Key takeaways
- Google warnings come from Safe Browsing and Search's hacked-site detection; they are removed by cleaning the site and requesting a review.
- The Security Issues report in Google Search Console tells you what Google found and lists sample URLs.
- Request a review only when the site is fully clean; a failed review delays recovery.
- Other blocklists such as Norton Safe Web, Microsoft SmartScreen and email blocklists may need separate requests.
- Fix the entry point and monitor, or the warning is likely to return.
How do you remove a Google blacklist warning?
To remove a Google blacklist warning, verify your site in Google Search Console, open the Security Issues report to see exactly what Google found, clean every trace of the malware, phishing or spam, fix the entry point, then click Request Review and explain what you did. Google lifts the warning once a review confirms the site is clean.
"Google blacklist" is the everyday name for two related systems. Google Safe Browsing protects Chrome, Firefox, Safari and other browsers, and shows full-page red warnings such as "Deceptive site ahead" or "The site ahead contains malware". Google Search separately labels some results "This site may be hacked" when it detects hacked content such as spam pages. Both are handled through Search Console.
| Warning | Where it appears | Usual cause |
|---|---|---|
| Deceptive site ahead | Browser, full-page red warning | Phishing pages or social engineering content |
| The site ahead contains malware | Browser, full-page red warning | Malicious downloads or code that attacks visitors |
| This site may be hacked | Google search results | SEO spam, injected pages or cloaked content |
| This site may harm your computer | Google search results | Malware detected on the site |
If you would rather hand the whole process over, our Google blacklist removal service cleans the infection and handles the review request for you.
How do you check the Security Issues report in Search Console?
To check the Security Issues report, sign in to Google Search Console, select your site property and open Security & Manual Actions, then Security issues. The report names each problem type, such as hacked content, malware or deceptive pages, and lists sample URLs where Google found it. If the site is not yet verified, verify it first.
- Verify ownership. Add a Domain property using a DNS TXT record so every subdomain and protocol is covered.
- Open the report. Go to Security & Manual Actions, then Security issues.
- Read each issue. Expand each one to see the issue type and sample affected URLs.
- Check Manual actions too. Spam problems can trigger a separate manual action that needs its own reconsideration request.
Tip: the sample URLs are only examples. If Google lists five spam pages, there may be thousands. Use them as clues to the type of infection, not as a complete list of what to clean.
You can also check any site's current status, without logging in, using the Google Safe Browsing site status tool in the Google Transparency Report. Our security triage takes two minutes and tells you what to do next.
What do you need to clean before requesting a review?
Before requesting a review, remove every piece of malicious content Google could find, not just the sample URLs: injected spam pages, redirects, phishing folders, malicious scripts in files and the database, and cloaking rules that show different content to Google. Close the entry point too, or the site will be re-infected around the review.
Many hacked-site infections use cloaking, so the spam only appears when Google's crawler visits. You can test this by fetching a page with Googlebot's user agent and comparing it to a normal request:
# Normal visitor
curl -s https://www.example.co.uk/ | grep -ci "viagra\|casino"
0
# Pretending to be Googlebot
curl -s -A "Mozilla/5.0 (compatible; Googlebot/2.1)" https://www.example.co.uk/ | grep -ci "viagra\|casino"
37
A difference like this points to cloaking code, often in .htaccess, index.php or a malicious plugin. Use the URL Inspection tool in Search Console to see a page as Google sees it once you think it is clean.
Check subdomains as well as the main site. Google's warning can be triggered by a forgotten staging subdomain, an old shop on a separate folder or a phishing kit uploaded to a directory nobody visits. A Domain property in Search Console covers all of them, so review every URL pattern the report mentions.
- Remove spam pages and generated sitemaps; see our SEO spam removal guide.
- Remove redirect code; see our redirect hack guide.
- Remove phishing folders, webshells and backdoors.
- Clean injected scripts from the database.
- Remove unknown Search Console users and owners, which attackers sometimes add.
- Patch the vulnerable component and rotate every credential.
Security triage
Is your site showing any of this?
Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.
How do you request a Google review?
To request a review, return to the Security issues report in Search Console, tick the box confirming you have fixed the issues, click Request Review and describe what you found, what you removed and how you prevented it happening again. Be specific. Google then re-checks the site and emails the result, and the warning is removed if it passes.
