Home About

Services

Custom Web Design Custom eCommerce Custom Web Apps Search Engine Optimisation Speed Optimisation SEO Blog Writing Maintenance & Hosting Hacked Website Repair Projects Blog Contact Free Quote
Security 4 min read

Why Is My Website Redirecting to Spam? (And How to Fix It)

Visitors landing on gambling or casino pages instead of your website? What redirect malware is, why only some people see it, where it hides and how to fix it.

Fixing a website that redirects visitors to spam

A customer rings: "I clicked your website and ended up on a casino site." You check it yourself and everything looks fine. A week later it happens again, from a different person, on a different page. Welcome to one of the most common website infections there is, and one we have cleaned up first-hand.

Why is my website redirecting people to spam?

Because malicious code has been planted on it. Redirect malware intercepts visitors on their way into your site and bounces them to gambling, pharmacy, adult or scam pages, earning the attacker affiliate money from your traffic. It is not a browser problem or a hosting glitch: something on your site is doing it deliberately.

Why does the site look fine when I check it?

Because the malware is written to hide from you. Most redirect infections are selective: they fire only for first-time visitors, only on mobile, only for people arriving from Google, or only for visitors without your login cookie. You, the owner, checking your own site from your own desktop, are exactly who it avoids.

To see what your visitors see, open a private browsing window, ideally on your phone, search for your business on Google and click through from the results. If you get bounced somewhere strange even occasionally, the infection is real. Redirects like this are also one of the classic signs of a hacked website, and they rarely travel alone.

Where does redirect malware hide?

Redirect code has a handful of favourite hiding places, and a proper clean checks all of them, because it is often in more than one:

  • The .htaccess file. A few injected lines quietly rewrite where requests go, often only for certain visitors. Deleting the lines is not the fix: something keeps writing them back.
  • Injected JavaScript. Malicious script added to your theme, header or footer files that fires the redirect in the visitor's browser.
  • The database. Script tags stored inside content, widgets or settings, which file-level scans never see.
  • Plugin and theme files. Compromised or fake plugins carrying the redirect code, sometimes with innocent-sounding names.
  • Scheduled tasks. Cron jobs that reinstall the redirect on a timer, which is why sites appear to "re-hack themselves" days after a clean.
An orange detour sign with an arrow pointing left

Why deleting the redirect never fixes it

Because the redirect is the symptom, not the infection. Behind almost every redirect hack sits a backdoor: a hidden file or account that lets the attacker put the code straight back, often within hours. We have seen owners delete the same .htaccess lines a dozen times before accepting the pattern.

The fix that holds is the full sequence: find every copy of the redirect, find the backdoor that keeps restoring it, find the entry point that let the attacker in originally, and close all three. That is the method covered step by step in our guide on what to do when your website is hacked.

How do I fix a redirecting website properly?

Change your passwords from a clean device, tell your host, and get the site cleaned at hosting level: files and database swept, backdoors removed, software updated, entry point closed. If Google has already flagged the site, a security review lifts the warning once the clean is verified.

Speed matters with redirect hacks specifically, because every day the redirect runs, more of your visitors land on scam pages and more of your reputation leaks away. Our hacked website repair service treats them as same-day work: we find the redirect, the backdoor behind it and the door they came in through, and we close the lot.

Frequently asked questions

Why do only some visitors get redirected?

The malware filters on purpose: mobile-only, Google-referral-only or first-visit-only rules keep the redirect away from the site owner and make it harder to reproduce. That is also why one customer complaint deserves to be taken seriously even when the site looks fine to you.

Will the redirect harm my search rankings?

Yes, if it stays. Google detects malicious redirects and responds with warnings, labels and ranking drops. Cleaned quickly, most sites recover fully; our guide on recovering your SEO after a hack covers how rankings come back.

My host says the site is clean, but the redirect keeps happening. Who is right?

Your visitors. Host-level scanners check for known malware signatures and miss cloaked redirects regularly. If real people keep reporting the bounce, treat the site as infected and get it inspected properly at file and database level.

Can I just restore last week's backup?

Usually not: redirect infections tend to sit dormant before anyone notices, so recent backups carry the same code. And a restore does nothing about the entry point, so even a clean backup gets reinfected. Clean first, then use backups as the safety net.

Website bouncing your visitors to spam right now? We find the redirect, the backdoor and the entry point, and close all three. Get emergency help.

Want this handled for you?

We design, build and grow fast custom websites for Irish businesses.