HTTPError.net

The fastest way to diagnose, understand, and fix any HTTP status code

Unofficial HTTP Status Codes: nginx, Cloudflare, AWS & IIS

TL;DR

Not every status code you see is in the HTTP standard.

Web servers, CDNs, load balancers and frameworks define their own codes for situations the standard does not cover. They are not registered with IANA, so their meaning depends entirely on the product that sent them.

The official list of HTTP status codes is the IANA HTTP Status Code Registry, mostly defined by RFC 9110. The codes below are unofficial: you will find them in logs and error pages, but a generic HTTP client will only know that they belong to the 4xx or 5xx class.

Nginx

CodeNameWhat it means
444No ResponseNginx closes the connection without sending anything (return 444;). Used to drop unwanted requests.
494Request Header Too LargeUsed internally when request headers exceed large_client_header_buffers. The client receives 400 "Request Header Or Cookie Too Large".
495SSL Certificate ErrorThe client certificate failed verification. Sent to the client as 400.
496SSL Certificate RequiredThe client did not present a required certificate. Sent to the client as 400.
497HTTP Request Sent to HTTPS PortPlain HTTP arrived on an SSL port. Sent to the client as 400.
499Client Closed RequestLogged when the client disconnects before nginx answers. Never sent to a client.

Codes 494-497 can be caught with error_page to show a custom page or redirect; see the nginx SSL module documentation.

Cloudflare

Cloudflare sits between visitors and your origin server. When it cannot get a usable response from the origin, it shows its own error page with one of these codes:

CodeNameTypical cause
520Web Server Returned an Unknown ErrorEmpty, reset, or invalid response from the origin
521Web Server Is DownOrigin refused the connection
522Connection Timed OutTCP connection to the origin timed out
523Origin Is UnreachableNo route to the origin (DNS or network)
524A Timeout OccurredOrigin accepted the connection but did not answer within 100 seconds
525SSL Handshake FailedTLS handshake with the origin failed
526Invalid SSL CertificateOrigin certificate not valid in Full (strict) mode
530(with a 1xxx error)Shown together with a Cloudflare 1xxx error, e.g. origin DNS errors

Source: Cloudflare 5xx error documentation.

AWS Elastic Load Balancing (Application Load Balancer)

CodeWhat it means
460The client closed the connection to the load balancer before the idle timeout elapsed - the ALB counterpart of nginx's 499. Often a client timeout shorter than the target's response time.
463The X-Forwarded-For request header contained too many IP addresses (the limit is 30).
464The request protocol is incompatible with the target group's protocol version (for example HTTP/1.1 requests to a gRPC target group).
561Unauthorized: the identity provider returned an error while the load balancer was authenticating the user (listener rules with OIDC or Cognito authentication).

Source: AWS ALB troubleshooting documentation. ALBs also send standard codes such as 502, 503 and 504 when targets fail, are missing, or time out.

Microsoft IIS and Exchange

Microsoft products use a few extra codes, and IIS adds sub-status codes (the number after the dot) to its detailed error pages and logs. The client still receives the main code, e.g. 404.

CodeMeaning
440Login Time-out - used by Exchange / Outlook on the web when the session has expired.
449Retry With - Microsoft extension asking the client to retry after performing an action.
451Redirect - used by Exchange ActiveSync to point a client at a different server (unrelated to the standard 451 Unavailable For Legal Reasons).

Common IIS sub-status codes

CodeMeaning
401.1Logon failed (invalid credentials)
401.2Logon failed due to server configuration (no matching authentication method enabled)
401.3Unauthorized due to an ACL on the resource (file system permissions)
403.4SSL required
403.14Directory listing denied (no default document)
404.0Not found
404.3MIME map policy prevents this request (no MIME type for the file extension)
404.7File extension denied by request filtering
404.8Hidden namespace (e.g. App_Data, bin)
404.11URL contains a double escape sequence
404.13Content length too large (maxAllowedContentLength) - see 413
404.14URL too long
404.15Query string too long
500.19Configuration data is invalid (malformed web.config or a locked section)
500.21Module not recognized (e.g. a missing hosting module)
500.30ASP.NET Core app failed to start (in-process hosting)
502.3Bad gateway: forwarder connection error (ARR or the ASP.NET Core Module)
502.5ASP.NET Core process failure (out-of-process hosting)
503.0Application pool unavailable

Other Codes You May See

CodeUsed byMeaning
509cPanel / Apache hostingBandwidth Limit Exceeded - the hosting account used up its bandwidth quota.
419LaravelPage Expired - the CSRF token is missing or the session expired. Refresh the page and resubmit the form.
420Twitter API v1 (historic)Enhance Your Calm - an early rate-limiting response, replaced by 429.

Reserved Codes in the Official Registry

Two numbers are in the IANA registry but are deliberately not usable: 306 (Unused), left over from an early HTTP draft, and 418 (Unused), reserved because of the "I'm a teapot" April Fools' joke.

Should You Use Unofficial Codes in Your API?

Generally no. Clients, proxies and monitoring tools only understand the registered codes; an unknown code is treated as the generic x00 of its class (an unknown 4xx is handled like 400, an unknown 5xx like 500). Prefer a standard code and put the detail in the response body - for example with the application/problem+json format from RFC 9457.