Kaspersky Flagged My Website: How to Report a False Positive
To clear a Kaspersky false positive on a website, look the URL up on the Kaspersky Threat Intelligence Portal (opentip.kaspersky.com). If you disagree with the verdict, click 'Submit to reanalyze' on the results page, enter your email and explain what the site is and why the detection is wrong. Kaspersky's knowledge base describes this process and states no turnaround.
| Vendor | Kaspersky |
|---|---|
| Channel | Email (we send it for you; the vendor's own portal is below) |
| Where | Kaspersky Threat Intelligence Portal — Web Address Analysis → Submit to reanalyze |
| Account needed | None stated in Kaspersky's article; the form asks for an email address |
| Vendor states | No stated turnaround. |
| What we have seen | Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days. |
What a Kaspersky flag looks like
A Kaspersky page in the browser or a product alert — dangerous URL, web page blocked, or phishing link detected — from Kaspersky's desktop product or the Kaspersky Protection browser extension. On VirusTotal the domain shows Kaspersky as 'Phishing' or 'Malicious'.
Why clean sites end up flagged here
- A hack that has been cleaned: an injected script, redirect or phishing page Kaspersky recorded before the cleanup. Kaspersky's own article names hacked sites as the usual cause.
- A rebuilt site on a domain that was previously compromised, with the old verdict still attached.
- A new domain with login or payment pages that an automated classifier reads as phishing.
- A third-party script or file the page loads that is detected on its own.
Where to submit: Kaspersky Threat Intelligence Portal — Web Address Analysis → Submit to reanalyze
https://opentip.kaspersky.com/
Account: None stated in Kaspersky's article; the form asks for an email address.
What it asks for:
- The URL or domain (looked up first)
- Email address
- Comment: what the site is, how you came to check it, and why the verdict is wrong
Kaspersky customers can also go through Customer Service with request type 'Malware', topic 'False positive'. We send Kaspersky reports by email to an address held in our catalog; it is not printed here.
Step by step
- Look the URL up on OpenTIP. On opentip.kaspersky.com, open Web Address Analysis and check the exact flagged URL and the bare domain. Note the verdict shown.
- Fix or confirm the cause. Kaspersky's article says a blocked website has possibly been hacked. Check for injected code, redirects or phishing pages, remove them, and confirm from an outside network that the page is clean.
- Click 'Submit to reanalyze'. On the results page, click Submit to reanalyze. If the page misbehaves, Kaspersky suggests another browser or an incognito window.
- Enter your email and a detailed comment. Say what the site is, what was removed and when, and why the verdict is wrong. Kaspersky says more detail allows a more thorough analysis. Click Submit.
- Re-check and escalate only if it persists. Re-check the URL on OpenTIP after a few days. If the verdict stays and you are a Kaspersky customer, contact Customer Service with request type Malware, topic False positive, including a screenshot of the detection.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
False positive — {URL}
{URL} is detected by Kaspersky as {verdict shown, e.g. phishing}. The site is {one-line description of the site}. {Either: 'The site was compromised; the malicious content ({what}) was removed on {date} and the site was rebuilt from a clean source. The URL now returns {404 / the clean page}.' Or: 'The page has not changed and hosts no malware, phishing or redirects.'} It can be checked at {URL} from any network.
Please re-analyse the URL and remove the detection.Why requests get rejected, and the fix
- Re-analysis found the malicious content still there — a leftover file, a backdoor, or a redirect served only to some visitors. Clean every path and subdomain, test from outside your network and as a mobile client, and submit again with the removal date.
- The comment was too thin for an analyst to act on ('my site is clean'). Describe what the site is, what happened, what was removed and when. Kaspersky explicitly asks for detail.
Who copies this verdict
- Products and threat feeds built on Kaspersky data can carry the same verdict; VirusTotal shows Kaspersky's result as one of its engines.
Sources
- Kaspersky — False detections by Kaspersky applications. What to do?
- Kaspersky — What to do if a Kaspersky application blocks my website or application
- Kaspersky Threat Intelligence Portal
- Kaspersky Support Forum — an owner's report of a clean website detected as phishing
Longer read: why Kaspersky flags clean sites and how unflagdomain handles it.
Look the URL up on the Kaspersky Threat Intelligence Portal at opentip.kaspersky.com. If you disagree with the verdict, click 'Submit to reanalyze' on the results page, enter your email and describe the site, what happened and why the detection is wrong. Kaspersky customers can also open a Customer Service request with topic False positive.
Kaspersky's own knowledge base says a blocked website has possibly been hacked and contains malicious code or phishing links. That is the first thing to rule out. On a rebuilt or genuinely clean site, the verdict is usually a stale record from before the cleanup, which re-analysis can clear.
The 'Submit to reanalyze' flow on the Threat Intelligence Portal asks for an email address; Kaspersky's article does not state that a subscription is required. Customer Service requests are for Kaspersky customers and are not offered for Kaspersky Free. Forum moderators have given owners differing advice, so start with the portal.
Kaspersky does not publish a turnaround for re-analysis requests. Owners in Kaspersky's forum report analysts confirming a false positive and excluding the domain after review. Re-check on the portal after a few days. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
Yes, when a scan shows Kaspersky flagging the domain: a separate plain-text request goes to Kaspersky by email with your address as Reply-To, so any reply reaches you directly. We guarantee the request is sent; Kaspersky alone decides whether to reclassify. We do not remove malware.