DNS RobotDNS Propagation Checker
HomeDNS LookupWHOIS LookupIP LookupSSL Check
DNS RobotDNS Propagation Checker

Next-generation DNS propagation toolkit

Privacy PolicyTerms of ServiceAbout UsBlogContact

DNS Tools

DNS LookupDNS Speed TestDomain to IPNS LookupMX LookupView all

Email Tools

SPF Record CheckerDMARC CheckerDKIM CheckerSMTP Test ToolEmail Header AnalyzerView all

Website Tools

WHOIS LookupHosting CheckerDomain AvailabilitySubdomain FinderCMS DetectorView all

Network Tools

Ping ToolTraceroutePort CheckerHTTP Headers CheckSSL Certificate CheckView all

IP Tools

IP LookupWhat Is My IPIP Blacklist CheckIP to HostnameASN LookupView all

Utility Tools

QR Code ScannerQR Code GeneratorUPI QR Code GeneratorWiFi QR Code GeneratorMorse Code TranslatorView all
© 2026 DNS Robot. Developed by ❤ Shaik Brothers
All systems operational
Made with
Home/Blog/405 Method Not Allowed: What It Means & How to Fix It

405 Method Not Allowed: What It Means & How to Fix It

Shaik VahidSep 30, 20268 min read
405 Not Allowed nginx error page next to the step-by-step fixes for 405 Method Not Allowed
405 Not Allowed nginx error page next to the step-by-step fixes for 405 Method Not Allowed

Key Takeaway

405 Method Not Allowed means the server recognises the URL but doesn't accept the HTTP method you used there, for example a POST sent to a page that only accepts GET. RFC 9110 requires the server to list the methods it does accept in an Allow header, so start by reading that header. Typical causes are a form or API call using the wrong method, a POST to a static file on nginx, a route handler that doesn't export that method (Next.js, Flask, Django), WebDAV intercepting PUT and DELETE on IIS, and CORS preflight OPTIONS requests the server doesn't handle.

Advertisement

What Is a 405 Method Not Allowed Error?

405 Method Not Allowed is an HTTP status code meaning the server knows the address you requested, but doesn't allow the method your request used. RFC 9110 (section 15.5.6) defines it as the method being "known by the origin server but not supported by the target resource."

Every HTTP request has a method: GET to read a page, POST to submit a form or create something, PUT and PATCH to update, DELETE to remove, OPTIONS to ask what's allowed. A 405 means the URL exists, but not for that verb. If the URL didn't exist at all, you'd get 404 instead.

Because it's about how a request was made rather than about a missing page, a 405 is almost always something for the site's developer to fix. Visitors usually hit it after submitting a form or following an outdated link.

Note

The standard says a 405 response must include an Allow header listing the methods the URL does accept, for example Allow: GET, HEAD. It's the fastest clue to what went wrong.

What a 405 Error Looks Like

Server / frameworkTypical message
nginx405 Not Allowed (with nginx underneath)
ApacheMethod Not Allowed. The requested method POST is not allowed for this URL.
IISHTTP Error 405.0 - Method Not Allowed. The page you are looking for cannot be displayed because an invalid method (HTTP verb) is being used.
Next.js / APIsAn empty or JSON response with status 405, often visible only in DevTools
Browser console (CORS)A CORS error, because the OPTIONS preflight received a 405

Advertisement

Step 1: Read the Allow Header

Ask the server which methods it accepts for that URL. Either send an OPTIONS request, or repeat the failing request with headers shown:

bash
# Which methods does this URL accept?
curl -i -X OPTIONS https://example.com/api/contact

# Repeat the failing request and look at the status and Allow header
curl -i -X POST https://example.com/api/contact -d 'name=test'
# HTTP/2 405
# allow: GET, HEAD

DNS Robot's HTTP Headers tool shows the status code and headers a URL returns to a normal GET request, which helps when you're checking a page in the browser rather than an API.

Not every server follows the rule. nginx's built-in 405 page, for example, is sent without an Allow header, so on nginx you'll need to check which location block handles the URL instead (Fix 2).

If You're a Visitor

  • Go back and reload the page, then submit the form again. A form loaded from an old cached copy can post to an address that has since changed.

  • Don't refresh after submitting. Refreshing a page that was the result of a form can resend a POST to a URL that only accepts GET.

  • Check the address for a typo, or open the site's homepage and navigate again.

  • Report it. If a form on the site always fails, the site owner needs to fix it, so send them the page address.

Advertisement

Fix 1: Send the Right Method to the Right URL

The most common cause in code is simply a mismatch: a form or fetch() call uses POST while the endpoint only accepts GET, or the request goes to the page URL instead of the API URL. Compare the method in your code with the Allow header and the API's documentation.

javascript
// The endpoint only allows POST, so a GET (the default for fetch) returns 405
const res = await fetch("/api/contact", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({ name: "Ana" }),
})
if (res.status === 405) console.log("Allowed:", res.headers.get("allow"))

Tip

Watch for trailing slashes and redirects. If /api/contact redirects to /api/contact/ with a 301 or 302, many clients repeat the request as GET, and a POST-only endpoint then answers 405. Use the Redirect Checker to see every hop.

