Practical troubleshooting guide · The business scenario is illustrative, not a client case study. Administrative changes require authorised access.
A community organisation in the Niagara–Stoney Creek corridor enables an HTTPS setting and its event website stops opening. Browsers show ERR_TOO_MANY_REDIRECTS. Clearing cookies may help a browser-specific issue, but a server redirect loop needs its configuration corrected before visitors can reliably reach the event details.
Locate the loop before changing settings
Record what changed and save the current Cloudflare and hosting settings. Test the affected URL in another browser and inspect the Location headers with the command below. Repeated movement between http and https, or between www and the bare domain, points to conflicting redirects. Use your own domain only; these checks do not require account credentials.
Check how the origin connection is configured
With Cloudflare Flexible mode, the connection to the origin uses HTTP. If that origin always redirects to HTTPS, a loop can occur. Have the administrator check that the origin has a suitable valid certificate before moving to Full (strict). Do not disable transport security as a blanket fix. Other loops can come from application URL settings or competing www redirects.
Make the redirect rules agree
Choose the intended public URL and review edge rules, hosting rules and application settings together. Correct the conflicting layer, retaining a record of its previous value. A Cloudflare-hosted static site and a separately hosted WordPress origin have different settings; do not apply origin-server instructions to a setup that has no such server. Make one explainable change and retest before changing another layer.
Confirm every important entry path
Check http, https, www and bare-domain entry points that your business uses. They should converge on the intended secure destination without looping. Test the event form or contact link and confirm any embedded provider still works. If only one browser fails after the server fix, then investigate its cached state. Keep the final redirect and certificate arrangement documented for the next renewal or migration.
Technical check
Read-only redirect inspection — stops after ten redirects
curl.exe -I -L --max-redirs 10 https://example.comThis command reads public information; it does not change configuration. Example domains are placeholders.
MAKE IT ACTIONABLE
Your next steps
- Save the previous redirect and encryption settings.
- Find the repeating Location headers.
- Verify the origin certificate and all entry paths.
Official reference
Cloudflare: Too many redirects
Technical guidance checked October 1, 2026. Product features and requirements can change. The business checklists above are practical suggestions from Cyber Bounds.
PUT THE NEXT STEP INTO PRACTICE
Help with website maintenance.
Updates, backups, and practical checks that help your website stay useful and dependable. Tell us about your situation and we’ll discuss a suitable scope and quote.
Explore Website MaintenanceEmail us about this guide