Common causes
- WordPress Address (siteurl) and Site Address (home) do not match the URL the server redirects to
- Cloudflare SSL mode set to Flexible while the origin forces HTTPS
- WordPress behind a proxy or load balancer that does not tell it the request was HTTPS
- Conflicting www and non-www rules in .htaccess, Nginx and a plugin
- An SSL or redirect plugin fighting with server rules
- Stale cookies or cached redirects in the browser or page cache
How to fix it
- Clear cookies and test privately. Clear cookies for the site or open a private window. Then run curl -sIL https://example.com | grep -iE '^(HTTP|location)' to see the exact redirect hops without browser caching.
- Fix the WordPress URLs. Make sure both URLs use the same scheme and host you want, for example https://www.example.com. Without dashboard access, add define('WP_HOME', 'https://www.example.com'); and define('WP_SITEURL', 'https://www.example.com'); to wp-config.php, or run wp option update home and wp option update siteurl.
- Set Cloudflare SSL to Full (strict). In Cloudflare go to SSL/TLS > Overview and change Flexible to Full (strict), which requires a valid certificate on the origin. Flexible sends HTTP to the origin, which then redirects to HTTPS again, creating the loop.
- Tell WordPress about HTTPS behind a proxy. If a load balancer or proxy terminates SSL, add a check in wp-config.php that sets $_SERVER['HTTPS'] = 'on' when HTTP_X_FORWARDED_PROTO is https. Only trust that header if requests can only reach the server through your proxy.
- Remove duplicate redirect rules. Keep one place responsible for HTTPS and www redirects: either the server config or one plugin. Temporarily rename .htaccess or disable SSL/redirect plugins by renaming their folders to find the conflict.
- Purge caches. Clear the WordPress page cache plugin, server cache and CDN cache. A cached 301 can keep the loop going after the cause is fixed.
wp-config.php behind a reverse proxy
define( 'WP_HOME', 'https://www.example.com' );
define( 'WP_SITEURL', 'https://www.example.com' );
if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] )
&& $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
$_SERVER['HTTPS'] = 'on';
} How to stop it happening again
- Handle HTTPS and www redirects in one layer only
- Use Cloudflare Full (strict) with a valid origin certificate
- Check redirects with a chain checker after DNS, SSL or CDN changes
- Update siteurl and home immediately after migrations or domain changes