Every time a browser, search engine or app requests a page, the server answers with a three-digit number before anything else. That number, the HTTP status code, says whether the request worked, moved, failed because of the request, or failed because of the server. Visitors rarely see it unless something goes wrong, but search engines, monitoring tools and APIs rely on it completely. Getting the right code matters as much as getting the right content.
The five classes of HTTP status codes
The first digit tells you the category. The meanings are standardized in RFC 9110, the current HTTP semantics specification.
| Class | Meaning | In plain terms |
|---|---|---|
| 1xx | Informational | "Received, keep going" |
| 2xx | Success | "Here you are" |
| 3xx | Redirection | "Look elsewhere" |
| 4xx | Client error | "Something is wrong with the request" |
| 5xx | Server error | "The request was fine; we failed" |
The 4xx/5xx split is the most useful thing to remember when troubleshooting. A 4xx points at the URL, permissions or the data sent. A 5xx points at the server, application or something behind it.
2xx: success
- 200 OK: the standard success response. The page or data is in the body.
- 201 Created: used by APIs when a request created a new resource, such as a new order.
- 204 No Content: success, with nothing to return. Common for API deletes and updates.
- 206 Partial Content: only part of a file was sent, as requested. Video players and download managers use this to resume or seek.
3xx: redirects and caching
- 301 Moved Permanently: the resource has a new permanent address. Browsers and search engines update to the new URL. Use it for domain changes, HTTPS moves and restructured URLs.
- 302 Found: a temporary redirect; the original URL remains the main one.
- 303 See Other: "fetch the result with a GET at this other address", typically after a form submission.
- 304 Not Modified: the browser's cached copy is still valid, so no body is sent. This is a good thing; it saves bandwidth.
- 307 Temporary Redirect and 308 Permanent Redirect: like 302 and 301, but the browser must repeat the same method, so a POST stays a POST.
Avoid redirect chains, where URL A redirects to B, which redirects to C. Each hop adds delay, and search engines may stop following long chains. Point every old URL straight at its final destination.
4xx: client errors
- 400 Bad Request: the request was malformed: invalid JSON in an API call, an oversized cookie, a broken query string.
- 401 Unauthorized: authentication is required or failed. Despite the name, it really means "not authenticated".
- 403 Forbidden: the server knows who you are (or does not care) and still refuses. Common causes are file permissions, IP restrictions, or a web application firewall blocking the request.
- 404 Not Found: nothing exists at this URL. Normal for mistyped addresses; a problem when your own links or popular old URLs produce it.
- 405 Method Not Allowed: for example, sending POST to an endpoint that only accepts GET.
- 410 Gone: the resource was removed deliberately and will not return. Search engines may drop such URLs from their index sooner than a 404.
- 429 Too Many Requests: rate limiting. The client should slow down, and the response may include a
Retry-Afterheader.
5xx: server errors
- 500 Internal Server Error: a generic failure in the application, such as an unhandled exception or a PHP fatal error. The details are in the application or web server error log, not in the response.
- 502 Bad Gateway: a proxy, load balancer or CDN tried to reach the server behind it and got an invalid response. Typical causes: the application process (such as PHP-FPM or a Node.js app) has crashed or is not running.
- 503 Service Unavailable: the server is temporarily unable to handle the request, because of overload or maintenance. During planned maintenance, a 503 with a
Retry-Afterheader tells search engines to come back later rather than treating your pages as gone. - 504 Gateway Timeout: the proxy waited for the backend and gave up. Look for slow database queries, long-running scripts or an unreachable backend.
Status codes and SEO
- Avoid "soft 404s". A page that says "not found" but returns 200 confuses search engines and can get indexed as thin content. Missing pages should return a real 404 or 410, ideally with a helpful page body.
- Use 301 for permanent moves so search engines transfer the old URL's standing to the new one.
- Watch for spikes of 5xx. Persistent server errors can lead search engines to crawl less and eventually drop pages.
- Do not redirect every missing page to the home page. Search engines tend to treat that as a soft 404 anyway, and visitors find it disorienting.
How to check a page's status code
Browsers hide the code, so use a tool. Our HTTP header checker shows the status code and every redirect hop for any URL. From a terminal:
curl -I https://example.com/old-page
The first line shows the status, for example HTTP/2 301, followed by a location: header for redirects. To follow the whole chain:
curl -sIL https://example.com/old-page | grep -iE '^(HTTP|location)'
In the browser, the Network tab of the developer tools (F12) lists the status of every request on a page, which quickly reveals broken images and scripts returning 404. For 5xx errors, the server logs are the next stop; if they show resource exhaustion or crashing processes, it may be a capacity or server management issue rather than a code bug.
Key takeaways
- The first digit tells you the category: 2xx success, 3xx redirect, 4xx client problem, 5xx server problem.
- Use 301/308 for permanent moves and 302/307 for temporary ones; avoid redirect chains.
- Return real 404 or 410 codes for missing pages, never a 200 "not found" page.
- 502 and 504 usually mean the backend behind a proxy is down or too slow; check its logs.