Doorway Pages and Spam Directories on Your Domain

By · Updated · 4 min read

You search your own domain in Google and find pages about payday loans, replica handbags or online casinos, all on URLs you have never seen. Your site looks completely normal when you browse it. Somewhere on your server is a directory full of generated pages that exists purely to rank in search results, and it has been quietly building an audience on your domain's reputation.

What doorway pages are

A doorway page exists to capture a search result and move the visitor somewhere else. It is stuffed with terms for whatever the operator is selling, gets indexed, and then funnels anyone who clicks through to the real destination. On a compromised site these are generated in bulk — often thousands of them, each targeting a slightly different phrase.

They typically live in a directory you did not create, or are generated on the fly by a script that produces a page for any URL matching a pattern. The second kind is worse to deal with, because there is no folder full of files to delete; there is one script and an infinite supply of pages.

Why you never see them

Because they are not linked from your navigation and were never meant for you. Nothing on your site points at them. They were submitted directly to search engines, usually through an injected sitemap, and they get their traffic entirely from search results.

Many also check who is asking. A request that looks like a search engine crawler gets the keyword-stuffed page; a request from an ordinary browser gets a redirect to the sales destination, or sometimes your real site, so a casual check shows nothing wrong. That behaviour is cloaking, and my guide on cloaking hacks covers the mechanics in detail.

Finding the full extent

Start with a site search in Google restricted to your domain and page through the results, which shows you what is actually indexed rather than what is on disk. Search Console's coverage and performance reports are better still, because they will show you indexed URLs and the queries they receive — spam pages usually announce themselves as a cluster of impressions for terms wildly unrelated to your business.

Then find them on the server. List directories in your web root and look for folders you do not recognize, and sort the file tree by modification date. If no such folder exists but the URLs still work, you are dealing with generated pages: look at .htaccess for rewrite rules routing requests into a script, which my guide on hacked .htaccess files covers.

Removing them

Delete the directories and the generating script, then remove the rewrite rules that pointed traffic at them. Check every .htaccess on the site rather than just the one in your web root, since these hacks routinely drop copies deeper in the tree where people forget to look.

Then do the underlying cleanup, because doorway pages are a payload rather than a cause. Something wrote those files, and it is still there until you find it — look for backdoors, web shells, and administrator accounts you did not create. Rotate credentials and patch whatever let them in.

Getting them out of search results

Removing the pages is necessary but not sufficient, because Google will keep showing them until it re-crawls and discovers they are gone. Make sure the URLs now return a genuine 404 or 410 rather than redirecting to your homepage, which is slower to process and can look like more cloaking.

Then resubmit a correct sitemap and, if the volume is large, use the removal tools to accelerate things. My guide on removing spam URLs from Google's index walks through the options and the realistic timelines. If you picked up a manual action, filing a reconsideration request covers how to get it lifted.

What happens to your rankings

Expect some damage while this was running and some recovery afterwards. Thousands of thin, irrelevant pages dilute what search engines understand your site to be about, and a manual action for pure spam is a serious hit. Neither is usually permanent.

Sites I clean generally see the spam URLs fall out of the index over a few weeks and legitimate rankings return over the following month or two, provided the cleanup was complete and a reconsideration request was accepted. My guide on ranking recovery sets realistic expectations, and if you would rather have the technical side handled properly the first time, that is my malware removal service.

Common questions

Why do the spam pages load for Google but not for me?

Because the script checks the requester before deciding what to serve. A crawler gets the keyword-stuffed page; a normal browser gets a redirect or your real content. It keeps the pages indexed while keeping the site owner unaware, and it is why checking your own site is such an unreliable way to detect this.

I deleted the folder and the pages still work. What now?

The pages are being generated rather than stored. Look for rewrite rules in .htaccess routing requests into a script, and for the script itself. Until you remove both, every URL matching the pattern will keep producing a page even though there is no folder to see.

Should I redirect the spam URLs to my homepage?

No. Mass redirects to the homepage are processed slowly, look like another cloaking attempt, and delay the URLs dropping out of the index. A clean 404 or 410 is the correct signal and it resolves faster.

How long until they disappear from Google?

Usually a few weeks for the bulk of them once they return proper 404s and a corrected sitemap has been submitted, with a long tail that takes longer. Using the removal tools for the worst offenders speeds up the visible part considerably.

Will this damage last after the pages are gone?

Rarely permanently. Most sites recover their legitimate rankings within a month or two of a complete cleanup. What extends the damage is an incomplete cleanup — pages that keep reappearing, or a manual action left unaddressed because nobody filed a reconsideration request.