Skip to content

wp-sitemap.xml: the sitemap WordPress makes, why it answers 404, and which one to submit

WordPress has made its own sitemap at /wp-sitemap.xml since version 5.5. It answers 404 while search engines are discouraged or a filter has switched it off, and it redirects when an SEO plugin has replaced it. Submit one sitemap, the one on the Sitemap line of your robots.txt.

By
WP Ministry
Published
Tested on
WordPress 7.1.3, PHP 8.3.35

In short

  • /wp-sitemap.xml is an index. It points to one file for each kind of content, and each file holds up to 2,000 addresses.
  • It lists posts, pages, the home page, categories, tags in use and authors. Posts and pages carry a last-modified date. Images are not listed.
  • While "Discourage search engines from indexing this site" is ticked, the sitemap answers 404.
  • With plain permalinks the sitemap is at /?sitemap=index, and /wp-sitemap.xml is not.
  • Yoast SEO and Rank Math switch WordPress's sitemap off and send /wp-sitemap.xml to their own /sitemap_index.xml.
  • Submit one sitemap, the one your site serves. Google calls a submitted sitemap a hint.

WordPress makes a sitemap by itself, with no plugin, and has done since version 5.5. It is at /wp-sitemap.xml: an index that points to one file for each kind of content. The files list the addresses of your posts, pages, categories, tags and authors, up to 2,000 in each.

When that address answers 404, WordPress has been told to switch the sitemap off, or the request never reached WordPress. When it redirects, an SEO plugin has replaced the sitemap with its own. Either way there is one sitemap to give Google, the one your site serves, and the Sitemap: line in /robots.txt says which that is.

Where it is and what it looks like

Add /wp-sitemap.xml to your site's address. In a browser, WordPress styles the file as a page headed "XML Sitemap", with the line "This XML Sitemap is generated by WordPress to make your content more visible for search engines." A search engine receives the XML underneath. This is what a new site with one post and one page sends. WordPress writes it on one line; it is broken up here for reading, with example.com in place of the site's address.

text
<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://example.com/wp-sitemap-index.xsl" ?>
<sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <sitemap><loc>https://example.com/wp-sitemap-posts-post-1.xml</loc></sitemap>
  <sitemap><loc>https://example.com/wp-sitemap-posts-page-1.xml</loc></sitemap>
  <sitemap><loc>https://example.com/wp-sitemap-taxonomies-category-1.xml</loc></sitemap>
  <sitemap><loc>https://example.com/wp-sitemap-users-1.xml</loc></sitemap>
</sitemapindex>

Each address in the index is a file of its own. This is the one for pages:

text
<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://example.com/wp-sitemap.xsl" ?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://example.com/</loc><lastmod>2026-10-08T01:51:29+00:00</lastmod></url>
  <url><loc>https://example.com/sample-page/</loc><lastmod>2026-10-08T01:51:29+00:00</lastmod></url>
</urlset>

On a site installed at the root of its domain, WordPress also answers /sitemap.xml with a 301 redirect to /wp-sitemap.xml.

What is in it

Kind of contentFileLast-modified date
Postswp-sitemap-posts-post-1.xmlYes
Pages, and the home pagewp-sitemap-posts-page-1.xmlYes
Categorieswp-sitemap-taxonomies-category-1.xmlNo
Tagswp-sitemap-taxonomies-post_tag-1.xmlNo
Authorswp-sitemap-users-1.xmlNo

WordPress's developer note for the feature says a file is made for every public post type and taxonomy, so content that a plugin adds as a public post type gets files of its own by the same pattern.

A kind with nothing to list gets no file. The new site above has no tags file because no post has a tag yet. Give one post a tag and the file appears in the index. Until then its address answers 404, which is correct and not a fault.

A file holds at most 2,000 addresses. The 2,001st post starts wp-sitemap-posts-post-2.xml, and the index lists both. The figure is WordPress's own and a filter, wp_sitemaps_max_urls, changes it. Google's limit for one sitemap file is 50,000 addresses or 50MB, so WordPress's files are well inside it.

