Rebuilt September 2026

HTTP Status Codes and PHP: Redirects, Missing Pages and Server Errors

HTTP status codes tell browsers, APIs and search engines what happened to a request. Returning the correct status matters because a page that visually says “not found” while returning 200 is very different from a real 404 response.

Status-code classes

HTTP status codes are grouped by the first digit

RangeMeaningExamples
100–199Informational100 Continue
200–299Successful200 OK, 204 No Content
300–399Redirection301, 302, 307, 308
400–499Client error400, 401, 403, 404, 410, 429
500–599Server error500, 502, 503, 504
Permanent redirect

301 Moved Permanently

Use a permanent redirect when an old URL has a clear long-term replacement. RFC 9110 defines 301 as a permanent move, and Google recommends server-side permanent redirects such as 301 or 308 when a page has permanently moved.

<?php
header('Location: https://www.example.com/new-page.php', true, 301);
exit;
?>
Headers must be sent before output. Do not echo HTML, print spaces or send other body content before calling header().

This is the status we will normally use when retiring an old Plus2Net article that has a closely matching replacement. We should also update our own internal links to point directly to the new URL rather than relying on the redirect forever.

Permanent redirect with method preservation

308 Permanent Redirect

A 308 is also a permanent redirect. Unlike historical 301 behavior, it preserves the request method and request content. It can be useful for APIs or non-GET requests where method preservation matters.

Temporary redirect

302 Found and 307 Temporary Redirect

Use a temporary redirect when the original URL is expected to return to normal use. Google treats 302 and 307 as temporary redirect signals rather than as a permanent replacement.

<?php
header('Location: https://www.example.com/temporary-page.php', true, 302);
exit;
?>
Missing resource

404 Not Found

A 404 means the server did not find a current representation of the requested resource or is not willing to disclose that one exists.

<?php
http_response_code(404);
?>

<h1>Page not found</h1>
<p>Try the search box or return to the home page.</p>

A useful custom 404 page can retain your normal navigation and suggest helpful destinations, but the server must still return the actual 404 status. Returning a friendly error message with HTTP 200 can create a soft 404.

Permanently gone

410 Gone

RFC 9110 says 410 is preferred over 404 when the server knows the resource is intentionally and likely permanently unavailable.

<?php
http_response_code(410);
?>

For SEO migrations, however, if a useful replacement exists, a relevant 301 redirect is normally better for users than returning 410.

Authentication and authorization

401 Unauthorized vs 403 Forbidden

  • 401 Unauthorized: the request lacks valid authentication credentials. A 401 response includes a WWW-Authenticate challenge.
  • 403 Forbidden: the server understands the request but refuses to fulfill it. Authentication may exist, but access is not allowed.
Rate limiting

429 Too Many Requests

Use 429 when a client has sent too many requests under your rate-limiting policy. Where appropriate, a Retry-After header can tell the client when to try again.

Server problems

500, 502, 503 and 504

CodeTypical meaning
500The server encountered an unexpected condition.
502A gateway or proxy received an invalid response from an upstream server.
503The service is temporarily unavailable, often because of overload or maintenance.
504A gateway or proxy timed out waiting for an upstream server.

RFC 9110 allows a 503 response to include Retry-After when the server can suggest when the client should retry.

SEO decisions

Which status should a removed or moved page return?

SituationRecommended response
Old page has a close permanent replacement301 or 308 to the replacement
Move is temporary302 or 307
URL never existed / no replacement404
Content intentionally removed permanently with no replacement404 or 410; 410 communicates known permanent removal
Temporary maintenance/outage503 when appropriate

For our Plus2Net retirement workflow, see the internal rules captured in the Webpage Audit Framework: preserve useful material, update internal links, redirect to the closest relevant page and monitor Search Console afterward.

Summary

The HTTP code is part of the meaning of the response

Do not rely only on visible text. Use the status code that matches what actually happened: success, permanent move, temporary move, missing page, restricted access or server failure.

Official references

Further reading