A 301 says a page has moved for good. A 302 says it has moved for now. That is the whole difference in the HTTP specification, and for Google it decides which URL shows in search results. Neither code is a penalty. The harder parts are elsewhere: when 307 and 308 are the better choice, why a wrong 301 is hard to take back, and the cases where the right answer is no redirect at all. This page is a decision guide. It compares the four codes, walks through eight real situations, and shows how to check what a URL actually sends.
If you are fixing a redirect that already exists, look before you change anything. Browsers follow redirects silently, so the code you think you set and the code your server sends can differ. The free redirect checker shows every hop and its status code, as a browser sees it and as AI crawlers see it.
Google’s figures come from its site move guide[9] and its crawler documentation[8]. Vercel’s figures come from traffic on its own network, measured with MERJ, so they are a vendor study of one platform[15].
The difference in one minute
On screen, browsers treat both the same way. They read the Location header, load the new URL, and the visitor rarely notices[3][4]. The difference shows up in three places a visitor never sees: what search engines show in results, what browsers remember, and what happens to a form submission. For each code on its own, see 301 Moved Permanently and the 302 status code.
301 vs 302 vs 307 vs 308 compared
Four codes cover nearly every redirect, plus 303 for one special case. They differ on four questions. Is the move permanent? Must the browser keep the request method, so a form POST stays a POST? May a browser store the redirect without being told to? And what does Google do with it?
| Permanent? | Request method kept? | Stored without cache headers? | What Google does | Typical use | |
|---|---|---|---|---|---|
| 301 Moved Permanently | ✓Yes | GET stays GET. A POST may become GET | ✓Yes | Strong signal: shows the new URL | Moved pages, domain moves, http to https |
| 308 Permanent Redirect | ✓Yes | Yes, always | ✓Yes | Equivalent to 301 | Permanent moves where forms or APIs send to the old URL |
| 302 Found | ✕No | GET stays GET. A POST may become GET | ✕No | Weak signal: usually keeps the old URL | A/B tests, login walls, short-lived moves |
| 307 Temporary Redirect | ✕No | Yes, always | ✕No | Equivalent to 302 | Temporary moves where the method must survive |
| 303 See Other | ✕No | No: always becomes GET | ✕No | Temporary, like 302 | Sending a browser to a result page after a form |
Permanence is the main question. RFC 9110 defines 301 and 308 as permanent and 302 and 307 as temporary[1]. Everything else follows from it.
The request method only matters when something other than a normal page visit reaches the URL. The specification’s own history note explains why there are four codes instead of two. Early browsers split on whether to resend a POST as a POST after a 301 or 302, and “prevailing practice eventually converged on changing the method to GET.” 307 and 308 were added later “to unambiguously indicate method-preserving redirects”[1]. For ordinary visits, MDN puts it simply: “307 and 302 responses are identical when the request method is GET”[5].
Caching is the column most comparisons leave out. RFC 9110 lists 301 and 308 as “heuristically cacheable”: a browser or proxy may store them and reuse them even when the response carries no caching headers. 302, 303 and 307 are not on that list[1]. So a 301 can keep working in a returning visitor’s browser after you remove it from the server. Next.js describes its 308 as one that “instructs clients/search engines to cache the redirect forever”[16]. That is a framework’s summary, not the specification’s, but the instinct is right: treat a 301 as hard to take back.
Google follows all of them. Its crawler documentation calls a 301 a “strong signal” and a 302 a “weak signal” that the redirect target should be processed. It treats 307 as “equivalent to 302” and 308 as “equivalent to 301”[8]. Its redirects guide says permanent redirects show the new URL in search results, and temporary ones show the source page[7].
302 vs 307, and 308 vs 301
These two pairs differ only on the request method. Within each pair, the codes mean the same thing about time.
302 vs 307. Both say temporary. After a 307, the browser “MUST NOT change the request method” when it follows the redirect. After a 302, the specification allows a POST to become a GET “for historical reasons”[1]. Use 307 when a form, an API call or a webhook might reach the URL during the move. For pages people simply open, the two behave the same[5].
