# 510 Not Extended (HTTP Extension Framework)

> 510 Not Extended comes from the experimental HTTP Extension Framework in RFC 2774, now historic. See what it meant and what to do if you hit it.

Source: https://howhttpworks.com/status-codes/510
Last reviewed: 2026-10-04

> **TL;DR:** 510 Not Extended belongs to RFC 2774, an experimental HTTP extension framework that went unused and was moved to Historic. A 510 today is a product-specific response you must read the body of, not a signal clients can act on in a standard way.

## What it was for

RFC 2774 (2000) defined a way for HTTP messages to declare mandatory extensions, using `Man` and `Opt` headers with a URI naming the extension and a header-prefix. A server that required an extension the request had not declared answered 510, and the client was meant to resend the request including the declaration.

```http
M-GET /resource HTTP/1.1
Host: example.com
Man: "http://example.com/ext/security"; ns=15
15-auth: token=abc123
```

```http
HTTP/1.1 510 Not Extended
Ext:
Content-Length: 0
```

The mechanism needed new methods (`M-` prefix) and header handling in every client and intermediary, and it never caught on. The IANA registry still lists 510 with RFC 2774 as its reference, and the RFC was later reclassified as Historic.

## What to do if you see one

1. Check who sent it: `Server`, `Via`, `X-Powered-By`, and the body. A real RFC 2774 response is empty or minimal and mentions an `Ext` header; anything else is a vendor reuse.
2. Read the vendor docs: some hosting stacks and appliances use 510 for their own conditions. The code does not tell you what.
3. Do not retry. A 5xx suggests a server problem, but a 510 is not a transient failure. Clients with no specific handling for a 5xx code treat it like [500](https://howhttpworks.com/status-codes/500).
4. If you maintain a service and consider emitting 510, do not. Use [501](https://howhttpworks.com/status-codes/501) for unsupported functionality, [400](https://howhttpworks.com/status-codes/400) for a malformed or missing request element, or [426](https://howhttpworks.com/status-codes/426) when the client must upgrade protocol.

## Why the code number is still around

The IANA registry keeps assigned codes listed, so 510 stays there even though the mechanism that defined it is dead. Libraries ship it in their enumerations (Python's `http.HTTPStatus.NOT_EXTENDED`, Go's `http.StatusNotExtended`) for completeness, and you can see it in API test suites that iterate over every status. That is different from being in use.

If you find it in logs of an old appliance or proxy, the likelier reading is that a vendor picked an unused 5xx number for its own error. Compare the timestamp with deployments, check for a custom error page, and ask the vendor, since nothing in the protocol can tell you what it means.

## Try it with curl

`510 Not Extended` belongs to the HTTP Extension Framework (RFC 2774, an experimental RFC that was never widely adopted), so no mainstream server sends it. If you meet one, `curl -i` is enough to read the status and any headers it carries.

```bash
curl -i https://legacy.example.com/resource
```

## Related

- [501 Not Implemented](https://howhttpworks.com/status-codes/501)
- [505 HTTP Version Not Supported](https://howhttpworks.com/status-codes/505)
- [426 Upgrade Required](https://howhttpworks.com/status-codes/426)
- [500 Internal Server Error](https://howhttpworks.com/status-codes/500)
