Avast Flagging Your Site as Phishing? How to Fix It

unflagdomain Team·UPDATED July 28, 2026

If Avast is blocking your website with a phishing or "URL:Phishing" warning, it usually means Avast's web shield put your domain on its threat list — sometimes by mistake. The page is still online; visitors using Avast or AVG are just being stopped at the door. You fix it by submitting a false-positive dispute, then waiting for Avast to re-check.

TL;DR: An Avast URL phishing false positive is a wrong reputation call by Avast's web shield, which protects more than 435 million users worldwide (Gen Digital). Your site isn't deleted — it's labelled. The fix: submit a false-positive report to Avast, confirm the block clears, and check whether other security vendors flagged you too.

This guide is for website owners, not file downloads. If Avast flagged a program or EXE you downloaded, that's a different (out-of-scope) issue. Here we cover the website/URL case: your domain showing a phishing or malware warning to anyone running Avast or AVG. It's common, it's fixable, and you don't need to be technical to handle it.

Why is Avast flagging my website as phishing?

Avast flags a website when its URL reputation system decides the domain matches a known phishing, scam, or malware pattern — and it shares one engine with AVG, since both are owned by Gen Digital. Avast says it blocked over 1.5 billion malware attacks in a single quarter (Avast Threat Labs, 2024), so the system errs toward caution, and clean sites sometimes get caught.

A few things commonly trigger an Avast block on a legitimate site:

  • A brand-new domain or fresh redesign. Sites with no track record look suspicious to reputation engines, which favour established history.
  • A login or payment form that resembles phishing layouts — Avast's heuristics watch for password and card fields on unfamiliar domains.
  • A real hack you can't see. Injected phishing pages or redirect scripts on an outdated plugin can be genuine — your homepage looks fine while the scanner found something underneath.
  • Shared hosting or a "bad neighbourhood" IP. If another site on your server was malicious, your domain can inherit the reputation hit.
  • A flat-out mistake. Automated classifiers misjudge clean sites, and that's exactly what a false positive is.

Because Avast and AVG run the same threat database, a single false positive usually blocks your site in both products at once — so a successful dispute clears two of your visitors' antivirus tools, not one. In our experience scanning domains across our catalog of active security vendors, people often report Avast and AVG as separate problems when they're really one shared flag. AVG also happens to be a form-only vendor: it accepts submissions through a web form rather than email, so we surface it as a guided dashboard card rather than auto-emailing it.

free blocklist check

Avast's web shield assigns every URL a reputation score and blocks domains it classifies as phishing or malware. With more than 435 million users on the Gen Digital network (Gen Digital), one wrong classification can stop a large share of your traffic — which is why prompt disputes matter for clean sites.

Is it a real threat or a false positive?

Before you dispute anything, confirm whether your site is actually clean — because requesting a false-positive review while a hack is still live just gets you re-flagged. A meaningful share of the sites Sucuri scans turn out to carry an active infection (Sucuri, 2023), so "it's definitely a false positive" deserves a quick check first.

Quick ways to tell

  • Check what Avast is actually claiming. The block screen names a category — phishing, malware, or deceptive content. That tells you what its scanner thinks it saw.
  • Scan your own files. Use your host's malware tools or a reputable security plugin to look for injected pages, unfamiliar admin users, and odd redirects.
  • See who else is flagging you. If several vendors block your domain at once, that points to a real problem rather than one engine's bad guess. You can check your domain against the major blocklists for free to see the full picture in one place.

In our experience running unflag, the giveaway for a true false positive is when only Avast/AVG flags the site while the rest of the engines stay clean. We scan each domain across more than 120 active security vendors — dozens of antivirus engines, the major web blocklists, and a handful of RBL and search-engine sources — so a lone Avast flag against an otherwise clean board is a strong signal. When a hack is real, the flags tend to cluster: several vendors light up together rather than one engine acting alone.

Confirming a clean site before disputing is essential: Sucuri's research found that a meaningful share of scanned websites carried an active infection (Sucuri, 2023). If you submit a false-positive report while injected content is still live, Avast re-scans, finds it again, and the block stays in place.

How do I submit a false positive dispute to Avast?

You report an Avast URL false positive through Avast's dedicated false-positive form, where you enter the blocked URL and explain that your site is clean. Avast then re-evaluates the domain. There's no instant "remove" button — like most reputation systems, it re-checks on its own schedule, typically within a few days.

Step 1 — Make sure the site is genuinely clean

If the flag came from a hack, remove the injected files, redirects, and unknown admin accounts first, then change passwords and update your plugins, themes, and core software. Outdated software is the most common entry point — known vulnerabilities account for the majority of compromises in vulnerability research (Patchstack, 2024). Skip this and you'll be back here next week.

