What Happens When Your Website Is Blacklisted? The Real Cost
About nine times in ten, a person who meets a browser security warning turns back. In Google's own Chrome data, users did not continue past 87% of malware warnings and 96% of phishing warnings (Reeder et al., CHI 2018). Chrome, Safari and Firefox show that warning when a domain is on Google Safe Browsing, the list that reaches the most visitors. The same listing can also stop your ads, put warnings on links to your site in email, and block the site on company networks and in antivirus products.
TL;DR: About nine in ten browser security warnings end with the person turning back: 87% of malware warnings and 96% of phishing warnings in Chrome. Across the published measurements we found, the share runs from 77% to 96%. The figures are from 2013 and 2015; we found nothing newer. A flag does not lower your Google ranking by itself, because Safe Browsing "isn't used as a ranking signal" (Google Search Central, 2021), but the hack behind the flag can. Google Ads disapproves ads that point to a compromised site, and mail filters, company firewalls and antivirus products block the domain from their own lists. Which of these costs you pay depends on which lists the domain is on, so check that first. Each list is lifted separately, usually only after the site is clean and someone asks for a review.
This is for the owner, or the agency looking after the owner, who has just learned the site is flagged and needs to know how bad it is. Every figure below links to its source. Where nobody has measured something, we say so.
How many visitors turn back at a browser security warning?
About nine in ten browser security warnings end with the person turning back. In Google's 2015 Chrome data, users did not click through 87% of malware warnings and 96% of phishing warnings. Across the published measurements we found, the share runs from 77% to 96%.
The Google figures come from a study of Chrome and Firefox users published at CHI 2018. It reports that in 2015 "Chrome users adhered to ... 87% of malware warnings, and 96% of phishing warnings." Adhered means the person did not continue to the site. Phishing warnings are the kind Chrome shows for a deceptive site. Those two figures cover all Chrome users. The study's own 5,041 Chrome volunteers turned back less often, from 76.9% of malware warnings and 79.9% of phishing warnings, and the paper notes that they "adhered at lower rates than the general Chrome population at the time."
An earlier study, which shares an author with the Google one, is larger. Akhawe and Felt counted 25,405,944 warning impressions of all kinds in Chrome and Firefox in May and June 2013. For the malware and phishing warnings among them, people clicked through 7.2% of Firefox's malware warnings and 23.2% of Chrome's, and through 9.1% and 18.0% of the phishing warnings (USENIX Security 2013). Put the other way round, between 77% and 93% turned back.
Google shows "more than 3 million user warnings for potential threats" every day (Google, 2024), and says Safe Browsing protects more than five billion devices (Google Safe Browsing). Chrome, Safari and Firefox all read Google's list (Apple; Mozilla). Microsoft Edge uses Microsoft Defender SmartScreen, which is Microsoft's own list.
In 2015, Chrome users turned back from 87% of malware warnings and 96% of phishing warnings, according to Google's field study published at CHI 2018. An earlier study of Chrome and Firefox (Akhawe and Felt, USENIX Security 2013) found that people turned back from 77% to 93% of malware and phishing warnings, depending on the browser and the type of warning.
What that number does not tell you
- It is old and desktop-only. The data is from 2013 and 2015. We found no newer published figure from Google, Mozilla or Microsoft, and none for phones.
- It counts warnings, not revenue. The figure is the share of warning views that did not continue. It does not say whether the person came back later.
- First-time visitors heed it most. A separate study of Chrome's malware warning, co-written by Google researchers, found that "users consistently heed warnings about websites that they have not visited before", while they "respond unpredictably to warnings about websites that they have previously visited" (Almuhimedi et al., SOUPS 2014). People arriving for the first time from an ad or a search result are the first kind.
- The warning can be bypassed. In Chrome it takes two clicks, Details and then "Visit this unsafe site", which Google's help page marks as not recommended. As the figures above show, most people do not take it.
Which of your visitors actually see a warning?
Which visitors are stopped depends on which list the domain is on. A Google Safe Browsing listing stops most browser users, while one antivirus vendor's listing stops only that vendor's customers. "Blacklisted" is not one list. Each row below is a separate list with its own owner and its own review process.
| Where the domain is listed | Who is stopped |
|---|---|
| Google Safe Browsing | Visitors using Chrome, Safari or Firefox, and people clicking links to your site in Gmail |
| Microsoft Defender SmartScreen | Visitors using Edge |
| One antivirus vendor's URL database | Only people who run that vendor's product |
| A web filter or protective DNS service (a DNS resolver that refuses to look up listed domains) | Everyone on a network or device that uses it |
| A domain blocklist used by mail filters | People receiving email that contains a link to your site |
A Safe Browsing listing is the expensive one, because it covers most browsers at once. A listing with a single antivirus vendor reaches a much smaller group, but you are unlikely to notice it yourself, because you probably do not run that product. You usually hear about it from a customer. Our guide on how to check if a domain is blacklisted covers how to find every listing, including the quiet ones.
Does a blacklist hurt your Google ranking?
