date). That way your rankings stay untouched. An example for nginx:

# nginx (Plesk: Additional nginx directives): maintenance mode
# while the file .maintenance-on exists in the web root
if (-f $document_root/.maintenance-on) {
    return 503;
}
add_header Retry-After 3600 always;

During updates, WordPress itself returns a 503 with Retry-After as long as the file .maintenance exists in the web root. If it is left behind after an aborted update, the site stays in maintenance mode: delete the file and you are done.

Google treats a 503 lasting more than one or two days as a permanent error, and pages drop out of the index. Better do longer rebuilds on a staging environment.

Narrowing down 5xx errors on the server

  • 500: start with the domain's error log (/var/www/vhosts/example.com/logs/error_log in Plesk) and the PHP log. For WordPress, WP_DEBUG_LOG helps.
  • 502: is PHP-FPM running? systemctl status plesk-php83-fpm (adjust the version), plus journalctl -u plesk-php83-fpm --since "1 hour ago".
  • 503 and 504: are all PHP-FPM workers busy? The FPM log then says server reached pm.max_children. The MySQL slow query log finds slow queries.

Server is clean. Is the site?

How fast does the website really load?

GENLOC.SEO measures PageSpeed and Core Web Vitals on mobile and desktop and tells you clearly what to fix first. Free, no time limit.

by GENLOC.NETWORK, the team behind myline.de

Bookmark this page: Press Ctrl + D (Mac: ⌘ + D) to have the status code reference ready for the next error in your logs.

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.