The site said “all good” to addresses that don't exist. And Google put them in first position.
Until 25 September 2026, Itria's website said “all good” to addresses that had never existed. Five of them were getting impressions on Google in first position.
Without a 404 page, Cloudflare Pages answers everything. Cloudflare's documentation says that if a project has no 404.html file at the root, Pages treats it as a single-page application and sends every address to the root. On itria.io, a non-existent address returned the home page with a 200 code.
Five addresses we never created were in Search Console. In the 28 days up to 25 September 2026 they picked up 7 impressions and 1 click, all in position 1. They were mangled versions of real addresses, served as copies of the home page.
The data doesn't show who generated them. They're addresses rebuilt from memory, and the most likely explanation is an AI assistant citing a page without copying its link. It's an inference, not a measurement, and we present it as such.
This is part of Itria's lab: things measured on our own site, with the real numbers, to understand how search engines and assistants read it. The service that grows out of it is visibility in search engines and AI assistants.
What happens to a site on Cloudflare Pages without a 404.html
A static site on Cloudflare Pages without a 404.html file at the root answers any address with the main page. Cloudflare's documentation explains it like this: without that file, Pages assumes the project is a single-page application and matches every path to the root.
“If your project does not include a top-level 404.html file, Pages assumes that you are deploying a single-page application.” (Cloudflare, Pages documentation, “Serving Pages”)
For a single-page application, that's the right behaviour. For a site made of real pages, it's an invisible flaw: anyone opening a wrong address sees the home page, with no error, and the server returns 200, meaning “page found”. On 25 September 2026 we measured it on our own site, during the hygiene audit.
The five ghost addresses
In the 28 days up to 25 September 2026, Search Console recorded five itria.io addresses we had never created. All in position 1, all served as a copy of the home page. Together they came to 7 impressions and 1 click: small numbers, but five pages that existed for Google and not for us.
| Ghost address | Impressions and clicks, 28 days | Closest real page |
|---|---|---|
| /modello-scheda-prodotto-alimentare | 3 impressions, 1 click, position 1 | /modello-scheda-tecnica-prodotto-alimentare |
| /modelo-scheda-tecnica-prodotto-alimentare | 1 impression, position 1 | /modello-scheda-tecnica-prodotto-alimentare |
| /esportare-alimenti-emirati | 1 impression, position 1 | /esportare-alimentari-emirati |
| /ai-act-gdpr | 1 impression, position 1 | /ai-act-e-gdpr |
| /richiesta-certificato-esportazione | 1 impression, position 1 | /richiesta-certificato-sanitario-esportazione |
Where they come from: an inference, not a measurement
Search Console tells you an address got impressions, not who wrote it. The five look like addresses rebuilt from memory: a word skipped, “alimenti” instead of “alimentari”, “modelo” instead of “modello”, a missing “e”. It's the kind of mistake made when someone cites a page without copying its link.
An AI assistant answering by citing a source from memory produces exactly this kind of address. That's why we think it's the most likely origin. But the Search Console data doesn't prove it, and with 7 impressions no data could: it remains a hypothesis, and we treat it as one.
What we did: a real 404 and five redirects
The fix has two parts. A 404.html page at the root, excluded from the index, pointing to services, articles and the Diagnostico: from then on, a non-existent address returns 404. And a permanent redirect, code 301, from the five ghost addresses to the closest real page, plus a rule for the whole “esportare-alimenti” family.
Measured on the evening of 25 September 2026: a made-up address returns 404; /ai-act-gdpr, /modello-scheda-prodotto-alimentare and /esportare-alimenti-cina return 301 to the right pages. Anyone arriving from a wrong link finds the page they were after, and Google stops counting copies of the home page.
The five-minute check, on your own site
The check takes one command and one search. Request an address that doesn't exist and look at the code it returns: it should be 404, not 200. Then, in Search Console, scroll through the list of pages with impressions looking for addresses you never created.
curl -s -o /dev/null -w "%{http_code}\n" https://yoursite.com/address-that-does-not-exist If the command prints 200, the site is saying “page found” even where there's nothing. On Cloudflare Pages the fix is a 404.html file at the root; on other services the name changes, the principle doesn't. Ghost addresses that already have impressions get a 301 to the closest real page.
Questions and answers
What happens to a site on Cloudflare Pages without a 404.html file?
It answers any address with the main page. Cloudflare's documentation says that, without a 404.html at the root, Pages treats the project as a single-page application and matches every path to the root.
On itria.io, until 25 September 2026, a non-existent address returned the home page with a 200 code.
Why can an address that doesn't exist get impressions on Google?
Because the server returns 200 with a real page, usually the home page, and Google treats it as a page that exists. On itria.io, five addresses we never created picked up 7 impressions and 1 click over 28 days, all in position 1.
Since the site got a real 404 and 301 redirects, made-up addresses return 404 and the ghost ones lead to the right page.
Are ghost addresses generated by AI assistants?
Probably, but that's an inference. The five itria.io addresses look like links rebuilt from memory, with words skipped or mangled, which is the kind of mistake made when someone cites a page without copying its link.
Search Console tells you an address got impressions, not who wrote it: the data doesn't prove it.
How do you check whether your site returns 200 for pages that don't exist?
Request an address that doesn't exist, for example with curl, and look at the response code: it should be 404. If it's 200, the site is saying page found even where there's nothing.
Then, in Search Console, look through the pages with impressions for addresses you never created.
How do you fix ghost addresses?
With a real 404 page, which on Cloudflare Pages means a 404.html file at the root, and with a permanent 301 redirect from each ghost address to the closest real page.
That way anyone arriving from a wrong link finds the page they were after, and Google stops counting copies of the home page.
Notes on sources
- Cloudflare, Pages documentation, “Serving Pages”: the behaviour without a 404.html at the root. The quotation is word for word.
- itria.io Search Console, page export for the 28 days up to 25 September 2026: impressions, clicks and position for the five addresses.
- Itria measurements: hygiene audit of 25 September 2026 (200 response with the home page) and check on the evening of the same day (404 on made-up addresses, 301 on the five ghost ones).
- The origin of the ghost addresses is an Itria inference, not a measurement: Search Console doesn't record who wrote a link.
See your own site the way search engines and assistants read it.
An address that returns 200 where there's nothing, an email address that isn't in the code: these are flaws you can't see from the browser. Drop us a line about what's slowing you down: we'll make the first move, even if we never end up working together.