Avast Flagged My Website: How to Report a False Positive
To clear an Avast false positive on a clean website, open Avast's 'Submit a website or a file to Avast for review' page, choose False positive, select URL, and give the exact blocked URL, the detection name (such as URL:Mal or URL:Phishing) and a short description. Avast and AVG share one Gen Digital engine, so one accepted report clears both. Avast states no turnaround.
| Vendor | Avast |
|---|---|
| Channel | Email (we send it for you; the vendor's own portal is below) |
| Where | Avast — Submit a website or a file for review → False positive |
| Account needed | None |
| Vendor states | No stated turnaround. |
| What we have seen | Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days. |
What a Avast flag looks like
A browser page or desktop pop-up reading 'Avast Web Shield has blocked a harmful webpage or file', naming the URL and a threat name such as URL:Mal, URL:Phishing, URL:Blacklist or HTML:Script-inf. AVG users see the same verdict under AVG branding.
Why clean sites end up flagged here
- A past compromise — an injected script, a redirect or a phishing folder — that Avast's crawler recorded before it was cleaned (HTML:Script-inf and URL:Mal are typical).
- A reputation-only verdict (URL:Blacklist) inherited from a shared host, a previous owner of the domain or a third-party feed.
- Content that reads as deceptive to an automated classifier: login forms, payment pages or download buttons on a new domain.
- A third-party script or ad tag that the page loads and that Avast has flagged on its own.
Where to submit: Avast — Submit a website or a file for review → False positive
https://www.avast.com/submit-a-sample
Account: None.
What it asks for:
- Your email address
- Detection name
- Alert ID
- File / Website (choose URL)
- Website URL
- Description
- Math question
The public route is the web form behind 'False positive' on the submission page. We send Avast reports by email to a Gen Digital address held in our catalog; it is not printed here.
Step by step
- Record the detection. Ask an affected visitor for a screenshot, or reproduce it with Avast installed. Note the exact URL blocked (page, path or script) and the threat name, e.g. URL:Mal or HTML:Script-inf.
- Fix or confirm the cause. Check the flagged URL for injected code, redirects or files that match the threat name. Remove them, or confirm from an outside network and a mobile user agent that the page is clean.
- Open the false-positive form. On avast.com/submit-a-sample, choose 'False positive', then set the type to URL. Enter your email, the detection name, the alert ID if the pop-up showed one, and the full URL.
- Describe the site in two or three sentences. Say what the site is, what was removed and when, or that nothing changed and the page hosts no malware. Answer the math question and submit once.
- Re-check with Avast and AVG. Avast sends no fixed-time confirmation. Re-test the URL in an Avast or AVG product after a few days; because the engine is shared, a cleared Avast verdict clears AVG too.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
False positive — {URL}
{URL} is blocked by Avast Web Shield as {threat name, e.g. URL:Phishing}. The site is {one-line description of the site}. {Either: 'The content that triggered the detection ({what}) was removed on {date} and the URL now returns {404 / the clean page}.' Or: 'The page has not changed and hosts no malware, phishing or redirects; it can be checked at {URL} from any network.'}
Please re-scan the URL and remove the detection.Why requests get rejected, and the fix
- The flagged object is a script or a sub-path, and the report named only the homepage. Report the exact URL from the block message. If a third-party script is flagged, remove or replace it; Avast will not clear another party's file for you.
- Avast re-scanned and the injected code or redirect was still served — to some user agents, some countries or on a subdomain. Test from outside your network and as a mobile client, clean every variant, and report again with the date it was removed.
Who copies this verdict
- AVG — same Gen Digital engine, so an Avast decision applies to both.
Sources
- Avast — Submit a website or a file to Avast for review
- Avast — Report False Positive (file or URL form)
Longer read: why Avast flags clean sites and how unflagdomain handles it.
Fix or confirm the flagged URL, then report it as a false positive through Avast's 'Submit a website or a file to Avast for review' page: choose False positive, set the type to URL, and give the exact URL and threat name from the block message. Asking visitors to add an exception only hides the block on their own device.
Usually not. Avast and AVG are both Gen Digital products and share one detection engine, so a URL cleared at Avast clears in AVG as well. AVG also has its own false-positive form; using it for the same URL does no harm but does not add a second review.
They are Avast threat names. URL:Mal marks a URL linked to malware, URL:Phishing a page judged to imitate another site, URL:Blacklist a reputation-only listing, and HTML:Script-inf a page carrying an injected script. The name tells you what to look for before you report, and belongs in the report itself.
Avast does not publish a turnaround for website reports and sends no fixed-time confirmation. Re-test the URL in an Avast or AVG product after a few days. We have not yet measured Avast on its own; in our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
Yes, when a scan shows Avast flagging the domain: a separate plain-text request goes to Avast by email with your address as Reply-To, so any reply reaches you directly. We guarantee the request is sent; Avast alone decides whether to reclassify the URL. We do not clean malware.