Skip to content

Your website redirects to spam or Japanese pages

Customers say your site sends them to spam, or Google shows Japanese pages, but it looks fine to you. Why that happens, how to confirm it and where it hides.

By Miro, Wave Digital. Updated .

If customers say your site sends them to spam, but it looks fine when you open it, your site has almost certainly been hacked. These hacks are built to hide from you: they often only fire for people on phones or people who clicked through from Google.

First, follow what to do in the first hour: tell your host, change passwords, check for unknown admin users. Then come back here.

Why you can't see it

The hacked code checks who is visiting first. Google says hacked sites can redirect some users based on where they came from, their browser or their device.

Diagram: hacked code on the website checks each visitor. Someone clicking from Google or on a phone is sent to a spam site. The owner, logged in and typing the address, sees the normal site.
The same hacked site can look normal to you and send your customers to spam
Version Who gets redirected Who sees the normal site
Only from Google People clicking your site in Google search results People typing the address straight in
Only on phones Mobile visitors Desktop visitors
Not for logged-in users Visitors who aren't logged in Anyone logged in, so the owner never sees it

The last one is how some WordPress malware works.

The "Japanese keyword hack" is a related trick. It creates new pages of Japanese text linking to shops selling fake brand goods. Click one and you might be redirected, see gibberish, or get "page not found". Google warns that not-found page can be fake.

How to confirm it

  1. Search Google for site:yourdomain.co.nz. Look through a few pages of results for addresses you don't recognise or titles in another language.
  2. Click a result from your phone. Use a private or incognito tab so you're not logged in, and click through from Google rather than typing the address. Try it a few times.
  3. Check Search Console. If you have Google Search Console, open Security issues. It names the type of hack and lists some affected pages, not all of them.
  4. Use URL Inspection. Paste an odd address into the URL Inspection tool and run a live test. It shows what Google's crawler actually gets.
  5. Check who else owns your Search Console. Go to Settings, then Users and permissions. An owner you don't know is a strong sign of a hack.

Where it hides

On WordPress sites, the usual spots are:

Where What to look for
.htaccess, a hidden settings file in the site's main folder Rules that check whether a visitor came from a search engine or is on a phone, then send them away
wp-config.php and core files like wp-load.php or index.php Extra code added near the top or bottom
The theme, especially functions.php, header.php and footer.php Extra code added
The database JavaScript added to posts or settings
A fake plugin A harmless or security-sounding name, sometimes hidden from the plugin list
Scheduled tasks (WordPress cron) Jobs that put the malware back or recreate a hidden admin user

The code is usually scrambled. Look for long strings of random characters and words like eval or base64_decode.

Why deleting the spam pages doesn't work

The spam pages are the symptom. Often they aren't real files at all. They're made on the fly by code sitting somewhere else. Delete the pages you can see and that code makes new ones.

There's often a second copy, a fake plugin or a scheduled task waiting to reinstall it. Google's cleanup guides say to:

  1. Replace .htaccess with a clean version.
  2. Reinstall WordPress and every theme and plugin from fresh copies.
  3. Check what remains.

The way they got in still needs closing too.

Getting Google's warning removed

Google shows "This site may be hacked" until the owner acts. Google says to fix the problem across the whole site first. Fixing only some pages won't get a partial return. Once the whole site is clean:

  1. Remove any Search Console owners you don't recognise, and their verification files.
  2. Check your sitemap in Search Console for spam addresses.
  3. Run the old spam addresses through URL Inspection again to confirm they're gone.
  4. In Security issues, click Request review. Say what you found, what you fixed and how.

Reviews can take several days or weeks.

Then keep the site updated so it doesn't happen again. See website maintenance.

When to get help

Confirming it is the easy part. Get someone in if you can't find the code, if the spam comes back after you cleaned it, if there are files you don't understand, or if you can't get into your hosting at all.

If you're not sure whether your site is affected, our free website check is a good place to start.

Is your site slow on phones, out of date or marked "Not secure"?

Put in your web address and find out free in about 30 seconds.

Rather not deal with this yourself?

Join Safe and we clean up the hack as part of moving your site to our hosting, ask Google to remove the warning, then keep the site patched and watched. Safe is $95 a month + GST, with no setup fee and no fixed term.