Skip to main content
All insights
Security8 min readSeptember 30, 2026

Google Shows Spam Pages for Your Website? How to Check and What to Do

The short answer

If Google shows pages on your domain that you never created while your site looks normal, the site has most likely been hacked to show spam only to Google's crawler. Confirm it with a site: search, your robots.txt file, and Search Console's owner list, security report and URL Inspection tool, then clean the infection.

By Timothy Indarsingh, Founder & CEO, Firelinkx

A customer searches for your business and Google shows pages you never wrote, selling cheap medicine or replica watches, sometimes in Japanese. You open your website and everything looks normal. Both are true at once, because the site is showing one version to people and another to Google.

What is happening to your site

Code an attacker has placed on your server checks who is asking for each page. A person in a browser gets your normal site. Google's crawler gets pages of spam links and keywords, which borrow your domain's standing in search to push the attacker's own sites up the results. Showing search engines different content from visitors is what Google calls cloaking, and its spam policies treat it, along with hacked content, as a violation.

The volume can be large. In the worst case we have cleaned up, one file on the server answered more than 100,000 requests in about ten days. Google's crawler sent nearly all of them, and almost every answer was a page of spam. The site itself looked normal in a browser throughout.

Why attackers hide the spam from you

Your domain has something a new spam site lacks: years of history with Google. Pages placed on it get crawled and ranked faster. Keeping the spam out of your sight keeps it running for as long as possible.

Two tricks keep Google coming back to the spam. The attacker adds Sitemap lines to your robots.txt file that point search engines at their own lists of spam pages. They also make themselves an owner of your site in Google Search Console, which lets them submit those sitemaps directly and watch how the spam performs. Google's guide to the Japanese keyword hack, a version of this attack common enough to get its own guide, describes the same Search Console step.

How to check your site

Most of these checks need access to your Google Search Console property. If nobody at your business has that access, get it set up first. Search Console is where Google reports problems with your site, and the Google Search Console guide explains how to add your site.

  1. Search Google for site: followed by your domain, for example site:yourbusiness.com, and scroll through the results. Pages you never created, especially in another language or about products you do not sell, are the plainest sign.
  2. Open yourbusiness.com/robots.txt in a browser. Legitimate Sitemap lines usually point to your own sitemap.xml, wp-sitemap.xml or sitemap_index.xml. A line pointing to another domain, or to an odd file name on yours, is a strong sign of this attack.
  3. In Search Console, open Settings, then Users and permissions, and look for owners nobody at your business can account for. Owner lists are kept per property. In one cleanup, the attacker was an owner of the site's https address only, while the Domain property listed nobody unexpected. Add the http and https versions of your address, with and without www, as URL-prefix properties and check each list. Google notifies every verified owner when a new owner is added, so that warning reaches you only if someone at your business is an owner.
  4. Open the Security issues report, where Google lists hacked content it has detected under labels such as content injection or URL injection, often with example URLs. Then open the Manual actions report, which is where a manual action for cloaking would appear.
  5. Paste one of the spam URLs into the URL Inspection bar at the top of Search Console and choose View crawled page. It shows the HTML Google stored from its last crawl, so spam you never see in your browser shows up there. A live test shows what Google's inspection tool receives today, but some hacks only answer requests that identify as Google's main crawler, so treat a clean live test as inconclusive.
  6. Open the Sitemaps report and look for sitemaps you did not submit.

When visitors from Google see it too

Some versions of this attack send visitors who arrive from a Google search to another site, while anyone who types your address directly sees the normal one. If a customer says clicking your site in Google took them somewhere strange, treat it as a sign of the same infection even if you cannot reproduce it yourself.

What to do when you find it

Work through these in order. Deleting the spam pages before anything else is a common mistake, because the files producing the spam are the trail back to how the attacker got in.

  1. Stop the spam reaching Google. Make the spam URLs return an error and restore a clean robots.txt. If your domain runs through Cloudflare, rules there can block the spam paths without changing anything on the infected server, so the investigation starts from an untouched copy.
  2. Remove the attacker from Search Console. Delete the unknown owner, then delete the verification method they used, such as an HTML file they uploaded to your site or a DNS record. Remove any sitemaps they submitted from the Sitemaps report too. Google's help on managing owners warns that a removed owner whose verification token is still in place can verify again, and that someone who hacked the site may be able to put the token back. The removal holds once the attacker's access to your server and DNS is gone.
  3. Clean the infection itself. Find the entry point, remove every file, user account and scheduled task the attacker added, and check every other site on the same hosting account. The guide on what to do if your website gets hacked covers the full cleanup.
  4. Ask Google to review the site. If the Security issues report flagged hacked content, request a review there once the site is clean. Google says a review takes from a few days to a few weeks.

How long the spam takes to disappear

Once the spam URLs return an error, they drop out of Google's results as Google recrawls them. That happens sooner on a site Google visits often, and a large batch of spam pages takes longer. The Removals tool in Search Console can hide the worst URLs from results temporarily in the meantime. Keep checking a site: search for your domain, and the Pages report in Search Console, until the spam has gone.

Keeping it from coming back

An infection whose entry point stays open tends to return the same way. Update or remove old plugins and themes, and delete sites and hosting accounts you no longer use. Turn on two-factor authentication for your hosting, domain registrar, email and Search Console accounts. Checking the owner list on each property every few months is quick, and it is where this attack is easiest to spot.

Frequently asked questions

Do spam pages in Google mean customer data was stolen?

Not necessarily. The attacker's goal here is search traffic. Anyone able to add spam pages could also read what the site stores, though, so treat customer records on the site as exposed until the entry point is found and you know what was reached.

What is the Japanese keyword hack?

It is a widespread form of this attack. It fills Google's results for your domain with automatically generated pages in Japanese, usually selling counterfeit goods. The fix follows the same steps as any hacked content, starting with the entry point and ending with Search Console.

Why do the spam pages keep coming back after I delete them?

Deleting pages removes what Google can see today. The code that generates them is still on the server, and the way the attacker got in is still open, so new pages appear. The spam stops once the attacker's files and access are gone and the entry point is closed.

Will Google warn people about my site?

It may. Google can mark your listing in search results with a note that the site may be hacked, which puts people off clicking. Once the site is clean, requesting a review from the Security issues report is how you get the note removed.

Can I fix this myself?

You can run every check in this guide yourself. Removing the infection is harder, because the attacker's files are made to blend in with the site's own and one missed file can bring the spam back. For that part, get help from someone who has dealt with this kind of attack before.

Want your security gaps checked?

Firelinkx handles the cleanup for sites these checks flag, including the Search Console and robots.txt work.

WhatsApp Us