Malware
Doorway page
Doorway page is a thin page built to rank for a search phrase and then push the visitor somewhere else. It has no real content of its own, only a route to the page the owner actually wants seen.
How it is measured
Spot them by pattern. Many near-identical pages that differ only in a city or product name, little original text, and an immediate redirect, meta refresh, or big link to a different domain. Crawl the site and cluster pages by text similarity and by outbound destination.
In Search Console, look at which URLs get impressions that you never wrote. A directory of thousands of URLs under `/wp-content/uploads/` or `/cache/` is a typical hosting spot for hacked doorways.
Worked example
A plumber's WordPress site gets a message from Google about thin content. Browsing `/areas/` shows 4,200 pages such as `/areas/emergency-plumber-springfield.html`, each with 60 words and a redirect to a lead-selling site. The plumber never made any of them.
They were generated by a script dropped in the theme folder. Deleting the folder, removing the script, and filing a reconsideration request clears the warning in about two weeks.
How it differs
A doorway page is the bait in the search results. Cloaking is the technique of showing crawlers different content from people, which doorways often use together. A doorway can be honest about its redirect and still violate search rules. SEO spam is the wider category of hacked-site abuse that also includes injected links in existing posts.
Common errors
Dismissing them as a search problem, when the files sit on your server. Deleting the pages but not the generator that makes new ones. Blocking them in robots.txt, which hides them from your own review. Missing them because they never appear in your sitemap. Checking only the homepage.
In practice
Run a site: search for your domain with words like "cheap", "replica", or "casino". Review the newest files on the server by modification date, remove the generator, and request removal of the dead URLs in Search Console.