Every website error message explained: HTTP codes, browser errors and email bounces
An index of the errors you'll meet running a website, sorted by the layer that failed: DNS, network, HTTPS, HTTP 4xx and 5xx, Cloudflare 52x and email bounces, each with a full guide and a free tool to check it.
· 4 min read · By the Spot Downtime team
Error messages are short on purpose, and that makes them cryptic. But each one says something specific about where a request failed: in DNS, on the network, during the secure handshake, inside the server, or at a mail server's front door. Once you know which layer is complaining, you know where to look.
This page is the index. Each error links to a guide with the usual causes, the commands to check them, and the fix.
Start here: which layer failed?
| You see | The failure is in | Check with |
|---|---|---|
| DNS_PROBE_FINISHED_NXDOMAIN, ERR_NAME_NOT_RESOLVED | DNS: the name doesn't resolve | DNS lookup |
| ERR_CONNECTION_REFUSED, ERR_CONNECTION_TIMED_OUT | Network: nothing answers on the port | Port checker |
| NET::ERR_CERT_…, ERR_SSL_… | TLS: the secure connection can't be trusted or set up | SSL checker |
| 4xx status codes | The request: the server refuses it | HTTP headers |
| 5xx and Cloudflare 52x codes | The server or the path to it | Down checker |
| 550 / 554 bounces | Email delivery or authentication | SPF/DKIM/DMARC checker |
Browser connection errors
| Error | In short |
|---|---|
| DNS_PROBE_FINISHED_NXDOMAIN | The domain or hostname doesn't exist in DNS. |
| ERR_CONNECTION_REFUSED | The server is reachable, but nothing is listening on the port. |
| ERR_CONNECTION_TIMED_OUT | Nothing answered at all: a firewall, wrong IP or a server that's down. |
| ERR_CONNECTION_RESET | The connection was cut partway through. |
| ERR_EMPTY_RESPONSE | The server closed the connection without sending anything. |
| ERR_TOO_MANY_REDIRECTS | A redirect loop, often an SSL or www setting. |
Certificate and HTTPS errors
| Error | In short |
|---|---|
| NET::ERR_CERT_DATE_INVALID | The certificate expired, or the device clock is wrong. |
| NET::ERR_CERT_COMMON_NAME_INVALID | The certificate is for a different hostname. |
| NET::ERR_CERT_AUTHORITY_INVALID | Untrusted issuer: self-signed or a missing intermediate. |
| ERR_SSL_PROTOCOL_ERROR | No valid TLS handshake, or no shared protocol version. |
| Expired certificates | Why auto-renewal still fails, and how to catch it early. |
HTTP 4xx: the request was refused
| Code | In short |
|---|---|
| 400 Bad Request | The server can't parse the request: bad JSON, cookies or headers. |
| 401 Unauthorized | Missing, expired or wrong credentials. |
| 403 Forbidden | Refused by permissions, a firewall or bot protection. |
| 404 Not Found | Nothing at this address: a moved page or a broken deploy. |
| 405 Method Not Allowed | Right address, wrong method (GET vs POST). |
| 408 Request Timeout | The client was too slow to send its request. |
| 413 Content Too Large | An upload over a size limit somewhere in the chain. |
| 429 Too Many Requests | Rate limited: slow down and retry later. |
| 431 Header Fields Too Large | Too many cookies, almost always. |
HTTP 5xx: the server failed
| Code | In short |
|---|---|
| 500 Internal Server Error | An unhandled error in the app or its configuration. |
| 502 / 503 / 504 | Crashed app, no capacity, or a slow backend behind a proxy. |
| 508 Resource Limit Is Reached | A shared hosting account ran out of processes. |
Cloudflare 52x errors
| Code | In short |
|---|---|
| 520 | The origin sent an empty, invalid or unexpected response. |
| 521 | The origin refused the connection: web server down or firewall. |
| 522 | The connection to the origin timed out. |
| 523 | The origin is unreachable: usually the wrong IP in DNS. |
| 524 | The origin took over 100 seconds to respond. |
| 525 | The SSL handshake with the origin failed. |
| 526 | The origin's certificate is invalid in Full (strict) mode. |
Email bounce errors
| Error | In short |
|---|---|
| 550 5.7.26 | Gmail rejected unauthenticated mail (SPF, DKIM or DMARC). |
| 550 5.1.1 | The mailbox doesn't exist. |
| 554 5.7.1 | Rejected on policy: blocklists, reverse DNS or relay denied. |
| SPF PermError | The SPF record needs more than 10 DNS lookups. |
Looking up a status code?
100 Continue to 526 Invalid SSL Certificate, with what each means and whether monitors treat it as up or down.Hear about errors before your users do
Most of these errors are found by a customer first. An uptime monitor checks your site, API, ports and DNS from outside, records the exact error or status code each time, and alerts your team as soon as one appears.
All free toolsDown checker, SSL checker, DNS and MX lookup, port checker, HTTP headers and more. No sign-up.Keep reading
- HTTP errors · Troubleshooting500 Internal Server Error: how to find the cause and fix itA 500 hides its reason on purpose. Where to look first, the usual causes from unhandled exceptions to full disks, and the extra checks for WordPress and PHP sites.October 5, 2026 · 5 min read
- HTTP errors · Troubleshooting404 Not Found: fix broken pages, missing routes and soft 404sWhich 404s you can ignore, which ones cost you visitors and rankings, and how to fix a whole site or section that suddenly returns Not Found.October 5, 2026 · 4 min read