Why are unknown pages from my website appearing on Google?

Seeing pages on Google that you never created? Learn the possible causes, from hacked spam pages to old or staging URLs, and how to check and clean them safely.

Open a support ticket

If you search for your business and find pages from your own domain that you never created, it is understandable to feel worried. The titles may be in another language, promote products you do not sell, or simply look unfamiliar.

You may notice:

  • results with your domain name but titles about pharmaceuticals, replica goods, gambling or loans
  • pages written in Japanese, Chinese or another language you do not use
  • old pages you thought had been removed
  • strange URLs with long codes or parameters
  • an increase in "indexed pages" in Google Search Console that you cannot explain
  • a message from Google about hacked content

Unknown pages do not always mean that your website has been hacked. Some causes are harmless, such as old content, a staging copy of the site or automatically generated WordPress pages.

However, when the pages contain spam or content unrelated to your business, they should be treated as a possible security incident. Spam pages can harm your reputation in search results, mislead visitors and lead to a security warning from Google.

This guide explains how to tell the difference, which checks are safe to do, how to clean the problem and how to ask Google to remove the pages from its results.

What does it mean when unknown pages appear on Google?

Google shows pages it has found and decided to index. If a page appears in search results with your domain name, Google found it at some point on your website, or found a link pointing to a URL on your domain.

That leaves three broad possibilities:

  • someone added pages without your permission, usually through a security weakness
  • your website generates pages you did not realize existed, such as attachment pages, search result pages or URLs with parameters
  • the pages are old or come from another copy of the site, such as a staging or development version

The first step is not to delete anything, but to understand which situation you are dealing with.

Could my website have been hacked?

If the unknown pages promote products or services you have nothing to do with, a compromise is the most likely explanation.

This type of attack is often called SEO spam. The attacker uses the reputation of your domain to push their own content up in search results. A well-known example is the so-called "Japanese keyword hack", but the same technique appears in many languages and topics.

How SEO spam usually works

Typically, the attacker:

  • gains access through a vulnerable plugin, theme, stolen password or another weakness
  • adds files or database entries that generate large numbers of spam pages
  • sometimes submits a fake sitemap so Google discovers the pages faster
  • may verify their own account in Google Search Console for your domain
  • links to the pages from other compromised websites

The pages may be thousands of automatically generated URLs, each with spam keywords in the title. Visitors who click them may be redirected to a shop, a scam or another unrelated website.

Why you may not see the pages yourself

Many SEO spam infections use a technique called cloaking. The malicious code shows one thing to Google and something else to you.

For example, the spam pages may:

  • appear only when Google's crawler requests them
  • appear only to visitors arriving from Google search
  • show a normal page or a "not found" error to logged-in administrators
  • appear only on mobile devices or in certain countries

This is why the website can look completely normal when you open it, while Google shows hundreds of spam results. Not being able to see the pages is not evidence that they do not exist.

What other causes are there?

Before assuming the worst, consider the harmless explanations. They are common, and sometimes they appear together with a real compromise.

Old pages

Pages you deleted long ago may still be indexed, especially if they still return content, redirect incorrectly or are linked from other websites. Pages from a previous version of the site, or from a former owner of the domain, can also remain in Google's index for a while.

A staging or development site

Many websites have a copy used for testing, often on a subdomain such as staging.example.com or dev.example.com. If it was not protected or set to discourage search engines, Google may have indexed it. The pages will look like yours, but with test content or outdated information.

Internal search result pages

WordPress creates a page for every search made on the site, with addresses such as example.com/?s=keyword. Spammers sometimes link to these URLs with spam phrases as the search term, so Google indexes pages that display their text on your domain. No file on your site has been changed, but the result still looks bad.

Attachment pages

Older WordPress sites may create a separate page for every uploaded image or document. These pages usually show just the file and a title. Newer WordPress installations disable them by default, but older sites may still publish them.

URLs with parameters

Filters, sorting options, tracking codes and session values can create many versions of the same page, such as ?orderby=price or ?utm_source=newsletter. Google may index some of them, which makes the list of indexed pages look longer and stranger than expected.

Tag, category and author archives

WordPress and many themes create archive pages for tags, categories, authors and dates. If many tags were created over the years, Google may show pages you never consciously published.

How can you tell which situation you are in?

