Cleaning malware from a website is only half the job. After an SEO spam hack, Google may still have thousands of spam URLs from your domain in its index, showing your brand next to counterfeit goods, pharmacy products or gambling links. Those pages can linger for months if handled incorrectly, and they continue to affect how Google sees your site. This guide covers the recovery process we use after cleaning hacked sites, so the spam disappears as quickly as possible and your real pages regain their place.
This article is part of our complete guide: WordPress Security and Malware Removal: The Complete Guide.
Before you start: make sure the site is really clean
Do not try to remove spam URLs from Google while the site is still generating them. Confirm that:
- The malicious code, backdoors and database injections have been removed.
- The entry point (vulnerable plugin, weak password, compromised account) has been fixed.
- Spam URLs no longer show spam content to Googlebot. Use URL Inspection’s live test to check, because cloaked spam may only appear for Google.
If you are unsure, read signs your WordPress site is hacked and our Japanese keyword hack guide, or get professional help.
Step 1: Make spam URLs return 404 or 410
This is the most important step. Spam URLs must return a “not found” (404) or “gone” (410) status code. Google drops URLs that consistently return these codes. Common mistakes that keep spam alive:
- Redirecting spam URLs to the homepage. Google may treat this as a soft 404, and it keeps the URLs connected to your site. Do not do it.
- Returning 200 with the homepage content, often caused by a catch-all rule or a theme that shows the homepage for unknown URLs.
- Blocking spam URLs in robots.txt. This stops Google from crawling them, so it never sees the 404 and keeps them indexed longer. Leave them crawlable.
If spam URLs follow a pattern (for example, a specific folder or parameter), you can return 410 for that pattern with a server rule. Test with a header checker after any change.
Step 2: Clean up Search Console
- Users and permissions: remove any owner or user you do not recognise, and remove their verification files or tags from the site.
- Sitemaps: delete any sitemap you did not create. Submit your genuine sitemap. See submitting a sitemap.
- Change of address and settings: confirm no unexpected changes were made.
Step 3: Request a security review
If Search Console shows a security issue (such as “Hacked: content injection” or “Malware”), open the Security Issues report, confirm you have fixed the problem, and click Request review. Describe what you found, what you removed, and how you closed the vulnerability. Google typically processes reviews within a few days. Once approved, warnings in search results and browsers are removed.
Step 4: Use the Removals tool for the worst URLs
The Removals tool in Search Console temporarily hides URLs from search results for about six months. It does not remove them from the index permanently; the 404/410 status does that. Use it for:
- The most visible spam URLs, such as those appearing for your brand name.
- URL prefixes, if spam lives under a specific folder (choose “Remove all URLs with this prefix”).
Be very careful with prefix removals. Removing a prefix that also contains real pages will hide them too.
Step 5: Help Google recrawl the spam URLs
Google needs to revisit each spam URL to see the 404 or 410. For large hacks, this can take a while. Options that help:
- Keep the spam URLs crawlable, as above.
- Optionally, create a temporary sitemap containing the spam URLs so Google recrawls them faster, then remove it once most have dropped out. This is a common recovery technique; only use it once the URLs return 404/410.
- Ensure your server responds quickly so Google can crawl efficiently.
Step 6: Reinforce your real pages
While the spam fades, strengthen the signals for your genuine content: request indexing for key pages, review internal links and titles, and make sure your sitemap lists only real, indexable URLs. If spam altered titles or descriptions of real pages through cloaking, the live test should now show the correct versions; request indexing so Google refreshes them.
Step 7: Monitor
- Run
site:yourdomain.comsearches weekly for spam keywords. - Watch the Page indexing report: “Not found (404)” will rise as Google processes spam URLs, which is expected and healthy.
- Watch Performance for spam queries disappearing and your real queries recovering.
- Keep security monitoring active to catch reinfection early.
How long does it take?
- Security warning removal: usually days after a successful review.
- Most visible spam URLs: hidden immediately with the Removals tool, dropped permanently over weeks.
- Large volumes of spam URLs: several weeks to a few months.
- Ranking recovery for real pages: often starts within weeks of the clean-up, depending on how long the hack lasted.
Communicating with customers during recovery
If customers saw warnings or spam results, a short, honest message helps protect trust. Post a brief update on your social channels or send an email to existing customers explaining that the website was affected by a security issue, that it has been fixed, and whether any personal data was at risk. Do not speculate. If you run an online store or collect personal details, check whether your data protection obligations require you to notify anyone. Being open usually costs far less goodwill than silence.
What not to do
- Do not disavow links as a fix for hacked pages; that tool is for unnatural backlinks, not spam pages on your own site.
- Do not mass-redirect spam URLs.
- Do not block them in robots.txt.
- Do not create a new domain unless the old one is beyond recovery, which is rare.
Real experience
We have handled this process for WordPress and WooCommerce sites, including the recovery described in our hacked WooCommerce store guide. The pattern is consistent: once the site is truly clean and spam URLs return proper status codes, Google steadily removes them and real pages recover.
Stopping it from happening again
Most reinfections happen because the original vulnerability was never closed, or a backdoor was missed. After recovery, keep plugins updated, remove unused ones, enforce strong passwords and two-factor authentication, block PHP in uploads and keep reliable backups. Our WordPress security checklist lists every step.
Related guides and services
- Japanese keyword hack: how to remove Japanese spam pages from WordPress and Google.
- Signs your WordPress site is hacked: the warning signs and what to do in the first hour.
- Soft 404 errors: why Google treats some live pages as missing.
- WordPress malware removal: emergency clean-up and hardening for hacked WordPress sites.
- Google indexing fix service: we diagnose and fix pages Google will not index.
Get expert help
We clean hacked sites, make spam URLs return the right status codes, handle the Google security review and monitor recovery until the spam is gone. Start with our WordPress malware removal service, browse real client results in our case studies, or contact us for a free, no-pressure review of your website.
Frequently asked questions
Will Google remove spam pages automatically?
Yes, once they return 404 or 410 and Google recrawls them. The Removals tool can hide the worst ones faster.
Should I redirect hacked URLs to my homepage?
No. Return 404 or 410 so Google drops them.
How do I know if Google still sees spam?
Use URL Inspection’s live test on spam URLs and on your real pages to see what Googlebot receives.
Can a hack cause a manual action?
Yes. Hacked content can trigger security issues or manual actions, which are lifted after a successful review.