Cloudflare

Cloudflare redirect chains: Always Use HTTPS

Cloudflare redirects at the edge, your origin redirects too, and the hops stack. The exact settings, the documented loop causes, and how to count hops.

Cloudflare redirect chains form when "Always Use HTTPS," Redirect Rules or Page Rules, and origin redirects all act on the same request. Set the SSL mode to Full or higher, choose one layer for each redirect, remove duplicate rules, and check each host and protocol variant until only the intended hop remains.

Why Cloudflare does this

Cloudflare adds redirects at its edge on top of whatever the origin does, which is how chains appear without anyone writing them. Their docs: "Always Use HTTPS redirects all your visitor requests from http to https, for all subdomains and hosts in your application", enabled on "the Edge Certificates page". They warn: "Cloudflare recommends not performing redirects at your origin web server, as this can cause redirect loop errors." The ERR_TOO_MANY_REDIRECTS page lists the causes: "A misconfiguration of your SSL/TLS Encryption mode", "Various settings on the Edge Certificates page", and "A misconfigured redirect rule", with the classic being Flexible mode: "Redirect loops will occur if your origin server automatically redirects all HTTP requests to HTTPS." For forwarding rules they say to "review your various redirect rules and Page Rules" when rules conflict.

Check it right now

Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.

Run the check

How to fix it

  1. Open the Cloudflare dashboard and go to the SSL/TLS Overview page for the domain.
  2. Check the SSL/TLS encryption mode: Flexible mode plus an origin HTTPS redirect is the documented loop, so move to Full or higher.
  3. Go to the Edge Certificates page and check whether Always Use HTTPS is on.
  4. Review your redirect rules and Page Rules for a rule that conflicts with the origin redirect.
  5. Remove one layer: the origin redirect or the edge redirect, not both.
  6. Re-check the URL with the free redirect checker below and count the hops.

Why it happens again

Every layer owns one hop: the edge owns http to https, a redirect rule owns www to non-www, and the origin owns whatever it wants. Each is configured by a different person at a different time, none can see the others, and the chain only becomes visible when a crawler counts hops or a visitor hits the loop. Their docs diagram exactly this: http bouncing to https and back.

stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.

See what monitoring covers

Catching it next time

Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.

Other ways Cloudflare loses pages

A broken or chained redirect, on other platforms

Sources

Every claim about Cloudflare above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.