Site cleaned, but Google still shows spam pages: how to remove them from the index
This guide covers remove spam pages from from confirmation through cleanup and prevention.
The site has been cleaned. Infected files replaced, the database reviewed, passwords changed, and the check says everything is fine. Then you type your company name into Google and see the same results as a week ago: Japanese characters, pill ads, casino bonuses or watch shops, all under your domain.
This is one of the most common and most frustrating situations after a hack. The owner assumes the cleanup failed or that the attacker got back in. Sometimes that's true, but usually the reason is much simpler: Google hasn't found out yet that anything has changed.
The good news is that this part of the job can be done systematically and has a clear end. The bad news is that it's easy to make a mistake that drags the process out by months, and very few site owners know in advance the rules Google applies here.
In this article we explain why Google remembers the spam after a cleanup, how to check whether the problem is in the index or on the site itself, and the order in which to remove the spam results so they disappear as quickly as possible, without the mistakes that add months to the process.
Why Google still shows spam after the cleanup

When dealing with remove spam pages from, order matters more than speed.
Google doesn't look at your site live every time someone searches. Results come from the index, a huge database of pages Google has visited and stored earlier. When you clean the site, the index doesn't change at that moment. Google has to revisit every spam URL, see that it no longer exists, and only then drop it.
Google visits small sites relatively rarely
Large portals are crawled several times a day. A small business site may be visited once every few days, and individual less important URLs even less often. If the attacker injected hundreds or thousands of spam pages, Google needs time to go through them all again.
Spam URLs aren't in your sitemap
Google finds legitimate pages through your sitemap and internal links. The attacker usually "announced" the spam pages through external links from other infected sites. Once you remove them, there's no natural signal telling Google to check them again, so they stay in the crawl queue longer than you'd like.
The server doesn't always respond correctly
This is the most common technical reason. After a cleanup, spam URLs often return the homepage or an empty page with a 200 status, which to Google means "the page exists and everything is fine". Google then has no reason to drop it from the index. More on this below, because it's the key part of the fix.
First check: is the problem in the index or on the site?

Before working on the index, you have to be sure the site really is clean. If the attacker still has access, no amount of work on the index will help.
Live URL test in Search Console
Take a few spam URLs from Google's results and check them with the URL Inspection tool in Search Console. Click Test live URL. This test sends Google's crawler to the address right now, so you see what Google actually gets today.
- If the test shows spam content, the site isn't clean. Cloaking code is still active somewhere in the files, database or server rules. Go back to the cleanup. The article Spam links in my site's Google results will help.
- If the test shows a 404 or 410 error, the site is clean and the problem is only in the index.
- If the test shows your homepage or another normal page, the site is probably clean, but the server is responding incorrectly to spam URLs. You need to fix that before anything else.
Check from a browser, as a visitor from Google
Open a private window, search for your company name in Google and click a spam result. If it sends you to someone else's site, the infection is still active. Read more about this form of attack in Site redirects to another site.
Step 1: Make spam URLs return the right response
When Google visits a URL that no longer exists, the server has to tell it clearly that the page has been removed. That's done with the HTTP status, a number the server sends with every response.
404 or 410
- 404 (Not Found) means "this page doesn't exist". Google will drop it from the index over time.
- 410 (Gone) means "this page existed and has been permanently removed". Google treats this as a somewhat more definitive signal, so URLs returning 410 are usually dropped a little faster.
For spam URLs after a hack, the best choice is 410. The difference in speed isn't huge, but when you have thousands of URLs, every bit helps.
A common mistake: redirecting spam URLs to the homepage
Many owners, and even developers, set up all non-existent URLs to redirect to the homepage so the visitor "doesn't see an error". For Google that's a problem. Redirecting thousands of non-existent URLs to the homepage is usually treated as a so-called "soft 404", Google isn't sure what to do with them, and the process takes longer. Spam URLs shouldn't be redirected; they should return 410 or 404.
When spam URLs have parameters
A common situation after a pharma or Japanese hack is spam URLs that look like yoursite.com/?abc=buy-cialis or yoursite.com/index.php?page=replica-watches-123. WordPress normally shows the homepage with a 200 status for such URLs, because it simply ignores unknown parameters. So Google sees a "normal page" and doesn't drop the URL.
The fix is a server rule that recognises the pattern of the spam URLs and returns 410 for them. The pattern is determined from the actual spam URLs in Search Console: a shared parameter, a shared part of the path or characteristic words. The rule goes into .htaccess (Apache/LiteSpeed), the Nginx configuration, or a redirect plugin that supports the 410 status. It has to be precise so it doesn't accidentally block legitimate pages or parameters the site really uses (search, shop filters, UTM tags).
Don't block spam URLs in robots.txt
The instinct is to disallow spam URLs in robots.txt. That's a mistake. If you block Google from accessing a URL, it can't see that it returns 410, so it may keep it in the index for months with the note "Indexed, though blocked by robots.txt". Google has to be able to reach the spam URLs to learn that they're gone.
Step 2: Temporarily hide the worst results

