My Online Store Is Blocked — Emergency Guide for Shop Owners
If your online store is suddenly blocked, take a breath: your site, products, and orders are still there. A security vendor — usually Google Safe Browsing — has flagged your domain, so browsers warn shoppers away before the page loads. The fix is to clean the site, then request a review with each vendor that flagged you.
TL;DR: A blocked store means a security vendor put your domain on a blocklist, not that your site is gone. Google Safe Browsing alone protects billions of devices (Google), so one flag can stop nearly all your traffic. Clean the issue first, then request a re-check — there's no instant unblock button, and no vendor guarantees how fast they'll clear you.
You probably found this page because sales dropped to zero in an hour and you don't know why. That's the worst part — the silence. This guide is the emergency triage: what to check first, why it happened, and the fastest legitimate path back to taking orders. No jargon, no panic.
My online store is blocked — what's actually happening?
Your store isn't down; it's been flagged. A security vendor added your domain to a blocklist, so browsers like Chrome show a red full-page warning instead of your shop. The site, your product data, and customer orders are untouched — visitors are just being intercepted and warned away until the flag clears.
This matters because the warning is built to scare people, and it works. When a blocking interstitial appears, a large share of shoppers bail instantly — abandonment is commonly reported around 45% or higher (Guardio, 2025). For a store, that's most of your revenue paused, not lost forever.
Here's what trips up most shop owners: a blocked store and a down store feel identical from the customer's seat, but they're opposite problems. A down site is a hosting or DNS fault you fix on your server. A blocked site is clean on your server but labeled "dangerous" by an outside vendor — you fix it by changing the vendor's mind, not your hosting. Confusing the two wastes your first, most valuable hour.
If you're not sure which one you're facing, our plain-language walkthrough on what to do when your website is flagged as dangerous helps you tell them apart fast.
[IMAGE: A laptop showing a red full-page browser security warning over an e-commerce storefront — search terms: "browser security warning ecommerce"]
How do I know if my store is flagged and not just down?
Check what your visitors see in a regular browser first. A flagged store shows a colored full-page warning — "Deceptive site ahead" or "This site may harm your computer" — but the page is still reachable. A down store shows a connection error, blank page, or hosting message. The warning means a flag; the error means a server problem.
Run two quick checks before you touch anything. Open your store in an incognito window on your phone's mobile data, then run your domain through a free blocklist checker to see which security vendors have flagged you. Most flags trace back to Google Safe Browsing, which guards Chrome, Safari, Firefox, Android, and Gmail.
The 5-minute triage checklist
In our experience running unflag, the calmest recoveries follow the same order — and they all start by knowing exactly who flagged you, since we routinely see a single store flagged across multiple vendors at once. Do these in sequence, not all at once.
- Confirm the warning. Visit your store in incognito. Screenshot the exact warning text — you'll need the wording later.
- Identify the vendor. Run a blocklist scan to list every security service flagging you, not just Google.
- Check Google Search Console. If it's a Google flag, the Security Issues tab names the problem.
- Tell your shoppers. Post on social or email your list: "We're aware of a security flag and fixing it." Honesty protects your reputation.
- Don't request a review yet. Reviewing a still-dirty site just gets you re-flagged.
If your warning specifically reads "Deceptive site ahead," we've written a dedicated fix for that exact screen: the "deceptive site ahead" removal guide.
Why did my online store get flagged as unsafe?
Stores get flagged when a vendor detects content matching a harm category — most often a hidden hack you can't see from the front end. Google flags sites primarily for social engineering like phishing and deceptive pages, per Google Search Central. Your homepage can look perfect while injected malware sits underneath.
E-commerce platforms are a frequent target because they handle payments. WordPress and WooCommerce stores are especially exposed — WordPress powers around 43% of all websites (W3Techs, 2026), so attackers automate attacks against its plugins at scale. Sucuri's cleanup data found that the vast majority of infected CMS sites it remediated were running on WordPress, with outdated plugins a leading entry point (Sucuri).
The trigger is usually one of four things, and not all are your fault:
- A silent hack. Attackers inject phishing pages, spam, or redirect scripts through an outdated plugin or weak password. The scanner finds the hidden content; you never saw it.
- A malicious third-party script. A compromised payment widget, ad, or chat tool loading dangerous code.
- Deceptive content the vendor reads as social engineering — fake login forms or misleading buttons.
- A false positive. A clean store flagged by mistake — a new domain, an aggressive script, or a bad automated guess.
Shopify store flagged as unsafe — is that different?
A Shopify store flagged as unsafe usually points to your custom domain or third-party apps, not Shopify's core servers. Because Shopify hosts the platform, the malware-injection risk is lower than self-hosted WordPress — but installed apps, custom theme code, and redirect scripts can still trigger a flag. Check your installed apps and recent theme edits first.
In our experience running unflag, the flagged stores we scan tend to split into two buckets: self-hosted stores (WordPress, Magento) most often flagged for an actual injected hack, and hosted-platform stores (Shopify, Squarespace) more often flagged for a sketchy third-party script or an outright false positive. Because we scan each domain across 124 active security vendors — 78 antivirus engines, 38 web blocklists, and 6 RBL/search-engine sources — we can see at a glance how widely a flag has spread before deciding where requests need to go. Knowing your bucket points you at the right fix faster.
