VirusTotal False Positive: How to Report & Clear It

unflagdomain Team·UPDATED June 16, 2026

A VirusTotal false positive happens when one or more of the ~70 security engines that VirusTotal aggregates flags a clean website as malicious. VirusTotal is a scanner, not a blocklist authority — it doesn't delist anything itself. To clear the flag, you dispute it with each engine that reported it.

TL;DR: VirusTotal aggregates around 70 antivirus and URL-reputation engines. A "false positive" usually means just one or two of them flagged your clean site. Because VirusTotal only reports what those engines say, the fix is disputing the flag directly with each flagging vendor — not with VirusTotal.

If your site got flagged here, the panic is understandable. A red detection count next to your domain looks alarming to visitors, partners, and you. The good news: a low detection score is often a single engine being overzealous, and there's a clear path to fix it. Let's walk through what the flag actually means and how to report it.

check which vendors flag your site

What is a VirusTotal false positive?

A VirusTotal false positive is a detection where a security engine labels a clean URL as malicious, suspicious, or phishing. VirusTotal pools results from roughly 70 antivirus and URL-scanning engines (VirusTotal documentation, 2024). When you see "2/70," that means 2 engines flagged your site and 68 considered it clean.

The key thing to understand: VirusTotal doesn't make the verdict. It's an aggregator. Each engine — BitDefender, Kaspersky, Fortinet, Sophos, and dozens more — runs its own scan and reports its own opinion. VirusTotal just collects and displays those opinions side by side.

That distinction changes everything about how you fix it. There's no "VirusTotal delist button" because VirusTotal has nothing to delist. The flag lives in the engine's database, not in VirusTotal's.

VirusTotal aggregates results from roughly 70 independent antivirus and URL-reputation engines (VirusTotal documentation, 2024). A reported "false positive" reflects one or more of those engines flagging a clean site — VirusTotal itself stores no verdict and performs no delisting.

Website flag vs. flagged file — they're not the same

This article covers website and URL false positives only. If VirusTotal flagged a downloadable file — an .exe, an installer, a compiled binary — that's a different problem with a different process. File detections often involve code-signing, packers, and per-vendor file-submission portals. Everything below is about your domain or page being marked, not a file you distribute.

Why does VirusTotal flag a clean website?

Clean sites get flagged for reasons that have nothing to do with current malware. The most common trigger is a stale detection: your site was compromised, you cleaned it, but the engine still remembers the bad signature. A meaningful share of cleaned sites are already blocklisted by at least one authority at cleanup time (Sucuri Website Threat Report, 2024).

Other causes are surprisingly mundane. Shared hosting means a neighbor's hacked site can taint your IP's reputation. A sloppy ad network or third-party script can trip a heuristic. Aggressive obfuscated JavaScript — even legitimate minified code — sometimes looks suspicious to pattern-matching engines.

In our experience running unflag, the single most frequent cause we see is timing: the cleanup was done correctly, but no one told the flagging engines. We don't scan or clean sites ourselves — we trust your cleanup and clear the residual flags — and a stale flag will sit in an engine's database until someone actually files a review. Detections don't expire quickly on their own.

Hacked websites are common enough that automated cleanup tools process them at scale — Sucuri reported that a meaningful share of cleaned sites were already blocklisted by an authority at cleanup time (Sucuri Website Threat Report, 2024). Stale detections surviving after cleanup are a leading false-positive cause.

Clean first, dispute second

Before you report anything, make sure the site is genuinely clean. Reporting a false positive on a site that's still infected wastes everyone's time and can get your dispute ignored. Scan your files, check for injected scripts, review recent uploads, and confirm there are no unexpected redirects.

confirm your site is actually clean before disputing

This matters because the engines often re-scan when you submit. If they find live malware, your report gets rejected and your credibility takes a hit. Clean thoroughly, then dispute.

How do you report a VirusTotal false positive?

You report a VirusTotal false positive by disputing it with each engine that flagged you — not with VirusTotal. Click the detection count on your VirusTotal report to expand the engine list, note exactly which engines show a red verdict, then submit a false-positive request to each one through its own portal or contact channel.

VirusTotal's role ends at telling you who flagged you. From there, the work is per-vendor. Here's the practical sequence we recommend.

Step 1: Identify every flagging engine

Open your domain's VirusTotal report and click the detection ratio. You'll see the full engine list with each one's verdict — "clean," "malicious," "phishing," or "suspicious." Write down only the ones with a non-clean verdict. Those are your targets.

Don't guess. A "3/70" needs exactly three disputes, aimed at the right three engines. Disputing the wrong vendor does nothing.

Step 2: Submit a false-positive report to each engine

Each engine has its own way in. Most major vendors run a false-positive or "report incorrect detection" form. You'll typically provide your URL, a short explanation that the site is clean (and was cleaned, if it was hacked), and sometimes contact details so they can follow up.

