The short answer

An unexpected redirect to spam or an unfamiliar domain can indicate a compromised website. Preserve the symptoms and ask your host to help contain the problem. Removing one redirect or restoring a backup is not enough unless the remaining infection and the way it entered are also addressed.

Document the redirect without trusting its destination

Record the original page URL, the destination domain, the time and whether you were logged in. Include whether the report came from a phone, a desktop or a search result. Do not sign in, download software or enter payment details at an unexpected destination.

A legitimate migration or redirect rule can also send a visitor elsewhere. Check whether the destination is one your business intentionally configured. If the behavior is unexplained, or a host or security service has flagged the site, treat it as a suspected compromise while it is investigated.

Contain the problem and preserve evidence

Contact your host with the affected URL and symptoms. Ask about temporarily restricting public access at the hosting layer while allowing secure investigation. A maintenance page inside WordPress may be insufficient if the malicious redirect runs before that page can load.

Preserve a copy of the current files, database and available logs for investigation. Label that copy as potentially infected and keep it separate from known-good backups. Record changes made during cleanup so you can distinguish the original compromise from later work.

Cleanup needs to cover more than one visible redirect

The investigation should determine which of these checks matter for your site. Deleting every unfamiliar file can destroy legitimate functionality. A scanner can help locate suspicious material, but a clean result from one scan should not be the only acceptance check.

If a backup is used, establish whether it predates the compromise and address the weakness before reopening the site. Restoring a previously vulnerable setup can leave the same route available to an attacker.

  • Inspect affected files and database content for injected code or spam.
  • Review administrator accounts and other access for unauthorized changes.
  • Check plugins, themes and server redirect configuration where relevant.
  • Replace compromised components with trusted copies while preserving legitimate custom work.
  • Investigate the entry point, such as vulnerable software or compromised credentials.

Review access as part of recovery

Use a trusted device and agree an access-reset plan with your host or developer. Depending on the compromise, this may include WordPress, hosting and file-transfer credentials, as well as active sessions and unfamiliar accounts. Update affected software from trusted sources.

WordPress security guidance treats access control, updates, backups and monitoring as complementary measures. None of them creates an absolute guarantee, and a monthly maintenance plan is not a substitute for investigating an active infection.

Verify the original symptom and the restored website

Repeat the reported journey after cleanup, including the original page and the conditions under which the redirect appeared. Check key pages, forms and other customer actions, and review fresh security findings and logs where available. Agree a period of follow-up monitoring.

Your host or a search provider may have its own review process before removing a suspension or warning. Confirm who will request that review and what evidence is needed. A warning disappearing and a complete cleanup are separate checks.

For cleanup help, send the website URL, redirect symptoms and any warning from your host. Existing infections are assessed and quoted separately from monthly care.

Explore malware removal and hacked-site cleanup.

Official references

Use these references alongside the checks and questions in this guide. Interfaces and provider requirements can change.