Every website error message explained: HTTP codes, browser errors and email bounces

An index of the errors you'll meet running a website, sorted by the layer that failed: DNS, network, HTTPS, HTTP 4xx and 5xx, Cloudflare 52x and email bounces, each with a full guide and a free tool to check it.

· 4 min read · By the Spot Downtime team

Error messages are short on purpose, and that makes them cryptic. But each one says something specific about where a request failed: in DNS, on the network, during the secure handshake, inside the server, or at a mail server's front door. Once you know which layer is complaining, you know where to look.

This page is the index. Each error links to a guide with the usual causes, the commands to check them, and the fix.

Start here: which layer failed?

You seeThe failure is inCheck with
DNS_PROBE_FINISHED_NXDOMAIN, ERR_NAME_NOT_RESOLVEDDNS: the name doesn't resolveDNS lookup
ERR_CONNECTION_REFUSED, ERR_CONNECTION_TIMED_OUTNetwork: nothing answers on the portPort checker
NET::ERR_CERT_…, ERR_SSL_…TLS: the secure connection can't be trusted or set upSSL checker
4xx status codesThe request: the server refuses itHTTP headers
5xx and Cloudflare 52x codesThe server or the path to itDown checker
550 / 554 bouncesEmail delivery or authenticationSPF/DKIM/DMARC checker

Browser connection errors

ErrorIn short
DNS_PROBE_FINISHED_NXDOMAINThe domain or hostname doesn't exist in DNS.
ERR_CONNECTION_REFUSEDThe server is reachable, but nothing is listening on the port.
ERR_CONNECTION_TIMED_OUTNothing answered at all: a firewall, wrong IP or a server that's down.
ERR_CONNECTION_RESETThe connection was cut partway through.
ERR_EMPTY_RESPONSEThe server closed the connection without sending anything.
ERR_TOO_MANY_REDIRECTSA redirect loop, often an SSL or www setting.

Certificate and HTTPS errors

ErrorIn short
NET::ERR_CERT_DATE_INVALIDThe certificate expired, or the device clock is wrong.
NET::ERR_CERT_COMMON_NAME_INVALIDThe certificate is for a different hostname.
NET::ERR_CERT_AUTHORITY_INVALIDUntrusted issuer: self-signed or a missing intermediate.
ERR_SSL_PROTOCOL_ERRORNo valid TLS handshake, or no shared protocol version.
Expired certificatesWhy auto-renewal still fails, and how to catch it early.

HTTP 4xx: the request was refused

CodeIn short
400 Bad RequestThe server can't parse the request: bad JSON, cookies or headers.
401 UnauthorizedMissing, expired or wrong credentials.
403 ForbiddenRefused by permissions, a firewall or bot protection.
404 Not FoundNothing at this address: a moved page or a broken deploy.
405 Method Not AllowedRight address, wrong method (GET vs POST).
408 Request TimeoutThe client was too slow to send its request.
413 Content Too LargeAn upload over a size limit somewhere in the chain.
429 Too Many RequestsRate limited: slow down and retry later.
431 Header Fields Too LargeToo many cookies, almost always.

HTTP 5xx: the server failed

CodeIn short
500 Internal Server ErrorAn unhandled error in the app or its configuration.
502 / 503 / 504Crashed app, no capacity, or a slow backend behind a proxy.
508 Resource Limit Is ReachedA shared hosting account ran out of processes.

Cloudflare 52x errors

CodeIn short
520The origin sent an empty, invalid or unexpected response.
521The origin refused the connection: web server down or firewall.
522The connection to the origin timed out.
523The origin is unreachable: usually the wrong IP in DNS.
524The origin took over 100 seconds to respond.
525The SSL handshake with the origin failed.
526The origin's certificate is invalid in Full (strict) mode.

Email bounce errors

ErrorIn short
550 5.7.26Gmail rejected unauthenticated mail (SPF, DKIM or DMARC).
550 5.1.1The mailbox doesn't exist.
554 5.7.1Rejected on policy: blocklists, reverse DNS or relay denied.
SPF PermErrorThe SPF record needs more than 10 DNS lookups.

Looking up a status code?

The HTTP status code reference has a short page for every code, from 100 Continue to 526 Invalid SSL Certificate, with what each means and whether monitors treat it as up or down.

Hear about errors before your users do

Most of these errors are found by a customer first. An uptime monitor checks your site, API, ports and DNS from outside, records the exact error or status code each time, and alerts your team as soon as one appears.

All free toolsDown checker, SSL checker, DNS and MX lookup, port checker, HTTP headers and more. No sign-up.

Keep reading