Every time a browser requests a page, the web server responds with an HTTP status code. These three-digit numbers tell browsers, search engines, APIs, and monitoring tools whether the request succeeded, failed, or needs additional action.
Understanding them helps you quickly identify problems that affect uptime, user experience, and SEO — and they're what your monitoring tool watches on every check. A 200 means all is well. A 500 means the server is on fire. Here's the full picture.
The 5 Categories
| Range | Category | What it means |
|---|---|---|
| 100–199 | Informational | Request received, processing continues |
| 200–299 | Success | Request completed successfully |
| 300–399 | Redirects | Visit another URL instead |
| 400–499 | Client errors | Problem with the request |
| 500–599 | Server errors | Problem on the server side |
1xx — Informational
These indicate the request has been received and is being processed. You'll rarely encounter them in normal browsing.
100 Continue — The server received the initial request and expects the client to continue. Common in API communications when sending large payloads.
101 Switching Protocols — The server agrees to switch protocols. Typical use: upgrading from HTTP to WebSocket for real-time connections.
2xx — Success
These mean the request worked. Most of what you see day-to-day is 200.
200 OK — Everything worked. Page loaded, API returned data, search engine can index the page. This is what your uptime monitor looks for on every check.
201 Created — A resource was successfully created. Common in API responses after creating a new user, order, or item.
204 No Content — Request succeeded but nothing is returned. Common for DELETE requests where there's nothing to show after the operation.
3xx — Redirects
These tell browsers (and crawlers) to go somewhere else.
301 Moved Permanently — The page has moved permanently. Good for SEO: search engines transfer ranking signals to the new URL. Use this when a page has permanently moved or a domain migrates.
302 Found — Temporary redirect. The page will return, so ranking signals aren't transferred. Use only when the move is genuinely temporary.
304 Not Modified — The browser already has the latest cached version. The server skips resending the content. Speeds up repeat visits.
307 Temporary Redirect / 308 Permanent Redirect — Same as 302/301 but explicitly preserve the original HTTP method (important for POST requests).
4xx — Client Errors
These indicate a problem with the request — the client asked for something the server can't or won't provide.
400 Bad Request — The request is malformed. Causes: invalid syntax, missing required parameters, corrupted payload. Common in API integrations when the request body doesn't match what the server expects.
401 Unauthorized — Authentication is required. The user must log in before accessing this resource. Different from 403 — this one implies they could get access if they authenticated.
403 Forbidden — The server understands the request but refuses to authorise it. The user is authenticated (or it doesn't matter) — they're simply not allowed. Common causes: IP blocked, file permissions wrong, security rules triggered.
404 Not Found — The page doesn't exist. The most common error on the web. Causes: deleted pages, broken links, incorrect URLs, typos. SEO note: too many 404s on pages that had inbound links dilutes your link equity — use 301 redirects for permanently moved pages instead of letting them 404.
405 Method Not Allowed — The server received the request but the HTTP method (GET, POST, PUT, etc.) isn't allowed for that endpoint.
429 Too Many Requests — Rate limit exceeded. The client is sending too many requests in a given window. Common when bots hammer your site or when API integrations aren't throttled correctly.
5xx — Server Errors
These mean the problem is on the server side. The request was valid — the server just failed to fulfil it. These are what your uptime monitor should fire alerts on immediately.
500 Internal Server Error — Generic server-side failure. The most common server error. Causes: PHP errors, plugin conflicts, database issues, misconfigured server. If your monitor detects repeated 500 responses, check server logs immediately.
502 Bad Gateway — One server received an invalid response from another upstream server. Common with reverse proxies, CDNs, and load balancers when the backend is down or slow.
503 Service Unavailable — The server is temporarily unable to handle requests. Causes: maintenance mode, server overload, traffic spike exhausting resources. Unlike 500, this often self-resolves — but it's still an immediate alert trigger.
504 Gateway Timeout — A server waited too long for a response from an upstream server. Common causes: slow database queries, slow backend APIs, network issues between servers.
Status Codes and SEO
Search engines use status codes to decide what to index and how to weight pages:
| Code | SEO behaviour |
|---|---|
| 200 OK | Page is crawlable and indexable |
| 301 | Ranking signals transfer to the new URL |
| 302 | Usually treated as temporary — signals don't transfer |
| 404 | Page may eventually be removed from the index |
| 410 Gone | Faster deindexing than 404 — use when a page is permanently removed |
| 500 | Persistent errors prevent crawling and can drop pages from index |
| 503 | Crawlers back off temporarily; long-running 503s cause deindexing |
Best Practices
- Keep important pages returning 200 OK — monitor them actively
- Use 301 redirects when URLs permanently change — never leave broken links when a page has moved
- Investigate recurring 5xx errors immediately — check server logs
- Use 410 Gone instead of 404 when deliberately removing a page permanently
- Monitor response time alongside status codes — a slow 200 is better than a fast 500 but still loses you visitors
- Test redirect chains — more than 2 hops wastes crawl budget and slows page loads