PROTOTYPE Click through the three steps. The report in step 3 is an example layout, not a scan result.
HackedIndex Check your site
Private check · free · no account

See your site the way Google sees it

We fetch your site with Google's crawler user-agent and as a visitor, read the sitemap and look for spam in Google results. The full report goes only to someone who proves they own the domain.

We keep the domain and the result. Nothing else, and nothing is shown to anyone until you verify.
5plain requests to your site, nothing more
2 axesyour site and your Google results
0 of 90false alarms on known-clean sites

Prove you own {{ domain }}

Pick one. It takes a few minutes and you do it once.
DNS recordRECOMMENDED
Add a TXT record to the domain:
hackedindex-verify=[token]
File on the server Upload /.well-known/hackedindex.txt with the same token.
Email on the domain We send a link to admin@{{ domain }} or webmaster@{{ domain }}.
PRIVATE REPORT · example.com EXAMPLE LAYOUT
Spam found on the site and in Google
3 of 5 checks found something. Details and evidence below.
Page for Googlebot vs page for visitorsSame address, fetched twice with different identities
Different
Hidden blocks with spam wordsContent hidden with CSS that matches the spam vocabulary
Found
SitemapPages you did not write, listed for Google
Clean
Site search probesOnly hard evidence counts here
Clean
Your Google resultsWhat people see when they search for your site
Spam visible
Software your site shows publiclyEXAMPLE · matched against the vulnerability radar
WordPress 7.1Your version is in the range attackers use now. Update to 7.1.2 today, then re-check
Likely affected · CVE-2026-87902
[plugin] [version]No match in the feeds we read on 28.09.2026
No match
What to do next
Watch daily · €5 / month
Re-check queued. This report updates in a few minutes, and we email you the result.
This report is free and stays free. Public institution or non-profit? Daily monitoring is free for you. See pricing
Fixing it yourself? The steps above are the full cleanup guide, free. Prefer help? Pass this report to your web developer or host, the evidence in it is enough to work from. HackedIndex doesn’t clean sites and takes no referral fees.

Why we ask you to verify

Anyone can type any domain. If we showed results to everyone, the index would become a shopping list of easy targets. So the details go to the owner only.

Got an email from us?

Our notices come from [notice address]. We never ask for passwords, payment or a plugin install. If an email does, it isn't us.

Not your site?

Tell the owner, or report it to CERT Polska at incydent.cert.pl.

Opt out of scanning

Add hackedindex-optout as a TXT record and we stop within 24 hours.