Thank you for the information.
That sucks. Unfortunately, the Drupal site was too infected to clean up after wasting days on it trying to. I still don't know where the security flaw was. It had gotten briefly compromised a month prior and had my developer clean it up and run security patches I had neglected. I guess this failed, because it was attacked again. This is really what caused me to just scrap the whole thing and move on. So I had to pull the plug and moved to WP and even changed hosting. Interestingly enough, I have no security alerts in Google Search Console. However, Google has blocked my domain from being mentioned in emails...so it kicks back all of my emails as non-deliverable. My domain and IP are all clear on the online tools to check for spam alerts and MX records, including Google servers. I had one report from SpamHaus, but it was easily removed. Even the Google Safe Browsing scan in the Transparency Project comes back as the site being clean.
My email runs through GSuite and they pre-emptively block my emails from going out if it contains my domain name. If it doesn't contain a link to my site, it goes through fine. I actually got a hold of someone earlier since I have paid GSuite, and they checked some stuff but he said it's just up to the mercy of the Gmail filter one day seeing it as legit again. Of course no time frame was mentioned. It's a local service business, but 98% of sales are from organic Google traffic. I can't even run Adwords traffic at this rate if Google is going to block my emails.
I have thousands of 404 errors in Search Console from the hack, but no security alerts so I can't try to submit anything for a manual review. I'm almost finished building out the new site and have been using same urls, descriptions, etc. for the best hope in something getting corrected. As soon as that is done I will submit the sitemap and wait and see. Not much else I can do.