Unofficial HTTP Status Codes: nginx, Cloudflare, AWS & IIS
Not every status code you see is in the HTTP standard.
Web servers, CDNs, load balancers and frameworks define their own codes for situations the standard does not cover. They are not registered with IANA, so their meaning depends entirely on the product that sent them.
The official list of HTTP status codes is the IANA HTTP Status Code Registry, mostly defined by RFC 9110. The codes below are unofficial: you will find them in logs and error pages, but a generic HTTP client will only know that they belong to the 4xx or 5xx class.
Nginx
| Code | Name | What it means |
|---|---|---|
| 444 | No Response | Nginx closes the connection without sending anything (return 444;). Used to drop unwanted requests. |
| 494 | Request Header Too Large | Used internally when request headers exceed large_client_header_buffers. The client receives 400 "Request Header Or Cookie Too Large". |
| 495 | SSL Certificate Error | The client certificate failed verification. Sent to the client as 400. |
| 496 | SSL Certificate Required | The client did not present a required certificate. Sent to the client as 400. |
| 497 | HTTP Request Sent to HTTPS Port | Plain HTTP arrived on an SSL port. Sent to the client as 400. |
| 499 | Client Closed Request | Logged when the client disconnects before nginx answers. Never sent to a client. |
Codes 494-497 can be caught with error_page to show a custom page or redirect; see the nginx SSL module documentation.
Cloudflare
Cloudflare sits between visitors and your origin server. When it cannot get a usable response from the origin, it shows its own error page with one of these codes:
| Code | Name | Typical cause |
|---|---|---|
| 520 | Web Server Returned an Unknown Error | Empty, reset, or invalid response from the origin |
| 521 | Web Server Is Down | Origin refused the connection |
| 522 | Connection Timed Out | TCP connection to the origin timed out |
| 523 | Origin Is Unreachable | No route to the origin (DNS or network) |
| 524 | A Timeout Occurred | Origin accepted the connection but did not answer within 100 seconds |
| 525 | SSL Handshake Failed | TLS handshake with the origin failed |
| 526 | Invalid SSL Certificate | Origin certificate not valid in Full (strict) mode |
| 530 | (with a 1xxx error) | Shown together with a Cloudflare 1xxx error, e.g. origin DNS errors |
Source: Cloudflare 5xx error documentation.
AWS Elastic Load Balancing (Application Load Balancer)
| Code | What it means |
|---|---|
| 460 | The client closed the connection to the load balancer before the idle timeout elapsed - the ALB counterpart of nginx's 499. Often a client timeout shorter than the target's response time. |
| 463 | The X-Forwarded-For request header contained too many IP addresses (the limit is 30). |
| 464 | The request protocol is incompatible with the target group's protocol version (for example HTTP/1.1 requests to a gRPC target group). |
| 561 | Unauthorized: the identity provider returned an error while the load balancer was authenticating the user (listener rules with OIDC or Cognito authentication). |
Source: AWS ALB troubleshooting documentation. ALBs also send standard codes such as 502, 503 and 504 when targets fail, are missing, or time out.
Microsoft IIS and Exchange
Microsoft products use a few extra codes, and IIS adds sub-status codes (the number after the dot) to its detailed error pages and logs. The client still receives the main code, e.g. 404.
| Code | Meaning |
|---|---|
| 440 | Login Time-out - used by Exchange / Outlook on the web when the session has expired. |
| 449 | Retry With - Microsoft extension asking the client to retry after performing an action. |
| 451 | Redirect - used by Exchange ActiveSync to point a client at a different server (unrelated to the standard 451 Unavailable For Legal Reasons). |
Common IIS sub-status codes
| Code | Meaning |
|---|---|
| 401.1 | Logon failed (invalid credentials) |
| 401.2 | Logon failed due to server configuration (no matching authentication method enabled) |
| 401.3 | Unauthorized due to an ACL on the resource (file system permissions) |
| 403.4 | SSL required |
| 403.14 | Directory listing denied (no default document) |
| 404.0 | Not found |
| 404.3 | MIME map policy prevents this request (no MIME type for the file extension) |
| 404.7 | File extension denied by request filtering |
| 404.8 | Hidden namespace (e.g. App_Data, bin) |
| 404.11 | URL contains a double escape sequence |
| 404.13 | Content length too large (maxAllowedContentLength) - see 413 |
| 404.14 | URL too long |
| 404.15 | Query string too long |
| 500.19 | Configuration data is invalid (malformed web.config or a locked section) |
| 500.21 | Module not recognized (e.g. a missing hosting module) |
| 500.30 | ASP.NET Core app failed to start (in-process hosting) |
| 502.3 | Bad gateway: forwarder connection error (ARR or the ASP.NET Core Module) |
| 502.5 | ASP.NET Core process failure (out-of-process hosting) |
| 503.0 | Application pool unavailable |
Other Codes You May See
| Code | Used by | Meaning |
|---|---|---|
| 509 | cPanel / Apache hosting | Bandwidth Limit Exceeded - the hosting account used up its bandwidth quota. |
| 419 | Laravel | Page Expired - the CSRF token is missing or the session expired. Refresh the page and resubmit the form. |
| 420 | Twitter API v1 (historic) | Enhance Your Calm - an early rate-limiting response, replaced by 429. |
Reserved Codes in the Official Registry
Two numbers are in the IANA registry but are deliberately not usable: 306 (Unused), left over from an early HTTP draft, and 418 (Unused), reserved because of the "I'm a teapot" April Fools' joke.
Should You Use Unofficial Codes in Your API?
Generally no. Clients, proxies and monitoring tools only understand the registered codes; an unknown code is treated as the generic x00 of its class (an unknown 4xx is handled like 400, an unknown 5xx like 500). Prefer a standard code and put the detail in the response body - for example with the application/problem+json format from RFC 9457.