A few questions help:

  • Is the content related to your business? Old pages, archives and attachment pages normally contain your own content. Spam about unrelated products is a strong warning sign.
  • Is the language one you use? Pages in a language you have never published are rarely harmless.
  • Is it a subdomain you recognize? A copy of your site on staging. or dev. points to an indexing problem rather than a hack.
  • Does Google report anything? A message about hacked content or spam in Search Console changes the priority immediately.
  • When did it start? A sudden jump in indexed pages after a plugin update or a period without maintenance deserves attention.

If you are unsure, assume the worst until someone has checked. It is safer to investigate a harmless issue than to ignore a compromise.

What are the safe first checks?

These checks only involve looking at information. They do not change your website.

Search Google for your domain

Search for site:example.com, replacing it with your domain. This shows a sample of the pages Google has indexed for your site.

You can narrow the search with terms that have nothing to do with your business, for example site:example.com casino or site:example.com viagra. You can also check subdomains with site:staging.example.com.

The results are not a complete list, and the number shown is only an estimate. But they often reveal the type of pages involved.

Avoid clicking spam results repeatedly. If you need to record them, take screenshots of the search results instead.

Check Google Search Console

If your website is connected to Search Console, look at:

  • Security & Manual Actions → Security Issues, to see whether Google has reported hacked content
  • Security & Manual Actions → Manual actions, to see whether Google has applied a penalty for spam
  • Indexing → Pages, to see how many pages are indexed and whether the number changed suddenly
  • Indexing → Sitemaps, to check that only sitemaps you recognize have been submitted
  • Settings → Users and permissions, to check for owners or users you do not know

An unknown owner in Search Console is an important sign. Attackers sometimes verify the domain so they can submit their own sitemaps.

If you do not have access to Search Console, ask your web agency, developer or marketing team who manages it.

Write down what you find

Collect:

  • screenshots of the strange search results
  • a list of example URLs
  • the date you first noticed them
  • any messages from Google or your hosting provider
  • recent changes to the website

This information will help whoever investigates the problem.

What should you do if the pages are spam?

If the pages are clearly spam, the order of the steps matters. Removing pages from Google before cleaning the website does not solve anything, because the malicious code will keep creating them.

1. Clean the website first

The cleanup should:

  • remove the files or database entries that generate the spam pages
  • remove any fake sitemaps
  • remove unknown administrator accounts, after recording their details
  • remove unknown owners from Search Console
  • find and close the entry point, such as a vulnerable plugin or a stolen password
  • check for backdoors that would allow the attacker back in

If you skip the last two steps, the spam often returns. See why malware keeps coming back for more on this.

2. Make sure the spam URLs return an error

Once cleaned, the spam URLs should return a "not found" (404) or "gone" (410) status. This tells Google the pages no longer exist. Avoid redirecting them all to your homepage, which can confuse Google and keep them in the index longer.

3. Ask Google to review and remove

If Google reported a security issue, request a review from the Security Issues report once the site is clean. Our guide on what to do when Google marks your website as dangerous explains the process.

You can also use Indexing → Removals in Search Console to temporarily hide specific URLs or URL prefixes from search results while Google recrawls the site. This is a temporary measure: the permanent removal comes from the pages returning an error.

Some spam results may take weeks to disappear completely, depending on how many there are and how often Google visits your site.

What should you do if the pages are not malicious?

For harmless causes, the fix depends on the source:

  • staging sites: protect them with a password or restrict access, and ask your developer to keep them out of search results
  • search result pages: check that your SEO plugin marks them as "noindex"; many do by default
  • attachment pages: disable them or redirect them to the file or the parent page
  • old pages: return a 404 or 410, or redirect them to a relevant current page
  • parameters and archives: review your SEO plugin settings and use canonical tags where appropriate

These are configuration changes, so make them one at a time and check the result.

What should you avoid?

Avoid:

  • assuming the pages are harmless because you cannot see them
  • requesting removals in Search Console before cleaning the website
  • deleting files at random
  • redirecting all spam URLs to your homepage
  • restoring an old backup without checking whether it is clean
  • leaving unknown Search Console owners in place
  • ignoring the problem because traffic looks normal

When should you ask for support?

Ask for help when:

  • the pages contain spam or a language you do not use
  • Google reports hacked content or a manual action
  • there are unknown owners in Search Console or unknown administrators in WordPress
  • the pages come back after you removed them
  • the website handles orders, payments or personal data
  • you do not know how the pages were created

You do not need to understand the cause before asking.

