How to Fix an HTTPS Redirect Loop in Joomla

Trace the exact redirect chain

Use a browser Network panel or an HTTP client that displays redirects and identify the two or more URLs repeating in the chain. Note whether the loop changes scheme, hostname, path, trailing slash, or index.php. That detail tells you which configuration layers to inspect.

Review Joomla Force HTTPS

Open System → Global Configuration → Server and check Force HTTPS. Joomla can force HTTPS for selected areas or the entire site. If another infrastructure layer already performs the redirect, verify that Joomla receives accurate information about the visitor's original scheme before leaving both mechanisms enabled.

Check TLS termination at a proxy or CDN

A common proxy loop occurs when the visitor connects to the CDN with HTTPS but the CDN connects to the origin with HTTP. If the origin blindly redirects that internal HTTP request to HTTPS and the proxy repeats the same origin connection, the cycle continues. Configure the proxy and origin according to the provider's secure-origin model.

Inspect web-server and hosting redirects

Check .htaccess, Nginx, IIS, control-panel redirect tools, and virtual-host configuration for rules that force a different scheme or hostname. Remove obsolete rules left from a migration or earlier certificate setup. Keep Joomla SEF rewriting separate from HTTPS canonicalization where possible.

Check hostname and port assumptions

Make sure redirects do not send https://www.example.com to https://example.com while another rule immediately reverses it. Also avoid constructing public URLs from an internal proxy port. The destination should use the one public canonical scheme and hostname intended for visitors.

Purge redirect caches carefully

After fixing the configuration, purge CDN or reverse-proxy caches that may contain redirect responses and test with a private browser session. Permanent redirects can also be cached by browsers, so confirm the current server behavior with a fresh HTTP request rather than relying only on an old tab.

Retest authentication and forms

Once ordinary pages load, test Administrator login, frontend login, contact forms, account pages, and other session-sensitive routes. Confirm cookies are secure where expected and that redirects preserve paths and query strings. The fix is complete only when HTTPS works consistently across normal Joomla workflows.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket