Fix redirect loops: HTTPS, www and reverse proxies
Find the conflicting rule and verify the complete route to your page.
check.uk.app technical team · Reviewed 26 September 2026
Recognise the repeated URL
A loop returns to an earlier URL: /shop → /store → /shop. A long chain may still finish successfully. Open Redirect chain in your check.uk.app report and compare addresses and status codes. A timeout or hop limit alone does not prove a loop.
Record the public response
Replace example.com with a public URL you control. This GET command saves headers for every hop and the final body. It stops after ten redirects or thirty seconds. In Windows PowerShell use curl.exe. Never share diagnostic output containing private tokens.
curl --silent --show-error --location --max-redirs 10 --max-time 30 --proto "=http,https" --proto-redir "=http,https" --dump-header headers.txt --output body.html https://example.com/Identify the conflicting layer
Inspect the CDN, proxy, web server and application. One layer may add www while another removes it. A TLS-terminating proxy may forward HTTP to an application that redirects back to the same public HTTPS URL. Choose the canonical host and scheme, then compare logs at the time of the request.
Pass the scheme through trusted proxies
At the TLS-terminating Nginx proxy, proxy_set_header X-Forwarded-Proto $scheme can communicate the external scheme. The application must trust only known proxies. On an inner HTTP proxy hop, $scheme is no longer the original scheme; preserve it only through an explicitly trusted chain. Never accept arbitrary client-supplied forwarding headers as authoritative.
Verify and keep a rollback
Save the original rules. Change one layer, validate its configuration and repeat the GET for HTTP, HTTPS and both hostname variants where configured. Verify the original path and query string. The route should finish at the intended page without oscillating hosts or downgrading HTTPS.
Check sign-in and forms too: redirect status codes can affect the request method. Compare a fresh browser session with curl because browser cache and HSTS can alter behaviour. Restore the saved rule if navigation breaks. Clearing cookies does not fix a server-side redirect conflict.