Website redirecting to spam or scam sites

Why a site redirects some visitors to spam, where the redirect code usually hides — .htaccess, PHP files, the database, JavaScript — and how to remove it.

TroubleshootingIntermediate2 min readUpdated

Does this match what you’re seeing?

  • Visitors from Google end up on a spam or scam site
  • Mobile visitors are redirected but desktop visitors aren’t
  • The redirect only happens on the first visit

Malicious redirects are designed to hide from site owners: they often trigger only for visitors arriving from search engines, on mobile, or on a first visit.

Reproduce it

  • Use a private window on mobile data
  • Click through from a Google search result for your site
  • Use an online redirect checker that shows each hop

Where redirect code hides

1. .htaccess

Look in public_html/.htaccess and every subfolder’s .htaccess for rules checking HTTP_REFERER (google, bing) or HTTP_USER_AGENT (android, iphone) and redirecting to unfamiliar domains:

RewriteCond %{HTTP_REFERER} (google|bing|yahoo) [NC]
RewriteRule .* https://unfamiliar-domain.example/ [R=302,L]

2. PHP files

Injected code at the top of index.php, wp-config.php or theme functions.php — often long unreadable strings using base64_decode, eval or gzinflate. How to find malicious files on your website

3. The database

In WordPress, check wp_options for siteurl and home values, and search posts and options for <script tags and unfamiliar domains.

4. JavaScript

Injected <script> tags in theme files or appended to legitimate .js files.

Remove it properly

Deleting the redirect alone isn’t enough; the code that injected it usually remains. Follow My website has been hacked: what to do from the start.

Popular

Tip: press / to search from any pageSee all results