Every response from a web server starts with a three-digit code. The first digit tells you which side to look at.
1xx: informational
Rarely seen by people. They are interim messages, such as 100 Continue, and you almost never need to think about them.
2xx: success
The request worked. 200 is the usual reply. 201 means something was created, and 204 means success with nothing to return.
3xx: redirection
The resource is somewhere else. 301 and 308 are permanent, 302 and 307 are temporary. Get these wrong and search engines either keep indexing the old URL or drop the new one. A chain of several redirects slows every visit, so aim for one hop.
4xx: the request is the problem
The server is saying you asked for something it cannot or will not provide. A 404 for a page that should exist, a 403 where you expected access, or a 429 from a rate limiter. These are often fixable on the site side, but the cause is in the request or the permission.
5xx: the server is the problem
The request was fine, but the server failed to handle it. 500 is the generic error, 502 and 504 mean a proxy or gateway got a bad or late response from something behind it, 503 means the service is temporarily unable. Look at server logs first.
| Code | Name | Meaning | Often caused by |
|---|
| 200 | OK | Request succeeded. | Nothing, unless the page content is wrong, in which case look at caching. |
| 301 | Moved Permanently | Resource has a new permanent URL. | Redirect loops; chains that are too long. |
| 302 | Found | Temporary redirect. | Using it where 301 was intended. |
| 304 | Not Modified | Cached copy is still valid. | Usually good news. |
| 400 | Bad Request | Server could not parse the request. | Oversized cookies or malformed headers. |
| 401 | Unauthorized | Authentication required. | Wrong credentials or missing token. |
| 403 | Forbidden | Server understood but refuses. | File permissions, .htaccess rules, WAF blocks. |
| 404 | Not Found | Nothing at that URL. | Broken links, changed permalinks. |
| 405 | Method Not Allowed | HTTP method not accepted. | POST to a static file. |
| 408 | Request Timeout | Client took too long. | Slow connections or a proxy timeout. |
| 410 | Gone | Permanently removed. | Useful to tell search engines a page is deleted. |
| 413 | Content Too Large | Upload larger than allowed. | upload_max_filesize or web server limits. |
| 429 | Too Many Requests | Rate limit hit. | Bots, aggressive plugins, brute-force attempts. |
| 500 | Internal Server Error | Generic server-side failure. | PHP fatal error, bad .htaccess, permissions. |
| 502 | Bad Gateway | Proxy got an invalid reply from upstream. | PHP-FPM or app server crashed. |
| 503 | Service Unavailable | Server overloaded or in maintenance. | Resource limits, maintenance mode stuck. |
| 504 | Gateway Timeout | Upstream did not answer in time. | Slow queries, long-running scripts. |
Seeing the code yourself
From a terminal, curl -I https://example.com prints just the response headers, starting with the status line. Add -L to follow redirects and see each hop. In a browser, open the developer tools, choose the Network tab and reload; each request shows its status code in a column.
If you are debugging a redirect problem, read the Location header at each step. If you are debugging a caching problem, look at Cache-Control, Age and any CDN-specific headers.