Fixing WordPress redirect loops (ERR_TOO_MANY_REDIRECTS)
How to diagnose and fix WordPress redirect loops by checking URL configuration, SSL settings, .htaccess rules, plugin conflicts, CDN settings and cached redirects.
A redirect loop happens when your browser is sent from one address to another, and then back again (or round a longer chain that ends where it started). The browser notices the cycle and gives up, showing an error such as "ERR_TOO_MANY_REDIRECTS" in Chrome or "The page isn't redirecting properly" in Firefox.
It's a common WordPress problem, and it almost always comes down to two or more things each trying to control where the browser goes. The most frequent triggers are a move to HTTPS that isn't set up consistently, a change of domain, mismatched address settings in WordPress and conflicting redirect rules in WordPress, your server and a CDN.
Once you find which layer is causing the conflict, the fix is usually straightforward.
Clear cookies and caches first
Before changing any settings, rule out old data in your browser or a cache.
Clear your browser's cookies for the site's domain (not all your browsing data), then try again, or test in a private or incognito window.
If your site uses a caching plugin, your host's cache or a CDN, clear those too. A redirect cached from an old configuration can keep looping even after you've fixed the cause.
Check your WordPress site addresses
WordPress stores two addresses under Settings → General: the WordPress Address (URL) and the Site Address (URL). If they don't match how your site is actually served (for example, one has www and the other doesn't, or one says http while the site uses https), WordPress can keep redirecting to the "right" address and end up in a loop.
If you can reach the dashboard, check both values are the same and match the address in your browser, including https:// and whether or not you use www. Note down the current values before changing anything, since a wrong change can lock you out.
If the loop is stopping you reaching the dashboard, you can override these addresses in wp-config.php. Download a copy of the file first, since a typo in it can take the whole site offline. Then add these lines just above the comment that reads /* That's all, stop editing! */:1
define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );
Replace https://example.com with your actual address. Use https:// only if your site has a working SSL certificate, and include www. only if your site uses it.
These lines override the stored addresses without changing them, and the fields under Settings → General are greyed out while they're in place.1 It's fine to leave them there. If you remove them later, the stored values need correcting first, or the loop will come back. Our guide to regaining access to WordPress admin explains the options.
Check your HTTPS setup
Switching from HTTP to HTTPS is the most common trigger for redirect loops, because an HTTPS redirect can be set up in several places, and having more than one active at once can cause a conflict.
You only need one redirect from HTTP to HTTPS. Check each of these and make sure only one is doing the job:
- A rule in your
.htaccessfile - A "Force HTTPS" or "SSL redirect" option in your hosting control panel
- An SSL or security plugin in WordPress
- Your CDN or proxy, such as Cloudflare's "Always Use HTTPS" setting
If two or more are active, a request can bounce between them. Pick one and switch the others off, one at a time, testing after each change.
If your SSL certificate itself is missing or invalid, you'll usually see a certificate warning rather than a redirect loop. Our guide to fixing "Not Secure" warnings and mixed content covers certificates and moving to HTTPS step by step.
Check your CDN or proxy settings
If your site sits behind a CDN or proxy such as Cloudflare, the way it connects to your server can cause a loop.
The classic example: visitors reach Cloudflare over HTTPS, but Cloudflare connects to your server over plain HTTP. Your server sees an HTTP request and redirects it to HTTPS. Cloudflare passes that redirect back and tries again, still over HTTP, and the cycle repeats.
In Cloudflare, this happens when the SSL/TLS encryption mode is set to Flexible while your server also redirects to HTTPS.2 If your server has its own certificate, setting the mode to Full or Full (strict) fixes it. If you're not sure whether your server has a certificate, ask your host before changing the mode.
Also check any page rules or redirect rules in your CDN that might be adding redirects on top of those already handled by WordPress or your server.
Some hosting setups put WordPress behind a proxy or load balancer in a similar way. WordPress's documentation covers how it can be told about the HTTPS connection in that case,3 but it's a job for your host or developer.
If you're not sure whether the CDN is involved, pausing it briefly (so traffic goes straight to your server) and loading the site shows whether the loop goes away. Pausing Cloudflare switches off its protection too, so turn it back on straight after testing.
Reset .htaccess
On Apache and LiteSpeed servers, conflicting or broken redirect rules in .htaccess can cause a loop on their own.
Connect via SFTP or your hosting file manager and rename .htaccess to .htaccess_old. Renaming rather than deleting keeps a copy of your existing rules. Try loading the site. If the loop stops, the file was the problem.
Create a clean file by going to Settings → Permalinks in the dashboard and clicking Save Changes without changing anything.
If you need a redirect (such as www to non-www, or HTTP to HTTPS) and it isn't handled elsewhere, add back a single rule for it, copying it from .htaccess_old if it was there before. Avoid multiple rules that do the same job, since overlapping rules are a common cause of loops.
If your server runs Nginx, there's no .htaccess file. Ask your host to check the Nginx configuration instead.
Check redirects in your hosting control panel
Some hosting control panels let you set up redirects separately from WordPress, often in a "Redirects" section or in the domain settings. These run before WordPress loads, so they can conflict with redirects in .htaccess or in WordPress plugins.
Check your hosting control panel for redirect rules and make sure they're not doing the same job as redirects set up elsewhere. Note any rule before removing it, so you can put it back.
Check plugins and your theme
Plugins that manage redirects, SEO or security can all create redirect loops, particularly if they conflict with server rules or each other.
If you can reach the dashboard, deactivate plugins one at a time, starting with SEO, security and redirect plugins, and check whether the loop clears after each. Deactivating plugins switches their features off for visitors, so do it at a quiet time if you can.
If you're locked out, connect via SFTP or your hosting file manager, go to wp-content/plugins/ and rename plugin folders one at a time (for example, from plugin-name to plugin-name-disabled), testing after each. Rename them back when you've finished and check they're active again under Plugins. Our guide to regaining access to WordPress admin covers other lockout causes.
To rule out your theme, rename your active theme's folder inside wp-content/themes/. WordPress then switches to its default theme if one is installed, so you'll need to reactivate your own theme afterwards and check your menus and widgets.
After moving to a new domain
After a move to a new domain, a loop is usually caused by the WordPress site addresses (see above) still pointing at the old domain while the old domain forwards to the new one.
Once the loop is fixed, links inside your content, menus and settings may still point at the old domain. They won't normally cause a loop, but they do need updating. WordPress's migration documentation covers the full process.4
Take a fresh database backup immediately before updating them. A search and replace touches almost every table, and a mistake is much easier to undo from a backup than by hand.
With WP-CLI, run the command with --dry-run first to see what would change without saving anything:
wp search-replace 'https://olddomain.com' 'https://newdomain.com' --all-tables --dry-run
Replace the domains with your actual old and new addresses (and repeat for variations such as http:// or www. if your old links used them). If the results look right, run the same command without --dry-run. It handles WordPress's stored settings safely.5
Without WP-CLI, use a search and replace plugin such as Better Search Replace rather than running SQL queries in phpMyAdmin. A plain SQL find and replace can corrupt some stored settings, which can wipe widgets and plugin settings. Our mixed content guide explains why in more detail.
Still stuck in a redirect loop?
Redirect loops can be hard to track down when several layers (WordPress, your server and a CDN) are involved. Your hosting provider can check server-level redirects and configuration. My WordPress development service and emergency WordPress support can also help trace the redirect chain and fix conflicting rules.
wp-config.php, WordPress Advanced Administration Handbook. ↩ ↩
ERR_TOO_MANY_REDIRECTS, Cloudflare Docs. ↩
wp search-replace, WP-CLI Commands. ↩