A blacklist flag does not lower your Google ranking by itself. Google said in August 2021 that "Safe Browsing isn't used as a ranking signal" (Google Search Central, 2021), and we found nothing later that reverses it. The hack behind the flag can cost ranking. Three things get mixed together here:
- The flag puts a warning in front of people. It does not move your position.
- The hack behind the flag can. Google treats hacked content as a spam policy violation, and says that "sites that violate our policies may rank lower in results or not appear in results at all" (Google spam policies). Bing's guidelines say that sites that "participate in phishing, malware distribution, or other harmful activities risk demotion or removal", without separating out hacked sites (Bing Webmaster Guidelines).
- The label in results. Google can show "This site may be hacked" under your listing. The Security Issues report says affected pages "can appear with a warning label in search results or an interstitial warning page in the browser" (Search Console Help). An interstitial is the full-page warning shown before the site loads.
We found no published figure for how much a label in search results reduces clicks. You will see percentages quoted for it. We could not trace any of them to a source, so this guide does not give one.
Cleaning half the site does not get you half the way back. Google again: "Fixing the issue on just some pages will not earn you a partial return to search results."
What happens to your ads when your site is flagged?
Google Ads disapproves ads that lead to a hacked site, so they stop serving until the domain is cleared. The policy is named Compromised sites, and it lists "destinations that are hijacked and hacked" among the reasons for disapproval (Google Ads policy). The account itself gets some notice: "A warning will be issued at least 7 days prior to any suspension of your account." Google Merchant Center applies the same rule to Shopping listings.
The way back runs through Search Console, not through the ads account. Google tells advertisers to "file an appeal through Google Search Console to have the domain removed from the Safe Browsing threat list", after which landing pages "should automatically be re-enabled to serve ads". Our page on a Google Ads "Compromised site" disapproval walks through that order.
Microsoft Advertising is stricter on timing. It says it "will remove the offending ads immediately, without warning" when ads lead to malware or to malicious domains (Microsoft Advertising policies).
Does a blacklisted website affect your email?
A blacklisted website can hurt your email through the links in your messages. Mail filters check linked domains against domain blocklists, and Gmail warns on links that Safe Browsing considers dangerous. This is separate from a mail server's IP address landing on a spam blocklist, which our guide to email reputation versus website blocklisting covers.
Some blocklists track domains instead of senders. The Spamhaus Domain Blocklist includes "hijacked domains otherwise used for legitimate purposes", and mail servers use it by "looking up domains appearing in the mail headers and body e.g., URLs" (Spamhaus). SURBL lets filters act on "links in the message body, regardless of sender IP addresses" (SURBL). So a newsletter, an invoice or an order confirmation that links to your site can be rejected or sent to junk even when it leaves a clean server.
Mail that does arrive can still carry a warning. Google says Safe Browsing protects Gmail users "by identifying dangerous links in email messages and showing warnings" (Google Safe Browsing). In organisations that use Microsoft Defender for Office 365, Safe Links checks the address when the recipient clicks and shows a warning page if the site "has been identified as malicious". Whether the recipient can continue past it is up to their administrator (Microsoft).
One thing we could not confirm: whether Gmail uses link reputation to decide between inbox and spam. Google does not document it, so we do not claim it.
Who else blocks a flagged site without telling you?
Company firewalls, protective DNS services, antivirus web protection and social platforms can all block a flagged site, and you should not expect a notice from any of them.
- Company firewalls. Palo Alto Networks recommends that its customers block the category it describes as "benign or legitimate sites that have been hacked or infected" (Palo Alto Networks). Cloudflare's gateway has a Compromised Domain category, and Fortinet's FortiGuard has one called Malicious Websites. If you sell to businesses, the buyer may be behind one of these.
- Protective DNS. With 1.1.1.1 for Families, Cloudflare's free filtering DNS, "when a queried domain is classified as malicious, Cloudflare returns the address 0.0.0.0" (Cloudflare), so the site does not load at all.
- Antivirus web protection. Bitdefender: "Whenever you try to visit a website classified as unsafe, the website is blocked and a warning is displayed in your browser" (Bitdefender). Kaspersky's Web Anti-Virus watches for attempts to visit a phishing website and "blocks access to such websites" (Kaspersky). This happens whatever the browser itself thinks of the site.
- Social platforms. X may show "a warning notice when the link is clicked", or block the link "so that it can't be posted at all", and a warned link "will also have limited visibility" (X Help Center).
A request blocked by a firewall or a DNS filter never reaches your server. It leaves no trace in your analytics, which is why these losses are easy to miss.
How do you estimate what a flag costs you?
Multiply your normal daily visits by the share that meets a warning, the share that turns back, your conversion rate, your average order value and the number of days the listing lasts. The inputs:
- Normal daily visits, from your analytics for the weeks before the flag.
- The share that meets a warning. With a Safe Browsing listing, that is nearly everyone on Chrome, Safari and Firefox. With one antivirus vendor, it is only that vendor's users.
- The share that turns back: 77% to 96% of browser warnings, depending on the study. The example below uses 87%.
- Your conversion rate and average order value, and the number of days until the listing is lifted.
