Request a review  |  Articles  |  web.dev Skip to main content Resources Web Platform Dive into the web platform, at your pace. HTML CSS JavaScript User experience Learn how to build better user experiences. Performance Accessibility Identity Learn Get up to speed on web development. Learn HTML Learn CSS Learn JavaScript Learn AI Learn Performance Learn Accessibility More courses Additional resources Explore content collections, patterns, and more. AI and the web Explore PageSpeed Insights Patterns Podcasts & shows Developer Newsletter About web.dev Discover Baseline How to use Baseline Blog Case Studies / English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어 Sign in Articles AI and the web Fast load times Learn Core Web Vitals Identity Progressive Web Apps Payments Notifications How to optimize INP Network reliability React Animations Mini apps Media Safe and secure WebAssembly Devices Easily discoverable Test automation Angular Resources More AI and the web Fast load times Learn Core Web Vitals Identity Progressive Web Apps Payments Notifications How to optimize INP Network reliability React Animations Mini apps Media Safe and secure WebAssembly Devices Easily discoverable Test automation Angular Discover Baseline How to use Baseline Blog Case Studies Understand security basics Security should not be so scary! What are security attacks? Understanding "same-site" and "same-origin" Security headers quick reference Secure connections with HTTPS Why HTTPS matters Enabling HTTPS on your servers What is mixed content? Fixing mixed content When to use HTTPS for local development How to use HTTPS for local development Prevent info leaks Browser sandbox Same-origin policy Cross-Origin Resource Sharing (CORS) Making your website "cross-origin isolated" using COOP and COEP Why you need "cross-origin isolated" for powerful features Protect your resources from web attacks with Fetch Metadata Protect websites from XSS Prevent DOM-based cross-site scripting vulnerabilities with Trusted Types Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP) Securely hosting user data in modern web applications Protect users from tracking Understanding cookies SameSite cookies explained SameSite cookie recipes First-party cookie recipes Referer and Referrer-Policy best practices User-agent client hints Schemeful Same-Site Monitor security violations and deprecations Reporting API Migrate to Reporting API v1 Network Error Logging (NEL) Help! I've been hacked Help, I think I've been hacked How do I know if my site was hacked? Top ways sites get hacked by spammers Build a support team Quarantine your site Use Search Console Assess spam damage Fix the Japanese Keyword hack Fix the gibberish hack Fix the cloaked keywords and links hack Hacked with malware Identify the vulnerability Clean and maintain your site Request a review Glossary for hacked sites FAQ for hacked sites Web Platform HTML CSS JavaScript User experience Performance Accessibility Identity Learn Learn HTML Learn CSS Learn JavaScript Learn AI Learn Performance Learn Accessibility More courses Additional resources AI and the web Explore PageSpeed Insights Patterns Podcasts & shows Developer Newsletter About web.dev Home Articles Resources Safe and secure Request a review Stay organized with collections Save and categorize content based on your preferences. You must request a review from Google to have your page or site unflagged as dangerous or possibly deceptive to users. You'll need the following: Knowledge of shell or terminal commands What you'll do 1. Prerequisites Before requesting a review, confirm that you've taken the following steps: Verified ownership of your site in Search Console Cleaned your site of the hacker's vandalism Corrected the vulnerability Brought your clean site back online 2. Double-check that your pages are available and clean To be safe, use either Wget or cURL to view pages on your site, such as your homepage and a URL modified by the hacker. These pages should now be clean. If they are, and you're confident that the rest of the pages on your site are also clean, it's time to request a review. Note: Your pages must be available to be crawled by Googlebot to ensure that they're clean. Make sure they're not roboted out or blocked from indexing by noindex robots META tags or directives. 3. Request a review Before requesting a review: Be sure that the problem is truly fixed; requesting a review if the problem still exists will only prolong the period of time that your site is flagged as dangerous. Double-check where you should request a review; the review process will take place in a specific tool, depending on the issue your site is facing. Refer to the following channels: A. Hacked site If you received a hacked site notification in the Security Issues report in the Search Console: Now that you have gone through the successive steps of the clean-up process, return to the Security Issues report report and find the issue either as a site-wide match, or as a partial match. Select Request a review. To submit a review, we recommend that you provide more information on what you did to clean your site. For each category of hacked spam, include a brief explanation of how the site was cleaned (for example, "For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin."). B. Unwanted software (including malware) If you received a malware or unwanted software notification in the Security Issues report in the Search Console: Open the Security Issues report again in the Search Console. The report might still show the warnings and sample infected URLs you saw before. Select Request a review. To submit a review, we recommend that you provide more information on what you did to remove the policy violation from your site. For example, "I removed the 3rd-party code that was distributing malware on my website and replaced it with an updated version of the code". If you didn't receive a malware or unwanted software notification in the Security Issues report in the Search Console, but you received a notification in your AdWords account, instead request a review through the AdWords support center. C. Phishing or Social Engineering If you received a phishing notification in the Security Issues report in the Search Console: Open the Security Issues report again in the Search Console. The report might still show the warnings and sample infected URLs you saw before. Select Request a review. To submit a review, we ask you to provide more information on what you did to remove the policy violation from your site. For example, "I removed the page that was asking users to enter personal information". You can also request a review at google.com/safebrowsing/report_error/. In addition to serving as a reporting tool for site owners who believe their page was incorrectly flagged for phishing, this report will trigger a review of phishing pages that have been cleaned to lift warnings. 4. Wait for the review to be processed Hacked with spam review process time: Reviews for sites hacked with spam can require up to several weeks to process. This is because spam reviews can involve manual investigation or a complete reprocessing of the hacked pages. If the review is approved, Security Issues will no longer display hacked category types or example hacked URLs. Malware review processing time: Reviews for sites infected with malware require a few days to process. Once the review is completed, the response will be available in your Messages in the Search Console. Phishing review processing time: Phishing reviews take about a day to process. If successful, the user-visible phishing warning will be removed and your page can surface in search results. If Google finds that your site is clean, warnings from browsers and search results will be removed within 72 hours. If Google determines that you haven't fixed the problem, the Security Issues report might display more sample infected URLs to assist your next investigation. Malware, phishing or hacked with spam site warnings will remain in search results and browsers as a caution to protect users. Final steps If your request was approved Verify that your site works as expected, that pages load properly and links are clickable. To keep your site safe, we encourage all site owners to implement the maintenance and security plan created in Clean and maintain your site. If your request was not approved {not-approved} Reassess your site for malware or spam, or for any modifications or new files created by the hacker. You can also request more help from specialists on your support team. Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates. Last updated 2015-01-01 UTC. [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2015-01-01 UTC."],[],[]] web.dev web.dev We want to help you build beautiful, accessible, fast, and secure websites that work cross-browser, and for all of your users. This site is our home for content to help you on that journey, written by members of the Chrome team, and external experts. Contribute File a bug See open issues Related Content Chrome for Developers Chromium updates Case studies Podcasts & shows Follow @ChromiumDev on X YouTube Chrome for Developers on LinkedIn RSS Terms Privacy Manage cookies English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어