Ranking Recovery
The server is clean. The index is not.
You stopped it. You found out how it happened. You closed the doors. The site loads, the files are yours again, and nothing hostile is running.
And Google still shows the damage. Spam pages under your domain. Your own pages missing. A warning label, or a ranking that is not where it was.
This is the fourth stage, and almost nobody writes about it, because it sits where two trades meet. The security people consider the job finished when the server is clean. The SEO people rarely see the inside of a compromise. What happens to a site in search after a hack — and what the owner can actually do about it — falls between them.
Two clocks
Cleaning a server takes days. Recovering in search takes months. They run on separate clocks, and only the first one is yours.
Google does not consult your website when someone searches. It consults its own stored copy, made on its last visit. Removing a file changes nothing in that copy until Google comes back, asks, and is told something different. For addresses it visits often, that is days. For addresses it only ever heard about, it can be most of a year.
Everything in this series follows from that. The work is not forcing Google to hurry. It is making sure that whenever Google does ask, it gets the right answer — and that nothing you did in a hurry is standing in the way.
The principle
You cannot speed Google up. You can certainly slow it down.
A redirect to the homepage, a block in robots.txt, a removal rule that quietly breaks: each is a reasonable-looking decision, and each can add months. Most of this series is about recognizing those obstacles, removing them, and keeping them removed.
The ten parts
1. Why Is My Website Not Showing Up on Google After a Hack? Four different problems hide behind “not showing up.” How to tell which you have, and the three well-meant mistakes that make it worse.
2. Google Ranking Drop After a Hack: What Was Actually Lost A drop after a hack is several losses stacked together. Which ones reverse on their own, which need work, and how to read the shape of the decline.
3. Google Search Console Removals Tool: What It Does After a Hack, and What It Does Not The removals tool hides results for about six months and deletes nothing. When to use it, when it cannot help, and the sequence that makes it permanent.
4. Google Search Console Crawl Errors After a Hack: Which Ones Are Good News After a hack, some errors are exactly what you want. Sorting the addresses into yours and theirs, and the rows that mean trouble.
5. Google Search Console Request Indexing: Getting Your Real Pages Back Getting the good pages back in. What the request button does, what to read before pressing it, and which pages to ask for first.
6. What Is a Sitemap, and Why It Matters After a Hack A sitemap is an invitation to crawl, and it was probably used against you. The sitemap you need now, and how links get dead addresses re-fetched.
7. Google Search Console Not Updating: Why Recovery Data Lags Three delays sit between your fix and the report. What lags, what is live, and why undoing a correct fix is the real danger.
8. Why Is My Website Marked as Unsafe? Clearing Warnings After a Hack Four separate sources of warnings, each with its own list. Finding out what was flagged, asking for review, and what lingers after it clears.
9. Google Index After a Hack: How Long the Spam Pages Stay Indexed spam clears in weeks. The never-fetched tail can take most of a year. What shortens the wait and what lengthens it.
10. How Do I Improve My Google Ranking After a Hack? The cleanup returns you to zero, not to first. What is specific to a hacked site, what is the same for everyone, and a realistic timeline.
Where this sits
| Stage | Question |
|---|---|
| Emergency Authority | It’s happening now — stop it |
| Invasion Investigation | The fire is out — understand it |
| Site Hardening | Stop it happening again |
| Ranking Recovery (you are here) | Get back what it cost |
This series assumes the first three are done. If the way in has not been found and closed, recovery work is wasted: the spam returns, the warning returns, and Google is more cautious the second time.
About the evidence in this series
The examples come from the same compromise documented in the earlier series: 8,452 spam addresses on one domain, 900 of them indexed, discovered in January 2026. The recovery described here is the author’s own, mistakes included. Three of the obstacles in Part 9 are ones he put in his own way.
It is also unfinished, and these articles say so. Eight months on, Search Console still listed several hundred of the spam addresses. Where something is known, it is stated. Where it is the owner’s judgment, or cannot be proven either way, that is stated too.
Recovery in search depends on knowing what Google is still holding and what the server answers today. A Recovery Review establishes both before any of the steps in this series are taken.
Start a Recovery ReviewPaid assessment · scope agreed up front
Back: ProVAE Blog
