blaircox.com

Website emergency? Start here.

Pick what's happening below. You'll get the safe first steps in order, what not to touch, and how to tell whether it can wait until morning.

No email asked, nothing to download, works on a phone. Every scenario has a printable card.

Most of these situations are recoverable. The worst moves are the fast ones, so go steady.

Nothing you tap here leaves your browser.

Pick the closest match.

If you're not sure, start with what you saw last. The steps redirect you if it's really something else.

About this guide

This guide covers the common ways a small business website goes wrong: outages, hacks, expired domains, broken email, lost access, vanished developers, misleading invoices, and a suspended Google profile. Each path gives the safe first steps in order, what not to touch, what to gather before contacting support, and an honest read on urgency. It's written for the owner, not the technician: plain words, no products, nothing to install. Everything runs in your browser, and nothing you tap is sent or stored anywhere. Print the card for any scenario and keep it where the router lives. The advice is general; your host, registrar, or provider always has the final word on their own systems.

Common questions

Is the website gone for good?

Almost never. Expired domains usually have recovery windows, hacked sites get cleaned, and hosts keep backups. Expired domains are the most time-sensitive of the lot, so check that one today.

Someone emailed offering to fix it. Should I pay them?

No. People who contact you uninvited about a broken site found it by scanning for broken sites, which is also how attackers found it. Pick your own help.

I don't know any of my logins. Where do I start?

Your card statements show who you actually pay. Those companies can verify you as the paying customer and help recover access. The record sheet on this site collects all of it for next time.

How do I keep this from happening again?

Three habits cover most of it: know who holds your accounts, keep a backup that lives outside your hosting, and put renewal dates in a calendar with a month of warning.

One page, the first moves for every scenario, and this address. Tape it inside a cupboard door.

I do the full human version of this for a handful of businesses. Ask me.

If your website is down

Start over All scenarios

A suspension notice usually means billing or an abuse complaint, and the notice says which. Log into the hosting account, not the site, and read the message there. Then check the inbox that receives hosting invoices, spam folder included, for a failed payment. Pay or reply from inside the account, and the host can usually switch it back on quickly.

Continue with the steps

Start over All scenarios

Working for some people usually means an address change or a network still settling, not a dead site. Try your phone on cellular data with wifi off, and a private window. If it loads there, the site is up and your device or network is holding an old copy. Restarting the router clears most of it; the rest usually clears on its own within a day. If it fails everywhere, continue below.

Continue with the steps

Start over All scenarios

That points at the domain, not the site. Go to: The domain expired.

The domain expired A parking page appeared, or renewal mail went somewhere old.
Start over All scenarios

That has its own path. Go to: It redirects somewhere else.

It redirects somewhere else Your address opens someone else's site.
Start over All scenarios

Down is loud, but it's usually the easiest emergency on this page. Most outages end on the host's side without anything lost. Work in order.

  1. Confirm it's down for everyone

    Try your phone on cellular data with wifi off, in a private window. Then search the phrase is my site down for everyone and run your address through one of the free checkers. If it's only down for you, it's a device or network problem, and the works-for-some path above covers it.

  2. Look at what the error says

    Photograph the screen. An error mentioning suspended points at hosting or billing. A page about parking or expiry points at the domain. Words like can't be reached or took too long point at the server or the address system. You don't need to fix any of it yourself; the wording just decides who you contact.

  3. Rule out the domain

    Expired domains take sites down quietly and get worse on a schedule. Search whois lookup, enter your address, and check the expiry date. If it's past, stop here and switch to the expired-domain path, because that one is genuinely time-sensitive.

  4. Log into the hosting account, not the site

    Look for a banner about maintenance, suspension, or an unpaid invoice, and check the billing inbox for failed-payment mail. If everything looks normal there, open a support ticket or chat and say: the site is down from multiple networks since this time, what do your logs show. That sentence answers their first three questions in advance.

  5. If it broke right after a change

    An update, a new plugin, or developer work just before the outage is worth mentioning to support first. Ask what backups the host holds and whether restoring one is reversible before agreeing to it. A restore that can't be undone deserves a second opinion.

Whatever else happens tonight, don't:

  • keep retrying a failed renewal or card payment over and over. Repeated attempts can double-charge or lock the account.
  • let anyone who phoned you fix your computer remotely. Hosts almost never call you first; an unexpected call about your broken site is usually a scam.
  • change settings you don't understand in the hosting panel or the domain's address records. A wrong move there extends the outage.
  • rebuild the site somewhere new tonight. Outages end; a rushed rebuild creates two half-sites to untangle.

What to have ready before you contact anyone

  • The exact error wording, or the photo of it.
  • When it last worked, best guess.
  • Your hosting company and the email on that account.
  • Anything that changed recently: updates, new plugins, developer work, a moved office, a new card.
  • Whether email on your domain still works, because that narrows the cause fast.

