Webroot Blocking My Website: How to Clear a BrightCloud False Positive

unflagdomain Team·UPDATED September 24, 2026
LAST VERIFIED SEPTEMBER 24, 2026
// ANSWER

Webroot's website verdicts come from OpenText BrightCloud. To clear a Webroot false positive, look up the domain in the BrightCloud URL or IP Lookup tool, then submit the 'Request a Change' form below the result with the URL, a contact email and a comment of up to 150 characters. Webroot's knowledge base states the BrightCloud team responds within 24–48 hours.

Webroot (OpenText BrightCloud) false-positive removal at a glance
VendorWebroot (OpenText BrightCloud)
ChannelWeb form (owner submits; we prepare the text)
WhereOpenText Threat Intelligence (BrightCloud) — URL or IP Lookup → Request a Change
Account neededNone (a reCAPTCHA check on the lookup)
Vendor statesWebroot's knowledge base states the BrightCloud team responds within 24–48 hours after the change request is submitted.
What we have seenNot measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.

What a Webroot (OpenText BrightCloud) flag looks like

A Webroot browser block page from Web Threat Shield that names the site as malicious or a phishing risk, based on its BrightCloud reputation. Visitors behind a firewall or router that licenses BrightCloud see that product's own block page instead, usually with a category such as 'Malware Sites' or 'Phishing and Other Frauds'.

Why clean sites end up flagged here

  • A past compromise — injected redirect, spam pages or a phishing directory — that BrightCloud recorded and has not re-evaluated since the cleanup.
  • A low reputation score inherited from the domain's history, its hosting neighbourhood or a previous owner.
  • A new or rarely visited domain with too little data for BrightCloud to score it favourably.
  • A wrong content category (for example 'Questionable' or 'Spyware and Adware') that a customer's policy blocks, even though the site is not flagged as malicious.

Where to submit: OpenText Threat Intelligence (BrightCloud) — URL or IP Lookup → Request a Change

https://support.threatintel.opentext.com/tools/url-ip-lookup.php

Account: None (a reCAPTCHA check on the lookup).

What it asks for:

  1. URL or IP (required)
  2. Optional: a suggested category for the URL
  3. Your email (required; used only to follow up)
  4. Your product/integration (optional — can be left blank)
  5. Additional comments (150 characters max)

Webroot's 'vendor dispute' form is for files only. Website verdicts go through the BrightCloud change request; the old brightcloud.com lookup address now redirects to the OpenText page above.

Step by step

  1. Look up the current rating. Open the OpenText BrightCloud URL or IP Lookup page, enter the domain or the exact URL that is blocked, pass the reCAPTCHA and click Look up. Note the category and the reputation shown.
  2. Fix or confirm the cause. If the site was compromised, remove what the category describes and verify from an external network. If the site never had a problem, note that — the comment field is short, so decide on the one sentence that matters.
  3. Fill in Request a Change. Below the lookup result, enter the URL, optionally suggest the correct category, add your email, leave the product field blank if you are not sure, and write a comment of up to 150 characters.
  4. Submit and wait for the reply. Submit once per URL. Webroot's knowledge base says the BrightCloud team responds within 24–48 hours. Re-run the lookup afterwards to confirm the new rating.
  5. Clear the consumers. Webroot endpoints and the firewalls that license BrightCloud pick up the new rating on their own update schedule. If a specific visitor is still blocked a day later, ask which product shows the block.

What to write

Short, specific, impersonal. What was found, what was removed, when, and how it was verified. No marketing language, no attachments, no threats.

Clean site, {one-word type e.g. retail/blog}. {Cause} removed {date}; verified clean. Please re-rate as {category}.

Why requests get rejected, and the fix

  • The re-evaluation still found the content — on another path, a subdomain, or only for some user agents. Search the site for the same pattern, test from an external network and a mobile user agent, remove it, then submit a new request.
  • The request went through the Webroot file 'vendor dispute' form. That form is for files. Website ratings change only through the BrightCloud URL change request.
  • The comment did not say what changed. Use the 150 characters for the cause and the date it was removed, or a plain statement that the site never hosted it.

Who copies this verdict

  • Firewalls, routers and web filters that license BrightCloud web classification block on the same verdict and clear when BrightCloud re-rates.

Sources

// WEBROOT (OPENTEXT BRIGHTCLOUD) FAQ
  • Webroot does not rate websites on its own: its Web Threat Shield uses OpenText BrightCloud's reputation and category data. A block means BrightCloud rates the URL as malicious, phishing or low reputation, or puts it in a category the user's policy blocks. The fix is a change request to BrightCloud, not to Webroot support.

  • On the OpenText BrightCloud URL or IP Lookup page. Look up the URL, then use the Request a Change form below the result: URL, optional suggested category, your email, an optional product field and a comment of up to 150 characters. Webroot's own 'vendor dispute' form handles files only.

  • Webroot's knowledge base states the BrightCloud team responds within 24–48 hours after the form is submitted. Products that use the feed then refresh on their own schedule, so a block on a specific firewall can linger a little longer than the rating change itself.

  • One fact that lets the reviewer decide: what was on the site and the date it was removed, or that the site never hosted what the category describes. Skip greetings and signatures. If you know the correct category, select it in the optional category list rather than spending characters on it.

  • BrightCloud takes website disputes through a web form, so Webroot appears on your dashboard as a prepared card with the text ready to paste. Vendors that accept email get a plain-text request sent for you, with your address as Reply-To. We guarantee the requests are sent; each vendor decides the outcome.

// OTHER VENDOR GUIDES