A client's site loads, but shows the wrong page
No error, no spinning, no warning. The address answers, and what comes back is not the client's website. Here is the order we would work in.
1. What are you looking at?
- A page of ads, or the registrar's logo, with the domain name in large letters. The domain has probably expired, or its nameservers were changed, and the registrar is showing its own parking page. See what to do when a domain stops working, step 3.
- "Welcome to nginx!", "It works!", "Apache2 Default Page" or a hosting company's "coming soon" page. A web server is answering, but not with this site. Usually DNS points at a new or wrong server, or the site's configuration on the server was lost or replaced.
- "Account suspended", or a page about bandwidth or billing from the host. The host has switched the site off. Look for an email from them.
- "Index of /" and a list of files. The site's home page file is missing, so the server lists the folder instead. Something was deleted, or an upload did not finish.
- A blank white page. Often the site's code failed and the error is hidden from visitors. Many of those answer 500, but not all. See what to do about a server error, which says where the error is written down.
- Someone else's content: spam, a pharmacy, a casino, or a redirect to another site. The site may have been hacked. Some hacks only show to visitors arriving from a search engine, or only on phones, so the owner sees a normal site.
- An old version of the site. A cache, a CDN or the client's browser is serving a saved copy. Try a private window. If the live site behind it is broken, the saved copy can hide that for a while.
2. Is it wrong for everyone, or just for you?
Ask the server directly for a phrase that is always on the real site, such as the client's business name, and count the lines of the page it appears on. The first part reads only the top 256 KB of the page, the same amount a monitor like ours reads:
curl -sSL https://example.com | head -c 262144 | grep -ci "Acme Plumbing"On Windows, use curl.exe -sSL https://example.com | find /i /c "Acme Plumbing". It reads the whole page, so if the phrase is only near the bottom of a very long page, pick one nearer the top. Then try the site on your phone with Wi-Fi turned off.
- 0, and the phone shows the wrong page too. It is wrong for everyone. Go to step 3.
- 0, but the site looks right in a browser. The phrase may be added by a script after the page loads, so it is not in what the server sends. Try another phrase: text from the footer, or a phone number.
- More than 0 from curl, wrong on your screen. Your own browser, network or DNS has an old or wrong answer. Clear the cache, or wait for a DNS change to reach you.
3. The usual causes
- The domain lapsed. Renew it at the registrar. Check the nameservers afterwards, because some registrars leave the parking page in place until you change them back.
- DNS points at the wrong server. Common after a move to a new host, or when an old server is switched off and its address given to someone else. Compare the address in the domain's A record with the one the host says the site is on.
- The host lost or replaced the site's settings. A new server, a control panel change or an expired plan can leave the address answering with the server's default page. The host can put it back.
- A hack. Change every password with access to the site, including the hosting and FTP accounts, restore from a backup taken before it started, and update everything. Ask the host for help; many will scan for you.
4. Check the fix
Run the command from step 2 again. It should print a number above 0. Then check from your phone on mobile data, and in a private window, so you know the fix reaches everyone and not only your own computer.
5. Tell the client what happened
They may have seen the wrong page themselves, or a customer may have told them. For example:
For a while the website address was showing a page that was not yours, because the domain renewal did not go through. I have renewed it and checked your site is showing normally again.
6. Next time, hear about it first
A check that only asks whether the site answered calls every page above Online, because each of them answers 200. Bionic Uptime can also check what the page says. When you add the website, turn on Also check what the page says, choose Must say, and type a phrase that is always on the client's real page, such as their business name. Do not use the domain name: a parking page shows it too. Once it is saved, the website's Edit page has a button to test the phrase.
We look for the phrase in the HTML the server sends, in the first 256 KB, ignoring capitals. We do not run the page's scripts, so pick a phrase that step 2 finds. A missing phrase is treated like any other failed check: when both of our locations, on two different companies' networks, and a retry agree within 45 seconds, while both locations are known to be working, it is confirmed and each person on that website's alert list gets one email. It says the site answered, so you do not go looking for a server that is fine: “Both checking locations loaded the page (HTTP 200), but it did not contain "Acme Plumbing".”
What it cannot see: a hack that leaves the client's page in place and adds something to it, or one shown only to visitors from a search engine. The phrase is still there, so the check passes. For a page that answers 200 with a known error message, choose Must not say and type the message instead.
3 websites are free, forever, with no card. Looking after several client sites?