Tonight, or tomorrow morning

Handle it tonight if any of these is true:

  • the site takes orders, bookings, or payments
  • paid ads are running and sending people to it
  • email on the domain is down with it
  • the outage came with a scary notice about the domain

A brochure site that went quiet overnight keeps until morning. Tell the host, then sleep; their queue moves whether you watch it or not.

A professional is worth it when the host insists everything is fine and the site still won't load, or when the same outage keeps returning.

If the site goes down

  1. Check from your phone on cellular data, wifi off.
  2. Photograph the error. Its wording decides who you contact.
  3. Look up the domain expiry with a whois search.
  4. Log into hosting. Check for suspension or failed payment.
  5. Contact the host: down from multiple networks since when, what do the logs show.

Don't: retry payments repeatedly, take fixer calls you didn't place, change settings you don't understand.

Have ready: error photo, when it last worked, hosting company name, recent changes.

Tonight if it takes orders or email is down too. Otherwise morning is fine.

If your site was hacked or defaced

Start over All scenarios

Some attacks show the normal site to you and something different to visitors or to Google. Looking fine from your own chair settles nothing yet. Check from your phone on cellular data, in a private window. Search your business name and click through from the result, since some attacks trigger only for visitors arriving from a search. Ask whoever reported it for a screenshot. If every check comes back clean and the report arrived by email pushing you to click a link or pay for a fix, the email itself is probably the scam. If any check shows the problem, keep going below.

Continue with the steps

Start over All scenarios

Leave the message alone and don't pay. Paying doesn't clean the site, and your host may hold a clean backup that makes the demand worthless. Mention the message when you contact your host in step three.

Continue with the steps

Start over All scenarios

That one has its own path, because the first moves differ. Go to: It redirects somewhere else.

It redirects somewhere else Your address opens someone else's site.
Start over All scenarios

That warning has its own path. Go to: A security warning appears.

A security warning appears Browsers say not secure, not private, or deceptive.
Start over All scenarios

This is recoverable. Hacked sites get cleaned up and come back every day, usually with nothing lost for good. Work the steps in order.

  1. Photograph everything first

    Before touching anything, take photos of the screen with your phone, with the address bar in the shot. If different pages look different, photograph two or three. Whoever cleans the site will read these the way a mechanic listens to a noise, and they prove what happened and when.

  2. Change the passwords that open other doors

    Email first. Your inbox can reset every account you own, which makes it the master key. Then the hosting account, then the site login. If you have any reason to distrust your own computer, do this from your phone on cellular data. Make each password long and different from the others. A password manager helps; a notebook gets you through tonight.

  3. Tell your hosting company

    Contact your host's support and use the word compromised. Ask three things: whether they can scan the account, whether anything else on the account is affected, and whether their logs show when it started. Hosting support handles hacked sites routinely. You won't be their first today.

  4. If the site takes payments or holds customer details, pause that part

    Stop orders or bookings until someone qualified confirms the site is clean. If customer information may be exposed, say that plainly to whoever helps you. Canada has reporting rules for some breaches, and they can tell you whether this one qualifies.

  5. Leave the mess where it is

    Don't delete strange files, pages, or user accounts, and don't restore a backup as your first move. The mess shows the cleanup person how the attacker got in. A backup taken after the break-in, or restored before the hole is found, puts the problem right back. Whoever does the cleanup, ask them to name the way in before they call the job done.

Whatever else happens tonight, don't:

  • pay anyone who contacted you first offering to fix it. People who email hacked sites uninvited found you the same way the attacker did.
  • restore last night's backup as step one. If the break-in is older than the backup, the backup carries it.
  • post about it from your business accounts yet. Anything announced before the facts are in may need correcting later.
  • keep using email tied to the site's hosting for sensitive messages. If mail runs on the compromised hosting, someone else may be reading it.
  • pay a ransom message. Your host's backup usually makes it pointless, and paying marks you as someone who pays.

What to have ready before you contact anyone

  • The photos from step one.
  • When the site last looked normal. Best guess, day and hour.
  • Where the site is hosted and where the domain is registered. Not knowing is common; it's also worth fixing once this is over.
  • Anything that changed in the last month: a new plugin, a new person with access, a shared password, a developer who stopped answering.
  • Whether the site takes payments or stores customer information, and roughly how many people that could touch.

Tonight, or tomorrow morning

Handle it tonight if any of these is true:

  • the site takes payments or holds customer information
  • visitors are being redirected right now
  • browsers show a red warning to visitors
  • you can't get into your own email or hosting account

It can wait for morning if the site is informational only, the key passwords are changed, and your host has been told. Morning cleanup with clear eyes is usually the better cleanup.

A professional is worth it when payments or customer information are involved, or when the same problem returns after a cleanup.