What is not in it

  • Images, video and news. The developer note says these sitemap extensions are left to plugins.
  • Attachment pages. WordPress leaves the attachment post type out of the sitemap.
  • Drafts. Only published content is listed. The new site above has a draft privacy policy page, and it is not in the pages file.
  • Priority and change frequency. WordPress does not write them, and Google's documentation says it ignores both.

The last-modified date is newer than the feature. The 2020 developer note says WordPress lists only the address. Since WordPress 6.5, posts, pages and a home page that shows the latest posts carry lastmod. Categories, tags and authors still do not. Google's documentation says it uses lastmod when the value is consistently accurate.

Why /wp-sitemap.xml answers 404 or redirects

Start by asking for the address and reading the answer. From a terminal, with your own address in place of example.com:

bash
curl -sI https://example.com/wp-sitemap.xml

The first line is the status. A redirect also has a Location line that says where it leads.

text
HTTP/1.1 200 OK
Content-Type: application/xml; charset=UTF-8
The answerWhat it points to
200 and application/xmlThe sitemap is working.
404Search engines are discouraged, a filter has switched the sitemap off, permalinks are plain, or the request never reached WordPress.
301 to /sitemap_index.xmlAn SEO plugin has replaced the sitemap with its own.
301 to /wp-sitemap.xml/, with a slash on the endPermalinks are plain.
200 but the content is not the index aboveA file on the server is answering in WordPress's place.

If you have SSH and WP-CLI, three commands narrow it down. Run them from the site's main folder.

bash
wp option get blog_public
wp option get permalink_structure
wp eval 'var_dump( wp_sitemaps_get_server()->sitemaps_enabled() );'

On a site whose sitemap works, they print this:

text
1
/%postname%/
bool(true)
LineIf it saysThen
First0Search engines are discouraged. See reason 1.
SecondNothingPermalinks are plain. See reason 2.
Thirdbool(false) while the first line is 1A plugin or a filter has switched the sitemap off. See reasons 3 and 4.

The second line can be any structure. What matters is that it is not empty.

1. "Discourage search engines" is ticked

Under Settings, then Reading, the box labeled "Discourage search engines from indexing this site" does two things to the sitemap. Every sitemap address answers 404, and the Sitemap: line leaves robots.txt. WordPress decides whether the sitemap is on by reading that one setting.

Untick the box and save. With WP-CLI:

bash
wp option update blog_public 1

The sitemap answers on the next request. The box does more than this, and what "Discourage search engines" does covers the rest. It is the first thing to check on a site that was just launched or rebuilt, which is why it is on the WordPress launch checklist.

With the Plain permalink setting, WordPress has no pretty addresses at all, and /wp-sitemap.xml is one of them. The sitemap still exists, at a different address:

text
https://example.com/?sitemap=index

The files it points to are query addresses too, such as /?sitemap=posts&sitemap-subtype=post&paged=1.

What /wp-sitemap.xml itself answers depends on the server. Where nothing hands the request to WordPress, the server answers 404 with its own bare page. Where a rule still sends every request to WordPress, WordPress redirects to /wp-sitemap.xml/ and shows the home page there, which is a web page and not a sitemap. /robots.txt is in the same position.

So on a site with plain permalinks, /?sitemap=index is the sitemap's address. Choosing another permalink structure moves the sitemap to /wp-sitemap.xml, but it also changes the address of every post, so read how to change permalinks safely before you do it for this reason alone.

3. An SEO plugin has replaced it

An SEO plugin that makes its own sitemap can switch WordPress's off, so that a site does not have two. What these two do is in their own documentation and code:

  • Yoast SEO. Its changelog for version 14.5 says the release "Disables the WP Core sitemaps as introduced in WordPress 5.5." Its specification puts its own index at /sitemap_index.xml. Its source code redirects /wp-sitemap.xml there with a 301, and does both only while its own XML sitemaps setting is on.
  • Rank Math. Its documentation says its sitemap index is at /sitemap_index.xml. The code of its Sitemap module switches WordPress's sitemap off and redirects /wp-sitemap.xml to that address with a 301.

With either, nothing is broken. The site has one sitemap, and it is the plugin's. With Yoast SEO, switching its XML sitemaps setting off brings WordPress's own back.

Other plugins make their own choices. The Location line in the answer above tells you where a redirect leads, whichever plugin sent it.

