Job ssl-too-many-redirects-after-https-or-cloudflare · revised 11 October 2026
Fix "too many redirects" on a site behind Cloudflare
For a site behind Cloudflare, trace the redirect chain, find the two settings that disagree and fix them so each http and https address reaches your site within two redirects, tested with a log-in.
You might be seeing
- The browser says the site redirected you too many times, or shows ERR_TOO_MANY_REDIRECTS
- The site loads for some visitors and loops for others
- The WordPress admin login loops but the home page opens, or the reverse
- It started right after you changed the encryption or SSL setting at Cloudflare
No passwords, keys, card details or admin invites needed to start.
What usually happened
A redirect loop means two rules each send the visitor to the address the other forbids. A common case behind Cloudflare is its encryption mode set to reach your host over plain HTTP while the host redirects every plain-HTTP request to HTTPS; another is Cloudflare forcing HTTPS while the host or the WordPress address setting sends the visitor back to HTTP, or two redirect rules that point at each other. Each rule looks right alone, so nothing short of tracing the chain shows which two disagree. This fixed job covers sites behind Cloudflare only.
Who it’s for: Owner of a small business whose website sits behind Cloudflare and began showing "this page is not working: redirected you too many times" after turning on HTTPS, adding Cloudflare, or changing the site address.
Usually starts when: You added Cloudflare, forced HTTPS in one place, changed the WordPress site address, or moved host, and the site or the admin login now loops.
The result: Each of the http and https versions of the bare and www addresses reaches your site after at most two redirects with a 200 status, HTTPS is enforced in one named place, and a log-in to the site works without a loop.
Check whether this job fits
Four questions, about two minutes. Your answers stay on this page unless you choose to email them.
Checks you can run yourself
Trace the redirects
On a Mac or Linux terminal, follow the redirects from the plain-http address and print each step. Stop after ten.
curl -sSIL --max-redirs 10 -o /dev/null -w "%{url_effective} %{http_code} %{num_redirects}\n" http://yourbusiness.co.ukLook for: A loop ends with an error about too many redirects. A clean chain shows one final address, a 200 status and two redirects at most. Send us the result.
What you get
- A hop-by-hop trace of the loop before the fix and the clean chain after it
- The changed settings, with their previous values
- A short note of which place now enforces HTTPS, and what must not be changed back
- A results table for the four address variants and the log-in
Included
- One site behind one Cloudflare account, with its DNS and SSL settings readable by us
- Tracing the redirect chain for four address variants and the log-in page, with each hop recorded
- Reading Cloudflare's encryption mode, its always-HTTPS and automatic-rewrite settings, any redirect or page rules, the host's force-HTTPS rule and, for WordPress, the site address settings
- Naming the two settings that disagree, and fixing them so HTTPS is enforced in exactly one place
- A check that the connection between Cloudflare and the host is as Cloudflare documents for the mode chosen, and that the certificate at the host is valid where the strict mode needs it
Not included
- A redirect loop on a site that is not behind Cloudflare (another CDN, or none): it is not covered by a fixed-price outcome, so ask for a quote
- Buying or installing a certificate at the host: see the certificate job
- Mapping old page addresses to new ones for search ranking
- Cleaning up mixed-content warnings across the whole site beyond a list of what we find on five agreed pages
- Moving the site, changing DNS provider or setting up caching
- Loops that come from a security plugin or firewall we are not permitted to change
How we know it’s done
Agreed with you before work starts. Each check produces evidence you keep.
Each of http://domain, https://domain, http://www.domain and https://www.domain ends at one address with status 200 after at most two redirects, and none ends in a redirect loop.
Evidence: A four-row table of start address, final address, status and redirect count
curl -sSIL --max-redirs 10 -o /dev/null -w "%{url_effective} %{http_code} %{num_redirects}\n" http://yourbusiness.co.ukA test log-in reaches the site's dashboard or account page without a redirect loop, and a second page view in the same session also loads.
Evidence: Screenshots of the log-in and the second page
The setting that now enforces HTTPS is named in the hand-over, and the settings at the CDN, the host and the site address agree with it.