If the site is hacked or defaced

  1. Photograph the screen, address bar included.
  2. Change passwords: email first, then hosting, then the site.
  3. Tell your host. Use the word compromised.
  4. If the site takes payments, pause orders until it's confirmed clean.
  5. Delete nothing. Restore nothing. Evidence first, cleanup second.

Don't: pay uninvited fixers, post about it yet, pay ransom messages.

Have ready: photos, when it last looked normal, host and registrar names, recent changes, whether customer data is involved.

Payments, customer data, live redirects, or red warnings mean tonight. Passwords changed and host told means morning is fine.

If your domain expired

Start over All scenarios

That fits. When a domain expires, email on it usually fails with the website. Fixing the domain fixes both, so go through these steps and skip the separate email path for now.

Continue with the steps

Start over All scenarios

Verify the notice before paying anything. Go to: A scary notice arrived.

A scary notice arrived An invoice or warning about your domain or site, maybe real, maybe not.
Start over All scenarios

Recovering the account is its own path. Go to: Locked out. Then come back; the clock here matters.

Locked out You can't get into the site, the domain, or the Google profile.
Start over All scenarios

This is the one emergency on this page with a real clock. The path back is wide at first and narrows on a schedule, so act today, not this weekend. Recovery is still the likely outcome.

  1. Confirm what actually expired

    Search whois lookup and enter your address. Read three things: the expiry date, the registrar's name, and the domain status. This takes about two minutes and stops you paying the wrong company, which matters, because expiry is exactly when misleading invoices tend to show up.

  2. Renew at your registrar today

    Log in directly, never through a link in any notice, and renew. Most registrars hold a grace window after expiry where the normal price still works. If the card on file failed, fix the card first, then renew, then turn auto-renew on.

  3. If the registrar says it's in redemption

    Past the grace window, domains sit in a recovery period, commonly around thirty days. In it, the registrar can restore the name for a fee that stings but costs far less than losing it. Ask for the exact fee and deadline in writing. Canadian .ca domains follow the same shape under their own rules.

  4. If someone else has already registered it

    Once a dropped domain sells to someone new, your options are buying it back, negotiating, or moving on to a new name, and none of those is a tonight decision. Get the facts from the lookup first: who holds it now and since when. Then decide with clear eyes, ideally with someone who has handled one of these.

  5. Close the loop so this never repeats

    Auto-renew on, a current card, a second contact email that isn't on the domain itself, and the renewal date in your calendar a month early. That last one matters most: renewal mail sent to an address on the expired domain is mail nobody gets.

Whatever else happens today, don't:

  • pay any invoice or for-sale page before the lookup confirms who really holds the domain. Expiry season attracts fake bills.
  • buy a lookalike name as tonight's fix. It splits your email and identity, and you'll still want the real one back tomorrow.
  • wait for the weekend. The recovery path narrows on a schedule, and the cost grows a step at each stage.
  • let anyone who emailed you about the expiry handle the renewal. Renew only inside your own registrar account.

What to have ready

  • The lookup results: registrar, expiry date, status.
  • The email addresses that might be on the registrar account, old ones included.
  • A card that works.
  • Whether email runs on this domain, so you can warn people if it's been bouncing.

Right now, or later

Renewing is a today job even if the site can limp. Every day inside the grace window is cheap; the stages after it cost money, then cost the name. If you're inside business hours, the registrar's own support can often walk you through it live.

A professional is worth it when the domain has entered redemption, when someone else now holds it, or when the registrar account itself is in a vanished person's name.

If the domain expired

  1. Whois lookup first: real registrar, real expiry date.
  2. Log into the registrar directly. Never through a notice's link.
  3. Renew today. Grace windows are cheap; the stages after aren't.
  4. In redemption: ask the exact fee and deadline in writing.
  5. Then: auto-renew on, current card, calendar reminder a month early.

Don't: pay unverified invoices, buy a lookalike name in panic, wait for the weekend.

Have ready: lookup results, possible account emails, a card that works.

This is the time-sensitive one. Today beats tomorrow.

If your business email stopped working

Start over All scenarios

First check webmail: sign into your mail provider in a browser instead of your phone or mail app. If messages are there, the account is fine and the device or app lost its connection; re-adding the account usually fixes it. If webmail is empty too, check whether the mailbox is full, then contact the provider. And confirm the domain hasn't expired; that silences everything at once.

Continue with the steps

Start over All scenarios

This one is rarely sudden and rarely an accident. The big mailbox providers now expect proof that mail claiming to come from your domain really does. The proof lives in a few technical records attached to your domain, and missing or broken records push honest mail toward spam. The email checker on this site reads yours and translates what it finds. Fixing the records is normally a small, one-time job for whoever manages your domain or email.

Continue with the steps

Start over All scenarios

Both at once usually means the domain. Go to: The domain expired.

The domain expired A parking page appeared, or renewal mail went somewhere old.
Start over All scenarios

Email failures feel total but usually have one specific cause: the domain, the mailbox, the device, or the proof records. The steps find which.