Here's what most guides miss: the engines that feed VirusTotal are the same blocklist authorities that flag your site elsewhere. So a single Fortinet or Sophos dispute can clear your detection on VirusTotal and improve your standing in browsers and email filters that license the same data. One well-aimed report can fix multiple visible problems at once. It's exactly why, when we scan a domain across our catalog of 124 active security vendors at unflag, we treat each flagging vendor as its own target — the overlap between VirusTotal's engines and the wider web blocklists is real, and clearing one upstream source often ripples outward.

see per-vendor removal steps for each engine

Step 3: Wait, then re-scan

After submitting, give each vendor time to review. Turnaround varies widely — some respond in a day, others take a week or more. Once they update, request a fresh VirusTotal scan (the "reanalyze" option) so the report reflects the cleared verdict instead of a cached one.

VirusTotal performs no delisting of its own; clearing a detection requires disputing with the specific engine that reported it, then requesting a re-analysis so VirusTotal refreshes its cached verdict (VirusTotal documentation, 2024). Response times are set entirely by each individual vendor.

How long does it take to clear a VirusTotal flag?

There's no fixed timeline — each engine decides on its own schedule, and VirusTotal can't speed it up. Some vendors process false-positive reviews within 24 to 72 hours; others take a week or longer. Browser-facing blocklists tend to move faster than niche antivirus engines, but every vendor controls its own review queue.

A few things genuinely speed things up. A clean re-scan at submission time helps. A clear, specific message — naming the cleanup and the date — helps. Submitting to the right engine helps most of all.

What doesn't help: resubmitting the same request repeatedly. That can push you to the back of the queue or get you flagged as spammy. Submit once, well, and wait.

What if multiple engines flagged you?

When several engines flag your domain, you'll be running parallel disputes — each on its own timeline. That's where a single false positive becomes a small project. Disputing five engines means five forms, five formats, five follow-up windows, and tracking which ones have cleared.

This is exactly the tedious, repetitive part where a tool helps. unflagdomain generates a tailored removal request for each flagging vendor — varied so they don't read as identical spam — and dispatches them sequentially over a randomized window of roughly an hour, with your own email set as Reply-To so any vendor reply lands straight in your inbox. Vendors that only accept web forms or a manual review (Google Safe Browsing among them) become guided dashboard cards instead, since there's no email path for those. You clean the site; it handles the per-vendor outreach and shows real sent, bounced, and failed counts per vendor, re-dispatching on a bounce. To be clear about what's promised: it guarantees the requests go out, not that any vendor delists. The vendors always decide.

Does VirusTotal include Google Safe Browsing?

VirusTotal does surface Google Safe Browsing as one of its engines, but Safe Browsing is the one flag VirusTotal can never help you clear automatically. Google Safe Browsing protects billions of devices (Google Safe Browsing, 2024), and its review is a manual process you complete yourself.

If Safe Browsing is among your flagging engines, you have to verify your site in Google Search Console, open the Security Issues report, and request a review there by hand. There is no API, no automation, and no third party can submit it for you. You copy your explanation into Search Console and click request review yourself.

This trips people up constantly: they assume clearing the "70 engines" clears Google too. It doesn't. Safe Browsing sits in its own lane, and the manual Search Console review is the only path. It's the one vendor we can never email on your behalf at unflag — there's no submission API — so we surface it as a guided dashboard card with the explanation text ready to paste, rather than a dispatched request. Treat it as a separate task from your other VirusTotal disputes, because it is one.

Conclusion

A VirusTotal false positive feels worse than it usually is. Most are a single engine remembering an old problem you've already fixed. Because VirusTotal only aggregates around 70 engines' opinions and stores no verdict of its own, the fix is always the same shape: identify each flagging engine, confirm your site is clean, and dispute with that vendor directly.

Work through the engines one at a time, request a re-scan after each clears, and handle Google Safe Browsing separately through Search Console. If you're staring at several flags at once, that's where the repetitive outreach gets painful — and where automating the dispatch saves real time.

start by checking exactly who flags your domain

// FAQ
  • A false positive itself won't infect your site, but it harms your reputation. Browsers, email filters, and ad networks that license engine data may warn visitors or block your domain. Even a single engine flagging you can hurt traffic and trust, so it's worth clearing promptly.

  • No. VirusTotal aggregates roughly 70 engines and stores no verdict of its own, so there's nothing for it to delist. You report the false positive to each engine that flagged you through its own portal, then request a VirusTotal re-analysis to refresh the cached result.

  • VirusTotal caches the last verdict each engine gave. Cleaning your site doesn't notify those engines automatically — stale detections can linger for weeks. You must dispute with each flagging engine, then click reanalyze so VirusTotal pulls fresh verdicts instead of showing the old cached ones.

  • There's no official threshold, but even 1 of about 70 engines is worth disputing because licensed data spreads it. A higher count signals a more serious or recent issue. Either way, confirm your site is genuinely clean first, then report to each flagging engine individually.

  • No. Google Safe Browsing protects billions of devices and runs its own manual review. You must verify your site in Google Search Console and request a review there by hand. There's no API and no automation — it stays a separate task from your other VirusTotal engine disputes.