October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

Forcing IIS to Display Custom Error Messages

Use IIS’s httpErrors section to map status codes to files, internal URLs, or redirects while keeping detailed diagnostics local and protecting remote users.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure IIS’s <httpErrors> section under <system.webServer>. For a safe troubleshooting setup, use errorMode="DetailedLocalOnly": requests from the server itself receive details, while remote clients receive your custom response. Set this in ApplicationHost.config for server-wide behavior or in an application or site Web.config when delegation permits it.

First identify which layer generated the error

IIS-generated HTTP errors are controlled by <system.webServer><httpErrors>. ASP.NET’s <customErrors> section is separate and applies to framework-generated errors. Changing one does not automatically change the other.

Before editing configuration, reproduce the failure and note the HTTP status and IIS substatus. A 404 substatus, for example, can distinguish a missing file from an unmapped extension, missing handler, filtering rule, or hidden file. The status and substatus tell you which error entry IIS must match and whether the underlying problem is routing, configuration, security, or application code.

Choose who should see details

Goal Setting Result
Debug locally without exposing internals errorMode="DetailedLocalOnly" Detailed errors for local requests; configured custom errors for external requests. This is the documented default.
Show a friendly page to every client errorMode="Custom" Uses custom errors for local and remote requests, including when the request originates on the server.
Temporarily diagnose a problem from any client errorMode="Detailed" Sends detailed errors to all clients. Do not leave this enabled on a publicly reachable site because the response can disclose internal information.

Use Detailed only for a controlled, short-lived investigation. Return to DetailedLocalOnly or Custom after testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set a custom page for a status code

Add an <httpErrors> element to the relevant configuration scope. This example keeps details local and serves a static file for HTTP 500 responses:

<configuration>
  <system.webServer>
    <httpErrors errorMode="DetailedLocalOnly" defaultResponseMode="File">
      <remove statusCode="500" />
      <error statusCode="500"
             path="C:inetpubcusterr500.htm"
             responseMode="File" />
    </httpErrors>
  </system.webServer>
</configuration>
  • Confirm that C:inetpubcusterr500.htm exists and is readable by IIS.
  • <remove statusCode="500" /> removes an inherited entry before defining the site’s version.
  • The path is a file-system path because the response mode is File.

Microsoft’s configuration reference also documents language-specific files through prefixLanguageFilePath. Use that pattern when the error page must vary by language.

Understand the three custom-response modes

File: serve static content

Use responseMode="File" when the value of path identifies a file on the server, such as an HTML error document. This is appropriate for a self-contained static page.

ExecuteURL: run an internal URL

Use responseMode="ExecuteURL" when IIS should execute a server-relative URL internally. The target is an application path, not a file-system path and not an external address.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Redirect: send the client elsewhere

Use responseMode="Redirect" when the client should receive a redirect. The target must be an absolute URL. A redirect causes a new client request, so it is different from serving or executing an error page inside the current request.

An <error> entry can match a status code and, where needed, a substatus. If an inherited entry prevents the desired match, remove that entry or clear inherited entries at the appropriate scope.

Control whether IIS replaces an application response

An application, managed module, or framework may already have produced an error body. The existingResponse setting determines whether IIS preserves that body or substitutes the configured custom response.

Value Behavior
PassThrough Preserves the existing response.
Replace Replaces the existing response with the IIS custom error response.
Auto Lets IIS apply its ordered rules based on the error mode, whether a response body exists, and whether the producing module set the fTrySkipCustomErrors flag.

If your application returns a carefully designed 500 or 404 body but IIS shows a different page, inspect existingResponse and the application’s response handling before changing the page path. Conversely, if IIS should enforce one standard page, Replace is the explicit choice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A reliable troubleshooting sequence

  1. Reproduce and record the code. Capture the HTTP status and IIS substatus from the response, browser tools, or logs.
  2. Identify the producer. Decide whether IIS, ASP.NET, another framework, or application code generated the response. Configure <httpErrors> only for the IIS layer.
  3. Check exposure settings. Review errorMode and existingResponse. Also check whether application code supplied a body or asked IIS to skip custom errors.
  4. Verify the matching entry. Confirm that the required status and substatus entry exists, and that its responseMode agrees with the path or URL format you supplied.
  5. Validate scope and inheritance. A server-level setting in ApplicationHost.config can be inherited by sites and applications. A Web.config change may be blocked when the section is not delegated; in that case, have the server administrator make the change or adjust delegation deliberately.
  6. Trace failures that are hard to reproduce. Configure IIS Failed Request Tracing for the relevant failure condition, then inspect its events. It can capture useful diagnostics for intermittent failures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common reasons the custom page does not appear

The request is local

With DetailedLocalOnly, a request made on the IIS server is expected to show detailed information rather than the remote custom page. Test from a separate client when checking the external experience, or temporarily choose Custom.

The application supplied its own body

existingResponse="Auto" may preserve an application response, especially when the module indicates that IIS should skip custom errors. Inspect the response producer and choose PassThrough or Replace intentionally.

The target value uses the wrong kind of path

A file-system path belongs with File; an internal server-relative URL belongs with ExecuteURL; an absolute URL belongs with Redirect. Mixing these formats prevents the intended action.

An inherited entry wins

Remove the specific inherited status entry, or clear inherited entries where appropriate, before adding the site-level rule. Confirm that the configured status and substatus actually match the failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Learn Windows IIS in a Month of Lunches
  • Used Book in Good Condition

The error is not an IIS error

If ASP.NET or application code generated the response, configure that framework or code path instead of expecting <httpErrors> to control it.

Version and deployment scope

The <httpErrors> section was introduced in IIS 7.0 and the Microsoft reference lists it as unchanged in IIS 8.0, 8.5, and 10.0. IIS 6.0 uses a different metabase property. Configuration support and delegation still depend on how the server is administered, so verify the target IIS version and whether the section is allowed at the scope where you are editing.

Quick Recap

SaleBestseller No. 3
SaleBestseller No. 4
SaleBestseller No. 5
Learn Windows IIS in a Month of Lunches
Learn Windows IIS in a Month of Lunches
Used Book in Good Condition
$42.06

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.