  1. Find the direction of the failure

    Send a test from your business address to a personal one, and from the personal one back. Note which direction fails and keep any bounce message that comes back. The bounce text looks like gibberish and is actually the diagnosis.

  2. Read the bounce message

    Words like mailbox full mean storage. Words like blocked, rejected, or spam mean reputation or proof records. Words like does not exist or could not be found often mean the domain or the mail records behind it changed or expired. Copy the whole thing; whoever helps you will want it exactly.

  3. Check the domain and the provider, in that order

    Run the whois lookup for expiry, then sign into webmail directly. If you don't know who provides your email, your card statements do. Email running on the web hosting account is common for older setups, and it means a hosting problem is an email problem too; say that first when you contact support.

  4. Contact the provider with specifics

    Give them: which direction fails, since when, the exact bounce text, and what changed recently. Ask them to say plainly whether the problem is the mailbox, the domain records, or the sending reputation. Those are different repairs, and naming the lane saves a day of guessing.

While it's broken, don't:

  • delete and recreate the email account. That can destroy stored mail permanently and rarely fixes the cause.
  • keep resending to addresses that bounced. Repeats can make a reputation problem worse.
  • switch providers tonight on the first advice you hear. Moving email badly loses history; it's a planned move, not a panic move.
  • announce a new email address to customers yet. If the domain is fixable, you want the old address back, not a confusing second one.

What to have ready

  • The exact bounce text, complete.
  • Which direction fails, and since when.
  • Who provides the email, or the card statement that shows it.
  • Whether the website and email share one hosting account.
  • Recent changes: a new website, a host move, a lapsed payment, new marketing software sending in your name.

Tonight, or tomorrow morning

Handle it tonight if any of these is true:

  • orders, bookings, or quotes arrive by email
  • bounces say the domain does not exist
  • the website is down with it

One correspondent not getting through, or mail drifting to spam, is a real problem on a calm clock. Morning, with the bounce text in hand, beats midnight guessing.

A professional is worth it when both directions fail while the domain checks out fine, or when your mail has been living in spam folders for weeks.

If email stops working

  1. Test both directions with a personal address. Keep the bounce.
  2. Check webmail in a browser, not just your phone.
  3. Whois lookup: check the domain isn't expired.
  4. Find who you pay for email. Card statements know.
  5. Give support: direction, since when, exact bounce text, recent changes.

Don't: delete the account, resend to bounces, switch providers in panic.

Have ready: bounce text, failure direction, provider name, whether email shares the web hosting.

Tonight if orders arrive by email or the domain looks dead. Otherwise morning.

If your web developer vanished

Start over All scenarios

Fix the breakage first and the relationship question after. Go to the scenario that matches what's broken, and when it asks who to contact, the answer for now is your hosting company, not the missing person. Then come back here.

Continue with the steps

Start over All scenarios

That's more common than you'd think, and it's fixable without them. Start at step two and treat it as a recovery project, not a confrontation.

Continue with the steps

Start over All scenarios

A vanished developer feels like an emergency and is usually a deadline instead. Nothing may be wrong today. The risk is the renewal or breakage that arrives later with nobody home, so the job now is quiet inventory, not panic.

  1. Try the boring explanations once

    One email, one text, spaced a few days apart, no heat in either. Something like: are you still available to look after the site, and if not, no hard feelings, I just need a proper handover. People get sick, move, and shut down quietly; a graceful exit ramp gets more replies than an accusation.

  2. Inventory what you actually hold

    Work out what you can get into today: the registrar, the hosting account, the site's admin, the email admin. The record sheet on this site walks through every blank. Each one you can't fill is a key someone else is holding, and the blanks decide the order of the next steps.

  3. Follow the money to find the accounts

    Search your card and bank statements for charges from hosting or domain companies. If the charges are yours, the accounts can be recovered as the paying customer through each company's normal process. If the charges were theirs, note it: those services are running on a stranger's card now, and each is a quiet deadline.

  4. Recover access without them

    Registrar and hosting companies deal with vanished-developer handoffs all the time and have processes for the paying business to take over. Start with the whois lookup and your statements, then each company's account recovery. The locked-out path on this page covers each account type in order.

  5. Only then decide about the relationship

    Once you hold the keys, the vanished person becomes a footnote instead of a crisis. If they resurface, you can choose the terms calmly. If they don't, you've lost a contractor, not a business.

However annoyed you are, don't:

  • post reviews or public complaints yet. You may still need their cooperation for a clean handover, and heat closes that door.
  • hire someone to break into anything. Every account has a legitimate recovery path for the paying customer, and break-ins can cross legal lines.
  • stop paying the invoices that keep the site alive, even out of frustration. The site dies before the point lands.
  • rebuild from scratch before the inventory is done. You might own more than you think.