4. A filter has switched it off

WordPress has a filter for switching the sitemap off, and the developer note gives it as one line. A theme's functions.php, a plugin or a must-use plugin can carry it:

wp-content/mu-plugins/sitemap-off.php
<?php
// Switch WordPress's own sitemap off.
add_filter( 'wp_sitemaps_enabled', '__return_false' );

With that file in place, /wp-sitemap.xml and every file under it answer 404, and the Sitemap: line leaves robots.txt, exactly as with the box ticked. The Reading setting still shows the site as visible, which is what makes this one hard to spot. It is also how to switch the sitemap off on purpose: the file goes in wp-content/mu-plugins.

To find the line, search the site's code for the filter's name:

bash
grep -rn "wp_sitemaps_enabled" wp-content/

Each result is a file and a line number. A result inside an SEO plugin's folder is reason 3. A result in your theme or in wp-content/mu-plugins is a line someone added on purpose: ask why before you remove it. A file in mu-plugins loads on every request and cannot be switched off in the dashboard, only by removing the file.

5. A file or a server rule is in the way

The rules WordPress writes for Apache send a request to WordPress only when no real file has that name. So a file called sitemap.xml or wp-sitemap.xml in the site's main folder is served as it is, and WordPress is never asked. A file like that was put there once, by a plugin or a sitemap generator, and it lists the site as it was that day.

Look in the site's main folder, over SSH or in your host's file manager:

bash
find . -maxdepth 1 -name '*sitemap*'

A site with no such file prints nothing. If one is listed, set it aside by renaming it, and ask for the address again:

bash
mv sitemap.xml sitemap.xml.old

A rule in the server's own configuration can do the same thing: answer for .xml addresses, or redirect them, before WordPress is asked. One sign is the 404 page itself. WordPress's is drawn by your theme, with the site's own header, under the title "Page not found". A bare page from the server means the request never reached WordPress, and the server's configuration is your host's to check.

One answer is not a 404 at all. WordPress needs PHP's SimpleXML extension to write the sitemap, and the developer note says that without it the sitemap address shows an error message with status 501. That is also one for the host.

Which sitemap to submit

One: the one your site serves. A site should not have both WordPress's sitemap and a plugin's submitted, because only one of them exists. The other address is a 404 or a redirect.

The quickest way to learn which one your site serves is to read robots.txt:

bash
curl -s https://example.com/robots.txt
text
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php

Sitemap: https://example.com/wp-sitemap.xml

WordPress writes the Sitemap: line itself, and it follows the sitemap: /wp-sitemap.xml normally, /?sitemap=index with plain permalinks, and no line at all while the sitemap is off.

If there is no Sitemap: line, ask for /wp-sitemap.xml as in the first step. A 200 means that is your sitemap. A redirect means the address on the Location line is. Open whichever you settle on and check that it is XML and lists your pages.

If robots.txt is a real file on the server, WordPress does not write it and the line may be missing or out of date. Where robots.txt is and how to change it covers that case.

Submit it in Search Console

Google can find a sitemap from the Sitemap: line in robots.txt without being told. Submitting it in Search Console adds a report: when Google read the file, and any errors in it. Google's help page says the Sitemaps report shows only sitemaps submitted through the report or its API, not ones found through robots.txt.

  1. Step 1: Check that you are an owner of the property

    Google's help page says you need owner permission on a property to submit a sitemap in the report.

  2. Step 2: Test that Google can fetch the sitemap

    Google's help page gives the test: run a live URL inspection on the sitemap's address and check that Page fetch says "Successful".

  3. Step 3: Submit it

    Open the Sitemaps report, paste the address into the "Add a new sitemap" box and click "Submit". Submit the address that answers 200 itself, not one that redirects to it.

  4. Step 4: Read the status

    Google's help page says the sitemap should be fetched immediately, that crawling the addresses in it can take some time, and that not every address in a sitemap is necessarily crawled.

The report's list gives each sitemap one of three statuses. This is what Google's help page says each means:

Status in the listMeaning
"Success"Google fetched the sitemap and read it with no errors.
"Couldn't fetch"Google could not fetch the sitemap.
"Sitemap had X errors"Google fetched the sitemap and read part of it, with errors.

Further down, where the same help page describes the report's Status column, the third is written "Has errors".

