Back to the knowledge base
Webhostingtroubleshooting

Error codes 403, 404 and 500: what do they mean?

Error codes 403, 404 and 500 each tell you where a request went wrong. A 404 means there is nothing at that address, a 403 means the server understands the request but refuses access, and a 500 means the code of your site crashes before the page is ready. Codes that start with a 4 point to the request; codes that start with a 5 point to the server or the code behind it.

404: not found

The server can be reached, but it finds nothing at the requested address. The most common causes:

  • A deleted or moved page. Set up a redirect to the new location; how to do that is explained in setting up a 301 redirect.
  • Every page returns a 404 except the home page. Typical for WordPress after a migration: the rewrite rules in .htaccess are missing. In the dashboard, open Settings → Permalinks and click Save Changes without changing anything. WordPress then writes the rules again.
  • Capital letters. On a Linux server, Photo.jpg and photo.jpg are two different files.

403: forbidden

The address exists, but the server is not allowed or not willing to show it. Work through these causes in order:

  1. No index file. If the folder contains no index.php or index.html, the server has nothing to show. Listing the contents of a folder is usually switched off, and the result is a 403. You often see this right after an upload where the files ended up one folder too deep.
  2. File permissions. The usual values are 755 for folders and 644 for files. If a folder is set to 700 or a file to 600, the web server cannot read it. You change permissions with your FTP program.
  3. A rule in .htaccess that denies access: a block on an IP address, or a rule that closes off an entire folder. What the file does is explained in what you can do with an .htaccess file.
  4. A security plugin that blocked your own IP address after a few failed logins. Test over the mobile network of your phone: if the site works there, you are the one who is blocked.

401: login required

The server asks for a username and password and did not receive valid ones. You see this on a folder that is protected with a password. With the right credentials you do get in; with a 403, logging in does not help.

500: internal server error

The most serious of the series: the page no longer loads, and the server does not say why. Four causes cover almost everything:

  • An error in .htaccess. A single typo, or a directive the server does not know, takes the whole site down.
  • A PHP error in a plugin, a theme or custom code, usually right after an update.
  • A PHP version that does not match the code. Old code breaks on a new version, and recent plugins refuse an old one.
  • The memory limit. A heavy page builder or a large import asks for more memory than the script is allowed to use. Read raising the PHP memory limit before you increase it.

Fixing a 500 error in five steps

  1. Find out what changed last: an update, a new plugin, a line in .htaccess, a different PHP version.
  2. Read the error log of your hosting, or ask support for it. The last line almost always names the file where things went wrong, and the folder name in that path gives away the plugin.
  3. No log at hand? Give .htaccess a different name for a moment. If the site works again, the error is in that file.
  4. With WordPress: use the file manager or FTP to rename the folder of the suspect plugin in wp-content/plugins. WordPress then deactivates the plugin and you can log in again.
  5. If you cannot work it out, there is the backup. We back up our hosting plans every day and keep each backup for 14 days; you request a restore through support. More on backup and restore.

502, 503 and 504 in brief

  • 502 Bad Gateway — a server that sits between the visitor and your site received an invalid response from the server behind it.
  • 503 Service Unavailable — the site is temporarily unavailable, because of overload or maintenance. WordPress itself returns a 503 while it installs updates. If that message does not go away, an update was interrupted: delete the .maintenance file from the root folder of the site.
  • 504 Gateway Timeout — the server behind it did not answer in time. Usually a script that runs too long, such as a large import or export.

If your site runs through Cloudflare, you will sometimes see the codes 520 to 526. These are not standard codes: Cloudflare could not reach your server, or could not reach it correctly.

Frequently asked questions

Is a 404 bad for my ranking in Google?

A 404 on a page that is really gone is normal and not a penalty. It becomes a problem when pages with visitors or inbound links suddenly disappear. Redirect those with a 301 to the best replacement.

I get a 500 error, but only in the WordPress dashboard. What now?

That points to a plugin that only loads in the dashboard, or to the memory limit. Deactivate the plugin that was updated most recently.

My site is unreachable, but I see no error code. What then?

If you get a timeout or the message that the server cannot be found, the problem lies before the web server: with the DNS, the domain name or the network. In that case, follow the steps in my site is down.

Still stuck?

Send us your domain name, the address that returns the error, the error code and the time it happened via contact.

#403 error#404 error#500 error#website error codes
Still stuck?

Does it behave differently than described above, or are you stuck anyway? Get in touch with your domain name or customer number at hand and we will take a look with you.

Contact support
Call us
Send an email