What to have ready

  • Old emails and invoices from them, especially anything mentioning accounts, logins, or renewals.
  • Card and bank statements showing web-related charges.
  • The whois lookup for your domain.
  • A list of what they controlled, best guess, blanks included.

Tonight, or this week

Tonight only if something is actively broken, and then it's the other scenario's problem. Otherwise this is a steady this-week project: inventory, statements, recoveries, in that order. Steady beats fast here; recovery processes reward patience and paperwork.

A professional is worth it when the accounts are tangled in the missing person's name, or when a renewal is close and nobody holds the keys.

If the developer vanished

  1. One calm email, one text, days apart. Offer a graceful exit.
  2. Inventory what you can open today: registrar, hosting, admin, email.
  3. Search card statements for hosting and domain charges.
  4. Recover each account as the paying customer.
  5. Decide about the person only after you hold the keys.

Don't: go public, break in, stop paying the bills that keep it alive.

Have ready: old invoices and emails, card statements, the whois lookup, a list of what they controlled.

A this-week project, not a tonight one, unless something is actively broken.

If you're locked out of your site, domain, or Google profile

All scenarios

Locked out is a paperwork problem wearing an emergency costume. Every one of these accounts has a recovery path for the legitimate owner, and none of them is improved by frantic guessing. Pick the door and work the path.

Locked out of which?

Start over All scenarios

Start with the normal reset: the login page's forgot-password link, sent to the admin email. If that email is the missing developer's, or the reset never arrives, skip the guessing and go through the hosting company instead. Hosts can reset site access from their side once you verify as the account holder. Repeated wrong guesses can trigger temporary lockouts on some sites, so two tries, then the host.

Continue with the steps

Start over All scenarios

Use the provider's account recovery, and expect to prove you're the paying customer: the card on file, invoice numbers, the account email. If the account was opened by someone else, ask the provider for their process to transfer or re-establish the account for the business that pays. Persistence and paperwork win these; phone support often moves faster than ticket queues for identity matters.

Continue with the steps

Start over All scenarios

The registrar controls the domain, so this one gets priority. Run the whois lookup first to confirm which registrar and which account email. Then account recovery. If the account was never yours, this becomes an ownership question, and registrars have formal change processes for exactly that; expect documents proving the business's identity. Start it now; these run on their own clock.

Continue with the steps

Start over All scenarios

Two different situations. If it's your account and the password is the problem, use the account recovery for that email address. If someone else owns the profile, sign in, find your business, and use the request-access option. The current owner gets a short window, typically days, to respond, and if they stay silent you can usually proceed to claim it. Gather proof that matches the business name and address either way: registration, a utility bill, signage photos.

Continue with the steps

Start over All scenarios
  1. Prove who you are, in advance

    Recovery teams believe payments and documents, not urgency. Pull together the card on file, an invoice or receipt, the account email possibilities, and for the Google profile, proof matching the public business name and address. Arriving with these usually shortens the wait considerably.

  2. Change the pattern that caused it

    Once you're back in: a password manager, two contact emails on every critical account with one off the domain, and a second trusted person who can reach the criticals. One person holding every key is one vacation away from doing this again.

While locked out, don't:

  • guess passwords until something locks harder. Two tries, then the recovery path.
  • create a duplicate account or a second business profile as a workaround. Duplicates confuse recovery and can get both versions suspended.
  • pay anyone who promises to force access from outside. Legitimate recovery is free or cheap and doesn't come from strangers.
  • take it out on whoever answers first at support. The person reading the ticket didn't lock you out, and goodwill moves tickets.

What to have ready

  • Payment proof: the card, a statement line, an invoice number.
  • Every email address the account might live under.
  • For the Google profile: documents and photos matching the public name and address.
  • The whois lookup results if the domain is involved.

Tonight, or tomorrow morning

Lockouts alone are morning work; recovery teams mostly run on business hours anyway. It becomes tonight work only when the lockout is paired with active damage, like a defacement or redirect you can't reach in to fix. Then contact the host tonight and say both things: compromised, and locked out.

A professional is worth it when the accounts were never in the business's name, or when a recovery stalls after honest tries.

If you're locked out

  1. Two reset tries, then the provider's recovery path. No guessing sprees.
  2. Gather proof first: payments, invoices, account emails, business documents.
  3. Site admin locked: your host can reset it from their side.
  4. Google profile owned by someone else: request access, wait the window, then claim.
  5. Back in: password manager, second contact email, second trusted person.

Don't: create duplicates, pay access-forcers, burn goodwill with support.

Have ready: payment proof, every possible account email, documents matching the business name and address.

Morning work, unless paired with active damage. Then tell the host: compromised and locked out.

If browsers show a security warning on your site

Start over All scenarios

Small-text not secure means the site isn't using an encryption certificate, or a page mixes secure and insecure pieces. It's not an attack and probably didn't start today; someone just noticed. It still deserves fixing soon: browsers keep making it more visible, and forms on an unencrypted page leak trust and sometimes data. It's a small job for your host, on a calm clock.

