Skip to content
Web Hosting

Fix "Too Many Redirects" (ERR_TOO_MANY_REDIRECTS)

ERR_TOO_MANY_REDIRECTSredirected you too many timesredirect loop
7 min read Updated 12 June 2026 ESAGAMES Team

A redirect loop means two rules keep bouncing the browser back and forth — A sends you to B, B sends you back to A. It's almost always an SSL/Cloudflare or WordPress URL mismatch. Here is the fix.

Cause 1: Cloudflare SSL mode

The classic loop: Cloudflare's SSL is set to Flexible while your server also forces HTTPS. Cloudflare talks http to your server, your server redirects to https, forever. Set Cloudflare SSL to Full (strict) when your server has a valid certificate.

Cause 2: WordPress URL mismatch

If the WordPress and Site URLs disagree (http vs https, www vs non-www), it loops. Set both consistently in wp-config.php:

define('WP_HOME','https://example.com');
define('WP_SITEURL','https://example.com');

Cause 3: conflicting .htaccess redirects

Two rules — one forcing www, another forcing non-www (or http↔https) — fight each other. Keep one canonical redirect direction and remove the duplicate.

Clear cookies/cache to test

Your browser caches redirects, so test in a private window after each change — otherwise you'll keep seeing the old loop even once it's fixed.

A loop = two rules disagreeing. Fix Cloudflare SSL to Full, match WordPress URLs, and keep one canonical redirect.

Cause 4: a security/redirect plugin fighting the server

A "force SSL" or caching plugin can add its own redirect on top of one already forced by the server or .htaccess. Two independent layers each redirecting for the same reason is the most common way loops reappear after everything looks fixed. Disable one side — usually the plugin — and let the other handle it.

Cause 5: a stale CDN or browser cache

Even after the underlying cause is fixed, a cached redirect response (or a cached page from before the fix) keeps looping. Purge the CDN/Cloudflare cache and test in a fresh private/incognito window.

How to prevent redirect loops

  • Pick ONE canonical URL (https, with or without www) and enforce it in exactly one place.
  • When using Cloudflare, keep SSL mode at Full (strict) once your origin has a valid certificate.
  • Avoid stacking a "force SSL" plugin on top of a server-level HTTPS redirect.
  • Test any SSL/URL change in a private window before assuming it's still broken.

Related errors

If the loop started right after installing or renewing SSL, see SSL / Let's Encrypt renewal. If Cloudflare can't reach your origin at all rather than looping, that's error 521. If the domain itself doesn't resolve, see DNS_PROBE_FINISHED_NXDOMAIN.

SSL done right

Our web hosting includes valid SSL and sane redirects out of the box, with DDoS protection on NVMe.

See web hosting
FAQ

Frequently asked questions

What causes ERR_TOO_MANY_REDIRECTS?

Two redirect rules bouncing the browser in a loop — most commonly Cloudflare's Flexible SSL fighting a server HTTPS redirect, mismatched WordPress URLs, or conflicting www/non-www rules in .htaccess.

How do I fix a redirect loop with Cloudflare?

Set Cloudflare's SSL/TLS mode to Full (strict) when your origin has a valid certificate, instead of Flexible. Flexible plus a server-side HTTPS redirect creates an endless loop.

Why does my WordPress site keep redirecting?

Usually the WordPress Address and Site Address disagree (http vs https or www vs non-www). Set WP_HOME and WP_SITEURL to the same canonical URL in wp-config.php.

Why did the redirect loop come back after I fixed it?

Usually a cached redirect — either a CDN/Cloudflare cache or your own browser cache is still serving the old redirect response. Purge the CDN cache and test in a private/incognito window.

Can a plugin cause a redirect loop even with correct WordPress URLs?

Yes — a "force SSL" or security plugin can add its own redirect on top of one the server or .htaccess already applies. Having two layers both redirecting for the same reason is a classic cause of loops that "shouldn't" be happening.

Does ERR_TOO_MANY_REDIRECTS mean my site was hacked?

Rarely — it's almost always a configuration conflict (SSL mode, WordPress URLs, or duplicate .htaccess rules), not malware. Only suspect a hack if you also see unfamiliar redirects to other domains, which points to injected code instead.

Knowledge base

Related articles

Skip the troubleshooting

Managed, protected hosting in Frankfurt — we handle the Linux, the network and the DDoS so you don't have to.

Payments Secure checkout with cards, banking apps and digital wallets.

Choose the payment flow that fits your stack and region without leaving the platform.

Pay by Zen Visa Mastercard Paysafecard PaysafeCash Skrill Trustly Bancontact UnionPay iDeal WebMoney