VirusTotal Flagged My Website: How to Clear a False Positive
VirusTotal cannot remove a detection because it does not create one: it displays the verdict of each contributing engine. To clear a website false positive on VirusTotal, identify the engines marked malicious or phishing, file a false-positive report with each engine through its own channel, and after they update, click Reanalyse on the VirusTotal URL page. Engines respond in hours to weeks.
| Vendor | VirusTotal |
|---|---|
| Channel | Aggregator — report to each flagging engine |
| Where | VirusTotal — false positive process (report to the engine, not to VirusTotal) |
| Account needed | None for the engines' own forms; a free VirusTotal account only to comment or vote |
| Vendor states | VirusTotal states no turnaround because it does not process disputes; each engine sets its own. |
| What we have seen | Across our dispatches, engines that answer at all mostly do so within a week; some feeds clear silently on their next crawl and some never reply. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days. |
What a VirusTotal flag looks like
A VirusTotal URL or domain report with N/97 marked 'Malicious', 'Phishing', 'Malware' or 'Suspicious', and a red score in the summary. Customers rarely see VirusTotal directly; they see the block from a firewall, an email gateway or an antivirus that consumes one of those engines.
Why clean sites end up flagged here
- One engine's automated feed picked up a redirect, a spam URL or a phishing page that has since been removed, and has not re-scanned.
- A threat-intelligence feed (CRDF, URLhaus-style lists, alphaMountain, Sophos, Fortinet) categorised the domain from a single past sighting.
- The domain is new, parked, or shares hosting or a certificate with something that was flagged.
- A file hosted on the site — not the site itself — is detected. That is a file false positive with a different process.
Where to submit: VirusTotal — false positive process (report to the engine, not to VirusTotal)
https://docs.virustotal.com/docs/false-positive
Account: None for the engines' own forms; a free VirusTotal account only to comment or vote.
What it asks for:
- For each flagging engine: the URL, the detection name VirusTotal shows, and the evidence it is clean
- VirusTotal itself accepts no dispute; its contributors page lists each engine's contact
'1/97 engines' on a URL is usually one automated feed. It still matters: firewalls and email filters that consume that feed block on a single verdict.
Step by step
- Read the detections, not the score. Open the URL and the domain report on VirusTotal and note each engine marked malicious, phishing or suspicious, with the detection name it shows. Ignore 'Unrated' and 'Clean'.
- Fix or confirm the cause. Check the site for what the detection names describe — a redirect, injected script, phishing directory, a downloadable file. Remove it, or confirm the page is clean from an external network and a mobile user agent.
- Report to each flagging engine. Each engine has its own false-positive channel: a web form (Fortinet, Webroot, Trend Micro, AVG, Avira, Norton), an email address documented in its knowledge base (ESET, Sophos, Kaspersky, McAfee, Bitdefender), or a self-service lookup. VirusTotal's contributors page links each one. Use the exact URL VirusTotal shows.
- Reanalyse after the engines update. Engines update their own databases first; VirusTotal shows the new verdict only when the URL is re-scanned. Click 'Reanalyse' on the URL page a day or two after each engine confirms. Do not reanalyse hourly — it changes nothing on the engine side.
- Clear the consumers. Firewalls and mail gateways that blocked on an engine's feed refresh on their own schedule, usually within a day of the engine clearing. If a specific customer is still blocked, ask which product blocks and check that vendor's own guide.
What to write
Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.
Subject: False positive — {URL}
{URL} is flagged by {engine} as {detection name shown on VirusTotal}. The site is a {one-line description of what the site is}. {Either: 'The content that triggered the detection ({what}) was removed on {date} and the URL now returns {404 / the clean page}.' Or: 'The page has not changed and hosts no {malware / phishing / redirect}; it can be verified at {URL} from any network.'}
Please re-scan and reclassify the URL.Why requests get rejected, and the fix
- The engine re-scanned and the content was still there — on a different path, a subdomain, or only for certain user agents. Search the site for the same pattern, test as a mobile client and from outside your network, remove it, and report again with the date it was removed.
- The report went to VirusTotal (a comment or vote) instead of to the engine. Comments and votes are visible to other users but change no engine's verdict. File with the engine's own form or address.
- The detection is on a file the site hosts, not on the URL. Use the engine's file-submission process with the file or its hash; the URL process will not clear it.
Who copies this verdict
- Firewall and email-gateway products that consume VirusTotal engine feeds block on a single 'Malicious' verdict.
- Free 'website blacklist checkers' mostly re-display VirusTotal results, so they clear when the engines do.
Sources
- VirusTotal docs — I am experiencing a false positive, my file or site should not be detected
- VirusTotal docs — Contributors (each engine's contact)
- VirusTotal docs — How it works
Longer read: why VirusTotal flags clean sites and how unflagdomain handles it.
No. VirusTotal aggregates the verdicts of contributing engines and does not generate or remove classifications. To clear a flag, the engine that raised it has to reclassify the URL; VirusTotal then shows the new verdict on the next analysis.
Usually yes. A single verdict from a feed that firewalls or mail filters consume is enough to block visitors or bounce email at organisations that use that product, and other engines sometimes ingest the same feed. It is worth one report.
Ask a blocked visitor for a screenshot: the block page names the product (Fortinet, Webroot, Sophos, Trend Micro, ESET…). Then use that vendor's own guide. VirusTotal tells you which engines detect; the screenshot tells you which one is in the way.
Once, after the engines confirm they have reclassified the URL. Reanalysing before that just re-displays the same engine verdicts. Reanalysing repeatedly changes nothing on the engines' side.
Yes — for every flagging engine that accepts a false-positive report by email, a separate plain-text request goes out with your address as Reply-To; form-only engines get a prepared card on your dashboard. We guarantee the requests are sent; each engine decides its own outcome.