While Google revisits the URLs, the spam results keep damaging your reputation. Search Console has a tool that hides them temporarily.
The Removals tool
In Search Console, open Indexing → Removals and click New request. You can ask for the removal of one exact URL or all URLs that start with a certain prefix, for example https://yoursite.com/shop/.
It's important to understand what this tool does:
- It hides URLs from search results temporarily, for roughly six months.
- It doesn't delete them permanently from the index. If during that time the URL doesn't return 404 or 410, it will return to the results when the request expires.
- That's why it's used together with step 1, never instead of it.
What to remove first
If there are many spam URLs, you don't need to report every one. Focus on those that show up for your company name and your main services, because those are what clients see. If the spam URLs share a common prefix, one request can cover hundreds of them.
Don't enter a prefix that also covers legitimate pages. A request for https://yoursite.com/ would temporarily hide the entire site.
Step 3: Help Google visit the spam URLs sooner
Google will revisit the spam URLs on its own eventually, but you can speed that up.
Update and resubmit your sitemap
Make sure your sitemap (sitemap.xml) contains only legitimate pages, then resubmit it in Search Console. This helps Google recrawl your real pages sooner and correct their titles and descriptions, especially if the attacker changed the titles of existing pages.
A temporary sitemap of spam URLs
A known technique for getting a large number of URLs dropped faster is a temporary, separate sitemap containing only the spam URLs, with a recent modification date. Google then has a reason to visit them sooner, sees the 410 status and drops them. Remove this sitemap once the number of spam URLs in the index has dropped significantly, usually after a few weeks. This step is optional and only makes sense when you have hundreds or thousands of spam URLs.
Request indexing for key pages
For a handful of your most important pages (homepage, main services, contact), use the Request indexing button in URL Inspection. That way Google refreshes their title and description faster if the attacker changed them. The number of these requests per day is limited, so use it only for the pages you care about most.
Step 4: Submit a review request if there's a warning

Use this checklist whenever remove spam pages from shows up again after a partial cleanup.
If Google flagged the site for hacked content, you'll see it in Search Console under Security & Manual Actions, in "Security issues" or "Manual actions". While the warning is active, the site may have reduced visibility or a browser warning.
How to write a good request
Once the site is clean and the spam URLs return 410, click Request review. In the request, briefly and specifically describe:
- what was found (for example, cloaking code injected into theme files and the database, spam pages about medication),
- what was removed and replaced,
- how the way in was closed (vulnerable plugin updated, passwords changed, two-factor authentication enabled),
- how repeat infections are prevented (monitoring, regular updates).
Google doesn't expect a technical essay, but a clear and honest explanation improves the chance of approval on the first try. A review usually takes from a few days to a few weeks. Read more in Website blacklisted by Google: fix guide.
Don't submit the request too early
If you submit while the site isn't fully clean, Google will reject it, and each following review may take longer. It's better to wait a day or two and check everything once more than to rush.
How to track progress

Owners often underestimate remove spam pages from until Search Console or clients raise the alarm.
Removing spam URLs isn't instant and doesn't move in a straight line. Here's where to look and what's normal.
The Page indexing report
In Search Console's Page indexing report, watch two things. The number of indexed pages should gradually fall towards the real number of pages on your site. The number of pages under "Not found (404)" or similar categories for removed pages should grow. That's a good sign: Google is visiting the spam URLs and seeing that they're gone.
The report updates with a delay of a few days, so don't check it every hour.
The "site:" search
A site:yoursite.com search gives a rough picture, but the number of results isn't precise and fluctuates from day to day. Use it to see whether spam still shows up for your company name, not as a precise measure of progress.
How long it takes
There's no fixed deadline. With smaller infections of a few dozen spam URLs, most results disappear within two to four weeks. With large infections of thousands of URLs, it can take two to three months, and individual URLs sometimes reappear later. What matters is a clearly downward trend.
Special cases
The attacker changed the titles of your real pages
In some infections, especially the Japanese keyword hack, the attacker doesn't only create new spam pages but also changes the title and description of existing ones, so your homepage shows a Japanese or pharma title in Google. These pages shouldn't be removed from the index, because you need them. After the cleanup, check them with URL Inspection, make sure the live test shows the correct title, then request reindexing. Google usually refreshes the title within a few days.
The spam is on a subdomain
Sometimes the attacker creates a subdomain, for example shop.yoursite.com or a random name, and puts the spam there. Check your domain's DNS records and remove subdomains you don't recognise. If you use a Domain property in Search Console, you'll see results from subdomains too, so you can track them in one place.
Bing and other search engines
The same spam is usually indexed in Bing as well, which also powers some other search engines and AI assistants. The process is similar: add the site to Bing Webmaster Tools, submit a correct sitemap and use their content removal tool for the worst results. The 410 status on the server works for Bing too.
Mistakes that drag the process out

In practice, these are the most common reasons spam stays in Google much longer than it should:
- Working on the index before the site is fully clean. Google sees the spam again and keeps the URL.
- Redirecting all non-existent URLs to the homepage. Google doesn't get a clear signal that the page has been removed.
- Blocking spam URLs in robots.txt. Google can't see the 410 status.
- Relying only on the Removals tool. After six months the results come back.
- Deleting and recreating the Search Console property. You lose history and gain nothing.
- Submitting the review request too early. A rejected request lengthens the whole process.
Recovering rankings after the cleanup
Once the spam is gone from the index, the site's rankings usually recover gradually, but not always to the same level and not straight away. For a while Google saw your site as a source of spam, and it needs time to trust it again.
Recovery is helped by regularly publishing useful content, correct titles and descriptions on key pages and a technically sound site. Naturally earning new links from reputable sites helps too. None of it is worth anything if the infection returns, though, so monitoring after the cleanup is as important as the cleanup itself. Why infections come back is explained in Infection returns after cleanup.
Next step

If you still see spam in Google after a cleanup, run a free website check to confirm the infection is no longer visible from the internet. If you'd like someone to take over the whole process, from the cleanup through correct server responses to the Search Console review request, get in touch or call +381 65 402 5000.