Sucuri SiteCheck Says My Site Is Blacklisted: How to Clear It
When Sucuri SiteCheck says a site is blacklisted, read which list it names. SiteCheck also shows Google Safe Browsing, McAfee, ESET, PhishTank, Yandex and Opera, and each of those needs its own request. Only a Sucuri Labs listing is Sucuri's own. Report that one by email to Sucuri's Research / Labs address, which is listed on Sucuri's contact page, with the URL and evidence the site is clean.
| Vendor | Sucuri |
|---|---|
| Channel | Email (we send it for you; the vendor's own portal is below) |
| Where | Sucuri contact page → Report Security Issue → Research / Labs |
| Account needed | None |
| Vendor states | No stated turnaround for Sucuri Labs blacklist reviews. |
| What we have seen | Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days. |
What a Sucuri flag looks like
A SiteCheck report with a red 'Site is Blacklisted' result and a list of blocklists, each marked either 'Domain clean by …' or flagged. The Sucuri Labs line links to Sucuri's own record. On VirusTotal, Sucuri's verdict appears as the engine 'Sucuri SiteCheck'.
Why clean sites end up flagged here
- Another list flagged the site and SiteCheck is displaying it: Google Safe Browsing, McAfee, ESET, PhishTank, Yandex or Opera. Sucuri has not flagged it.
- SiteCheck found malware, SEO spam or suspicious JavaScript in the page as a browser sees it, and Sucuri Labs recorded the domain.
- A conditional redirect or injected script that shows only to some visitors, so the owner sees a clean page and the scanner does not.
- A past infection that has since been removed but has not been re-checked.
Where to submit: Sucuri contact page → Report Security Issue → Research / Labs
https://sucuri.net/company/contact-us/
Account: None.
What it asks for:
- The exact domain or URL SiteCheck lists as blacklisted by Sucuri Labs
- What SiteCheck showed (the Sucuri Labs line and any malware signature it linked)
- What the site is, what was removed and when, or why the detection is wrong
Sucuri does not publish a dedicated false-positive process for its Labs blocklist; the contact page lists the Research / Labs address, and that is the channel. Sucuri also sells cleanup with blocklist removal as a paid plan. That is a service for hacked sites, not a dispute channel.
Step by step
- Read which list SiteCheck names. Scan the domain on SiteCheck and open the blacklist section. Note every list that is not marked 'Domain clean by …'. If Sucuri Labs is marked clean, Sucuri is not the vendor to contact.
- Route the other lists to their own vendors. Google Safe Browsing is cleared in Search Console, and McAfee, ESET, PhishTank, Yandex and Opera each have their own process. Writing to Sucuri about them changes nothing.
- Check what SiteCheck found. If SiteCheck reports malware or spam, note the signature it links to and look for that exact code on the site, as a mobile user agent and from an external network. Remove it, then re-scan until SiteCheck shows no malware.
- Email Sucuri Labs. Use the Research / Labs address on Sucuri's contact page. Send one plain message with the domain, what SiteCheck showed and when it was fixed, or why the detection is wrong.
- Re-scan and reanalyse. Re-run SiteCheck after Sucuri replies or after a few days, and reanalyse the URL on VirusTotal so the 'Sucuri SiteCheck' engine result updates.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
Subject: False positive: {domain} on the Sucuri Labs blacklist
SiteCheck lists {domain} as blacklisted by Sucuri Labs{, with the signature {signature name} on {URL}}.
The site is {one-line description of what the site is}. {Either: 'The code that triggered the detection ({what, where}) was removed on {date}; a SiteCheck scan on {date} shows no malware.' Or: 'The site does not contain that code; the flagged script is {what it actually is, e.g. a known analytics or payment library}.'}
Please re-check the domain and remove it from the Sucuri Labs blacklist.Why requests get rejected, and the fix
- The flag was from another list that SiteCheck displays, not from Sucuri Labs. Contact the vendor SiteCheck actually names; Sucuri cannot remove another vendor's listing.
- SiteCheck still detects the code, sometimes only for a mobile or search-engine user agent. Search the site for the exact signature SiteCheck links to, remove it from every file and the database, and re-scan before writing again.
- The message gave no evidence: no domain, no detection, no date. Name the exact domain, what SiteCheck showed, and what was changed and when.
Who copies this verdict
- VirusTotal shows Sucuri's verdict as the 'Sucuri SiteCheck' engine.
- Free 'is my site blacklisted' checkers often re-display SiteCheck results, so they clear when Sucuri and the other lists do.
Sources
- Sucuri SiteCheck — website security scanner
- Sucuri — Contact us (Report Security Issue: Research / Labs)
- Sucuri Docs — How to get off a blacklist?
- Sucuri — Website blocklist removal and repair (paid service)
Longer read: why Sucuri flags clean sites and how unflagdomain handles it.
Not necessarily. SiteCheck shows the status of several lists, including Google Safe Browsing, McAfee, ESET, PhishTank, Yandex, Opera and Sucuri Labs. Each line reads 'Domain clean by …' unless that list flags you. Only the Sucuri Labs line is Sucuri's own verdict; the others are cleared with those vendors.
For a Sucuri Labs listing, email the Research / Labs address shown on Sucuri's contact page. Include the exact domain, what SiteCheck showed (and the malware signature it linked, if any), and what was removed and when, or why the detection is wrong. Keep it short and plain; one message is enough.
No. Sucuri sells malware cleanup with blocklist removal for hacked sites, where its team contacts the blocklist companies after cleaning. For a site that is already clean, you can report a Sucuri Labs listing directly and handle the other lists with their own vendors, without a plan.
SiteCheck scans the page as a browser receives it. Some infections show only to certain visitors: mobile browsers, search-engine crawlers, or first-time visitors. Test with a different user agent and network, and look for the signature SiteCheck links to. Code on the server that is never sent to browsers is outside what SiteCheck can see.
Yes. If Sucuri flags your domain, a plain-text removal request goes to Sucuri by email with your address as Reply-To, so Sucuri's reply reaches you directly. Lists that SiteCheck only displays are handled with their own vendors. We guarantee the requests are sent; each vendor decides its own outcome.