Guide SSL & Security

How to clear a Google "deceptive site" warning

Cleaning the site is only step one. The warning stays until you request a review and Google confirms the site is genuinely clear.

Updated 7 min read Intermediate

A full-page red warning telling visitors a site is dangerous or deceptive is one of the more alarming things a site owner can encounter, and it is worth understanding upfront that fixing the underlying problem is only half the job. The warning itself does not disappear on its own — it stays until you have actively requested a review and it has been confirmed clear.

This is a different warning to a certificate error

It is worth being clear about which warning you are actually dealing with, because the fix is completely different. A certificate problem — covered in how to fix "Your connection is not private" — is about the encryption on the connection itself and is resolved entirely on your side, often within minutes, once the certificate issue is corrected. A "deceptive site" or "the site ahead contains malware" warning is a judgement made by a third-party safe browsing service about the content of the site, based on a scan it ran independently, and clearing it requires that same service to actively confirm the problem is gone — your side of the fix is necessary but not sufficient on its own.

Find out exactly what triggered it

Warnings of this kind are generated for a specific, identifiable reason: malware found on the site, content matching known phishing or deceptive patterns, or unwanted software being distributed through it. Google Search Console, once you have verified ownership of the site, shows the specific reason and, where available, examples of the affected pages. Working from the actual reason given is far more efficient than assuming and cleaning the wrong thing.

Verify the site in Search Console if you have not already

You need to prove ownership of the domain before Search Console shows you the specific details or lets you submit a review request. If this is not already set up, do it as an early step rather than leaving it until you are ready to request the review.

Clean the site completely, not just the flagged page

A warning triggered by one page does not mean the compromise is limited to that page. Work through scanning your site for malware across the whole site, and follow what to do first if your website is hacked for containing and cleaning the compromise properly, including finding and closing whatever allowed it in the first place. A review requested against a site that is only partially cleaned risks being rejected, and a rejected review is slower overall than taking the time to be thorough the first time.

Closing the cause matters as much as removing the content

If the vulnerability that allowed the original compromise is still open, cleaning the visible content without fixing it can result in the site being reinfected and reflagged shortly after the warning is lifted.

Request a review

Once you are genuinely confident the site is clean — not just the flagged page, the entire site — submit a review request through Google Search Console. You will typically be asked to describe what happened and what you did to resolve it. Being specific and accurate here is worth more than being brief; a vague description gives the reviewer less to confirm your fix against.

While you wait

There is no fixed timeframe for a review, and it is not something you can meaningfully speed up beyond making sure the initial submission is accurate and complete. During this period, the warning will typically still show to visitors arriving through Chrome and other browsers using the same Safe Browsing data, and search results may still carry a warning label as well, so expect reduced traffic during the review window regardless of how quickly you cleaned the site.

If the warning reappears after being cleared

A warning that comes back after a successful review almost always means the original vulnerability was not actually closed, rather than a new, unrelated compromise. Go back through how to tell whether your website has been hacked and treat this as reason to look harder at the cause specifically, not just repeat the same cleaning process and request another review.

Preventing it happening again

Once the warning is cleared, the priorities are the same ones that would have prevented it in the first place: keep every piece of software on the site updated, use strong unique passwords with two-factor authentication where available, take regular backups so a future compromise can be resolved by restoring rather than manually cleaning under pressure, and set correct file permissions so a single compromised script has as little reach as possible. Each of those is covered in its own guide elsewhere in this section.

Frequently asked questions

Will fixing the site remove the warning automatically?

No. Cleaning the site stops it being dangerous, but the warning itself is only lifted once you have requested a review and Google has confirmed the site is clear. The two steps are separate, and skipping the review request leaves the warning in place indefinitely even on a genuinely fixed site.

How long does the review take?

It varies and there is no fixed guaranteed timeframe. Submitting a review request before the site is genuinely and completely clean is the most common reason a review is rejected, which then requires resubmitting and waiting again — so it is worth the extra time upfront to be thorough before requesting one.

Related reading