Spam Pages Showing in Google Results for Your Site
Higher-risk issue — be cautious and consider professional help sooner.
Google shows pages under your domain that you never made — Japanese text, cheap pharmacy pills, casino or replica-product listings — and they are hurting how your business looks in search.
Common signs of this issue
- Searching Google for site:yourdomain.com shows pages you never created, often hundreds or thousands of them.
- The results have Japanese or Chinese text, or titles about pharmacy pills, casinos, loans, replica handbags, or adult content.
- Your site looks completely normal when you visit it yourself, yet Google keeps showing the strange pages.
- Clicking one of the spam results sends you to a shop or scam site somewhere else, or shows a page full of foreign-language product links.
- Google Search Console shows a sudden jump in indexed pages, a new sitemap you did not submit, or a Security Issues warning.
- Your normal search listings show odd titles or descriptions, or your real pages have slipped in rankings for no obvious reason.
- Customers or friends mention that searching for your business turned up something embarrassing.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Search Google for site:yourdomain.com (with your real domain) and scroll through several pages of results. Then try site:yourdomain.com viagra, site:yourdomain.com casino, or site:yourdomain.com plus a common Japanese word like jp. Take screenshots — they are useful evidence.
- Look closely at the spam URLs. If they look like yourdomain.com/?s=casino+bonus or /search/ followed by spammy words, spammers may be abusing your site's own search box rather than hacking you. That is a much smaller problem, and worth knowing before you panic.
- Open one of the spam URLs directly in your browser. If it loads a real page on your site, the spam files exist on your server. If it shows a 404 page, the pages may already be gone and Google simply has not caught up yet.
- In Google Search Console, check Security & Manual Actions for a hacked-content notice, check Sitemaps for any sitemap you did not add, and check Settings > Users and permissions for owners you do not recognize. Attackers often add themselves as an owner so they can submit their own sitemaps.
- Use Search Console's URL Inspection tool on one spam URL and view the crawled page. Many of these hacks use cloaking — showing spam only to Google while showing you a normal site — and this is the easiest way for a non-technical owner to see what Google sees.
- If you use WordPress, look at the Users list for administrator accounts nobody created, and note any plugins or themes you do not recognize. Do not delete anything yet; just write it down.
- From a device you trust, change your hosting, WordPress admin, and Search Console Google account passwords, then tell your hosting company the site is compromised and ask whether their malware scan found anything.
What this usually means
When real spam pages exist under your domain, it almost always means an attacker got access to your site — usually through an outdated plugin or theme or a stolen password — and is renting out your domain's good reputation. The Japanese keyword hack, the pharma hack, and casino or replica-goods spam are all the same business model: your domain has years of trust with Google, and pages hosted on it rank more easily than pages on a brand-new spam site. The attacker is not after you personally; they want your search standing.
These hacks are built to go unnoticed. The spam is often hidden from normal visitors and from you when you are logged in, and only shown to Google's crawler or to people arriving from a search. Some versions generate thousands of pages on the fly from a single hidden file, and many plant extra backdoor files so the attacker can get back in after the visible pages are removed. That is why owners are often shocked to learn about the problem months after it started.
There is also a less alarming lookalike: site search spam. Here, nobody has broken in — spammers link to your own search results page with spammy words in the address, and Google indexes those results as if they were pages. It still looks bad and should be fixed, typically by telling search engines not to index internal search pages, but it is a settings job rather than a security cleanup. Telling the two apart is the first real decision, because one needs a thorough malware cleanup and the other does not.
What not to do
- Don't just delete the spam pages you can find and call it fixed. In a real hack, the pages are generated by hidden files that will simply recreate them.
- Don't use Google's Removals tool as your cleanup. It only hides URLs from results for about six months and does nothing about the files on your server.
- Don't assume the site is clean because it looks normal to you. These hacks commonly hide the spam from site owners and logged-in users.
- Don't ignore unknown owners or users in Search Console. An attacker left as a verified owner can keep submitting spam sitemaps after the cleanup.
- Don't request a review from Google before the cleanup is truly finished. A failed review delays the next one.
- Don't pay someone who contacts you out of the blue saying they spotted spam on your site. Unsolicited fix-it offers are frequently scams themselves.
When to get help
If the spam pages load on your live site, this is a genuine compromise and cleanup is detective work: finding the hidden files that generate the pages, the backdoors that let the attacker return, and the original way in, then cleaning up Search Console, returning proper 404 or 410 responses for the spam URLs, and requesting Google's review. Bringing in someone experienced with hacked-site cleanup is honestly the faster and cheaper path here, because a partial cleanup usually means the spam returns within days. If it turns out to be site search spam rather than a hack, that is a much smaller job, and a helper can usually confirm which one you have and fix the search-page settings in a short session.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What is the Japanese keyword hack?
It is a common attack where hidden code on your site creates large numbers of pages filled with Japanese text and links to shops selling counterfeit goods. The attacker uses your domain's reputation in Google to get their pages ranked. It often comes with the attacker adding themselves as an owner in your Google Search Console.
Why can't I see the spam pages when I visit my own site?
Many of these hacks use cloaking: the spam is shown only to Google's crawler or to visitors arriving from a search result, and a normal site is shown to everyone else, including you. The URL Inspection tool in Google Search Console lets you see the page as Google sees it.
Does this mean my site has been hacked?
Usually, but not always. If the spam URLs are your own search results page with spammy words in the address, spammers are abusing your search box rather than your server. If the spam pages load as real pages, or Search Console reports hacked content, treat it as a hack.
How long does it take for the spam to disappear from Google?
After a proper cleanup, the spam URLs return errors and Google drops them as it recrawls. That can take anywhere from a few weeks to a few months for large hacks. Returning a 410 status for the spam URLs and submitting a clean sitemap tends to speed it up.
Will my rankings come back after the cleanup?
In most cases, yes, gradually. Once the spam is gone, the site is secured, and any security issue or manual action is cleared by review, real pages typically recover over the following weeks. The longer the spam stays up, the longer recovery tends to take.
Can I just use the Removals tool in Search Console?
It is fine as a temporary way to hide the worst URLs while cleanup happens, but it is not a fix. Removals expire after roughly six months, and if the hack is still active the pages will simply come back.