What to check first
- Test from more than one device and network
- Record the destination and affected pages
- Review files, database content, users, and third-party scripts
Document when the redirect appears
Test from a clean browser, phone, and different network. Some injected redirects target only new visitors or search traffic. Record the destination and affected pages without asking customers to follow suspicious links.
Investigate the source
Preserve logs, files, and database before cleanup. Review administrator accounts, modified code, scheduled tasks, third-party scripts, and database entries. Removing one obvious script may not remove the access that inserted it.
Verify the site is safe
Rotate compromised credentials, update vulnerable components, and test again as an anonymous visitor. Watch for new warnings or changed files after reopening the site.
Will a backup alone solve it?
Only when the copy is clean and the original route of compromise is closed.
Long Island Webmaster is an independent website service provider. References to GoDaddy describe third-party products and do not imply affiliation or endorsement.
