Squarespace Hacked or Redirecting to Spam? Fix It
If your Squarespace site is redirecting to spam or showing a "deceptive site" warning, the fix depends on whether the problem is in your domain's DNS settings or inside your Squarespace account itself — and you can usually tell which one it is in under five minutes.
This is for Squarespace site owners who opened their site (or had a customer tell them) and found it redirecting somewhere else, showing spam content, or triggering a Google Chrome "Deceptive site ahead" warning. Unlike WordPress, you can't SSH in and inspect server files — everything you can fix lives in two dashboards: your Squarespace account and your domain registrar. This guide walks through both, in order, so you stop the bleeding first and clean up second.
Domain problem or account problem? Run this check first
Squarespace gives every site a free built-in preview address that looks like yourname.squarespace.com. You can find it under Settings > Domains in your dashboard. This one link tells you almost everything:
| What you see | What it means |
|---|---|
yourname.squarespace.com loads your real site fine, but your custom domain (yoursite.com) redirects to spam | Domain/DNS-level issue. Your Squarespace content is untouched — traffic is being hijacked before it ever reaches Squarespace's servers. |
Both the .squarespace.com link AND your custom domain show spam, blank pages, or unfamiliar content | Account-level compromise. Someone got into your Squarespace login and changed something inside your site. |
| Chrome/Safari shows a "Deceptive site ahead" warning but everything looks normal when you're logged in | Often cloaking — injected code that shows spam only to search engine crawlers or first-time visitors, not to logged-in admins. Still an account-level compromise. |
| A WHOIS lookup (whois.com) shows a registrar, expiry date, or owner you don't recognize | Your domain itself may have expired and been re-registered by someone else, or your registrar account was compromised — this isn't a Squarespace hack at all. |
Keep this table open while you work through the steps below — it decides which section applies to you.
If it's domain-level: your DNS or registrar was hijacked
A domain hijack happens when someone gets into the account that controls your domain's DNS records — the settings that say "send visitors of this domain to this server." If they change those records, your domain points to a spam or phishing server while your actual Squarespace site sits completely untouched.
This is common when your domain is registered with a third party (GoDaddy, Namecheap, Google Domains/Squarespace Domains, etc.) rather than through Squarespace directly, because it's a separate login with its own password and security settings that people forget about.
Do this now:
- Log in to your domain registrar directly (not Squarespace) and check your DNS records. If your domain points to Squarespace, the A records and CNAME should match what Squarespace's own DNS instructions specify — anything else was added by someone else.
- Check your nameservers (NS records). A more serious hijack replaces your nameservers entirely, moving DNS management to an attacker-controlled service. If your nameservers aren't the ones you originally set, that's the root cause.
- Change your registrar password immediately and enable two-factor authentication (2FA) on the registrar account — this is separate from your Squarespace account password and is very often the weaker link.
- Enable a registrar/transfer lock on the domain to stop it from being moved to another registrar without your approval.
- If your domain is a "Squarespace Domain" (bought through Squarespace itself), there's no separate registrar — everything lives under Settings > Domains in your Squarespace account, so go straight to the account-level steps below and contact Squarespace support.
- If you don't recognize the registrar account at all, or can't log in, contact that registrar's support immediately and explain the account may be compromised — most have a dedicated recovery process for exactly this.
If it's account-level: someone logged into your Squarespace account
Squarespace is a fully hosted platform, so there's no theme file or plugin for an attacker to plant malware in like on WordPress. Instead, a compromised account gets abused through Squarespace's own legitimate features — which is why it can be easy to miss.
Work through this checklist in order:
- [ ] Change your Squarespace password right away, using a unique password you don't reuse anywhere else, and turn on two-factor authentication under Account Settings > Security.
- [ ] Check Settings > Permissions & Ownership for any contributor or admin you don't recognize — remove them immediately.
- [ ] Check Settings > Advanced > Code Injection. This is the most common injection point: attackers paste malicious JavaScript into the Header or Footer fields, which then redirects visitors or loads spam content on every page. Copy out anything you didn't add (for later review), then delete it.
- [ ] Check Settings > Advanced > URL Mappings. This feature is meant for legitimate redirects (e.g., old page to new page), but attackers can add a rule that 301-redirects your entire domain to a spam or phishing site.
- [ ] Scan your Pages panel for pages you didn't create — spam campaigns often add "doorway pages" stuffed with keywords and links, built purely to manipulate search rankings.
- [ ] Check Settings > Advanced > External Services / Connected Accounts for any integration or API connection you don't recognize, and revoke it.
