Website Redirects to Strange Pages
Higher-risk issue — be cautious and consider professional help sooner.
Visitors who open your site get sent to spam, ads, gambling, adult, or other unrelated pages. This is one of the clearest external signs of injected malware.
Common signs of this issue
- Opening your site briefly shows your page, then jumps to another site entirely.
- It happens mainly on phones, only the first visit, or only from Google results — but typing the address directly works fine.
- Customers report being sent to ads, fake virus warnings, prize scams, gambling, or adult content — while the site looks normal to you.
- Google results for your site show odd titles or descriptions you didn't write.
- Browser security warnings or a drop in traffic arrived around the same time.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Reproduce it the way victims meet it: on a phone, on mobile data, in a private window, entering via a Google search result rather than a typed address. Redirect malware deliberately spares owners — typed visits from your desktop are exactly what it ignores.
- Note the pattern precisely: which devices, which entry route, every time or only first visit, and where it lands (screenshot the destination address from a device you don't log into). This fingerprint speeds up professional cleanup considerably.
- Search
site:yourdomain.comon Google and look for pages, titles, or languages you never published — injected redirects and injected spam pages usually travel together. - Check Google Search Console's Security issues section (read-only, free) — Google's crawler often detects the injected code before owners do.
- Run an external scan (Google Safe Browsing site status, or a reputable free website malware scanner) — outside-in checks are safe and need no credentials.
- Establish your last clean backup date — when did the site last verifiably NOT redirect? Reports from customers help date it. Don't restore anything yet; just know what exists and from when.
- Rule out the one common non-hack lookalike: a rogue ad network. If you run third-party ad code and redirects happen on desktop too, ads are worth suspecting — try temporarily removing ad code if you can do so safely.
What this usually means
Selective redirects — mobile-only, search-visitors-only, first-visit-only — are the signature of malicious code injected into your files, theme, or database, usually via an outdated plugin or theme, or a stolen password. The selectivity is engineered: the site's owner types the address on a desktop, sees a healthy site, and the infection monetizes everyone else for weeks.
The code hides deliberately: obfuscated snippets in legitimate files, database entries that rebuild deleted files, scheduled tasks that re-add what cleanup removes. This is why deleting the one suspicious thing you find rarely ends it — real cleanup finds every copy, closes the entry point, and rotates all credentials, or the redirects return within days.
The clock matters more here than with most problems: every redirected visitor is being handed to scammers under your brand's name, and Google flags redirecting sites with 'deceptive site' warnings that then block nearly all traffic and take days-to-weeks to lift after cleanup. Early action is dramatically cheaper.
What not to do
- Don't enter logins on a device that's showing the redirects — treat the whole page as untrusted until cleaned.
- Don't delete files at random hoping to hit the payload — you'll destroy the evidence of the entry point while other copies rebuild what you removed.
- Don't just restore a backup and consider it done — if the vulnerable plugin or stolen password remains, reinfection is near-certain, and recent backups may already contain the malware.
- Don't ignore it because the site 'looks fine to you' — that's the malware's design working as intended; your customers see a different site.
- Don't pay anyone who cold-contacts you about the redirects — attackers and their affiliates monitor infected sites and pose as rescuers.
When to get help
Malicious redirects are among the strongest cases on this site for prompt professional help: the code hides from casual inspection, partial cleanup reliably fails, and the longer it runs the more likely Google's red warning makes everything worse. Proper cleanup — locate all injected code, close the entry point, rotate credentials, then request Google review — is specialist work with a clear definition of done. Meanwhile, your documentation (devices, entry routes, destinations, dates) and password changes from a clean device genuinely help.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
Why does my site only redirect on mobile?
By design — injected code commonly targets mobile and search-referred visitors specifically so the owner (desktop, typed address) sees a healthy site. Mobile-only redirecting is one of the most reliable indicators of compromise rather than misconfiguration.
Will changing my passwords fix the redirects?
Change them (from a clean device) — but no, passwords don't remove code already injected into files or the database. Cleanup removes the code; new credentials and updated software keep it from coming back. All three are required.
Why can't I see the redirect myself?
The code checks who's visiting — device, referrer, cookies, sometimes your IP — and behaves for anyone who looks like the owner. Test as a stranger: phone, mobile data, private window, entering from a Google result.
How did the redirect malware get in?
Most often an outdated plugin or theme with a known vulnerability, a stolen or weak password, or contamination from another site on the same hosting account. Identifying the actual entry point is part of proper cleanup — it's what prevents round two.
Will Google penalize my site for the redirects?
Effectively yes: Safe Browsing flags redirecting sites with 'deceptive site' warnings that block nearly all visitors, and rankings suffer while the flag stands. After verified cleanup you request a review in Search Console; clearing typically takes days. Speed of cleanup is what limits the damage.
Can I just take the site offline while I figure it out?
A maintenance page stops the harm to visitors, which has real value — but it doesn't clean anything, and extended downtime has its own SEO cost. Use it as a tourniquet while arranging cleanup, not as the plan.