// META ADS · LANDING PAGE REJECTIONS

Meta rejected the ad. Check the domain.

unflagdomain Team·UPDATED September 26, 2026
// ANSWER

Meta's Advertising Standards require a landing page to match the ad and forbid linking to malicious code such as malware or spyware. Meta doesn't publish which security signals it uses, so when a clean creative is rejected over the landing page, the fastest way to rule the domain in or out is a blocklist scan. If vendors list it: clean the site, request the Safe Browsing review in Search Console, send removal requests to the other vendors the same day, then use the one review request Meta gives you per ad. Meta says it aims to decide within 48 hours.

The rejection points at the landing page or the destination, not at the image or the text. Ads to a different domain from the same account run fine. Maybe visitors from the ad see a red Chrome warning before they see your page. Two minutes tells you whether the domain is the reason.

Free, 133 vendors, no signup. Empty list: the domain is ruled out. Not empty: you know what to clear before you spend the review.

Meta landing page rejection at a glance
What Meta requiresThe landing page matches what the ad promotes, loads, triggers no automatic download, and doesn't link to malware or spyware (Advertising Standards, Cybersecurity).
What Meta says about security signalsNothing. No outside feed is named in the ad standards or the community standards. A flagged domain is a plausible cause, not a documented one.
What needs no documentationIf Google Safe Browsing lists the domain, Chrome shows a full-page warning to every visitor who clicks the ad, whatever Meta decides.
The reviewInitial review typically within 24 hours. One review request per ad; Meta aims to decide within 48 hours. A second rejection closes review for that ad.
What 39 buysA separately written removal request to every flagging vendor that takes one, sent within 48 hours, in practice within the hour. It does not speed up Meta's review.

// sources: Meta Advertising Standards · Cybersecurity standard · How to troubleshoot a rejected ad

// IS IT THE DOMAIN?

Meta removed more than 159 million scam ads in 2025 and says 92% came down before anyone reported them. Review is automated first and fast, and an automated system judging a destination leans on reputation signals it doesn't explain. So you test instead of guess. The domain is your first suspect when the rejection names the landing page or the destination rather than the creative; when every ad to this domain is rejected and ads to another domain pass; when opening the page in Chrome shows “Deceptive site ahead” or “The site ahead contains malware”; when the site was hacked or a plugin with a known vulnerability was exploited; and when the scan above lists one or more vendors.

Before any of that, check the three things Meta actually states: the page loads, it matches what the ad promises, and it starts no download. If one of those fails, fix it first. It's cheaper than everything below and it's Meta's written rule.

// AD ACCOUNT DISABLED OR RESTRICTED: IS YOUR DOMAIN THE CAUSE?

Usually not. A rejected ad is about one ad and its destination. A disabled or restricted ad account is about the account's behaviour and history, and Meta handles it in Account Quality as a separate case. A flagged domain is a likely contributor only when individual ads were rejected for the landing page before the restriction arrived. If that's your sequence, the scan is worth two minutes. If the account went first, this page won't get it back, and we'd rather say so than sell you a scan.

// THE ORDER THAT WORKS

Meta gives you one review request per ad. Everything else comes before it. Steps 2 and 3 run in parallel.

  1. 01

    Clean the site.

    Remove injected code, close the entry point, update the exploited plugin or theme, rotate passwords and keys. Every vendor re-scans when it reviews a request, so a live infection keeps the flag. We don't do this step and we don't verify it.

  2. 02

    Request the Google Safe Browsing review in Search Console, today.

    This one counts twice for a Meta campaign: it may feed whatever Meta checks, and it definitely feeds the Chrome warning every ad click runs into. Security & Manual Actions → Security issues, describe per issue what was found and removed, request review once. Google's own pages give a range from about 24 hours to a few weeks.

  3. 03

    Send the other removal requests the same day, in parallel.

    In our data the median flagged domain carries 11 listings, mostly URL-reputation engines that browsers, corporate filters and ad systems consume. Each has its own channel and its own wording, and the Search Console review touches none of them. This is the step we do for €39.

