Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

HTTP 511 means “Network Authentication Required.” An intercepting proxy on the network path is blocking access until you complete a required step, such as signing in to a Wi-Fi captive portal, accepting terms, or otherwise authenticating. The requested website usually did not generate the response, and fixing the website’s own login will not normally resolve it.

What a 511 response means

Status code 511 is defined for a network intermediary that controls access to the internet connection. It tells your client that the original request cannot reach its destination until the network’s requirement has been satisfied.

The common example is public Wi-Fi. A hotel, airport, café, school or enterprise network may allow only the portal itself before you accept terms or enter a password. Requests to ordinary websites are intercepted and answered with 511 until that process is complete.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Network-controlled: the response normally comes from an intercepting proxy, gateway or firewall.
  • Not the origin site’s login: the website in your address bar is generally not asking for these credentials.
  • Usually temporary: after the network marks your device as authorized, retrying the request should work.

Why 511 is different from other authentication errors

Status Typical source What it indicates
401 Unauthorized The origin server The requested resource needs HTTP authentication, such as a bearer token or basic credentials.
403 Forbidden The origin server or an intermediary The server understood the request but refuses to authorize it.
407 Proxy Authentication Required An explicit proxy The client must authenticate to the proxy itself.
511 Network Authentication Required An intercepting network proxy The network requires a separate access step before forwarding traffic to the destination.

That distinction matters operationally. Adding an Authorization header for the destination website will not satisfy a captive portal. You must use the network’s access process.

#1 Best Overall
Sale
Pearson Computer Networking, 8E
  • brand: Pearson
  • Computer Networking, 8e

What the 511 response should contain

RFC 6585 specifies that a 511 representation should include a link to a separate resource where the user can submit credentials or complete the requirement. The 511 response itself should not embed the login challenge or pretend that the destination website owns the form. Otherwise, a browser could make a network login appear to belong to the URL the user intended to visit.

The network may require a password, payment, terms acceptance, device registration or another access action. Follow the supplied network link, complete that process, then request the original URL again.

How to fix a 511 error as a user

  1. Check the network you joined. Confirm that you are on the expected Wi-Fi or wired network rather than a similarly named access point.
  2. Open the portal link. Use the link in the 511 response if one is shown. If your browser does not display it, open a new tab and visit a plain HTTP address you trust; captive portals often use an HTTP request to trigger their sign-in page.
  3. Complete every required step. Sign in, enter an access code, accept terms, pay if required, or register the device according to the network’s instructions.
  4. Retry the original page. Reload the tab or repeat the API request after the portal confirms access.
  5. Check the device and network state. Disconnect and reconnect Wi-Fi, disable and re-enable the interface, or restart the device if the portal says you are authorized but traffic remains intercepted.
  6. Ask the network operator for help. Provide the time, your device, the network name and the exact 511 response. The operator may need to clear a stale session or authorize your device’s MAC address.

When HTTPS appears to fail instead

Modern browsers normally cannot safely redirect an HTTPS request to an unrelated login page. You may therefore see a certificate warning, a connection failure or a page that never loads instead of a readable 511. Disconnecting from a VPN temporarily, opening the portal through the network’s official sign-in mechanism, or contacting the operator is safer than bypassing a certificate warning. Do not enter credentials into a certificate warning page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Diagnosing 511 in command-line clients and applications

First inspect the status and headers without assuming that the destination application is at fault:

curl -i https://example.com/

Look for HTTP/1.1 511 or HTTP/2 511, a Location header, and a response body containing the network’s instructions. Follow only a login URL that you recognize as belonging to the network operator.

Do not cache the response

RFC 6585 requires that a 511 response not be stored by a cache. It describes the access state of a particular client and network, not a reusable representation of the origin resource. Reverse proxies, service workers and application caches should treat it as non-cacheable and retry only after the access requirement has been completed.

What automated clients should do

  • Record the 511 status, response headers and a bounded portion of the body for diagnosis.
  • Expose the network-login link to an operator or user instead of silently retrying forever.
  • Stop automatic retries until the network state changes; repeated requests do not authenticate a captive portal.
  • After authorization, create a fresh request rather than replaying credentials intended for the origin.
  • Keep secrets out of logs. A portal URL can contain session data even when it does not contain a password.

Common causes and targeted fixes

Public Wi-Fi session has not been accepted

Open the venue’s portal, accept its terms and retry. If the portal is not appearing, forget and rejoin the network, then make a normal HTTP request to trigger discovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VPN, proxy or secure DNS is hiding the portal

Some networks cannot redirect traffic correctly while a VPN or manually configured proxy is active. Temporarily disable it only long enough to authenticate on a network you trust, then restore the setting. Do not disable security software permanently.

Authorization expired

Captive-portal sessions can expire after a time limit or when your device changes its network identity. Sign in again or ask the operator to renew the session.

Only one application receives 511

Compare that application’s proxy, DNS, certificate and IPv4/IPv6 settings with a browser that can reach the portal. A system-wide gateway may be reachable while an application is pinned to a different proxy or resolver.

A server or API monitor receives 511

Check whether the monitoring location is behind a corporate gateway, hotel network or cloud egress policy. The origin server cannot generally fix an intermediary-generated 511. Move the request to an authorized network or configure the intermediary according to its administrator’s instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How networks are moving beyond ad-hoc interception

RFC 6585 (April 2012) documents the 511 response in the captive-portal context and notes that it is intended to limit damage to software expecting a response from the contacted server, not to promote captive portals.

Newer specifications provide an explicit discovery and API model:

  • RFC 8910 (September 2020) defines DHCPv4, DHCPv6 and IPv6 Router Advertisement options that can tell a client it may be behind a captive portal and provide the Captive Portal API URI. The option code is 114; it replaced the earlier code point 160 from RFC 7710.
  • RFC 8952 (November 2020) describes an architecture based on network provisioning, an optional captive-portal signal and an HTTPS API, avoiding the fragile practice of altering DNS or forging ordinary HTTP responses.
  • RFC 8908 specifies the Captive Portal API and requires its endpoint to use HTTPS.

These mechanisms let capable clients discover portal state directly instead of learning about it only after an unrelated request is intercepted. They do not change the meaning of an existing 511 response.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Capturing evidence when troubleshooting a 511

A screenshot can preserve the portal instructions, browser warning and visible network branding for an administrator. Capture only pages and information you are authorized to handle; portal screens may display account details or session identifiers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

ScreenshotNeo can request a page with one HTTP call and return PNG, JPEG, WebP or PDF. Its cleanup step accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. A 511 generated by a private captive network may still require access from an authorized network, but ScreenshotNeo is useful for documenting a publicly reachable error page.

See the full parameter list in the ScreenshotNeo documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

511 implementation checklist

  • Generate 511 only from a network intermediary that controls access, not from the origin website’s normal authentication handler.
  • Include a link to a separate network login or access resource.
  • Do not place the network’s authentication challenge in the 511 response as if it belonged to the destination.
  • Mark the response non-cacheable.
  • Provide clients with a clear recovery path and avoid endless automated retries.

Frequently Asked Questions

Is HTTP 511 a permanent error?

No. It normally describes the current access state of a client on a controlled network. It can disappear after the required portal step is completed, although a network operator may impose a recurring or time-limited requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a website owner remove a visitor’s 511 response?

Usually not. Because 511 is normally inserted by a network intermediary, the site owner can only investigate if its own infrastructure is incorrectly emitting the status.

Is it safe to submit credentials on any page linked from 511?

Use only the network operator’s recognized portal and verify the connection and certificate. Do not override browser certificate warnings or enter credentials into an unfamiliar page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.