Requesting a review to remove security warnings

If Google has flagged your site as dangerous or deceptive, you must submit a review request before the warning will be lifted. Before you begin, confirm that you can use shell or terminal commands, and that you have completed the following cleanup steps:

  • Verified site ownership in Search Console.
  • Removed the hacker's vandalism.
  • Fixed the underlying vulnerability.
  • Restored the clean site to a live state.

Confirm your pages are clean

Use Wget or cURL to inspect your homepage and any URLs that were modified by the attacker. If those pages are clean and you are confident the rest of the site is too, you can proceed with the review request.

Submit the review through the correct channel

The review process depends on the type of issue you are facing. Do not submit a review before the problem is fully resolved; doing so only extends the time your site remains flagged.

Hacked site

If you received a notification in the Security Issues report in Search Console:

  1. Go to the Security Issues report and locate the issue, listed as a site-wide or partial match.
  2. Click Request a review. For each type of hacked spam, include a brief description of the cleanup steps you took (such as removing spam content and updating an outdated plugin).

Unwanted software (including malware)

If you received a malware or unwanted software notification in the Security Issues report in Search Console:

  1. Open the Security Issues report; the warnings and sample infected URLs may still be visible.
  2. Click Request a review and explain how the policy violation was addressed (for example, by removing third-party code that distributed malware and replacing it with an updated version).

If the notification came from your AdWords account rather than Search Console, request the review through the AdWords support center.

Phishing or social engineering

If you received a phishing notification in the Security Issues report in Search Console:

  1. Open the Security Issues report and the warnings or sample URLs may still appear.
  2. Click Request a review and describe what you removed (such as a page that asked users for personal information).
  3. You can also request a review at google.com/safebrowsing/report_error/. This tool reviews cleaned phishing pages and also covers incorrectly flagged pages.

Review processing times

Processing times vary based on the issue type:

  • Hacked with spam: Can take up to several weeks, due to manual investigation or full reprocessing of affected pages.
  • Malware: Typically a few days; results are delivered in Search Console's Messages.
  • Phishing: About a day. On approval, the user-visible warning is removed.

If your site is approved as clean, browser and search result warnings should disappear within 72 hours. If Google determines the issue remains, the Security Issues report may show additional sample infected URLs, and search and browser warnings will remain in place.

After your review is approved

Confirm that pages load correctly and links are functional. To prevent future incidents, follow the maintenance and security plan outlined in Clean and maintain your site.

If your review is rejected

Re-examine your site for malware or spam, and check for any new files or modifications left by the attacker. You can also reach out to specialists on your support team for further help.