Evidence: Screenshots of each setting and the previous values
Sign-off. You sign off after the four-address table, the log-in test and the named-setting record all pass.
If it fails. If the loop cannot be removed within the agreed settings, you do not pay. The previous settings are put back and we tell you what the host or CDN holder must change.
When it fits, and when we stop
It fits when
- The site is behind Cloudflare, and you or the account holder can show us the settings or invite us with read access, or will make the changes from our steps
- You can see the host's redirect or force-HTTPS setting, or its support will tell you what it is
- The site was working before the change, or the loop is the only fault
We stop and tell you if
- The host has no valid certificate and cannot install one, but you want the strict encryption mode
- The loop comes from a plugin or firewall that nobody is allowed to change
- The site is also down for another reason, such as an expired domain
- The site is not behind Cloudflare (another CDN, or none): this fixed job does not cover it, so ask for a quote
What could go wrong
Every setting is recorded with its previous value, so the account holder can put it back. A Cloudflare setting change can take a short time to show, so re-test before judging.
Scroll the table sideways to read it all.
| Risk | How we handle it |
|---|---|
| The fix leaves traffic between Cloudflare and the host unencrypted. | We state which encryption mode results, say what it means, and recommend a stricter mode where the host has a valid certificate. The choice is yours. |
| Turning on a stricter mode fails because the host's certificate is not valid. | We check the host's certificate before recommending it, and stop if it cannot be made valid. |
| A change to the WordPress site address locks you out of the dashboard. | We change it only with a recorded previous value and a second way in, and test the log-in. |
A second reviewer, separate from the work that produced the change, checks it against the evidence before you are asked to apply or approve it. No human supervisor is included unless your proposal names one. At launch much of the preparation is automated, and we say so.
How we deliver
We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.
- Trace the chain for four address variants and the log-in page, and record each hop
- Read the Cloudflare encryption mode and its HTTPS and rewrite settings, any rules, the host's redirect and the site address settings
- Name the two settings that disagree and choose one place to enforce HTTPS
- A second reviewer checks the proposed change, including what it does to the connection between Cloudflare and the host
- You or the account holder apply the change; we re-trace the chain and test a log-in
This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.
Need to keep it working?
To keep certificates and redirects checked, ask about the standing domain and DNS responsibility.
Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.
Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.
What you can check
This is a new service. We have not delivered this job for a client yet.
Other ways to get this done
- Cloudflare documents the common causes and fixes for this error, starting with the SSL/TLS encryption mode. If you can read your own settings, that page is a good first check. developers.cloudflare.com
- Your host's support can tell you whether it redirects HTTP to HTTPS itself, which is half the picture.
Questions
Will you change my security settings?
Only the ones that disagree, and we tell you what each change means for the connection between Cloudflare and your host before you approve it.
It only loops in the admin area. Is that this job?
Often yes, if the site is behind Cloudflare. A site address setting or a cookie-related rule can loop only on log-in, and the trace and the log-in test cover it.
Do I need a certificate on my host?
Cloudflare recommends it for the stricter modes. If your host has none, we explain the trade-off and you choose.
My site has no Cloudflare in front of it. Does this cover me?
No. This fixed price covers sites behind Cloudflare, because it works from Cloudflare's documented settings. A redirect loop without Cloudflare is not covered by a fixed-price outcome; ask for a quote and tell us what sits in front of your host.
Send an enquiry
Send us
- The site address and what you see, with a screenshot of the error
- What you changed just before it started: Cloudflare, SSL setting, host, plugin or site address
- Whether the site runs WordPress
- Who can see the Cloudflare settings and the host's settings
Later, once you agree
- A read-only invitation to the Cloudflare account, or screenshots of the SSL/TLS, edge certificate, rules and redirect pages
- A screenshot or export of the host's force-HTTPS or redirect setting, and for WordPress the Settings page for the site address
- A test log-in account that you create and delete afterwards
- No live passwords or keys by ordinary email
The site, the Cloudflare account and the host stay in your name. We ask for read access and make changes only through you or a scoped invitation you can withdraw.
Email fallback: open your mail app
If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “ssl-too-many-redirects-after-https-or-cloudflare” as the subject.