What ERR_TOO_MANY_REDIRECTS means in WordPress
A redirect is normal when it happens once, for example sending an HTTP request to HTTPS or an old address to its replacement. The error appears when two or more rules keep sending the browser back to addresses it has already visited.
A typical loop might send http://example.com to HTTPS at the hosting layer while WordPress or a plugin sends the HTTPS request back to HTTP. Similar loops can occur between www and non-www versions, login URLs, language paths or proxy rules.
Because the redirect happens before WordPress can finish serving a page, the dashboard may also become inaccessible. The exact chain matters. Browser developer tools, server logs or a redirect checker can show which URLs and HTTP status codes are repeating.
Common causes of WordPress redirect loops
The WordPress Address and Site Address must describe the intended installation and public site correctly. A mismatch introduced during a migration, domain change or HTTPS conversion can create a loop.
Security, SSL, caching, membership and redirection plugins can also conflict with server-level rules. A common hosting scenario involves a reverse proxy or CDN terminating HTTPS before the request reaches WordPress. If WordPress incorrectly believes that request arrived over HTTP, it can repeatedly request another HTTPS redirect.
Redirects in .htaccess, Apache virtual-host configuration or Nginx configuration may conflict with WordPress rules. Cached redirects and browser cookies can sometimes preserve a problem after the original configuration has been corrected, so testing in a private browser window is a useful early check.
How to fix too many redirects safely
Take a full backup of the website files and database before editing files, URL values or database records.
- Try a private browser window and clear cookies for the affected domain. If the loop remains, continue with the site itself.
- Check WordPress URLs if you can access the dashboard. Under Settings, then General, review WordPress Address and Site Address. Do not change them simply to experiment.
- Clear website, host and proxy caches. This rules out a cached 301 or 302 response.
- Test plugins safely. If a security, SSL or redirect plugin was changed immediately before the fault, deactivate the suspected plugin. If the dashboard is inaccessible, take a backup and rename only that plugin's directory inside wp-content/plugins using hosting file management or SFTP, then test again.
- Inspect server redirects. Review .htaccess on Apache or the relevant Nginx configuration. Avoid adding duplicate HTTP-to-HTTPS or www rules when the host or proxy already performs that redirect.
- Use recovery routes only if login access is also a problem. Start with the normal Lost your password email. If another administrator account exists, use it to restore access. With SSH and WP-CLI, an administrator can set a new password using wp user update. As a fallback, WordPress documents changing user_pass through phpMyAdmin using its MD5 compatibility route, after a database backup. WordPress upgrades that password hash after a successful login. WP-CLI is preferable where available.
Never send an administrator password by email or include one in a support ticket.
When to stop changing redirect settings
Stop if the redirect chain involves a CDN, load balancer, reverse proxy or server configuration you do not control. The same applies if WordPress URL values have already been edited in the database and you are not certain which domain or protocol should be authoritative.
Repeatedly adding redirect snippets can hide the original fault and create new loops. A useful diagnosis compares the requested URL, each Location response header and the protocol WordPress believes it is receiving.
Web Support Services offers an Emergency Fix for £249 per incident, with a response within 2 working hours. Care plans start from £59 a month for ongoing maintenance and monitoring intended to reduce repeat incidents.