An illustration with made-up round numbers, not data: a shop with 400 visits a day, 2% of them buying, at €60 an order, takes about €480 a day. Assume every visitor meets a malware warning (in practice Edge users would not) and 87% turn back. That is 348 visits and roughly seven orders gone, about €418 a day. Over a one-week review that comes to about €2,900, before counting paused ads or email that never arrived.
If your analytics already shows the drop, use that figure instead.
How long does the damage last?
The damage usually lasts until the site is clean and each list has reviewed it again. A flag records what the domain served, not what is on the server today, and most listings stay until someone asks for a review. Some lift by themselves: Google says its warnings about uncommon downloads "are lifted automatically" once it verifies the files are safe (Search Console Help). Do not plan around that.
For Google, the request is made in Search Console, and Google's current wording on the wait is: "A review can take from a few days to a few weeks to complete" (Search Console Help). Every other vendor runs its own form or inbox on its own schedule. Our guide on how long blacklist removal takes goes through them.
Do not ask before the cleanup holds. Sites get hacked again: a Google and UC Berkeley study found "over 12% of sites falling victim to a new attack within 30 days" (Li et al., WWW 2016). A review that finds the infection still there fails, the flag stays, and you have spent the wait for nothing.
Google can also block reviews for 30 days for a site that keeps switching between compliant and harmful, which it calls a Repeat Offender (Google Search Central). When Google introduced the rule it said hacked websites are not classified this way, only sites that post harmful content on purpose (Google Security Blog, 2016). The current policy page does not repeat that exemption.
While the listing stands, hold back newsletters and paid campaigns that link to the site. They send people into the warning.
What should you do about it?
Clean the site first, then find every list you are on, then request Google's review in Search Console and ask every other vendor separately. Each step depends on the one before it.
- Clean the site and close the way in. Nothing else holds until this is done. Our guide to cleaning a hacked website covers it. If you believe the flag is a mistake, read why antivirus flags clean websites first.
- Find every list you are on. Our free blocklist check looks the domain up across security vendors and shows which ones flag it, with no signup. It is a reputation check, not a malware scan.
- Ask Google for a review yourself. That is the Security Issues report in Search Console, and there is no API for it. If Google's review finds the site clean, this is what removes the browser warning for most visitors and lets Google Ads serve again. Our Google Safe Browsing removal walkthrough has the clicks.
- Ask every other vendor separately. Each one has its own false-positive form or security inbox.
Step 4 is the gap unflagdomain.com fills. We send a removal request to each flagging vendor that accepts one by email for a one-time €39: plain text, written separately for each vendor, with your own address as Reply-To so the replies come to you. Our catalog covers 133 active vendors. 104 of them take requests by email; for the ones that only take a web form, and for Google Safe Browsing, you get a ready-to-paste request and a guided step on your dashboard. The limits, stated plainly: we do not scan for or remove malware, and we guarantee the dispatch, never the delisting, because each vendor decides on its own. If the re-scan after payment finds zero flags, the payment is refunded automatically.
The short version
About nine in ten browser security warnings end with the person turning back, and who meets a warning depends on which list the domain is on. The flag does not lower your ranking; the hack behind it can. Google Ads disapproves ads to a hacked site, links in email get filtered or warned about, and firewalls and antivirus products block the site where you cannot see it. Listings are usually lifted only after the site is clean and someone asks. Clean first, find out where you are listed, then ask.
If the domain is on Google Safe Browsing, Chrome, Safari and Firefox show a full-page warning before the site loads, and about nine times in ten the person turns back. Other lists, such as one antivirus vendor's, block only that vendor's users. The same listing can get Google Ads disapproved, put warnings on your links in email, and block the site on company networks. Each list is separate and is usually lifted only after the site is clean and a review is requested.
Most visitors who see it turn back. In Google's Chrome data from 2015, users turned back from 96% of phishing warnings and 87% of malware warnings (Reeder et al., CHI 2018). A 2013 study of Chrome and Firefox found people turned back from 77% to 93% of malware and phishing warnings. We found no newer published figures, and both studies cover desktop browsers only.
Not by itself. Google said in August 2021 that Safe Browsing isn't used as a ranking signal. What can cost ranking is the hack behind the warning: Google treats hacked content as a spam policy violation, and sites that violate its policies may rank lower or not appear at all. Google can also show a warning label under the result.
It can, through the links in your messages. Domain blocklists such as the Spamhaus DBL and SURBL list domains, including hacked legitimate ones, and mail filters check them against links in the message body whatever server sent it. Gmail also shows warnings on links that Safe Browsing considers dangerous. A mail server's IP landing on a spam blocklist is a separate problem.
Yes, if Google is the one flagging it. The Compromised sites policy disapproves ads whose destination is hacked, and Google warns at least seven days before suspending the account. Ads come back after the domain is removed from the Safe Browsing list through a Search Console review; Google says landing pages should then be re-enabled automatically. A listing with a single antivirus vendor does not by itself stop Google Ads.
Usually not. A listing records what the domain served, and most listings stay until someone asks for a review. Google's review is requested in Search Console and can take from a few days to a few weeks. Every other vendor has its own form or inbox, so a site flagged by several vendors needs several requests.