ESET Blocked My Website: How to Report a False Positive
ESET takes website false-positive reports by email to its Research Lab, at the address documented in ESET knowledge-base article KB141. Put 'Domain whitelist' followed by the blocked domain in the subject line, list the complete blocked URLs and say why it is a false positive, in plain text with no other links. ESET says to follow up if it is not resolved within three days.
| Vendor | ESET |
|---|---|
| Channel | Email (we send it for you; the vendor's own portal is below) |
| Where | ESET KB141 — Submit a suspicious website / potential false positive website (email to the ESET Research Lab) |
| Account needed | None |
| Vendor states | No fixed turnaround. KB141 says to send a follow-up if the issue is not resolved within three days and the matter is urgent. |
| What we have seen | Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days. |
What a ESET flag looks like
An ESET page in the browser saying the website was blocked — access denied because the page is on ESET's list of websites with potentially dangerous content — or a phishing warning from ESET's anti-phishing module. Visitors running ESET at home or on a company endpoint see it; other visitors see nothing.
Why clean sites end up flagged here
- A past compromise — injected redirect, malicious script or phishing page — that ESET's lab listed and has not re-checked.
- A phishing detection triggered by a login or payment form that resembles another brand.
- A detection on a file the site hosts, which blocks the URL that serves it.
- Parental Control or Web Control miscategorisation — a category block, not a threat detection, reported through a different ESET process.
Where to submit: ESET KB141 — Submit a suspicious website / potential false positive website (email to the ESET Research Lab)
Account: None.
What it asks for:
- Subject: 'Domain whitelist' followed by the blocked domain
- Body: the complete URLs being blocked
- Body: why you think it is a false positive
- Recommended: a screenshot of the block notification
- Format: plain text, no other links, email addresses or images, no footer
The address is documented in KB141. ESET users can also submit from inside the product (Select sample for analysis → False positive site).
Step by step
- Capture the block. Get a screenshot of the ESET block page and the exact URL it names. Note whether it says potentially dangerous content, phishing, or a category block from Parental or Web Control.
- Fix or confirm the cause. Remove any injected content, redirect or phishing page and check from an external network. If the site never hosted anything like it, say so plainly in the email.
- Write the email as ESET specifies. Subject: 'Domain whitelist' and the blocked domain. Body: the complete blocked URLs and why it is a false positive. Plain text, no other links, email addresses or images, and no footer. Attach the screenshot if you have one.
- Send it to the address in KB141. ESET documents the Research Lab address in KB141. Send one message per domain, listing every blocked URL on that domain.
- Follow up after three days if urgent. If the issue is not resolved within three days and it is urgent, ESET asks for a follow-up with the original subject line, the date and time it was sent and the sending address.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
Subject: Domain whitelist {domain}
Blocked URL(s):
{full URL 1}
{full URL 2}
Why this is a false positive: {domain} is a {one-line description of what the site is}. {Either: 'The content that triggered the block ({what}) was removed on {date} and the URL now returns {404 / the clean page}.' Or: 'The site has not hosted malware, phishing or redirects; the page can be checked from any network.'}
Please re-check the domain and remove it from the blocklist.Why requests get rejected, and the fix
- The message did not follow ESET's format — no 'Domain whitelist' subject, HTML, extra links or a signature footer. Resend as plain text with the required subject, only the blocked URLs, and no footer.
- The lab re-checked and still found the content, on the same or another URL. Search the site for the same pattern, remove it, and report again with the removal date.
- The block is a Parental Control or Web Control category, not a threat detection. Use the miscategorisation process in KB141 for category blocks.
Who copies this verdict
- Products that license ESET's detection technology clear when ESET updates its list.
Sources
- ESET KB141 — Submit a virus, website, or potential false positive sample to the ESET Research Lab
- ESET Online Help — Select sample for analysis: False positive site
Longer read: why ESET flags clean sites and how unflagdomain handles it.
Email ESET's Research Lab at the address given in knowledge-base article KB141. Use the subject 'Domain whitelist' followed by the domain, list the complete blocked URLs and explain why it is a false positive. Send plain text with no other links, images or footer, and attach a screenshot of the block if you have one.
The URL is on ESET's blocklist of malicious or potentially dangerous sites. Common causes are a past compromise that has not been re-checked, a phishing detection on a form, or a file the site hosts. If the block is a category from Parental or Web Control instead, it is a miscategorisation with a separate process.
ESET does not publish a fixed turnaround. Its KB141 says that if the issue is not resolved within three days and it is urgent, you can send a follow-up quoting the original subject line, the date and time you sent it, and the address you sent it from.
Yes, if you run an ESET product: its Select sample for analysis tool has a 'False positive site' option with a notes field for extra information. Site owners without ESET installed use the email route in KB141, which works the same way for anyone.
Yes. ESET accepts website reports by email, so when ESET flags your domain a plain-text request in ESET's required format is sent for you, with your address as Reply-To, so the lab's reply comes straight to you. We guarantee the request is sent; ESET decides the outcome.