Start over All scenarios

A red deceptive-site or harm warning means the site got flagged for hosting something harmful, which most often traces back to a compromise. Treat it as the hacked scenario first: photos, passwords, host, in that order. Once the site is confirmed clean, the flag gets lifted by requesting a review through the site's Search Console account, and clean sites typically clear in days. Cleanup first, review second; a review request on a dirty site just slows everything down.

Hacked or defaced The site shows things you didn't put there, or someone says it's compromised.
Start over All scenarios

One device seeing warnings that others don't often means that device's clock is wrong, its browser is outdated, or its network is interfering. Check the date and time settings first; a wrong clock makes valid certificates look expired. If the device checks out fine, run the site through the steps below anyway.

Continue with the steps

Start over All scenarios

A connection-not-private page usually means the site's encryption certificate expired or got misconfigured, and visitors are being told not to trust it. It looks alarming and is normally a small repair on the hosting side.

  1. Read the warning's own details

    The warning page usually has an advanced or details link that names the reason. Expired says expired. A name mismatch means the certificate belongs to a different address, common after site moves. Photograph what it says; that wording is the whole diagnosis.

  2. Check it from a second device and network

    Your phone on cellular data settles whether it's everyone or just one machine. If it's just one machine, the one-device path above applies.

  3. Contact the host with the specifics

    Most certificates renew automatically, and the failures cluster around changes: a host move, an address change, a lapsed plan. Tell support the certificate error text, when it started, and what changed recently. Renewing or reissuing is routine for them.

  4. If it takes payments, treat it as urgent

    Checkout behind a certificate warning is checkout that isn't happening, and clicking past the warning is the wrong habit to teach anyone. Pause promotions pointing at the site until it's fixed.

While the warning is up, don't:

  • tell customers to click past it. Training people to ignore security warnings costs more than the outage, and if the cause is worse than a certificate, you walked them in.
  • dismiss it because your own browser stopped warning. Browsers remember when you click through, and yours may just be remembering.
  • buy a new domain to escape a red deceptive-site flag. The flag follows the problem, and a clean site clears instead.
  • pay a stranger who emailed about the warning. The warning is public; the emails it attracts are the same crowd every broken site attracts.

What to have ready

  • A photo of the warning, details expanded.
  • When it started and what changed around then.
  • Whether it shows on multiple devices and networks.
  • Your hosting company and account email.

Tonight, or tomorrow morning

Handle it tonight if any of these is true:

  • the warning is the red deceptive or harm kind
  • the site takes payments or logins
  • the warning appeared alongside other strangeness, like redirects

The small not-secure text, or an expired certificate on a brochure site, keeps until morning. Send the host the photo tonight and let the ticket age in the queue.

A professional is worth it when the red flag mentions deception or malware, or when a renewed certificate keeps failing to take hold.

If browsers show a security warning

  1. Open the warning's details. Photograph the reason it names.
  2. Check from a second device on cellular data.
  3. One affected device may just have the wrong date and time.
  4. Certificate problems: the host renews or reissues. Routine for them.
  5. Red deceptive-site page: treat as hacked. Clean first, then request review.

Don't: tell people to click past it, escape to a new domain, pay warning-chasers.

Have ready: warning photo with details, when it started, which devices see it.

Red warnings and payment sites mean tonight. Small not-secure text keeps until morning.

If your website redirects somewhere else

Start over All scenarios

Parking pages usually mean the domain lapsed. Go to: The domain expired.

The domain expired A parking page appeared, or renewal mail went somewhere old.
Start over All scenarios

That's usually the address system pointing the wrong way rather than a hack: a lapsed domain re-registered, an address-record change, or a hosting move gone sideways. Run the whois lookup first. If the domain is yours and current, contact whoever manages your domain's address records, often the registrar, and ask what changed and when. If the lookup shows a new owner, the expired-domain path has the honest options.

The domain expired A parking page appeared, or renewal mail went somewhere old.
Start over All scenarios

Redirects that come and go are still real. Many trigger only for phones, only from search results, or only for first-time visitors, which is why it looks fine from your desk. Trust the reports and work the steps.

Continue with the steps

Start over All scenarios

A site sending people somewhere seedy is almost always a compromise, and it's doing harm while it runs, so this one moves tonight. The repair path is the hacked path with sharper edges.

  1. See it the way visitors do

    Use your phone on cellular data in a private window, and arrive by searching your business name instead of typing the address. Photograph or screen-record where it lands. If you can't reproduce it, ask whoever reported it for a screenshot and what they tapped.

  2. Change the key passwords

    Email first, then hosting, then the site login, from a device you trust. Same logic as any break-in: the inbox resets everything else, so it gets locked first.