308 vs 301. Both say permanent, and Google treats them the same[8]. A 308 keeps the method; a 301 may turn a POST into a GET[6]. The specification adds one caution: 308 “is much younger (June 2014) than its sibling codes and thus might not be recognized everywhere”[1]. For a plain page move, 301 is the safe default. Use 308 for endpoints that receive data.
You may see 307 and 308 without choosing them. Next.js sends 308 for a redirect marked permanent and 307 for one that is not, precisely to keep the request method[16]. That is fine. A checker that reports 308 on a Next.js site is reporting a permanent redirect. Our Next.js SEO guide covers what else a Next.js site sends to AI crawlers.
| People and crawlers open it | Forms, APIs or webhooks send to it | |
|---|---|---|
| For good | 301 (308 also fine) | 308 |
| For now, or not sure | 302 (307 also fine) | 307 |
One more code fits a narrow job. After a form is submitted, a 303 sends the browser to a result page with a GET, so a refresh does not resubmit the form. The specification says 303 is “primarily used to allow the output of a POST action to redirect the user agent to a different resource”[1].
Decide in five steps
Most wrong redirects come from skipping the first question. Work through these in order.
Sources for the steps: Google on outages[11], on when to use permanent redirects[7] and on language redirects[12].
Eight real scenarios
The same two questions settle almost every case. In three of these eight, the honest answer is not a redirect at all.
| Send | Why | Watch out for | |
|---|---|---|---|
| Site migration or URL change | 301 (or 308) | The old URLs are retired for good | Chains. Map each old URL straight to its final URL |
| http to https | 301 (or 308) | The http address is never coming back | Fixing https and www in two hops instead of one |
| A/B test on a separate URL | 302 | Google asks for it, so the original stays indexed | Leaving the test running longer than needed |
| Maintenance | Whole site: no redirect, a 503. One service: 302 | The pages have not moved | Redirecting every URL to a maintenance page |
| Language or country | Ideally none. If you must: 302 | The answer depends on who is asking | Crawlers only ever seeing one version |
| Login wall | 302 or 307 to the login page; 303 after the form | The protected page still exists | A 301 that browsers may store |
| Out-of-stock product | None while it is coming back. 301 to a true replacement once it is gone | The product page is still the right page | Sending discontinued products to the home page |
| URL shortener or campaign link | 302 or 307 if the target may change; 301 if it never will | A 301 may be stored by browsers | Editing a link that browsers have already stored |
Site migration or URL change
Use a 301. Google recommends “a permanent server-side redirect whenever possible” when a URL changes[7], and its site move guide names 301 and 308[9]. Two details matter more than the code. Point each old URL straight at its final URL: Google advises redirecting to the final destination directly, or keeping a chain “ideally no more than 3 and fewer than 5” hops. And don’t send many old URLs to one unrelated page such as the home page, which Google says “might be treated as a soft 404 error”[9]. The 301 guide covers mapping and setup in detail.
http to https
Also a 301 (or 308), because the http address is not coming back. Google’s site move guide covers http to https moves, and notes you don’t need its Change of Address tool for them[9]. The common mistake is two hops: http to https, then the bare domain to www. Combine them, so every old variant reaches the final address in one redirect. Google says to keep redirects “for as long as possible, generally at least 1 year”, and from users’ perspective to “consider keeping redirects indefinitely”[9].
A/B test
Use a 302. Google is explicit: if a test redirects users from the original URL to a variation, “use a 302 (temporary) redirect, not a 301 (permanent) redirect”, so search engines keep the original URL in the index[10]. Google also accepts JavaScript redirects for tests. A crawler that does not run JavaScript will simply see the original page, which is what you want. End the test when it has its answer. Google warns that a site running an experiment “for an unnecessarily long time” may be read as an attempt to deceive search engines[10].