A good review request is short, factual and complete. For example:
The site was compromised through an outdated plugin. We removed injected spam pages and a malicious sitemap, deleted a webshell and an unauthorised admin account, replaced WordPress core and all plugins from official sources, removed a cloaking rule from .htaccess, updated all software, rotated every password and blocked PHP execution in uploads.
Avoid vague requests such as "the site is clean now, please remove the warning". They give the reviewer nothing to check against and are more likely to be rejected. Equally, do not claim fixes you have not made. If the review fails, Google will tell you, and the next request should explain what you found on the second pass.
After a successful review, use the Removals tool and an updated sitemap to help spam URLs drop out of search results faster. Spam pages you have deleted should return a 404 or 410 status so that Google understands they are gone for good.
Review times vary by issue type. According to Google's documentation, phishing reviews are often processed quickly, while malware and hacked content reviews can take several days. You will receive a message in Search Console with the outcome.
If a site is flagged repeatedly after reviews, Google may treat it as a repeat offender and stop accepting review requests for a period, which Google's help pages currently describe as 30 days. Make sure the site is genuinely clean before you ask.
What about other blocklists besides Google?
Other blocklists maintained by antivirus vendors, browsers and email services work independently of Google, so a clean Google status does not guarantee you are clear everywhere. Check the major ones after cleaning, and request removal from each that still lists you. Most have a free site owner form or a review process for rechecking a cleaned domain.
| Blocklist | Affects | How to request removal |
|---|---|---|
| Microsoft Defender SmartScreen | Edge and Windows users | Microsoft's site report / dispute form |
| Norton Safe Web | Norton users and browser extension | Norton Safe Web site owner re-evaluation |
| McAfee WebAdvisor | McAfee users | McAfee site reclassification request |
| Bing | Bing search results | Bing Webmaster Tools |
| Spamhaus and other email blocklists | Email delivery from your domain or IP | The blocklist's own lookup and removal page |
Most of these services recheck automatically over time, but a direct request is usually faster. Keep your explanation consistent with the one you gave Google, and keep a note of each request and its date so you can follow up if a listing persists. Some antivirus vendors only update their ratings after their own crawler revisits the site.
If your server was sending spam, fix that first, because email blocklists usually relist quickly. Your host may also have its own internal block that needs a support ticket.
How do you stop the warning coming back?
To stop the warning coming back, make sure the infection cannot return: close the entry point, remove every backdoor and scheduled task, harden the site, and monitor it continuously so any new problem is caught before Google finds it. Most repeat warnings happen because a hidden backdoor or a cron job was missed during the first clean-up.
- Scan the whole server, not just the flagged site. See why one hacked site infects the rest.
- Harden. Apply the controls in our WordPress hardening checklist.
- Monitor. Keep Search Console email alerts on and use continuous malware monitoring.
- Review regularly. Check administrator accounts, plugins and Search Console users each month.
PatientZero plans include unlimited malware removal, 24/7 monitoring and hardening from £99 a month per site, with no contract. If your site is flagged right now, start with our emergency help or call 01932 593642.
Frequently asked questions
How long does it take to remove a Google blacklist warning?
Once the site is fully clean and a review is requested, Google's documentation indicates phishing reviews are often quick while malware and hacked content reviews can take several days. The clean-up itself usually takes longer than the review, so the fastest route is a thorough clean-up first time.
Can I remove the warning without Search Console?
Not reliably. Google does recheck flagged sites over time, but the Security issues report and Request Review button in Search Console are the official route, and they show you what Google found. Verifying your site is free and takes only a few minutes.
Why was my review request rejected?
Usually because Google still found malicious content, often cloaked spam shown only to Googlebot, a redirect that fires only on mobile, or pages on a subdomain you did not check. Read the rejection message, inspect affected URLs as Googlebot, rescan the whole server and fix the entry point before trying again.
Will a blacklist warning damage my search rankings?
Warnings sharply reduce clicks while they are shown, and hacked spam pages can affect how Google sees your site. Rankings usually recover after a proper clean-up and successful review, although spam pages may take time to drop out of the index. Acting quickly limits the damage.