My website redirects to a spam site

You type your address and land on a casino, a pharmacy page or a fake prize. That is almost always one of three things: the site was hacked, the domain lapsed, or an ad script was swapped.

What to do, in order

  1. Check the domain is still yours. Run whois yoursite.com. If the expiry date passed or the owner changed, the domain was re-registered by someone else. Call your registrar today; some expired domains can still be recovered in the grace period.
  2. Check if it only happens from Google or on phones. Hacked WordPress sites often redirect only visitors who come from a search or a phone, so the owner never sees it. Search your site on your phone and click the result.
  3. Look for injected code. On WordPress, check .htaccess, wp-config.php, the theme's header.php and functions.php for long lines of scrambled text or eval(base64_decode. Check Users for admins you did not create.
  4. Clean and lock. Restore a clean backup from before the redirect started, update WordPress, every plugin and theme, delete plugins you do not use, change every password, including hosting and database.
  5. Ask Google to re-check. In Search Console, Security issues, request a review once it is clean.

If you cannot find the source, send me the address and I will tell you where the redirect comes from.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.