Maintenance
For a site-wide outage, the right answer is not a redirect. If a site must go offline for a day or two, Google recommends “an informational error page with a 503 HTTP response status code”, with a retry-after header giving a best-effort date or duration[11]. A redirect would tell crawlers your pages live somewhere else, which is not true. A temporary redirect does fit a narrower case. In Google’s own example, “if a service your site offers is temporarily unavailable, you can set up a temporary redirect to send users to a page that explains what’s happening”[7].
Language or country redirects
Google advises against them: “Avoid automatically redirecting users from one language version of a site to a different language version”, because these redirects “could prevent users (and search engines) from viewing all the versions of your site”[12]. Crawlers make it worse. Googlebot’s default IP addresses “appear to be based in the USA”, and it sends no Accept-Language header. Google also crawls from other countries, but it still recommends separate URLs for each locale[13]. In Vercel’s 2024 data, every AI crawler it measured ran from US data centres[15], so an IP-based redirect may show them only one version. Use separate URLs with hreflang and a visible language switcher. If you must send a bare domain to a locale, keep it temporary, because the answer changes with the visitor.
Login walls
When a logged-out visitor opens a members-only page, send a 302 (or 307) to the login page. The members page has not moved; it is just not for them yet. After the login form is submitted, a 303 is the textbook way to send the browser on to the next page[1]. A 301 would be wrong twice. The page has not moved, and because a 301 is heuristically cacheable, a browser may store it and keep sending a signed-in person back to the login page.
Out-of-stock products
While a product is coming back, don’t redirect at all. Google’s advice for shops is to “still allow that page, and mark it out of stock”, so people can understand what is going on[11]. Once a product is gone for good, our advice is a 301 to a genuine replacement, such as the newer model. If nothing truly replaces it, let the page return a 404 or 410 rather than sending everyone to the home page, which Google says may be treated as a soft 404[9].
URL shorteners and campaign links
A short link is a redirect you may want to edit later. If the destination might change, use a 302 or 307, which browsers do not store by default[1]. If the destination is fixed for good, a 301 is fine. Check which code your shortener sends before you count on editing a link later.
What happens when you pick wrong
Neither mistake is a disaster. Both cost time, and one is much harder to undo.
A 302 on a permanent move
Google says it does not use a temporary redirect as a signal that the target should be canonical, so the old URL tends to stay in results. It adds: “The target page might still be indexed if other canonicalization signals are present”[7]. Over time those other signals often win. Google’s John Mueller explained in 2021 that this is “why a 302 ‘source-preferred’ ends up being treated more like a 301 ‘destination-preferred’ over time”, for example when “all internal & external links point to the destination”. He added: “There’s no fixed cut-off time for that”[14].
So the cost is not a penalty. Mueller also said “the rankings will generally be the same” whichever URL is shown[14]. The cost is control. You leave the choice of URL to Google’s canonicalization, on its timetable, and other search engines and AI systems don’t document what they do. The fix is simple: change it to a 301 now.
A 301 on a temporary move
This one is harder to undo. Browsers may store a 301 without any cache headers, because the specification makes it heuristically cacheable[1]. Remove the redirect from your server, and returning visitors whose browser stored it can keep landing on the temporary page. There is no simple way to recall it from every browser that kept it. Google, meanwhile, takes the 301 as a strong signal[8] and may start showing the temporary URL. Its advice: use permanent redirects “when you’re sure that the redirect won’t be reverted”[7].
If you must send a 301 that might change, send an explicit freshness limit with it, such as Cache-Control: max-age=3600. The caching specification says a cache “MUST NOT use heuristics to determine freshness when an explicit expiration time is present”[2]. That caps how long a browser keeps it.
AI crawlers and 301 vs 302
Start with what is not known. OpenAI’s, Anthropic’s and Perplexity’s crawler documentation describes their bots and how to control them with robots.txt. None of it, read on 2 October 2026, says how their crawlers treat a 301 differently from a 302[17][18][19]. A claim that an AI engine “passes authority” through one code and not the other is a guess.
