Ffile2fix
Sign in Get started

How to fix "Cookies are blocked or not supported by your browser"

Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress.

WordPress sets a test cookie (wordpress_test_cookie) when the login page loads and checks for it when you submit the form. If the browser did not send it back, because it was never set, was set for another domain, or headers were already sent, login is refused with this message.

Also appears as: ERROR: Cookies are blocked or not supported by your browser. · Error: Cookies are blocked due to unexpected output. · Cookies are blocked or not supported by your browser (WordPress Multisite)

Common causes

  • Output (whitespace, BOM or a PHP notice) before headers in wp-config.php, functions.php or a plugin, which blocks Set-Cookie
  • siteurl/home domain differs from the domain in the address bar
  • A page cache or CDN serving wp-login.php without the Set-Cookie header
  • COOKIE_DOMAIN misconfigured, often on Multisite with domain mapping
  • The browser or an extension actually blocking cookies for the site

How to fix it

  1. Test in a clean private window. Open a private window with extensions off and try again. If it works, clear site cookies or adjust browser privacy settings.
  2. Look for unexpected output. If the message says 'due to unexpected output', check debug.log or the PHP error log for 'headers already sent' and the file and line that produced output.
  3. Remove whitespace and BOM. Check wp-config.php and your theme's functions.php for blank lines before <?php or after a closing ?>, and resave files as UTF-8 without BOM.
  4. Match the domain. Make sure siteurl and home use exactly the domain you log in on, including www and https.
  5. Exclude login from caching. Bypass /wp-login.php in your page cache, server cache (LiteSpeed, Varnish) and CDN so the test cookie header is sent fresh.
  6. Fix COOKIE_DOMAIN on Multisite. If COOKIE_DOMAIN is defined in wp-config.php, remove it or set it to false; mapped domains usually work best with the default behaviour.

wp-config.php (Multisite with mapped domains)

// Remove any hard-coded cookie domain that doesn't match
// define( 'COOKIE_DOMAIN', 'example.com' );
define( 'COOKIE_DOMAIN', false );

How to stop it happening again

  • Omit the closing ?> tag in PHP-only files to avoid trailing whitespace
  • Save PHP files as UTF-8 without BOM
  • Keep login and admin pages out of every cache layer

Frequently asked questions

Cookies are definitely enabled in my browser. Why the error?

Most of the time the server failed to send the cookie, typically because something printed output before headers. The browser never received a cookie to send back.

What does 'due to unexpected output' mean?

WordPress 5.x+ detects that headers were already sent when it tried to set the test cookie. Find the file named in the 'headers already sent' warning and remove the stray output.

Can a security plugin cause this?

Yes. Plugins that rename the login URL or add login protection sometimes break the test cookie. Temporarily rename the plugin folder to test.