Reputation
Google Safe Browsing: how it flags sites and how to clear yours.
Published 2026-05-15 · Last updated 2026-05-15 · Vantyris editorial
Every time a Chrome user clicks a link, the browser quietly checks it against Google Safe Browsing. Firefox and Safari check against the same list. If your domain ends up on it, browsers put a full-screen warning in front of your content and search results carry the line 'This site may harm your computer'. Gmail starts dropping your transactional emails into spam as well. The list is global and authoritative. Getting off it is straightforward once you know the steps.
What this means for your business
- Safe Browsing flags three classes of site: malware (drive-by downloads or hosted malware), phishing (impersonating another brand to steal credentials), and unwanted software (deceptive installers, browser hijackers). Most small-business listings are accidental. Typically a CMS plugin gets compromised and starts serving malware to one visitor in a thousand.
- Listing typically happens hours or days after the compromise. Google's crawlers visit your site as a real browser would. If any page on any subdomain matches a malware or phishing pattern, the entire root domain can be flagged.
- Cleaning up doesn't take your domain off the list. Google has to re-crawl and verify it, which typically takes 24-72 hours after you submit a review request. Without a review request, the listing can persist for weeks.
How to fix
Use the Security Issues report in Google Search Console to see what was flagged, fix the underlying compromise, then submit a review request. Re-crawl and clearance typically take 24-72 hours.
- Confirm the listing in the Safe Browsing diagnostic. Open transparencyreport.google.com/safe-browsing/search?url=yourdomain.com to confirm your domain is flagged and see what was detected (malware, phishing, unwanted software). If you don't have a Search Console property yet, add one and verify your domain first.
- Read Search Console's Security Issues report. Search Console → Security & Manual Actions → Security Issues. It lists the specific URLs Google flagged and the threat type. This is your work list.
- Find and fix the underlying compromise. If it's malware, scan your CMS database for injected JavaScript or PHP, and look in plugin files for recent modifications. The usual entry points are outdated plugins, weak admin passwords and exposed admin URLs. If it's phishing, check whether your site is hosting attacker pages (a hacker may have uploaded a fake login page to a subdirectory). If it's unwanted software, check what your site is offering as downloads.
- Verify the fix is complete. Use sucuri.net/scanner or virustotal.com to confirm the URLs no longer return malicious content. If they still do, go back to the previous step.
- Submit a review request. Search Console → Security Issues → Request Review. Explain what you found and fixed, and how you've prevented it happening again (updated plugins, rotated passwords, added a WAF, etc.). Be honest. Reviewers see through hand-waving.
- Wait for re-crawl. Typically 24-72 hours. You'll get an email when the listing clears, and the browser warnings disappear within minutes of that.
Owner: Your web host's support team or your developer for the cleanup. You submit the review request from Search Console. · Time: 2-8 hours to clean up + 1-3 days to clear the listing.
Common gotchas
- Don't submit a review request before the underlying issue is fixed. Reviewers re-scan. If they still find malware, your listing is extended and Google may rate-limit your future review requests.
- If you can't find the compromise, the problem may sit at your DNS or hosting layer (for example, a subdomain you didn't know existed is serving malware). Vantyris's attack-surface scan finds forgotten subdomains through Certificate Transparency logs.
- Once you've cleared the listing, make a repeat harder: keep CMS + plugins on auto-update, rotate admin passwords, enable MFA on the hosting account, and restrict the admin URL by IP if you can.
- Repeat listings are weighted heavily. A second listing in the same year extends review times and may damage your domain reputation for longer.
How to verify the fix
Run a Vantyris verified scan. The Reputation category shows Safe Browsing as healthy once you're cleared. Or check transparencyreport.google.com/safe-browsing/search directly.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
- A3. Security update management: software stays in vendor support, and high or critical patches go on within 14 days.
- A5. Malware protection: internet-facing devices protected against malicious code.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Can a competitor get my domain flagged maliciously?
Mostly no. Safe Browsing relies on Google's own crawlers detecting actual malicious content. A competitor can't trigger a flag on their own. They can submit reports that influence prioritisation if your site really does have an issue.
Does Safe Browsing only check the homepage?
No. Google crawls every reachable URL on your domain (and your subdomains). A compromised /wp-content/plugins/old-plugin/exploit.php is enough to flag the entire root domain.
Will Safe Browsing affect my email deliverability?
Indirectly, yes. Gmail and other major providers cross-reference Safe Browsing for inbound mail with your domain in the body or signature. Listed domains see deliverability drop quickly.
What's the difference between Safe Browsing and Spamhaus?
Safe Browsing focuses on web-based threats (malware, phishing, unwanted downloads). Spamhaus and similar RBLs focus on email-sending behaviour (sending spam, hosting spam-payload URLs). Vantyris's Reputation category checks both, because they catch different real-world failures.
References
- Google Safe Browsing transparency report Vendor
- Google: malware and unwanted software Vendor
- NCSC: handling a website compromise NCSC
Related explainers
- DNS-based blocklists: the silent reason your emails land in spam.
- What is DMARC, and why every business with a domain needs one.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris