ERR_TOO_MANY_REDIRECTS on WordPress: Causes and How to Fix It
Site "redirected you too many times"? How to fix redirect loops in WordPress: site URL settings, CDN flexible SSL, .htaccess, redirect plugins and cookies.

On this page
- ERR_TOO_MANY_REDIRECTS is a redirect loop, usually two rules disagreeing about https or www, and it can normally be fixed without losing content.
- Check the WordPress site URLs, set Cloudflare or similar proxies to Full (strict) SSL instead of Flexible, and keep each redirect in one place only.
- Test in a private window, trace the loop in the Network tab, rule out plugins and .htaccess rules, then clear every cache layer.
Instead of your website, Chrome shows "This page isn't working" and says your domain redirected you too many times, with the code ERR_TOO_MANY_REDIRECTS. Firefox calls it "The page isn't redirecting properly". It's alarming because the whole site can disappear at once, but the cause is almost always a settings conflict that can be fixed without losing any content.
What the error means
A redirect sends a browser from one address to another, for example from http to https, or from www to non-www. A redirect loop happens when two rules disagree: address A sends visitors to B, and B sends them straight back to A. The browser follows the loop a number of times, then gives up and shows the error.
The most common causes on WordPress sites:
| Cause | Typical trigger |
|---|---|
| Site URL settings don't match the server's redirects | Switching to https, or between www and non-www |
| CDN or proxy using "Flexible" SSL | Connecting Cloudflare, then forcing https on the server |
| The same redirect set up in several places | A hosting "force HTTPS" switch, an SSL plugin and .htaccess rules all at once |
| A faulty redirect rule | A redirect plugin rule that points a page back to itself |
| Stale cookies or cached redirects | Loops that affect only you, or only the login page |
| Settings left over from a migration | Site URL still pointing to the old domain or a staging address |
A different problem: if your site sends visitors to spam or gambling sites, that's malware, not a loop; see how to fix the WordPress redirect hack.
Step 1: Rule out cookies and your browser
Open the site in a private or incognito window, and on your phone using mobile data. If it loads there, the problem is on your device: clear cookies and cached data for that site only (in Chrome, through the site information icon next to the address bar), then try again.
If it fails everywhere, find the loop itself. In Chrome's developer tools (F12), open the Network tab, tick "Preserve log" and reload. You'll see the chain of 301 or 302 responses and exactly which addresses keep bouncing, for example https://example.com to http://example.com and back again. That tells you which two rules are fighting. For redirect basics, see 301 vs 302 redirects.
Step 2: Check the WordPress site URLs
WordPress stores two addresses, the WordPress Address and the Site Address, in Settings → General. Both must match your preferred version exactly: https, and either with or without www, the same way your server redirects.
If the loop stops you reaching the dashboard, a developer can set them from outside WordPress:
- Add
WP_HOMEandWP_SITEURLdefinitions to wp-config.php with the correct https address - Or edit the
siteurlandhomevalues in the options table using phpMyAdmin
Take a backup first. After a migration, check that neither address still points to the old domain or a staging copy.
Step 3: Check your CDN's SSL mode
This is the classic cause after connecting Cloudflare. In "Flexible" mode, Cloudflare talks to visitors over https but to your hosting over plain http. If your server or WordPress then redirects http to https, Cloudflare passes that redirect back to the browser, which asks again over https, and the loop begins.
The fix is to have a valid certificate on your hosting (most hosts provide free ones) and set Cloudflare's SSL/TLS mode to "Full (strict)". Dashboard menus change over time, so check the current wording. Other proxy and firewall services have similar settings. Behind some proxies or load balancers, WordPress can't tell that a visitor arrived on https and needs a small wp-config.php setting to recognise it; your host or developer can confirm. See what a CDN is for how proxy setups work.
Step 4: Remove duplicate redirect rules
Your http-to-https and www redirects should live in one place. Common places they pile up:
- A "force HTTPS" switch in the hosting panel
- Rules in the .htaccess file, on Apache and LiteSpeed servers
- An SSL plugin, a redirect plugin or the redirect feature of an SEO plugin
- Redirect rules or page rules at the CDN
To test .htaccess, rename it temporarily (for example to .htaccess-old) using File Manager or FTP. If the site loads, a rule inside it was the culprit. Go to Settings → Permalinks and click Save to regenerate WordPress's default rules, then add back only the redirects you actually need. On Nginx servers, redirects sit in the server configuration, so ask your host.
Step 5: Check plugins and caches
If the loop started after installing or updating a plugin, that's your first suspect. Without dashboard access, rename the plugins folder inside wp-content using File Manager or FTP to switch them all off. If the site loads, rename the folder back and reactivate plugins one at a time from the Plugins screen, testing after each. Redirect, SSL, caching, security and language or country redirect plugins are the usual culprits. A single redirect rule that sends a page to an address that redirects back is enough.
Browsers and caches can remember redirects. Once you've fixed the cause, purge the caching plugin, server cache and CDN cache, then test in a fresh private window; see why changes don't show on your site for every layer to clear.
When only the login page loops
Sometimes the front of the site works, but logging in sends you back to the login page again and again, or wp-admin redirects endlessly. Common causes:
- Old login cookies: clear cookies for the site and try again
- Site URLs using www while you log in without it, or the reverse
- The login page or admin area being cached, when both should always be excluded from caching
- A security plugin that changed the login address or is blocking your IP address
How to prevent redirect loops
- Choose one version of your domain (https, with or without www) and use it everywhere
- Handle each redirect in one place only, and write down where
- Test SSL, CDN and redirect changes on a staging site first when you can
- After a migration or SSL change, test the homepage, login, a few inner pages, forms and checkout
- Use uptime monitoring so you hear about a loop before your customers do
Site stuck in a loop and you'd rather not touch server files? I fix issues like this as part of WordPress maintenance, and set up SSL and redirects correctly during WordPress migrations.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


