424 status code and 5 other rare 4xx codes explained
·4 min read
A 424 status code, Failed Dependency, means the server could not perform a request because it depended on another action that failed. It comes from WebDAV and almost never reaches a search crawler, which is true of most rare 4xx codes. If one of them shows up on a public HTML page by accident, it is a bug, and Google treats it exactly like a 404.
You will meet these six codes in logs and API errors more often than in Search Console. For the codes that shape crawling every day, read HTTP status codes for SEO.
How Google treats rare 4xx codes
Google treats every 4xx except 429 the same way. Its HTTP status code documentation says Google doesn't use content from URLs that return a 4xx, removes already indexed URLs that return one, and does not change crawl rate because of them. A 416 or 424 on a page you want ranked ends like a 404.
| Code | Name | Defined in | Usual trigger | SEO risk |
|---|---|---|---|---|
| 402 | Payment Required | RFC 9110 | Payment APIs, pay-per-crawl for AI bots | Real if bots get it |
| 412 | Precondition Failed | RFC 9110 | If-Match on a write request |
Very low |
| 416 | Range Not Satisfiable | RFC 9110 | Range header past the end of a file |
Very low |
| 417 | Expectation Failed | RFC 9110 | Unsupported Expect header |
Very low |
| 424 | Failed Dependency | RFC 4918 | An action it depended on failed | Very low |
| 425 | Too Early | RFC 8470 | Request replayable in TLS 1.3 early data | Low |
402 status code: payment required for AI crawlers
RFC 9110 says only that 402 "is reserved for future use." MDN notes there is no standard convention for it.
It now matters for crawlers. Cloudflare's pay per crawl answers an AI crawler with a 402 and a crawler-price header. The crawler can retry with a crawler-exact-price header to agree to pay.
HTTP/2 402 Payment Required
crawler-price: USD 0.01If you turned this on, make sure it applies only to the AI crawlers you priced. Googlebot reading a 402 sees a missing page. An AI search crawler that gets a 402 can't read, and so can't cite, the page.
412 and 417: headers the server could not honor
412 precondition failed
A 412 means a condition in the request headers evaluated to false. It protects writes. A client sends If-Match with an ETag, and if someone else changed the resource first, the server refuses the update instead of overwriting it.
Crawlers don't trigger it. RFC 9110's precondition rules say a false If-None-Match or If-Modified-Since on a GET returns 304 Not Modified, not 412. A 412 on a plain GET usually means a CMS or proxy is checking ETags wrong. Test the URL with and without conditional headers.
417 expectation failed
A 417 means a server in the chain could not meet the Expect request header. In practice that header is almost always Expect: 100-continue, which an upload client sends before a large request body. RFC 9110 says a client that gets a 417 for 100-continue should repeat the request without it. Expect 417s in upload logs, not on crawled pages.
416 status code: range not satisfiable
A 416 status code means the byte ranges in the Range header can't be served, usually because they start past the end of the file. A download resuming a file that has since shrunk is the usual cause. RFC 9110 says the server should report the real length.
HTTP/1.1 416 Range Not Satisfiable
Content-Range: bytes */47022Servers may ignore Range and send the whole file with a 200. A 416 on a normal page request means a cache or CDN stored a broken partial object. Purge it and refetch.
424 and 425 status codes
424 failed dependency
RFC 4918 defines 424 for WebDAV. Its example is PROPPATCH. If one command in the batch fails, the rest fail with 424. The same RFC notes that 424 appears only inside the body of a 207 Multi-Status response.
Outside WebDAV, some REST APIs reuse 424 when an upstream call fails. That is an API design choice, and crawlers never see it on HTML pages. If a public page returns 424, a backend dependency failed and your app picked the wrong code. A failed upstream is a server problem and should be a 502 or 503, which tells Google to retry instead of dropping the URL. See 502 Bad Gateway.
425 too early
A 425 status code means the server will not risk processing a request that could be replayed. RFC 8470 ties it to TLS 1.3 early data, also called 0-RTT, where a client sends its request before the handshake finishes. An attacker can replay early data, so a server or CDN may refuse non-idempotent requests that arrive that way, marked by Early-Data: 1.
The RFC says clients should retry automatically without early data, so users rarely notice. A 425 on a GET for a normal page means your 0-RTT rules are too strict. Allow early data for safe GET requests or turn 0-RTT off for that hostname.
Check status codes across a URL list
The HTTP Status Bulk Checker requests up to 20 pasted URLs with a GET, following up to 5 redirects. It returns each URL's final status code, the first redirect target, the hop count and the response time, and it flags any 4xx or 5xx. A rare code like 416 or 424 shows up as a client error on that row. When a site answers with a rate limit, a bot check or a 403, the tool marks the row as blocked instead. One run costs 20 credits.
It sends plain GETs without Range, If-Match or Expect headers and does not read page bodies. It shows what a normal visitor gets, not what an AI crawler under pay-per-crawl rules would get, and it cannot see what Googlebot recorded in Search Console.