Ranking Recovery · Part 1
The site is clean, and Google has not noticed
The files are gone. The passwords are changed. The site loads the way it should. And when you search for your own business, something is still wrong: your pages are missing, or buried, or sitting under a result in a language you do not speak.
This is the part of a hack nobody warns you about. Cleaning the server and recovering in search are two different jobs on two different clocks. The first can be finished in a day. The second runs on Google’s schedule, and it takes months.
This series covers that second job. It begins with the question every owner asks first: why is my website not showing up on Google, when I have already fixed it?
Four different problems that look the same
“Not showing up” describes at least four separate conditions. They have different causes and different fixes, and the first step is working out which one you have.
1. Your real pages are no longer in Google’s index. During the compromise, Google may have been served something other than your pages, or been blocked from them. It dropped them, and has not picked them back up.
2. Your real pages are indexed but outranked — by your own spam. Search for your name and Google returns the injected pages, because for a while they were the most active thing on your domain.
3. Your pages are indexed and ranking lower. Nothing is missing. The site simply does not stand where it stood.
4. A warning is keeping people away. The page is there, but a browser or Google puts a red screen or a caution label in front of it.
You can have more than one. Most hacked sites have the second and third together.
Website not showing in Google search: how to check which one
Three checks, each a few minutes, separate the four.
Search site:yourdomain.com. This lists what Google is holding for your domain. If your real pages are in the list, you do not have the first problem. If the list is full of pages you never wrote, you have the second. How to read what Google has indexed walks through this in detail.
Open Search Console and look at Pages. You get two totals, indexed and not indexed, with a reason for every page left out. Find your own important pages there. Each will show as indexed, or carry a reason.
Inspect one important URL. Paste your homepage or main service page into the inspection box at the top of Search Console. It tells you whether that exact page is in Google, when it was last crawled, and what Google saw.
Write down what you find, with the date. You will be comparing against it for months.
Why cleaning the server does not clean the index
Google does not look at your website when someone searches. It looks at its own copy, made the last time it visited. Deleting a file on your server changes nothing in that copy until Google comes back, asks for the page, and gets a different answer.
For pages Google visits often, that happens within days. For pages it visits rarely, weeks or months. And for addresses Google only ever heard about and never fetched, there may be no visit coming at all.
From the case file. The compromise behind these articles produced 8,452 spam addresses on one domain. Only 900 were ever indexed. The other 7,552 were discovered through links and never requested. The 900 cleared first, because Google asked for them and was told they were gone. The 7,552 lingered far longer, for the plain reason that an answer cannot be given to a question nobody asks.
The three mistakes that make it worse
Each of these feels like the responsible thing to do. Each one slows recovery.
- Redirecting the spam addresses to your homepage. It makes the links stop showing spam at once. It also tells Google that thousands of junk addresses are now your homepage. Google reads that as a page-not-found dressed up as success, and keeps the addresses.
- Blocking the spam addresses in robots.txt. A blocked address is one Google is not allowed to fetch. If it cannot fetch it, it can never learn the page is gone. The entry freezes in place.
- Asking Google to review or reindex before the cleanup is verified. A failed review costs more time than waiting a week to be sure.
From the case file. The owner made the first mistake himself. His first move on finding the spam was a rule sending those addresses to the homepage. The links died instantly and it looked like a fix. The server logs showed Google still requesting them and still receiving a success code. He replaced the redirect with a rule that answers “gone,” and that is the one still in place.
What recovery actually consists of
Recovery in search is not one action. It is five, done in order.
- Make the bad addresses answer correctly. Gone, permanently, with a code Google understands.
- Make sure Google can reach both the bad addresses and the good ones. Nothing blocked.
- Give Google a current, accurate list of your real pages.
- Clear any warnings through the proper review.
- Wait, and verify that each of the first four is still true while you wait.
The fifth is not a formality. Rules break. Caches hide the breakage. A recovery that was set up correctly in February can be quietly failing in March, and the only way to know is to check the live server.
What you control and what you do not
You control what your server answers. You control what your robots.txt permits, what your sitemap lists, and whether your own pages are worth indexing. You control how often you check.
You do not control when Google returns, how fast it processes what it finds, or where it ranks your pages afterward. No tool, no request form and no paid service changes that. Anyone promising a recovery date is promising something that belongs to Google.
That division is the most useful thing to understand at the start. It tells you where effort is rewarded and where it is wasted. Most of the frustration in recovery comes from working hard on the second list.
How this series is laid out
The next part looks at what was actually lost, because a ranking drop after a hack has several causes and only some of them are permanent. Then come the tools: what the removals tool really does, which crawl errors are good news, how to get your real pages requested again, and what a sitemap is for. The last parts cover the waiting — why the data lags, how long the spam stays, and what improving a ranking means once the cleanup is behind you.
If you are not certain the cleanup is finished, that comes before any of this. Website recovery begins with establishing what is still on the server and what Google is still holding, because recovery in search cannot start while either one is unknown.
Find out what actually happenedWebsite recovery and investigation
Next: Google Ranking Drop After a Hack: What Was Actually Lost
Hub: Ranking Recovery Blog Series
ProVAE builds and recovers websites in Douglas, Georgia, serving South Georgia.