  3. Tell the host it's compromised and redirecting

    Both words matter. Redirecting means visitors are being handed to someone hostile right now, which most hosts treat with more urgency than a quiet defacement. Ask them to scan the account, check for altered configuration, and say when it started.

  4. Pause anything sending people to the site

    Promotions, campaign emails, a link in your voicemail or invoices: anything actively steering people there is steering them to the destination instead. Turn it off until the site is confirmed clean.

  5. After cleanup, verify like a skeptic

    Check again from a phone, from search, in private windows, over a few days. Some redirects hide from repeat visitors and return on a schedule. Confirmed clean twice, days apart, is confirmed clean.

While it's redirecting, don't:

  • send the link to anyone, even to show them the problem. Screenshots travel safer than live redirects.
  • assume it's fixed because it stopped for you. Some redirects skip visitors they've seen before.
  • delete the site or its files in a rage. The evidence shows the cleanup how it got in.
  • ignore it because sales still happen. Every redirected visitor meets someone else first, and warnings or blacklisting tend to follow.

What to have ready

  • The recording or photos of where it goes.
  • Who reported it and from what kind of device.
  • When it started, best guess.
  • Hosting company, and whether anyone else has site access.

Tonight, or tomorrow morning

Tonight, as a rule. Visitors are being handed to a hostile destination while it runs, and the first three steps take under an hour. The exception is the wrong-real-business kind with the domain confirmed yours: that's a morning call to whoever manages the address records.

A professional is worth it when the redirect returns after cleanup, changes destinations over time, or arrived alongside a lockout.

If the site redirects somewhere else

  1. Reproduce it like a visitor: phone, cellular data, arrive from search. Record it.
  2. Passwords: email, hosting, site, from a trusted device.
  3. Tell the host: compromised and redirecting. Both words.
  4. Pause ads, emails, anything steering people to the site.
  5. After cleanup, verify twice, days apart, from a phone and from search.

Don't: share the live link, trust one clean check, delete the evidence.

Have ready: recording or photos, who reported it, when it started, hosting company.

Tonight, as a rule. Redirects do harm while they run.

If your Google Business Profile is suspended

Start over All scenarios

Missing isn't always suspended. Sign into the profile's dashboard and read what it says there. No notice and no dashboard access points at a lockout instead. If the dashboard shows a suspension or restriction notice, continue below. If everything looks normal, the profile may have dropped in ranking rather than existence, which is a different, slower conversation.

Continue with the steps

Start over All scenarios

Reviews after edits are normal and usually pass on their own. Editing more while it sits tends to reset the wait. Give it a few days of stillness before treating it as a suspension.

Start over All scenarios

Public suggestions and Google's own updates can change a profile; that isn't a hack. Sign in, correct the facts, and check who else is listed with access. If an old marketer or developer still has a role, remove what shouldn't be there. If you can't sign in at all, the locked-out path covers recovering access.

Locked out You can't get into the site, the domain, or the Google profile.
Start over All scenarios

A suspension feels like being erased, and it runs on Google's clock, not yours. The repair is a paperwork case: fix what tripped the rules, prove the business is real, file once, properly.

  1. Read the notice and find the tripwire

    The notice names a policy area even when it feels vague. Recent changes are the usual suspects: a new address, a name edited to include extra keywords, a category change, a home business showing a residential address publicly. Compare what changed recently against the profile rules before touching anything else.

  2. Fix the violation before appealing

    Appealing an unfixed profile burns the attempt. Make the profile match reality exactly: the registered name without stuffing, the real address handled per the rules, categories that match what the business does.

  3. Gather proof that matches the profile

    The reviewers believe documents where the name and address match the profile exactly: business registration or license, a utility bill for the address, tax paperwork, photos of real signage. Matching is the whole game; a perfect document with an old address argues against you.

  4. Appeal once, completely

    Use the official appeals tool signed in as the profile's owner, attach the evidence, and submit one complete case. Decisions typically come back within days. Multiple appeals for the same decision don't speed it up and can muddy the file.

  5. Hold position while it's reviewed

    Keep serving customers and keep the website's own contact page current, since that's where people land when Maps goes quiet. Update the profile's photos and posts only after reinstatement, not during review.

While suspended, don't:

  • create a second profile for the same business. It reads as evasion and can take the real one down with it.
  • pay cold-callers who promise guaranteed reinstatement. Nobody outside Google can guarantee that, and suspended owners are their favourite audience.
  • keep editing the profile during review. Every edit can restart scrutiny.
  • appeal on a phone in a waiting room. This one deserves a sit-down with documents open.

What to have ready

  • The suspension notice, complete.
  • Business registration or license matching the public name.
  • A utility bill or lease matching the address.
  • Photos of real signage at the location, if there is one.
  • A list of what changed on the profile recently.

Tonight, or this week

Never a tonight problem, always a this-week one. The clock that matters is Google's review queue, and the way to move fast is to enter it once with a complete case. Spend tonight gathering documents, not refreshing the dashboard.