How do I unblock my store and get sales back?
You unblock a store in two stages: make it genuinely clean, then ask each vendor to re-check it. Requesting a review before the problem is gone just re-flags you, because the vendor re-scans and finds the same issue. There's no button that skips the cleanup, and no service can promise a vendor will clear you on any timeline.
Step 1 — Clean the store (or confirm a false positive)
Find and remove what triggered the flag before anything else. If you suspect a hack, scan your store with a reputable malware tool, update every plugin and app, rotate all passwords, and remove any injected files or scripts. If you're confident the site is clean and it's a website false positive — not a flagged file or EXE download, which is a separate issue — document why so you can explain it in your review request.
To be clear: cleaning is your job or your developer's. Removal tools like ours don't scan or clean malware — we handle the next step, contacting the vendors, only after your store is actually clean.
Step 2 — Request review with every vendor that flagged you
Once the store is clean, ask each vendor to re-check it. For Google, this means requesting a review inside Google Search Console — it's a manual process with no API and no automation, so you submit the request and wait for Google's re-scan. Other vendors each have their own email or form-based request process, which is where multi-vendor flags get tedious.
This is the slow, frustrating part. A store can be flagged by several vendors at once, and each one needs its own correctly-worded request sent to the right place. Removing your website from blocklists the manual way means tracking down contact addresses, writing a clear non-spammy message per vendor, and following up. Miss one vendor and a chunk of shoppers still hit a warning.
Step 3 — Verify and reopen
After requests go out, monitor for clearance and keep your store locked down. Re-run a blocklist check every day or two to watch flags drop off one by one. Keep plugins and apps updated, keep strong passwords, and consider a firewall — re-infection is common when the original entry point isn't closed.
How long until my store is unblocked?
There's no fixed clearance time, and anyone promising a guaranteed deadline is guessing. Each vendor re-scans on its own schedule after you request a review — Google's Safe Browsing reviews typically resolve within a few days of a successful request, but this varies and isn't guaranteed. Your fastest lever is sending a clean, correct request to every vendor the first time.
In our experience running unflag, the single biggest delay isn't vendor speed — it's owners requesting review while the site is still dirty, getting silently re-flagged, and losing days before they realize the cleanup was incomplete. That's why we don't dispatch anything until you've cleaned the store; we trust your cleanup and clear the residual blocklist flags, rather than scanning or cleaning the site ourselves. Confirm the store is genuinely clean before you send a single review request. One clean submission beats three premature ones.
A quick reassurance on the things that actually keep you up at night: your customer data, past orders, and product catalog are not deleted by a flag. The block sits on your domain's reputation, not your database. Once vendors clear the flag, your store returns exactly as it was — same products, same orders, same checkout.
Can a tool send the removal requests for me?
Yes — a removal service can generate and dispatch the per-vendor requests once your store is clean, but no tool can guarantee delisting because the decision always sits with each vendor. What a service saves you is the manual grind: finding each vendor's contact channel, writing a unique non-spam message, and dispatching to all of them so no flag gets missed.
This is the gap our €39 pay-once tool fills. After you've cleaned your store, unflagdomain re-scans your domain, generates a unique removal request per flagging vendor — varied so they don't read as identical spam — and dispatches them sequentially over a randomized window of about an hour, with your email as the reply address so vendor replies go straight to you. Vendors that only accept web forms (like AVG or ESET) or manual review become guided dashboard cards instead of emails. For Google Safe Browsing, you still submit the review manually in Search Console, because that step has no API; we give you the guided steps and the text to paste. Throughout, the dashboard shows real sent, bounced, and failed counts per vendor, and we re-dispatch on a bounce.
What we never claim: that we'll get you delisted, or by when. We guarantee the requests go out, correctly worded, to every vendor — the vendors decide the rest. That honesty matters when your sales are on the line.
No. A blocklist flag labels your domain's reputation — it doesn't touch your database, orders, products, or customer accounts. Browsers simply warn shoppers away at the door. Once vendors clear the flag, your store returns exactly as it was, with every past order and product intact.
Most flags come from a hidden hack — injected phishing pages or malware through an outdated plugin or weak password. Google flags sites mainly for social engineering, per [Google Search Central](https://developers.google.com/search/docs/monitor-debug/security/social-engineering). Occasionally it's a false positive on a clean site. Either way, your visible storefront can look perfectly normal.
A Shopify store flagged as unsafe usually points to your custom domain, an installed third-party app, or custom theme code — not Shopify's core servers. Because Shopify hosts the platform, deep malware injection is rarer than on self-hosted WordPress. Check recent app installs and theme edits first, then scan for redirect scripts.
There's no guaranteed time. After you clean the store and request review in Google Search Console, Safe Browsing reviews often resolve within a few days, but this varies. The biggest delay is requesting review before the site is genuinely clean, which silently re-flags you and costs days.
No tool can automate Google Safe Browsing review — it's a manual submission in Search Console with no API, and no service can guarantee delisting. A [removal tool](/remove-website-from-blacklist) can generate and dispatch correctly-worded requests to other flagging vendors once your store is clean, saving you the manual contact grind.