- [ ] Contact Squarespace Support through your dashboard's Help panel and flag it explicitly as a security/account compromise. Their team can check account access logs, confirm whether the login came from an unfamiliar location, and help you verify the account is fully clean — something you can't fully do from the front end alone.
- [ ] For a single hijacked page, Squarespace's version history (available in the page editor on most 7.1 sites) lets you roll back that page's content to an earlier version — useful for undoing a specific vandalized page rather than the whole site.
For a broader walkthrough of the mindset and order of operations when any site gets compromised, see our general guide on what to do when your website is hacked.
Clearing a Google security warning after you've fixed it
If visitors are seeing a "Deceptive site ahead" or "This site may be hacked" warning, that's coming from Google Safe Browsing, not Squarespace. You can check your domain's current status there directly.
Once you've removed the malicious code or fixed the DNS records:
- Re-check the Safe Browsing Transparency Report for your exact domain.
- If your domain is verified in Google Search Console, go to Security Issues in the sidebar and click Request a Review after confirming the issue is resolved.
- Warnings typically clear within a few days once Google's crawler re-visits and confirms the site is clean — there's no fixed guarantee on timing, so don't repeat the review request more than necessary.
Preventing this from happening again
- Turn on 2FA on both your Squarespace account and your domain registrar account — two separate logins, two separate weak points.
- Use a password manager so you're not reusing a password that leaked in an unrelated breach; credential reuse is one of the most common ways accounts get taken over (OWASP: Credential Stuffing).
- Set a calendar reminder for your domain renewal date — a surprising number of "hijacked domain" reports turn out to be an expired domain re-registered by a squatter, not an actual break-in.
- Periodically glance at Code Injection and URL Mappings even when nothing looks wrong — they're the two places a compromise would most likely hide on a Squarespace site.
- Be alert for phishing emails pretending to be from Squarespace or your registrar asking you to "verify your account" — this is the most common way these logins actually get stolen in the first place (CISA: Avoiding Social Engineering and Phishing Attacks).
- If you're not sure whether your setup has other soft spots — old integrations, exposed forms, weak account permissions — a free passive security check will give you a quick yes/no on anything critical, no login required.
FAQ
My Squarespace site is hacked — what do I do first? First confirm whether it's account-level or domain-level using the yourname.squarespace.com preview link test above — that determines whether you're fixing things inside Squarespace or inside your domain registrar. Then immediately change your Squarespace password, enable 2FA, and check Code Injection and URL Mappings for anything you didn't add.
Why is my Squarespace site redirecting to another website? The two most common causes are malicious JavaScript pasted into Code Injection, or an unauthorized rule added under URL Mappings — both require someone to have your account login. If your .squarespace.com preview link still loads correctly while your custom domain redirects, the cause is DNS, not your Squarespace account.
Can a Squarespace domain actually be hijacked? Yes — if your domain's DNS or registrar account is compromised, attackers can point your domain to a completely different server without ever touching your Squarespace account. This is especially common when the domain is registered with a third party you log into separately and rarely check.
Will Squarespace restore my site if it's hacked? Squarespace support can review account access logs, help you confirm the login history, and guide you through securing the account, and page-level version history can roll back individual pages. There isn't a one-click "restore the whole site" button, which is why removing the malicious Code Injection or URL Mapping entries yourself is usually the fastest fix.
How do I get rid of a Google "deceptive site" warning on Squarespace? Fix the underlying cause first (bad code injection, rogue redirect, or hijacked DNS), confirm the site is clean, then request a review in Google Search Console under Security Issues if your domain is verified there. Clearance isn't instant, but it follows Google re-crawling a genuinely fixed site.
Key takeaways
- Use the
yourname.squarespace.compreview link as your fastest triage tool: if it's clean but your custom domain redirects, the problem is DNS, not your Squarespace account. - Account-level compromises almost always show up in Settings > Advanced > Code Injection or URL Mappings — check both first.
- Domain-level hijacks are fixed at your registrar, not inside Squarespace — log in there separately and lock the domain once you're back in.
- Enable 2FA on both your Squarespace account and your registrar account; they're two separate weak points attackers rely on.
- Once you're clean, use the Safe Browsing Transparency Report and Search Console's Request a Review to clear any Google security warning.
If you've locked things down but want a second set of eyes confirming there's nothing else exposed — an old integration, a leftover admin, a form that shouldn't be public — a real engineer manually checking your whole site for $49 through Bug Circuit's Circuit audit is a fast, honest way to be sure before you call it done.
A real human security engineer audits your whole site by hand and sends a full report — every issue, its severity, and the exact fix. From $49, with a 14-day money-back guarantee.
See pricing