HTTP status codes in plain English
Every time your browser asks a website for a page, the server answers with a three-digit number before it sends anything else. You rarely see it. When something breaks, though, that number tells you more about what went wrong than any error page will.
The first digit gives you the family. 2 means it worked, 3 means "go over there instead", 4 means the request had a problem, and 5 means the server did. Here are the ones you'll actually run into.
2xx: it worked
| Code | Meaning |
|---|---|
| 200 | OK. The page came back normally. This is what a healthy site returns almost every time. |
| 202 | Accepted. The server got the request and is still working on it. Some big sites (Amazon is one) send this to automated checkers. It still counts as up. |
| 204 | No content. It worked, and there's nothing to show. Common behind buttons and forms. |
3xx: look somewhere else
| Code | Meaning |
|---|---|
| 301 | Moved permanently. The page has a new address for good, like http:// moving to https://. |
| 302 / 307 | Moved for now. The usual trick behind sign-in pages and short links. |
| 304 | Not modified. Your browser's saved copy is still current, so nothing new was sent. |
Redirects are normal. The trouble starts when page A sends you to page B and page B sends you back to A. Browsers give up and show ERR_TOO_MANY_REDIRECTS. Our checker calls that down, because nobody can reach an actual page.
4xx: the request had a problem
| Code | Meaning |
|---|---|
| 400 | Bad request. The server couldn't understand what was asked for, often because of a mangled link. |
| 401 | Unauthorized. You need to sign in first. |
| 403 | Forbidden. The server understood and said no. Big sites send this to bots all day long. |
| 404 | Not found. The server is fine; that particular page isn't there. Check the link, or try the home page. |
| 410 | Gone. Like a 404, except the owner is telling you it was removed on purpose. |
| 429 | Too many requests. You (or your network) asked too often. Wait a minute. |
A 4xx doesn't mean the site is down. The server answered, which is the opposite of down. That's why our checker shows a 403 from a site like Reddit as up: it's turning away our robot, and it's working fine for people.
5xx: the server broke
| Code | Meaning |
|---|---|
| 500 | Internal server error. Something crashed in the site's own code. Generic, and always the owner's problem. |
| 502 | Bad gateway. A server in front of the site (a load balancer or proxy) got a broken answer from the one behind it. |
| 503 | Service unavailable. Overloaded, or down for maintenance. Often planned and short. |
| 504 | Gateway timeout. The front server waited for the one behind it and gave up. |
These are the codes that mean a site is down. If you see one, refreshing a few times in the next five minutes is reasonable. Refreshing 50 times in a row isn't, and it adds load to a server that's already struggling.
Cloudflare's own codes (520 to 526)
About a fifth of the web sits behind Cloudflare, which runs its own front door in front of a site's real server. When the front door works but the server behind it doesn't, you get a code in the 520s and a Cloudflare-branded error page.
| Code | Meaning |
|---|---|
| 520 | The site's server sent back something Cloudflare couldn't make sense of. |
| 521 | The site's server refused the connection. Usually it's switched off or crashed. |
| 522 | Cloudflare couldn't connect to the server in time. |
| 523 | Cloudflare can't find a route to the server at all. |
| 524 | Connected, but the server took too long to answer. |
| 525 / 526 | The secure connection between Cloudflare and the server failed, usually a certificate problem. |
When there's no code at all
Sometimes the server never answers, so there's no number to read. These show up as browser errors instead:
DNS_PROBE_FINISHED_NXDOMAIN: the address doesn't exist. Check the spelling, or the domain may have expired.ERR_CONNECTION_REFUSED: a server is at that address, but nothing is accepting connections.ERR_CONNECTION_TIMED_OUT: no reply at all. Our checker waits 8 seconds before calling it.NET::ERR_CERT_DATE_INVALID: the site's security certificate has expired. The site may be running fine underneath, but browsers block it with a warning page.
Is a site down right now? Check it in a few seconds.
Check a website