Website Redirects to Strange Pages

Higher-risk issue — be cautious and consider professional help sooner.

Visitors who open your site get sent to spam, ads, gambling, adult, or other unrelated pages. This is one of the clearest external signs of injected malware.

Common signs of this issue

Safe checks you can do yourself

None of these require sharing passwords with anyone.

What this usually means

Selective redirects — mobile-only, search-visitors-only, first-visit-only — are the signature of malicious code injected into your files, theme, or database, usually via an outdated plugin or theme, or a stolen password. The selectivity is engineered: the site's owner types the address on a desktop, sees a healthy site, and the infection monetizes everyone else for weeks.

The code hides deliberately: obfuscated snippets in legitimate files, database entries that rebuild deleted files, scheduled tasks that re-add what cleanup removes. This is why deleting the one suspicious thing you find rarely ends it — real cleanup finds every copy, closes the entry point, and rotates all credentials, or the redirects return within days.

The clock matters more here than with most problems: every redirected visitor is being handed to scammers under your brand's name, and Google flags redirecting sites with 'deceptive site' warnings that then block nearly all traffic and take days-to-weeks to lift after cleanup. Early action is dramatically cheaper.

What not to do

When to get help

Malicious redirects are among the strongest cases on this site for prompt professional help: the code hides from casual inspection, partial cleanup reliably fails, and the longer it runs the more likely Google's red warning makes everything worse. Proper cleanup — locate all injected code, close the entry point, rotate credentials, then request Google review — is specialist work with a clear definition of done. Meanwhile, your documentation (devices, entry routes, destinations, dates) and password changes from a clean device genuinely help.

Not sure what to do next?

Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.

Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.

Frequently asked questions

Why does my site only redirect on mobile?

By design — injected code commonly targets mobile and search-referred visitors specifically so the owner (desktop, typed address) sees a healthy site. Mobile-only redirecting is one of the most reliable indicators of compromise rather than misconfiguration.

Will changing my passwords fix the redirects?

Change them (from a clean device) — but no, passwords don't remove code already injected into files or the database. Cleanup removes the code; new credentials and updated software keep it from coming back. All three are required.

Why can't I see the redirect myself?

The code checks who's visiting — device, referrer, cookies, sometimes your IP — and behaves for anyone who looks like the owner. Test as a stranger: phone, mobile data, private window, entering from a Google result.

How did the redirect malware get in?

Most often an outdated plugin or theme with a known vulnerability, a stolen or weak password, or contamination from another site on the same hosting account. Identifying the actual entry point is part of proper cleanup — it's what prevents round two.

Will Google penalize my site for the redirects?

Effectively yes: Safe Browsing flags redirecting sites with 'deceptive site' warnings that block nearly all visitors, and rankings suffer while the flag stands. After verified cleanup you request a review in Search Console; clearing typically takes days. Speed of cleanup is what limits the damage.

Can I just take the site offline while I figure it out?

A maintenance page stops the harm to visitors, which has real value — but it doesn't clean anything, and extended downtime has its own SEO cost. Use it as a tourniquet while arranging cleanup, not as the plan.

Related free guides

WordPress site down?

Seeing “There has been a critical error on this website”?

Our guided repair tool logs in over secure FTPS and fixes the most common WordPress failures — safely, with every change backed up and reversible. Start with a free scan, no password needed.

Fix My WordPress Site → Free scan · No download of your site · Reversible