Step 2 — Submit the report to Avast

Go to Avast's official File/Website Whitelisting or false-positive submission form, enter your full domain, and select the website/URL category (not the file-detection one). Add a short, factual note: confirm the site is clean, mention any cleanup you did, and avoid marketing language. AVG users share the same submission path because of the shared engine.

Step 3 — Confirm the block has lifted

After Avast re-evaluates, test your site in a browser running Avast or AVG. Reputation databases also cache locally, so it can take a little while for every user's copy to update even after the central record changes. If the warning lingers for days past Avast's response, re-test on a fresh device before assuming it failed.

vendor-by-vendor removal guide

The official route for an Avast URL phishing false positive is Avast's website-whitelisting form, where owners submit the blocked domain for re-evaluation. Avast processes these reviews on its own timeline — usually a few days — and no third party can override that decision or guarantee a specific outcome.

What if Avast isn't the only vendor blocking me?

If multiple security vendors flag your domain at the same time, you'll need to dispute each one separately — there's no shared "clear me everywhere" button across the industry. This is common: a single hack or a shared-IP reputation hit often trips several engines together, and each runs its own independent review process.

Each vendor has its own front door

Avast and AVG share a form. But Google Safe Browsing, Microsoft SmartScreen, McAfee, Norton, and the dozens of smaller blocklists each have their own submission process, format, and timeline. One of the biggest is Google Safe Browsing, which protects billions of devices (Google) and clears flags only through a manual review you request inside Google Search Console — there's no API and no automation for it.

Doing it by hand vs. done-for-you

Chasing every vendor form individually is slow and easy to get wrong. Once your site is genuinely clean, you can have unflagdomain email every flagging vendor a removal request in one pass, with your own address as the reply-to so responses come straight to your inbox. To be clear about what that does and doesn't cover:

  • We don't scan or clean your site. You handle the cleanup first; we trust your description of what was fixed.
  • We guarantee dispatch, not delisting. Every vendor makes its own call on its own timeline — nobody can promise a removal.
  • Manual-only vendors stay manual. For Google Safe Browsing, we generate the text and guide you, but you submit it yourself in Search Console — that step can't be automated.

If you'd rather work through the disputes yourself, our step-by-step vendor blacklist removal guide walks through the major engines one at a time.

When several engines flag a site at once, each requires its own dispute — there's no industry-wide clearance. Google Safe Browsing alone guards billions of devices (Google) and only lifts a flag through a manual Search Console review, which no service can automate or rush on your behalf.

How long does it take for Avast to remove the flag?

After you submit a clean, accurate false-positive report, Avast typically re-evaluates and lifts the block within a few days, though it sets its own pace and complex cases run longer. The single biggest delay isn't Avast being slow — it's owners disputing while injected content is still live, which restarts the whole cycle.

A clear, factual submission that names exactly what you cleaned tends to move faster than a vague one. And don't expect the warning to clear by itself: reputation systems generally need an explicit report before they re-check, so doing nothing usually means the block — and the lost traffic behind it — simply stays. Phishing keeps climbing too; the APWG logged over 1 million phishing attacks in a single quarter (APWG, 2024), which is part of why engines like Avast stay aggressive and clean sites occasionally get caught in the net.

If you want to confirm the block is truly gone across the board, you can run a free blocklist check on your domain and follow the full removal path vendor by vendor if anything else is still flagging you.

// FAQ
  • Avast's web shield scores every URL for reputation and blocks domains matching phishing patterns. Clean sites get caught when they're brand-new, use login or payment forms, sit on a shared IP with a bad neighbour, or simply get misclassified. That's a false positive — your site is labelled, not deleted, and a dispute clears it.

  • Submit your blocked domain through Avast's official website-whitelisting or false-positive form, choosing the URL/website category rather than the file-detection one. Add a short, factual note confirming the site is clean. Because Avast and AVG share one threat engine, a single accepted report clears the block in both products at once.

  • Avast usually re-evaluates a clean, accurate false-positive report within a few days, though it sets its own timeline and complex cases take longer. Local reputation caches can also lag behind the central record. The biggest delay is disputing while a real hack is still live, which restarts the review cycle.

  • No. A website or URL block comes from Avast's reputation system rating your domain as phishing or malware, and you dispute it through the website-whitelisting form. A flagged file or EXE is a separate detection with its own submission path. This guide covers the website case only, not downloaded programs.

  • No. Avast and AVG are both owned by Gen Digital and share the same URL threat database, so one false-positive report covers both. Other vendors are separate, though — Google Safe Browsing, Microsoft SmartScreen, McAfee, and Norton each run their own independent review process with its own form and timeline.