Common causes
- Output (whitespace, BOM or a PHP notice) before headers in wp-config.php, functions.php or a plugin, which blocks Set-Cookie
- siteurl/home domain differs from the domain in the address bar
- A page cache or CDN serving wp-login.php without the Set-Cookie header
- COOKIE_DOMAIN misconfigured, often on Multisite with domain mapping
- The browser or an extension actually blocking cookies for the site
How to fix it
- Test in a clean private window. Open a private window with extensions off and try again. If it works, clear site cookies or adjust browser privacy settings.
- Look for unexpected output. If the message says 'due to unexpected output', check debug.log or the PHP error log for 'headers already sent' and the file and line that produced output.
- Remove whitespace and BOM. Check wp-config.php and your theme's functions.php for blank lines before <?php or after a closing ?>, and resave files as UTF-8 without BOM.
- Match the domain. Make sure siteurl and home use exactly the domain you log in on, including www and https.
- Exclude login from caching. Bypass /wp-login.php in your page cache, server cache (LiteSpeed, Varnish) and CDN so the test cookie header is sent fresh.
- Fix COOKIE_DOMAIN on Multisite. If COOKIE_DOMAIN is defined in wp-config.php, remove it or set it to false; mapped domains usually work best with the default behaviour.
wp-config.php (Multisite with mapped domains)
// Remove any hard-coded cookie domain that doesn't match
// define( 'COOKIE_DOMAIN', 'example.com' );
define( 'COOKIE_DOMAIN', false ); How to stop it happening again
- Omit the closing ?> tag in PHP-only files to avoid trailing whitespace
- Save PHP files as UTF-8 without BOM
- Keep login and admin pages out of every cache layer