Fix ERR_TOO_MANY_REDIRECTS cPanel [7 Solutions]
Stop redirect loops causing ERR_TOO_MANY_REDIRECTS in cPanel. Fix SSL mismatches, .htaccess rules, and WordPress conflicts in minutes.

On this page
TL;DR — Key takeaways
- ERR_TOO_MANY_REDIRECTS happens when your server and proxy create conflicting redirect rules, most often from Cloudflare SSL mode mismatches with cPanel SSL settings.
- Check .htaccess first for duplicate HTTPS redirect rules, then verify your Cloudflare SSL mode matches your cPanel SSL certificate configuration.
- WordPress siteurl mismatches between HTTP and HTTPS cause persistent loops; correct them via wp-config.php or direct database edit before touching .htaccess.
- Testing in incognito mode with browser DevTools Network tab shows you the exact redirect chain and which component starts the loop.
ERR_TOO_MANY_REDIRECTS shows up when your browser hits a redirect loop, usually between your cPanel server and a CDN like Cloudflare. The site bounces requests back and forth until the browser gives up.
I've seen this error hundreds of times in support tickets. The usual culprit is a mismatch between Cloudflare's SSL mode and your cPanel SSL setup, or duplicate redirect rules in .htaccess. WordPress sites add another layer with hardcoded URLs in the database. This guide walks through identifying the loop source, testing each layer, and fixing it without breaking your site.
Understanding the Redirect Loop Bottleneck
A redirect loop happens when two components disagree on the final URL. Your browser requests example.com, the server redirects to https://example.com, but something in the chain sends it back to http://example.com, and the cycle repeats.
In cPanel environments, the bottleneck usually sits at one of three points: Cloudflare SSL mode sending HTTP to an origin that forces HTTPS, .htaccess rules that conflict with server configuration, or WordPress siteurl values that don't match your actual domain protocol. Each creates a different signature in the redirect chain.
Performance impact goes beyond the error itself. Every redirect adds latency. A site with five redirects before serving content wastes seconds on mobile connections. Fix the loop and you fix the speed problem too.
Tracing the Redirect Chain
Open DevTools in Chrome or Firefox and go to the Network tab. Load your site in incognito mode to skip cached redirects. You'll see every request and its status code.
Look for 301 or 302 responses in the list. Click each one and check the Response Headers for the Location field—that's where the redirect points. If you see the same two URLs alternating, you've found your loop. Write down both URLs and note whether they differ by protocol (HTTP vs HTTPS), subdomain (www vs non-www), or both.
The first redirect in the chain tells you which component starts the loop. If the initial request to your domain returns a Cloudflare server header and redirects to HTTPS, but the HTTPS request redirects back to HTTP, your SSL mode is wrong. If both redirects show your origin server, the problem is in .htaccess or cPanel configuration.
Fixing Cloudflare SSL Mode Mismatches
Log into Cloudflare and go to SSL/TLS settings. Check your current mode. Flexible SSL encrypts traffic between the visitor and Cloudflare but sends plain HTTP to your origin. If cPanel has an SSL certificate and forces HTTPS, this creates the loop.
Switch to Full if you have any SSL certificate on cPanel, even a self-signed one. Use Full (Strict) if you have a valid certificate from Let's Encrypt or a commercial CA. Full modes encrypt the entire path and stop the loop.
After changing the mode, go to Caching and purge everything. DNS changes propagate fast, but cached redirects linger. Test in incognito again. Before the change, you'd see HTTP requests hitting your origin. After, you should see HTTPS throughout the chain with no redirect alternation.
Cleaning Up .htaccess Redirect Rules
Replace example.com with your domain. The [OR] means either condition triggers the rule. The [L] flag stops processing after this rule matches, preventing further redirects. Upload the file and test. If the error persists, comment out the entire RewriteCond block temporarily to see if another file or server config is causing it.
- RewriteCond %{HTTPS} off [OR]
- RewriteCond %{HTTP_HOST} !^www\. [NC]
- RewriteRule ^(.*)$ https://www.example.com/$1 [R=301,L]
Correcting WordPress Siteurl and Home Values
WordPress stores your site URL in two database fields: siteurl and home. If they're set to HTTP but your server forces HTTPS, every page load triggers a redirect that loops back. Check them in wp-config.php first, since it overrides the database.
Add these lines near the top of wp-config.php, right after the opening PHP tag:
define('WP_HOME', 'https://example.com');
define('WP_SITEURL', 'https://example.com');
Match the protocol and subdomain to your actual domain. Save and test. If it works, the old database values were wrong. You can leave the defines in place or update the database directly via phpMyAdmin in cPanel.
In phpMyAdmin, open your WordPress database, find the wp_options table, and locate the siteurl and home rows. Edit both to match your final URL including protocol and www preference. This method is faster for bulk changes, but wp-config.php overrides are safer if you're migrating or testing.
