Google Ads disapproved your ad. Your creative is fine. Check the domain.
When Google Ads labels a disapproval “Compromised site” or “Malicious Software” and the ad itself follows policy, the cause is the destination domain's security reputation, not the ad. Google's Compromised sites policy re-enables ads only after a Search Console security review clears the domain from Safe Browsing. That review is manual, free and yours to file. It clears Google; it doesn't clear the other security lists the domain is on, and nothing else does. Do both today: request the Search Console review yourself, and send a removal request to every other vendor listing the domain.
You're looking at Policy manager and it says status Disapproved or Eligible (limited), policy details Compromised site or Malicious Software. Every ad pointing at this domain is affected, appeals come back with the same label, and nobody can tell you when. Start with the two-minute check that tells you what Google's label doesn't.
Free, 133 vendors, no signup. Shows every list the domain is on and how each one takes a request.
| The label | Compromised site: a hacked destination, at least seven days' warning before any suspension. Malicious Software: intentional distribution, suspension without warning. A hacked-then-cleaned site is the first one. |
|---|---|
| What Google says re-enables ads | A successful security review in Google Search Console, then up to 72 hours for Google to recrawl the landing page. |
| Who files that review | You, as a verified owner of the property. No API, no fast lane, no agency can do it for you. We prepare the text. |
| What that review does not clear | The other security lists the domain is on. In our September 2026 data the median flagged domain carried 11 listings. |
| What 39 buys | A separately written removal request to every other flagging vendor, sent within 48 hours of payment, in practice within the hour. It does not speed up Google's review. |
| Appeal budget | Three appeals per ad, 24 hours apart. Spend one, after the site is clean and the review has cleared. |
// sources: Compromised sites policy · Malicious Software policy · Fix a disapproved ad or appeal · Security Issues report
The label is the diagnosis. Google's Compromised sites policy defines a compromised site as one whose code was manipulated to benefit a third party without the owner's knowledge, and its rule is one sentence: destinations that are hijacked and hacked are not allowed. Its examples are injected redirects, card skimmers, and a CMS with a known vulnerability that was exploited. So you already know it's the domain, not the creative, and you know the ad appeal comes last. Appealing the ad first is appealing in the wrong place.
What the label doesn't tell you is what else the domain is listed on. Google's Transparency Report says many of the unsafe sites Safe Browsing finds each day are legitimate websites that were compromised, and a hack that reached Google's list usually reached the URL-reputation feeds too. Those feeds are what your prospects' browsers, their employers' web filters and other ad systems read, and Google's review leaves every one of them in place. The scan above is the list Google's label leaves out.
Scan came back empty? Then the domain isn't it. Look at the technical side of Destination not working instead: HTTP errors returned to the AdsBot crawler, redirects, geo-blocking, a landing page that only fails on mobile. That's hosting, not reputation, and it's not what we fix.
Steps 2 and 3 run in parallel. Step 4 waits for step 2.
- 01
Clean the site. Actually clean it.
Remove the injected code, close the way in, update the exploited plugin or theme, rotate passwords and keys. Every vendor re-scans when it reviews a request, so a live infection keeps every flag in place. Nothing below works on a site that is still infected. We don't do this step and we don't check it.
- 02
Request the Search Console review yourself, today.
Security & Manual Actions → Security issues for the verified property. Tick that the issues are fixed and describe, per issue, what was found and removed, with paths and dates. Google's help asks for exactly that. Submit once. Google's own pages give two timelines: the Safe Browsing FAQ says a clean scan typically clears within 24 hours, Search Console says a few days to a few weeks. Plan for the second.
- 03
Send the other removal requests the same day, in parallel.
Google is one list. In our data the median flagged domain carries 11 listings, mostly URL-reputation engines that browsers, corporate filters and ad systems consume, and the Search Console review touches none of them. Each vendor has its own inbox or form and its own wording. This is the step we do for €39; doing it by hand is an afternoon.
- 04
Appeal once, after the review clears.
Tools → Troubleshooting → Policy manager → Policy issues → Appeal, reason “Made changes to comply with policy”, the reason Google's Compromised sites page recommends. Google allows up to 72 hours to recrawl the landing page, and three appeals per ad with 24 hours between them. Don't spend one before steps 1 and 2 are done.
// step 2 in detail, with the text to paste: the Search Console review, step by step · step 1: cleaning a hacked website
The part nobody documents in one place. When the security issue disappears from the Search Console report, Google says landing pages should be re-enabled for ads, but the ad keeps its label until you appeal. File one appeal with “Made changes to comply with policy”. The status moves to Under review; Google's help says most ad reviews finish within one business day and asks for up to 72 hours to re-evaluate the landing page. Don't file a second appeal inside that window. It doesn't move the queue and it spends one of your three.