Click a sitemap to open its details page. "Sitemap could not be read" is what the details page says when the fetch failed, so it goes with "Couldn't fetch" in the list. It is not a fourth status.

Google's reasons for a failed fetch include a robots.txt rule that blocks the sitemap, a sitemap address that answers 404, a server that was unavailable when Google asked, and a manual action on the site. The WordPress causes on this page show up as the second of those: the box ticked, plain permalinks, a filter. Mend the address first, then submit again. Google's help page says it retries a failed sitemap for a few days and then stops, and that you should resubmit once the fault is mended.

The report belongs to one property. A sitemap submitted for the http or www form of a site is not listed under the other.

What a sitemap does and does not do

A sitemap tells a search engine which addresses exist. Google's documentation calls submitting one "merely a hint": Google may not download it, and may not use it for crawling. The same documentation says a sitemap does not make every address in it be crawled or indexed.

It also says who needs one least: a site of about 500 pages or fewer whose pages all link to each other can usually be found without a sitemap. So on a small site, the sitemap is not the first place to look when pages are absent from Google. If that is the problem you are solving, start with why a WordPress site is not on Google.

Take something out of the sitemap

WordPress has no screen for the sitemap. What goes in it is changed with filters, and the developer note gives one for each job:

To leave outFilter
All authors, or all posts, or all categories and tagswp_sitemaps_add_provider
One post type, such as pageswp_sitemaps_post_types
One taxonomy, such as tagswp_sitemaps_taxonomies
Single postswp_sitemaps_posts_query_args

Take the author sitemap, which a site where one person writes every post has little use for. This is the developer note's own example. Create the folder wp-content/mu-plugins if it is not there, and save this in it:

wp-content/mu-plugins/sitemap-without-authors.php
<?php
// Leave author archives out of WordPress's sitemap.
add_filter(
	'wp_sitemaps_add_provider',
	function ( $provider, $name ) {
		if ( 'users' === $name ) {
			return false;
		}
		return $provider;
	},
	10,
	2
);

A mistake in a file in that folder takes the whole site down, so copy it exactly and be ready to delete it over SFTP or in your host's file manager.

Reload /wp-sitemap.xml. The line for wp-sitemap-users-1.xml is gone from the index, and that address now answers 404. The author pages themselves are untouched: /author/ addresses still load, and a search engine can still reach them through links. Leaving a page out of the sitemap does not keep it out of a search engine.

When to get help

  • Ask the host when the 404 is the server's own page, or the sitemap answers 501.
  • Ask whoever built the site before you remove a filter that someone added on purpose.
  • Hand it over if the box is unticked, permalinks are set, no filter and no file is in the way, and the address still fails. A one-time fix from WP Ministry covers one issue on one site and starts with a free diagnosis, which gives you a written cause and a fixed quote.

Common questions

Do I need a plugin to have a sitemap?

No. WordPress makes one with no plugin. A plugin's sitemap can hold more: Yoast SEO's specification, for one, has it list the images on each page. WordPress SEO without a plugin shows what WordPress does by itself.

Should I submit both wp-sitemap.xml and sitemap_index.xml?

No. A site serves one of them. With Yoast SEO or Rank Math making the sitemap, /wp-sitemap.xml is only a redirect to /sitemap_index.xml. With no such plugin, /sitemap_index.xml answers 404. Submit the one that answers 200.

Why are my images not in the sitemap?

WordPress's sitemap lists the addresses of pages, not of the images on them. Its developer note leaves image, video and news sitemaps to plugins. Google's documentation says a sitemap can carry image entries, and counts a site with a lot of images or video among those that might need one.

The sitemap opens in my browser, but Search Console says "Couldn't fetch". Why?

Google's help page lists causes that do not show in a browser: a robots.txt rule that blocks the address, a manual action on the site, or a server that was unavailable at the moment Google asked. Run a live test of the sitemap's address in the URL Inspection tool. Google's help page says to look for Crawl allowed "Yes" and Page fetch "Successful". Check too that you submitted the address for the right property, https or http, with www or without.

More on this subject

Quick Fix, done for you

Quick Fix is $49. One issue, one site, up to about an hour. No fix, no fee. 30-day warranty. It starts with a free diagnosis.