A professional is worth it when a complete, honest appeal comes back refused, or when the suspension followed a move or ownership change.

If the Google profile is suspended

  1. Read the notice. Find which rule tripped: name, address, category, recent edit.
  2. Fix the profile to match reality exactly.
  3. Gather matching proof: registration, utility bill, signage photos.
  4. Appeal once, complete, through the official tool.
  5. Then stop touching it while it's reviewed.

Don't: make a second profile, pay guaranteed-reinstatement callers, keep editing.

Have ready: the notice, registration or license, utility bill, signage photos, list of recent edits.

A this-week case, not a tonight one. Complete beats fast.

If a scary notice arrived about your domain or website

Start over All scenarios

The your-site-has-problems email is a volume business: scanners find sites, software writes scary findings, and the sender profits when you panic. Real problems don't announce themselves by strangers' email. If something in it worries you anyway, verify it independently: this page's scenarios cover the real versions of most of those claims, and the checkers on this site read your site's actual state without an agenda.

Start over All scenarios

That one is a long-running scam shape. A registrar overseas claims someone is about to register your name across other countries, then offers to defend it for a fee. The pressure and the deadline are the product. If protecting the name in other regions ever matters to your business, that's a decision made calmly with your own registrar, never with a stranger's countdown.

Start over All scenarios

Some notices are real, most are marketing wearing a bill's clothes, and a few are outright scams. You don't need to guess which; you need two lookups and five minutes.

  1. Never act through the notice itself

    Don't pay through it, click its links, call its number, or sign and return anything. Every real renewal can be handled inside the account you already hold, which is the only place you should act.

  2. Check who you actually pay

    Your registrar and host are on your card statements, and in the record sheet if you've filled one. If the notice's sender isn't a company you already pay, it isn't a bill, whatever it looks like.

  3. Run the lookup and compare

    Search whois lookup, enter your domain, and read the real registrar and the real expiry date. Scam notices quote your true domain and sometimes your true expiry because those are public. The sender name failing to match your real registrar is the tell that ends the mystery.

  4. Read the fine print for the confession

    Misleading mailers often carry a quiet line like this is not a bill or this is a solicitation, because that sentence is what keeps them legal. Finding it settles the question. Keep the notice; showing it to whoever manages your domain takes ten seconds.

  5. If money already moved

    Call your card company about reversing it, then log into your registrar and confirm the domain is still yours, still locked against transfer, and renewed where it should be. If anything looks changed, your registrar's support handles it from there, and being the paying customer is the strong position.

Whatever the notice says, don't:

  • pay it to be safe. Paying the wrong company can move your domain instead of renewing it.
  • meet its deadline. Manufactured urgency is the product; real renewals give weeks of notice through the company you pay.
  • ignore every notice forever after. The occasional one is real, which is what the lookup is for.
  • feel dumb if one nearly got you. They're built by professionals and mailed by the thousand.

What to have ready

  • The notice itself, kept.
  • Your real registrar and host names, from statements or the lookup.
  • Your domain's real expiry date.

Tonight, or never

Almost never urgent. The lookup takes five minutes whenever you have coffee in hand. The one exception: if you already paid and something about the domain changed, treat it like the expired-domain scenario and move today.

A professional is worth it when you can't tell which companies are really yours, or when a paid notice was followed by real changes to the domain.

If a scary notice arrives

  1. Act only inside accounts you already hold. Never through the notice.
  2. Check the sender against who you actually pay.
  3. Whois lookup: real registrar, real expiry. Compare.
  4. Find the fine print: this is not a bill means exactly that.
  5. Already paid: card company first, then confirm the domain is locked and yours.

Don't: meet its deadline, call its number, feel dumb. They're built to work.

Have ready: the notice, your real provider names, the real expiry date.

Almost never urgent. Coffee first.

When the website breaks

Calm first steps, in order. The full guide with all the details lives at the address below.

  • Site down: check from cellular data, photograph the error, check domain expiry, then the host.
  • Hacked or defaced: photograph it, change the email password first, tell the host: compromised.
  • Domain expired: whois lookup, renew directly at the registrar today. This one has a real clock.
  • Email broken: test both directions, keep the bounce message, check webmail and the domain.
  • Developer vanished: don't go public. Inventory logins, follow card statements, recover as the payer.
  • Locked out: two tries, then the provider's recovery. Gather payment proof and documents.
  • Security warning: photograph the details. Certificate problems are routine host repairs.
  • Redirecting: record it, change passwords, tell the host both words: compromised and redirecting.
  • Google profile suspended: fix the tripwire, gather matching documents, appeal once, completely.
  • Scary notice: never act through it. Check who you really pay, run a whois lookup, find the fine print.

Universal rules: photograph before touching. Email password first. Never pay whoever contacted you first. Manufactured urgency is a tell.