  4. 04

    Fix the landing page basics, then spend your one review request.

    Confirm the page loads, matches what the ad promises, and triggers no download. Then Business Support Home → select the account → select the ads → Request review → Submit. Meta says it aims to decide within 48 hours, and that a second rejection closes review for that ad. Request it after steps 1 to 3, not before.

// step 2 in detail: the Search Console review, step by step · step 1: cleaning a hacked website

// STEP 3, IN FIFTEEN MINUTES INSTEAD OF AN AFTERNOON

After you pay 39, once, for this domain: we re-scan it, cache ignored, and send a separately written plain-text removal request to every vendor that takes one by email, within 48 hours and in practice within the hour, with your address as Reply-To. Form-only vendors become dashboard cards with the text prepared. Google Safe Browsing becomes one too, with the exact text for Search Console; we never submit it for you. Replies go to your inbox, not ours.

It does not speed up Meta's review. It does not clean malware. It guarantees the dispatch, not the outcome. If the scan we run right after payment finds no vendor flagging your domain, we refund the full 39 automatically. No subscription, no account.

// free scan · payment only if vendors flag you and there are requests to send

pricing · refund policy · the 133 vendors and how each is contacted

// ONE DISPATCH, READ DAY BY DAY
Readings after one dispatch
Day 012 vendors flagging. Payment, re-scan, 12 separately written requests sent over one hour.
Day 38 of 12 vendors no longer returned the domain.
Day 7Still 8 of 12. The same eight.
Day 15All 12 cleared. VirusTotal's last analysis was dated day 15, so that is the latest day by which every vendor had cleared.

One dispatch is one dispatch: a case, not a rate. It was a false-positive flag on a site that had never been hacked, which is not the situation most people arrive here in. Vendors re-scan when they review, so a hacked site has to be clean before any of this moves. The customer's own account of that order, in his words:

“ESET flagged our client's website even though it had never been hacked. I wasn't sure whether I could trust an online service with this, but I decided to give it a try. Two weeks later, all 12 vendors that had flagged the site, including ESET, had cleared it.”

— Ervin, owner of a digital marketing agency, Hungary, dispatched August 2026

// full readings: the case study · in our September 2026 data the median flagged domain carried 11 listings, Google's among them: the report, vendor by vendor

// FAQ
  • Meta doesn't document its landing-page checks, so nobody can promise that, including us. Delisting removes the most likely external reason, and clearing Safe Browsing removes the Chrome warning your visitors see. Then you request review once in Account Quality; Meta says it aims to decide within 48 hours. The €39 dispatch does not speed up Meta's review.

  • Not documented. Meta's Advertising Standards and its Cybersecurity and Spam community standards name no outside feed. Treat a listing on those services as a signal that other systems will judge the domain the same way, and as worth removing whatever Meta reads.

  • Usually not. A disabled or restricted ad account is about account behaviour and history, and Meta handles it in Account Quality as its own case. A flagged domain is a likely contributor only when individual ads were rejected for the landing page before the restriction. This page is about a rejected ad; it won't get an account back.

  • Meta says a second rejection closes review for that ad. Fix the cause fully, which usually means cleaning, the Search Console review and vendor delisting, then create a new ad to the same destination once the domain is clear. Don't recreate the ad while the domain is still listed.

  • Yes. Listings attach to the domain name, not to its owner, so a domain hacked or abused under a previous registrant can still sit on vendor lists when you launch. Scan any domain before you buy it or before the first campaign.

  • One order per domain, 39, no account and no subscription. Run the free scan on every client domain before a launch. When one is flagged, the dashboard belongs to whoever pays, and vendor replies go to the address you enter.

  • Our part: requests out within 48 hours of payment, in practice inside the first hour. Vendors decide on their own time; in the one dispatch we've measured publicly, 8 of 12 cleared within 3 days and all 12 by day 15. Meta says it aims for 48 hours on the review itself. We don't promise a date.

// related: Google Ads disapproved instead? · what “Deceptive site ahead” means · customers say my website is dangerous · the complete removal guide, every vendor