Ffile2fix
Sign in Get started

Fix "ERR_TOO_MANY_REDIRECTS" on a WordPress site

This page isn't working. example.com redirected you too many times. ERR_TOO_MANY_REDIRECTS

The browser gave up because each response redirected to another URL that eventually redirected back. On WordPress this is usually a conflict between the site URL settings and HTTPS or www redirects at the server, CDN or plugin level, most often Cloudflare's Flexible SSL combined with a forced HTTPS redirect on the origin.

Also appears as: The page isn't redirecting properly. Firefox has detected that the server is redirecting the request for this address in a way that will never complete. · WordPress wp-admin redirect loop · Safari can't open the page because too many redirects occurred. · WordPress too many redirects after enabling SSL Cloudflare

Common causes

  • WordPress Address (siteurl) and Site Address (home) do not match the URL the server redirects to
  • Cloudflare SSL mode set to Flexible while the origin forces HTTPS
  • WordPress behind a proxy or load balancer that does not tell it the request was HTTPS
  • Conflicting www and non-www rules in .htaccess, Nginx and a plugin
  • An SSL or redirect plugin fighting with server rules
  • Stale cookies or cached redirects in the browser or page cache

How to fix it

  1. Clear cookies and test privately. Clear cookies for the site or open a private window. Then run curl -sIL https://example.com | grep -iE '^(HTTP|location)' to see the exact redirect hops without browser caching.
  2. Fix the WordPress URLs. Make sure both URLs use the same scheme and host you want, for example https://www.example.com. Without dashboard access, add define('WP_HOME', 'https://www.example.com'); and define('WP_SITEURL', 'https://www.example.com'); to wp-config.php, or run wp option update home and wp option update siteurl.
  3. Set Cloudflare SSL to Full (strict). In Cloudflare go to SSL/TLS > Overview and change Flexible to Full (strict), which requires a valid certificate on the origin. Flexible sends HTTP to the origin, which then redirects to HTTPS again, creating the loop.
  4. Tell WordPress about HTTPS behind a proxy. If a load balancer or proxy terminates SSL, add a check in wp-config.php that sets $_SERVER['HTTPS'] = 'on' when HTTP_X_FORWARDED_PROTO is https. Only trust that header if requests can only reach the server through your proxy.
  5. Remove duplicate redirect rules. Keep one place responsible for HTTPS and www redirects: either the server config or one plugin. Temporarily rename .htaccess or disable SSL/redirect plugins by renaming their folders to find the conflict.
  6. Purge caches. Clear the WordPress page cache plugin, server cache and CDN cache. A cached 301 can keep the loop going after the cause is fixed.

wp-config.php behind a reverse proxy

define( 'WP_HOME', 'https://www.example.com' );
define( 'WP_SITEURL', 'https://www.example.com' );

if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] )
     && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
    $_SERVER['HTTPS'] = 'on';
}

How to stop it happening again

  • Handle HTTPS and www redirects in one layer only
  • Use Cloudflare Full (strict) with a valid origin certificate
  • Check redirects with a chain checker after DNS, SSL or CDN changes
  • Update siteurl and home immediately after migrations or domain changes

Frequently asked questions

Why did this start right after installing SSL?

Usually the server or a plugin now forces HTTPS while something else, often Cloudflare Flexible SSL or the WordPress URL settings, still sends visitors to HTTP. Make every layer agree on HTTPS.

Why does only wp-admin loop?

A FORCE_SSL_ADMIN setting without proper HTTPS detection behind a proxy, or stale login cookies, are the usual causes. Clear cookies and add the HTTP_X_FORWARDED_PROTO check.

Will clearing my browser cache fix it?

Only if the loop was already fixed on the server and your browser cached an old 301 redirect. If curl still shows a loop, the problem is on the server side.