Fix 2: nginx Returns 405 for POST to Static Files

nginx's static file handler only serves GET and HEAD. A POST to an .html file, or to a location that serves files instead of passing the request to your application, gets 405 Not Allowed. This often happens when a form's action points at a static page, or when a location block meant for your app doesn't match.

The real fix is to send the POST to an application (PHP, Node, Python) with proxy_pass or fastcgi_pass in the right location block. Check which block handles the URL:

nginx
# Form posts must reach the app, not the static file handler
location /api/ {
    proxy_pass http://127.0.0.1:3000;
}

# Test and reload after changes
# sudo nginx -t && sudo systemctl reload nginx

Tip

Some guides suggest error_page 405 =200 $uri; to turn the 405 into a 200. That only hides the error: the POST data still never reaches your code. Route the request to the application instead.

Advertisement

Fix 3: IIS Blocks PUT and DELETE (WebDAV)

On Windows servers running IIS, the WebDAV module claims the PUT and DELETE verbs, so REST APIs (ASP.NET Web API and others) answer HTTP Error 405.0 for them. If you don't use WebDAV, remove it for your site in web.config:

xml
<system.webServer>
  <modules>
    <remove name="WebDAVModule" />
  </modules>
  <handlers>
    <remove name="WebDAV" />
  </handlers>
</system.webServer>

Also check the site's Request Filtering settings in IIS Manager (HTTP Verbs tab), which can deny specific methods outright (IIS reports those as 404.6, not 405).

Fix 4: Add the Method to Your Route Handler

Frameworks return 405 when a route exists but has no handler for the method used:

  • Next.js (App Router): a route.ts only answers the methods it exports. If it exports GET but not POST, a POST returns 405. Add export async function POST(request: Request) { … }.

  • Flask: routes accept only GET by default. Use @app.route("/contact", methods=["GET", "POST"]).

  • Django: class-based views return 405 for methods without a matching handler (add a post() method), and the require_http_methods decorator does the same.

  • Express: by default an unmatched method falls through to 404, not 405. If your API should return 405, add a catch-all handler that sets the Allow header.

Warning

Don't fix a 405 by allowing every method on every route. Allow only what each endpoint actually supports, and keep the Allow header accurate.

Advertisement

Fix 5: Handle CORS Preflight (OPTIONS) Requests

When a web page calls an API on another domain with JSON or custom headers, the browser first sends an OPTIONS preflight request. If the API answers that OPTIONS request with 405, the browser reports a CORS error and never sends the real request, even though the real endpoint would have worked.

Make the API answer OPTIONS for those routes with a 204 or 200 and the right Access-Control-Allow-Methods and Access-Control-Allow-Headers headers. Most frameworks have CORS middleware that does this for you. For example, DNS Robot's own DNS Lookup API answers the preflight with 204 and the CORS headers, so browsers can call it from any site.

Tip

In DevTools (F12) → Network, enable the filter that shows all requests and look for the OPTIONS request just before the failed call. Its status tells you whether the preflight was the problem.

405 vs 400, 403, 404 and 501

CodeMeaning
405 Method Not AllowedThe URL exists, but not for this method
400 Bad RequestThe request itself is malformed
403 ForbiddenThe server understood you but won't allow access
404 Not FoundNothing exists at this URL
501 Not ImplementedThe server doesn't support this method for any URL

Related guides: 400 Bad Request, 403 Forbidden and 401 Unauthorized.

Check what a URL returns

DNS Robot's HTTP Headers checker shows the status code and response headers for any URL, so you can confirm a 405 and see the server software behind it.

Try HTTP Headers Checker

Advertisement

Frequently Asked Questions

It means the server recognises the URL but doesn't accept the HTTP method used, such as a POST sent to a page that only allows GET. The response should include an Allow header listing the methods that URL does accept.

Related Tools

HTTP Headers CheckRedirect CheckerSSL Certificate Check

Related Articles

400 Bad Request: What It Means & How to Fix It403 Forbidden Error: What It Means & How to Fix ItHTTP 401 Unauthorized Error: What It Means & How to Fix It

Table of Contents

  • What Is a 405 Method Not Allowed Error?
  • What a 405 Error Looks Like
  • Step 1: Read the Allow Header
  • If You're a Visitor
  • Fix 1: Send the Right Method to the Right URL
  • Fix 2: nginx Returns 405 for POST to Static Files
  • Fix 3: IIS Blocks PUT and DELETE (WebDAV)
  • Fix 4: Add the Method to Your Route Handler
  • Fix 5: Handle CORS Preflight (OPTIONS) Requests
  • 405 vs 400, 403, 404 and 501
  • Frequently Asked Questions