How D4Hub can help

D4Hub can:

  • analyze the unknown pages and identify their source
  • check Search Console for security issues, unknown owners and fake sitemaps
  • find and remove spam files, database entries and backdoors
  • identify and close the entry point
  • fix indexing problems caused by staging sites, attachments or search pages
  • configure the correct responses for removed URLs
  • prepare and submit the Google review and removal requests
  • recommend measures to reduce the risk of it happening again

You can ask for support at any stage, from the first strange search result to a cleanup that did not work.

Open a support ticket

For hands-on users: finding the source of unknown pages

The following checks are for people comfortable with Search Console, SFTP or a hosting file manager and WP-CLI.

Before you start, take a full backup of the files and the database and keep it separate from the live site. It preserves evidence and gives you a way back. Most checks below only read information. Do not delete or change anything until you understand what it does.

Run targeted site: searches

Combine site: with unrelated terms, file types or subdomains:

site:example.com
site:example.com -inurl:www
site:example.com casino
site:staging.example.com

The -inurl:www search can reveal subdomains you did not know were indexed. Record the URL patterns you see, such as a common folder or parameter. They often point to where the spam is generated.

Inspect a URL in Search Console

Paste one of the suspicious URLs in the URL Inspection field at the top of Search Console. It shows whether the page is indexed, when Google last crawled it and how Google discovered it.

Use Test live URL and then View tested page to see the HTML Google receives. If it shows spam that you cannot see in your browser, the site is using cloaking.

Check the sitemaps

Open your sitemap, often at example.com/sitemap.xml or example.com/sitemap_index.xml depending on your SEO plugin. Check that it lists only your own content.

Then compare it with the sitemaps listed under Indexing → Sitemaps in Search Console. Any sitemap you did not submit, especially one with an unusual name, should be investigated.

List published content in WordPress

This command lists published content of all public types, newest first:

wp post list --post_type=any --post_status=publish --fields=ID,post_title,post_date --orderby=date --order=DESC

Look for titles you do not recognize or many entries created in a short time. Note that some SEO spam does not create posts at all, so a clean list does not rule out an infection.

Inspect the .htaccess file

On Apache and LiteSpeed servers, open the .htaccess file in the WordPress root folder. Beyond the standard # BEGIN WordPress block and clearly labeled sections from caching or security plugins, look for rewrite rules that send requests to unfamiliar PHP files or check HTTP_USER_AGENT for search engine names.

Check for .htaccess files in subfolders too. Sites on Nginx do not use .htaccess, so the server configuration must be checked with the hosting provider.

Look for unknown PHP files

PHP files have no reason to be in the uploads folder:

find wp-content/uploads -type f -name "*.php"

You can also list PHP files changed in the last 30 days:

find . -type f -name "*.php" -mtime -30

Legitimate updates change files too, so a recent date is not proof of infection. Look for unfamiliar names in the root folder, random-looking file names and folders that do not belong to any plugin or theme.

Verify core and plugin files

wp core verify-checksums
wp plugin verify-checksums --all

These compare your files with the official versions. Premium and custom plugins cannot be verified this way, which is not a sign of infection on its own.

If you find something you do not understand, stop there. D4Hub can review the results with you or take over the investigation.

FAQFrequently asked questions

Not if the malicious code is still on the website. It will keep serving the pages to Google. Once the site is clean and the URLs return an error, Google removes them gradually as it recrawls them.

No. It hides URLs from Google's results temporarily. The pages are removed permanently only when they return a 404 or 410 status, or are otherwise blocked from indexing.

The malicious code may use cloaking, which shows spam only to Google's crawler or to visitors coming from search results. Logged-in administrators often see a normal page. The URL Inspection tool in Search Console shows what Google actually receives.

It can. Spam pages can reduce trust in your domain, attract a manual action or a security warning, and push your real pages out of results. Cleaning the site quickly limits the damage.

Yes. If a staging or development copy is publicly reachable and not protected, Google can find and index it. Protecting it with a password is the most reliable solution.

If the pages are spam, yes, as part of the cleanup. Change WordPress, hosting, SFTP and database passwords, ideally after the entry point has been found, so the new passwords are not exposed in the same way.

Yes. D4Hub can help identify who manages the property, regain or verify access where possible and interpret what Google is reporting.