What has been measured is narrower. Vercel and MERJ found that ChatGPT’s crawler spent 14.36% of its fetches following redirects, against 1.49% for Googlebot. They also found that none of the major AI crawlers they measured render JavaScript[15]. Four practical rules follow.
- Redirect on the server. A JavaScript redirect is invisible to a crawler that does not run JavaScript. It reads the old page and stops there.
- Keep it to one hop. Each extra hop is another request for a crawler that already spends a large share of its fetches on redirects.
- Link to final URLs. Update internal links, canonicals and the sitemap so crawlers rarely meet a redirect at all. Vercel’s own advice is to keep sitemaps current and URL patterns consistent[15].
- Pick the honest code anyway. Google’s point about using the semantically right code so “other clients” benefit applies here[8].
A crawler can also be treated differently from a browser, for example by bot protection rules. The AI crawler checker shows whether your robots.txt lets each bot in, and the guide to AI crawler log file analysis shows how to see what they actually received.
How to check what a URL sends
Your browser hides redirects. It follows them before it shows you anything, so the address bar only shows the end of the trip. Three ways to see the codes:
A redirect checker. Paste a URL into the free redirect checker. It records every hop with its status code and Location, then runs the chain again as GPTBot, ClaudeBot, PerplexityBot and Googlebot, so you can see whether a crawler is sent somewhere else. Bulk mode takes up to 10 URLs at once.
Browser developer tools. Open the Network tab, turn on the option that keeps the log across page loads, and open the old URL. The first row shows the 3xx code and its Location header.
The command line. curl shows the first response without following it:
# Show the first response only, without following it curl -sS -o /dev/null -D - https://example.com/old-page # Look for two lines in the output: # HTTP/2 301 <- the status code # location: https://example.com/new-page
If the checker shows a chain that comes back to a URL it already visited, that is a loop, and browsers will stop with an error. ERR_TOO_MANY_REDIRECTS covers the usual causes and fixes.
Checking a whole site
Checking one URL at a time only finds the redirects you remember. The ones that pile up are usually old internal links and sitemap entries nobody has looked at in years. CoreCited’s GEO Audit crawls your site and flags every page that answers with a redirect instead of a clean 200. The free account audits 10 pages, and every limit is on the pricing page.
Questions people ask
What is the difference between a 301 and a 302 redirect?
A 301 says a page has moved permanently and the new URL should be used from now on. A 302 says it has moved temporarily and the old URL should still be used. Google shows the new URL in results for a 301 and usually keeps the old one for a 302. Browsers may also store a 301 without being told to; they do not store a 302 by default.
Is a 302 redirect bad for SEO?
No. A 302 is the right code for a temporary move, and Google asks for one during A/B tests. It is only a problem when the move is really permanent: Google then tends to keep the old URL in results until other signals win. John Mueller of Google has said a long-standing 302 often ends up treated like a 301, with no fixed cut-off time.
What is the difference between 302 and 307?
Both are temporary. A 307 forbids the browser from changing the request method, so a form POST stays a POST. After a 302, browsers may turn a POST into a GET. For ordinary page visits the two behave the same, and Google treats 307 as equivalent to 302.
Should I use 308 or 301?
For a normal page move, either. Google treats 308 as equivalent to 301. Use 308 when forms, APIs or webhooks send data to the old URL, because it keeps the request method. 301 is the safer default for plain pages, since the HTTP specification notes that 308 dates from 2014 and might not be recognised everywhere.
Can I change a 302 to a 301 later?
Yes, and you should as soon as you know the move is permanent. Google then gets a strong signal that the new URL is the one to show. Going the other way is harder: browsers may already have stored the 301, so returning visitors can keep following it after you change the server.
Do AI crawlers treat 301 and 302 differently?
Nobody outside the AI companies knows, and they do not say. OpenAI's, Anthropic's and Perplexity's crawler documentation does not mention redirect codes. What is measured: Vercel's data shows OpenAI's crawler following redirects, and none of the major AI crawlers it studied run JavaScript, so a JavaScript redirect leaves them on the old page.
