ShieldWave

All articles

Google says your site is dangerous: what to do, step by step

A red warning screen in the browser or a hacked label in Google results. Where they come from, how to confirm in Search Console, clean up and request a review.

Radek, ENSOMEDIAPublished 5 min readPo polsku

It usually starts with a message from a customer: "I tried to open your website, but my browser wouldn't let me in." Or you search for your business name and notice a line under your address that was never there before.

It is an unpleasant moment, but there is an orderly way out of it. The warning is not a penalty. It is a signal that Google found something on your site that could harm visitors. Below is how to find out exactly what it found, how to clean up, and how to ask for the warning to be removed.

What your customers see

The warnings come in two forms.

The first is a red screen in the browser that covers the whole page. In Chrome the heading reads something like "Deceptive site ahead" or "Dangerous site", depending on the browser version and the kind of problem. Firefox and Safari use the same Google Safe Browsing list, so their users see a warning too, just worded differently.

The second is a line under your result in Google Search, such as "This site may be hacked" or "This site may harm your computer". The page still opens, but few people will click on it.

The red screen is even stronger, because to get past it a visitor has to open the details and deliberately ignore the warning. If you run Google Ads, ads pointing to a flagged site may be paused as well.

Where the warning comes from

Google checks websites regularly for several kinds of problems. On small business sites it is usually one of these:

  • someone broke in and uploaded a fake bank login or parcel payment page into a hidden folder, which is phishing,
  • code was added to the site's files that redirects visitors elsewhere or pushes a download at them,
  • hundreds of spam pages about casinos, pharmacy or in Japanese appeared on the site,
  • the site loads a script or widget from another domain that has been flagged itself.

In every one of these cases the owner usually notices nothing. Attackers often show the spam only to Google's crawler or to people arriving from search results. You visit your site directly, logged in as an administrator, so it looks the same as always.

Step 1: confirm the problem in Search Console

The most reliable source is Google Search Console. If your site is not set up there yet, ask whoever manages your domain to verify it. The simplest way is a TXT record in DNS, which takes a few minutes to add, and then a short wait for it to take effect.

In Search Console, open the Security issues report. It shows the type of problem, such as hacked content, malware or social engineering, along with example addresses where Google found it. They are examples, not a complete list.

If you do not have access yet, you can check your domain straight away in the Safe Browsing site status tool in Google's Transparency Report. It shows whether the domain is flagged and why.

Also open the example addresses from the report in a private window, once on a computer and once on a phone, because some malicious redirects only fire on mobile devices. Then search Google for site:yourdomain.com, scroll through the results and click a few. You are looking for pages you do not recognise and redirects that should not be there.

Step 2: clean up before you ask for a review

This is a job for your developer or a company that specialises in cleaning infected sites. Google's own help even suggests taking a hacked site offline temporarily. Tell your hosting company straight away too, as many of them run their own scanners and can help.

A proper clean-up looks roughly like this:

  1. Someone saves a copy of the current, infected state, so it is possible to work out what happened.
  2. They find the way in: an outdated plugin, a stolen password, a forgotten admin account. Without this step the problem comes back within days.
  3. They remove the malicious files and injected code, or restore the site from a clean backup made before the infection, and then update it immediately, because the old backup has the same hole.
  4. They change every password: admin panel, hosting, FTP, database and email accounts. They remove any accounts nobody recognises.
  5. They check the whole site, not just the addresses in the report. Google expects all issues to be fixed on all pages.

If your site holds customer data and you cannot rule out that someone took it, remember GDPR and its 72-hour deadline. I covered that in a separate article.

Step 3: request a review

Once everything is clean, go back to the Security issues report and select Request Review. Google asks you to describe what was done. Be specific, for example:

The cause was an outdated contact form plugin. We removed the injected code from the theme files and deleted all spam pages, updated WordPress and every plugin, changed all passwords and removed an unknown administrator account.

You will get an email when Google receives the request and another when the review is complete. Do not send more requests while one is pending. If Google still finds something, it rejects the request and tells you where to look. You fix it and ask again.

How long it takes

I have to be honest here: nobody can tell you. Google's help says a review can take from a few days to a few weeks, and I do not know of any way to speed it up, apart from cleaning up thoroughly the first time. Even after a positive decision, browser warnings and search labels do not disappear in the same minute.

In the meantime, send your regular customers a short note saying you know about the problem and are fixing it. Do not ask them to click through the warning, though. Until Google confirms the site is clean, you cannot be sure it is safe for them.

Then make sure you do not go through this twice. Check that Search Console notifications reach an inbox you actually read, because next time Google will write there before your customers do. Agree regular updates with your developer, delete plugins you do not use, switch on two-factor login and keep backups off the server. These are the same things that close the most common ways in.