← All guides

Is my website hacked? Twelve signs, and a five-minute check

Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.

16 September 2026, 3 min read. From the sites people send us "just to be sure", about a third of which turned out to have a problem.

The unsettling thing about a hacked website is that it usually looks fine to the owner. The attacker wants it that way: a site that looks normal keeps earning for them longer. The signs show up elsewhere first, in search results, in email bounces, on a visitor’s phone. Here are the ones we check, roughly in order of how often they are the first clue.

The twelve signs

  1. Google shows pages you never made. Search for site:yourdomain.com. If you see pages about pharmaceuticals, gambling, designer goods, or in a language you do not use, the site is compromised.
  2. A red warning in the browser. “Deceptive site ahead” or “This site may harm your computer”. Google Safe Browsing found something.
  3. Visitors get redirected. Someone tells you the site sent them to a strange page. Often it only happens on phones, or only when arriving from Google, so you never see it yourself.
  4. Your emails bounce or land in spam. Because the server is sending thousands of spam messages from your domain, and mail providers have noticed.
  5. The host has suspended the site, or sent a notice about malware, resource abuse or outgoing spam.
  6. An admin user you did not create. Check the users list. Attackers add one, often with a plausible name.
  7. Files changed when nobody was working. Modification dates in the last few days on files nobody touched. A file called something like wp-cache.php in a folder where it does not belong.
  8. PHP files inside the uploads folder. There should never be any.
  9. The site is suddenly slow or the host reports high CPU usage. Malware mining, spam sending, or attacks launched from your server all cost resources.
  10. Scheduled tasks you do not recognise. WordPress and most platforms have a task scheduler. Attackers use it to reinstall their code every few hours.
  11. Changed settings. The site address, the admin email, a new default role. Small changes that let them back in later.
  12. Search Console warnings. Under Security issues, Google tells you directly. It also lists the site’s owners, and attackers add themselves there after a Japanese keyword hack. Look for owners you do not recognise.

The five-minute check

Once a week, or right now if something above sounded familiar:

  • Search site:yourdomain.com in Google and scan the results. Sixty seconds.
  • Open Search Console, Security issues, and the Users and permissions page. Sixty seconds.
  • Open the site on your phone, from a Google search rather than by typing the address. Sixty seconds.
  • In the admin, look at the users list and at the most recently modified files if your host shows them. Two minutes.

That catches most of the list. Our scanner does the outside part in ten seconds: the Safe Browsing status, the software versions attackers target, and whether the site is exposing the things it should not.

If you found something

Do not delete things yet. Take a snapshot first, then follow the cleanup order: contain, find the door, clean, rotate every password, patch, and watch for a month. We wrote that order up separately, and it matters more than any individual fix, because a cleanup that leaves the entry point open is a cleanup for a week.

If you found nothing but you are not sure, that is what the scanner is for, and the check above takes less time than worrying about it.

See where your own site stands.

The scanner checks the things this guide talks about, in about ten seconds, no signup.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.