Testing and Monitoring After Fixes
After each change, test from a clean browser session. Incognito mode is essential because cached redirects hide whether your fix worked. Check the DevTools Network tab again—you should see one redirect at most, from HTTP to HTTPS or non-www to www, then a 200 OK response.
Load time should drop. A site with a redirect loop might fail entirely or take 10-20 seconds before the error appears. A clean redirect completes in under 200ms on decent hosting. Run a speed test from GTmetrix or WebPageTest and compare the redirect count to your baseline.
Set up monitoring for redirect chains. Many uptime monitors flag excessive redirects. StatusCake and UptimeRobot both offer this. If the error reappears after a plugin update or config change, you'll know within minutes instead of waiting for user complaints.
Check your server logs in cPanel under Metrics → Errors. Look for repeated 301 or 302 entries for the same URL. High redirect counts correlate with memory spikes and CPU load because each redirect consumes a new request slot. Fixing loops reduces server load noticeably on high-traffic sites.
Preventing Future Redirect Loops
Document your redirect setup. Note your Cloudflare SSL mode, the .htaccess rules you settled on, and your WordPress URL settings. When you update plugins or migrate hosts, reference this doc to avoid reintroducing conflicts.
Test SSL changes in Cloudflare's development mode first. It bypasses the cache and shows you the real server response. You can confirm Full mode works before purging cache and affecting all visitors.
Avoid plugin-generated .htaccess rules when possible. Many security and SEO plugins insert redirect blocks that conflict with manual rules. If you need plugin features, disable their redirect options and handle it yourself at the top of .htaccess. Centralized control prevents loops.
Review .htaccess after every major update. WordPress core updates sometimes reset file permissions or append new rules. A quick scan catches duplicates before they cause outages. Keep your backup file dated so you can diff changes.
Quick troubleshooting checklist
- Back up .htaccess and note current Cloudflare SSL mode before changes
- Test site in incognito mode to bypass cache
- Check browser DevTools Network tab for redirect chain
- Verify Cloudflare SSL mode matches cPanel SSL certificate type
- Search .htaccess for duplicate redirect rules
- Confirm WordPress siteurl and home values match your target protocol
- Clear Cloudflare cache after any DNS or SSL changes
- Test from multiple networks to rule out local DNS cache
FAQ
What causes ERR_TOO_MANY_REDIRECTS in cPanel?
The error occurs when your server and CDN or proxy create a redirect loop, usually from Cloudflare Flexible SSL sending HTTP to a cPanel site that forces HTTPS, or from duplicate redirect rules in .htaccess conflicting with server-level redirects. WordPress siteurl mismatches between HTTP and HTTPS also trigger persistent loops.
How do I fix Cloudflare redirect loops with cPanel SSL?
Set Cloudflare SSL mode to Full or Full (Strict) if you have a cPanel SSL certificate installed. Flexible SSL sends unencrypted requests to your origin, which then redirects back to HTTPS, creating the loop. Full modes encrypt the connection end-to-end and break the cycle.
Can .htaccess cause too many redirects?
Yes. Multiple redirect rules that conflict, such as one forcing www and another forcing HTTPS in the wrong order, create loops. Rules that redirect HTTP to HTTPS when Cloudflare already handles it also cause the error. Remove duplicate rules and test one redirect at a time.
Related articles
- Hosting OperationsSelf-Hosted App Deployment Fails? Check DNS, SSL, Reverse Proxy, and Logs FirstTroubleshoot failed self-hosted app deployments by checking DNS, SSL, reverse proxy routing, container status, logs, and ports.
- Hosting OperationsSelf-Hosted PaaS on a VPS: What to Check Before Installing Coolify, Dokploy, or CapRoverA hosting support checklist for preparing a VPS before installing self-hosted PaaS tools like Coolify, Dokploy, or CapRover.
- Hosting OperationsLinux Server Security Lessons from the Arch Linux Malware Package IncidentPractical Linux server security checklist for VPS admins after package malware concerns, with safe checks, rollback steps, and support guidance.
- Hosting OperationsAWS Lightsail Hong Kong VPS Latency: Practical Hosting Guide for IndonesiaLearn how to test AWS Lightsail Hong Kong VPS latency, compare regions, migrate safely, and troubleshoot hosting performance.
- Hosting OperationsCloudflare Tomorrow Watchlist: A Practical Hosting Operations GuidePractical Cloudflare troubleshooting checklist for DNS, SSL, caching, WAF, origin health, safe testing, and rollback planning.
- Hosting OperationsNetwork Safety Checklist for AI Agent Skills in Hosting OperationsAudit AI agent skills safely with network checks, secret protection, sandbox testing, rollback steps, and hosting support troubleshooting guidance.