Guide

Remove a Google blacklist warning

A red warning screen in front of your site stops traffic almost immediately. It is a symptom, and it will not lift until the cause is gone — so the order of work matters.

A red warning screen in front of your website, or “This site may be hacked” beneath your listing, is Google Safe Browsing telling visitors not to trust you. Traffic stops almost immediately. The warning is a symptom, and it will not lift until the cause is gone — so the order of work matters.

First, work out which warning you have

  • “The site ahead contains malware.” Google believes your site serves or installs malicious software.
  • “Deceptive site ahead.” Usually phishing — a page impersonating somebody else to harvest credentials.
  • “This site may be hacked.” A label under your search listing rather than a full interstitial. Typically injected spam pages.
  • “Contains unwanted software.” Misleading downloads or bundled installers.

Google Search Console is where the detail lives. Under Security Issues it will name the category and often list example URLs — which is the fastest lead you will get on where the infection is. If you have never verified your domain in Search Console, do that first.

Do not request a review yet

A review request on a site that is still infected gets rejected, and repeated rejected requests slow down the ones that follow. Clean first, verify, then ask once.

Step one: clean the site properly

Removing the specific URLs Google listed is rarely enough — those are examples, not an inventory. A cleanup that survives review means finding the entry point, removing every backdoor and rogue administrator, repairing damaged files, and closing whatever was used to get in. Our full sequence is in emergency malware removal, and the WordPress specifics are in WordPress malware removal.

If the flagged site shares a server with others, check all of them. Getting one site delisted while its neighbour is still compromised tends to be temporary.

Step two: verify from the outside

Check the way the crawler sees you, not the way you see yourself:

  • Use the URL Inspection tool in Search Console on the example URLs and fetch them live
  • Search site:yourdomain.com and look for injected pages still in the index
  • Load the site in a private window, on mobile data, arriving from a search result — redirect malware is often conditional
  • Check the Safe Browsing status of your domain directly

Step three: request the review

  1. Open Security Issues in Search Console
  2. Confirm you have fixed every issue listed
  3. Select Request review
  4. Describe what you actually did — the entry point you found, what you removed, what you hardened. A specific, factual description is more convincing than "we removed the malware"
  5. Submit once and wait

Malware reviews are typically processed within a few days; deceptive-content reviews are often quicker. Google does not publish guaranteed times, so treat any specific promise you read elsewhere with suspicion.

If the review fails

A rejection almost always means something is still there — commonly a second backdoor, an injection in the database rather than the files, a conditional redirect that only fires for some visitors, or another site on the same server. Go back to investigation rather than resubmitting.

Recovering afterwards

  • Get injected pages out of the index. Return 404 or 410 for them so they drop out naturally; use removals for anything urgent.
  • Check your domain and IP against mail blocklists if the compromise was sending spam.
  • Expect a ranking dip. Recovery is usually gradual rather than immediate once the warning is lifted.
  • Keep monitoring. Being flagged twice is considerably more damaging than being flagged once.

Flagged right now? We clean it, harden it, and help you get the warning lifted.

Related guides

Unlimited malware removal, for one monthly price.

We clean websites and VPS servers as often as it happens, monitor them 24/7, and harden them so it doesn't happen again.

Book a demo