If you're doing this for a client, the question on day 3 is “so when?”, and the honest answer has a shape. This is the one we'd send:
Google has confirmed the site is clean (Search Console security review passed on {date}).
Ads are re-evaluated within about 72 hours of that; one appeal has been filed with "Made changes to comply with policy".
The other security lists that flagged the domain ({n} vendors) were sent removal requests on {date}; each clears on its own schedule.
Next update: {date + 3 days}, or sooner if the ads status changes.After you pay 39, once, for this domain: we re-scan it, cache ignored, and send a separately written plain-text removal request to every vendor that takes one by email, within 48 hours and in practice within the hour, with your address as Reply-To. Vendors that only take their own web form become dashboard cards with the text prepared. Google Safe Browsing becomes one too, with the exact text for Search Console; we never submit it for you. The dashboard shows real sent, bounced and delayed counts. Replies go to your inbox, not ours.
It does not speed up Google's review. It does not clean malware. It guarantees the dispatch, not the outcome: each vendor decides on its own schedule. If the scan we run right after payment finds no vendor flagging your domain, we refund the full 39 automatically. No subscription, no account.
// free scan · payment only if vendors flag you and there are requests to send
pricing · refund policy · the 133 vendors and how each is contacted
| Day 0 | 12 vendors flagging. Payment, re-scan, 12 separately written requests sent over one hour. |
|---|---|
| Day 3 | 8 of 12 vendors no longer returned the domain. |
| Day 7 | Still 8 of 12. The same eight. |
| Day 15 | All 12 cleared. VirusTotal's last analysis was dated day 15, so that is the latest day by which every vendor had cleared. |
One dispatch is one dispatch: a case, not a rate. It was a false-positive flag on a site that had never been hacked, which is not the situation most people arrive here in. Vendors re-scan when they review, so a hacked site has to be clean before any of this moves. The customer's own account of that order, in his words:
“ESET flagged our client's website even though it had never been hacked. I wasn't sure whether I could trust an online service with this, but I decided to give it a try. Two weeks later, all 12 vendors that had flagged the site, including ESET, had cleared it.”
// full readings: the case study · in our September 2026 data the median flagged domain carried 11 listings, Google's among them: the report, vendor by vendor
Not on their own. For Safe Browsing, Google's Compromised sites policy says landing pages should be re-enabled once the Search Console review succeeds; Google then allows up to 72 hours to recrawl. You still appeal once in Policy manager with “Made changes to comply with policy”. Delisting removes the reason; the appeal removes the label. The €39 dispatch does not speed up Google's review.
Compromised site. Google defines it as code manipulated without the owner's knowledge and gives at least seven days' warning before any suspension. Malicious Software means intentional distribution and is enforced as egregious, with suspension and no warning. If you were given the second label for a hack, say so in the appeal.
Usually not. Google's Destination not working policy covers destinations that return an HTTP error to the AdsBot crawler or don't function properly: hosting, redirects, geo-blocking. Run the scan to rule the domain out in two minutes; if no vendor lists it, the fix is technical, not reputational.
Google doesn't say. What it documents is Safe Browsing and its own AdsBot crawl. VirusTotal, which Google owns, aggregates around 90 engines, so a listing there tells you the domain sits on the feeds other systems consume. We use it as a detection source, not as evidence of Google's internal logic.
Yes. Listings attach to the domain name, not to its owner. A domain hacked or abused under a previous registrant can still sit on vendor lists when you launch, and Google names an exploited CMS as a Compromised site example whoever ran it. Scan a domain before you buy it or before the first campaign.
One order per domain, 39, no account and no subscription. Run the free scan on every client domain before a launch; it takes a minute and rules the domain in or out. When one is flagged, the dashboard belongs to whoever pays, and vendor replies go to the address you enter.
Usually not. A disabled or restricted ad account is about account behaviour and history, and Meta handles it in Account Quality as its own case. A flagged domain is a likely contributor only when individual ads were rejected for the landing page before the restriction. For a single rejected Meta ad, see the Meta page linked below.
Our part: requests out within 48 hours of payment, in practice inside the first hour. The vendors' part is theirs: in the one dispatch we've measured publicly, 8 of 12 cleared within 3 days and all 12 by day 15. Google quotes anything from 24 hours to a few weeks for its own review. We don't promise a date, and neither should anyone else.
// related: Meta rejected the ad instead? · the short Google Safe Browsing guide · the complete removal guide, every vendor · signs your website has been hacked