A client's site "redirected you too many times": what to do
The site sends the browser to another address, which sends it back, round and round, until the browser gives up. Nobody can see the page, so to visitors the site is down. Here is the order we would work in.
1. Make sure it is a redirect loop
Chrome says "This page isn't working. example.com redirected you too many times" with the code ERR_TOO_MANY_REDIRECTS. Firefox says "The page isn't redirecting properly". Safari says too many redirects occurred.
Try it in a private window. If it loads there, the loop depends on something your browser kept, usually a cookie from logging in or an old redirect it remembered. Clearing the cookies for that one site fixes it for you, but check whether visitors are affected before you close the ticket.
2. See every hop
From a terminal on macOS or Linux, this prints each answer and where it sent you next:
curl -sSL -o /dev/null -D - --max-redirs 10 https://example.com | grep -iE "^(HTTP/|location:)"The pattern usually names the cause. Addresses swapping between http and https point at the certificate setup. Swapping between www and no www points at two rules that disagree. The same https address sending you to itself points at a server that does not know the visitor already arrived over https, which is also how Cloudflare's Flexible mode looks from outside.
3. The usual causes
- Cloudflare's SSL mode is set to Flexible. Cloudflare then talks to the host over plain http, the host redirects to https, and Cloudflare asks over http again. Install a certificate on the host and set the mode to Full (strict).
- WordPress thinks it lives at a different address. Under Settings, then General, the WordPress Address and Site Address must match how the site is really served, including https and www. If you cannot log in, the same two values can be set as
WP_HOMEandWP_SITEURLinwp-config.php. - Two rules disagree. The hosting panel forces www and a plugin or
.htaccessrule removes it, or both force https in ways that fight. Keep one rule and remove the other. - A proxy or load balancer sits in front of the server. The visitor arrives over https, but the server only sees plain http from the proxy and keeps redirecting to https. The server has to be told to trust the proxy's forwarded header, often
X-Forwarded-Proto. - An old redirect is cached. A caching plugin or a CDN kept yesterday's redirect after the rules changed. Purge the cache after fixing the rules.
Most loops start right after a change: a move to https, a new host, Cloudflare switched on, or a plugin that forces an address. Start with whatever changed last.
4. Check the fix from outside
Run the command from step 2 again. It should end on a single 200 after at most one or two hops. Then open every version of the address in a private window: http and https, with and without www. Each should arrive at the same page.
5. Tell the client what happened
They may have seen the error themselves. For example:
The site was stuck sending visitors in a circle between two addresses, so the page never loaded. Two settings disagreed after a recent change. I have made them agree and the site is working normally again.
6. Next time, hear about it first
Bionic Uptime follows up to ten redirects on every check, and keeps any cookie the site sets along the way, as a browser does. If the address loops, or has not reached a page after ten, the check fails. When both of our locations, on two different companies' networks, agree, it is confirmed as an outage and each person on that website's alert list gets one email. For a loop, it says the address redirected in a way that never finished. See the exact outage email, or what to check when a site is down for another reason.
3 websites are free, forever, with no card. Looking after several client sites?