Fortinet FortiGuard False Positive: How to Get a Site Reclassified

unflagdomain Team·UPDATED September 24, 2026
LAST VERIFIED SEPTEMBER 24, 2026
// ANSWER

To clear a Fortinet FortiGuard false positive, look the URL up in the FortiGuard Web Filter Lookup at fortiguard.com/webfilter. If a FortiGate blocks the site under the wrong category, click Request a Review and submit the Web Filter Classification Rating Request. If VirusTotal lists Fortinet as malware or phishing, use the Malicious URL Appeal Form instead. Both forms are free and need no account.

Fortinet FortiGuard false-positive removal at a glance
VendorFortinet FortiGuard
ChannelWeb form (owner submits; we prepare the text)
WhereFortiGuard Web Filter Lookup → Request a Review (category) / Malicious URL Appeal Form (malicious verdict)
Account neededNone
Vendor statesThe FortiGuard Web Filter Lookup page says reviews are generally processed and updated within 24 hours. The Malicious URL Appeal Form states no turnaround.
What we have seenNot measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.

What a Fortinet FortiGuard flag looks like

Visitors behind a FortiGate firewall, or using FortiClient, get a 'Web Page Blocked!' page naming the URL and a FortiGuard category: 'Malicious Websites', 'Phishing', 'Spam URLs', or a wrong content category such as a gambling or adult one that their employer blocks. On VirusTotal the same domain may show 'Fortinet: Malware' or 'Fortinet: Phishing'.

Why clean sites end up flagged here

  • A past compromise: an injected redirect, spam pages or a phishing directory that FortiGuard saw before the cleanup and has not re-rated.
  • The domain is new, recently changed hands, or was parked, and was rated on what it hosted then.
  • Content that reads like another category to an automated rater: a crypto, finance or download page rated as something the employer blocks.
  • Shared hosting, a shared IP or a subdomain service with other sites that were flagged.

Where to submit: FortiGuard Web Filter Lookup → Request a Review (category) / Malicious URL Appeal Form (malicious verdict)

https://www.fortiguard.com/webfilter

Account: None.

What it asks for:

  1. Rating request: URL
  2. Rating request: suggested category (a drop-down of FortiGuard categories)
  3. Rating request: screenshot (optional, max 2 MB)
  4. Both forms: name, email, company name (all required)
  5. Both forms: comment (optional, but it is where the evidence goes)
  6. Both forms: CAPTCHA

Two different verdicts get confused. A FortiGate block with 'Category: …' is a Web Filter category: use the rating request. A 'Malware' or 'Phishing' result for Fortinet on VirusTotal is a malicious-URL verdict: use the Malicious URL Appeal Form. The Classification Dispute form is for software flagged as spyware, not for websites.

Step by step

  1. Look the URL up. Enter the exact URL or domain in the FortiGuard Web Filter Lookup. Note the category it returns. If a visitor sent a block page, compare the category on it; they should match.
  2. Pick the right form. A wrong category, including 'Malicious Websites' or 'Phishing' shown on a FortiGate block page, goes through Request a Review, which opens the Web Filter Classification Rating Request. A Fortinet malware or phishing result on VirusTotal goes through the Malicious URL Appeal Form.
  3. Confirm the site is clean. Check the site for whatever the category implies (a redirect, a phishing page, a downloadable file) from an external network and a mobile user agent. Remove it before filing. A reviewer who finds it still there keeps the rating.
  4. File the form once. Enter the URL, pick the category the site actually belongs to (rating request only), fill the required contact fields and put the evidence in the comment. Attach a screenshot if it helps. Submit once per URL.
  5. Re-check and clear the consumers. Look the URL up again after the stated review window. FortiGates pick up the new rating from FortiGuard on their own; a visitor still blocked can ask their admin to check for a local override. Reanalyse the URL on VirusTotal once Fortinet has updated.

What to write

Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.

URL: {URL}
Current FortiGuard rating: {category shown in the Web Filter Lookup or on the block page}.
Requested rating: {category that fits, e.g. Business / Information Technology}.
The site is {one-line description of what the site is}. {Either: 'The content that caused the rating ({what}) was removed on {date}; the URL now returns {404 / the clean page}.' Or: 'The site has not hosted malware, phishing or spam; it can be verified from any network.'}
Please re-evaluate and update the rating.

Why requests get rejected, and the fix

  • The wrong form was used: a malicious-URL verdict filed as a category change, or a website filed through the software Classification Dispute form. Match the form to the verdict: rating request for a Web Filter category, Malicious URL Appeal Form for a malware or phishing verdict.
  • The reviewer found the content still there, on another path, a subdomain, or only for some user agents. Search the whole site for the same pattern, test from outside your network and as a mobile client, remove it, and file again with the removal date.
  • The suggested category did not match the site, or the comment was empty. Choose the category that describes the site as it is today and state in the comment what the site is and what changed.

Who copies this verdict

  • FortiGate firewalls and FortiClient block on FortiGuard ratings, so one wrong rating blocks the site at every organisation that filters that category.
  • VirusTotal shows Fortinet's verdict as one of its URL engines.

Sources

// FORTINET FORTIGUARD FAQ
  • Look the URL up in the FortiGuard Web Filter Lookup, click Request a Review, and submit the Web Filter Classification Rating Request with the category the site belongs to and evidence in the comment. If the problem is a Fortinet malware or phishing verdict on VirusTotal, use the Malicious URL Appeal Form instead.

  • The Web Filter category is what a FortiGate uses to allow or block a site by policy, and it includes security categories such as Malicious Websites and Phishing. The Malicious URL Appeal Form covers URLs FortiGuard rates as malicious, which is what VirusTotal shows. Each has its own form; filing on the wrong one delays the fix.

  • FortiGuard's own lookup page says reviews are generally processed and updated within 24 hours. That is the vendor's statement, not a promise of a result. The Malicious URL Appeal Form gives no turnaround. After the rating changes, FortiGate devices pick it up from FortiGuard on their own schedule.

  • Both forms make name, email and company name required, so the reviewer can reply. That is separate from the comment: the comment only needs the URL, what the site is and what changed. Fill the contact fields as the form asks and keep the comment factual, with no signature needed.

  • Fortinet takes website disputes through web forms, so it is not emailed. When Fortinet flags your domain, your dashboard shows a prepared card with the form link and the text to paste. We guarantee that email requests to the other flagging vendors are sent; each vendor, Fortinet included, decides its own outcome.

// OTHER VENDOR GUIDES