CRDF flagged my website — how removal works

CATALOG ENTRY VERIFIED 2026-09-21

// ANSWER

CRDF is a reputation or threat-intelligence feed consumed by firewalls, CDNs, DNS filters, mail gateways and security plugins. It rarely shows a browser warning itself; the block appears downstream, often on a company network. It accepts website false-positive reports by web form. unflagdomain prepares the text and the exact place to submit it as part of a €39 dispatch; CRDF reviews the site itself and decides on its own schedule.

CRDF at a glance
List typeweb blocklist
ChannelWeb form
What unflagdomain doesPrepares the text and the exact place to submit it
Step-by-step guideNot yet — the general process below applies
Longer read

What CRDF is

CRDF Threat Center (France) publishes a malicious-URL feed that appears on VirusTotal and in several firewalls. False positives are filed through its own form, up to five URLs at a time.

What a CRDF flag looks like

Visitors on a network or device that consumes this feed cannot reach the site, or see a block page naming the product that consumed it. On VirusTotal and free checkers, a line under this vendor's name.

Why clean sites end up flagged here

  • A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone.
  • A single automated sighting — one crawler, one sample — with no human review.
  • Shared infrastructure: the same IP, certificate or hosting neighbourhood as something that was flagged.
  • A new or parked domain with no history to rate.

How a removal request reaches CRDF

This vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue.

The general procedure — clean, verify from outside, one specific request, wait for the re-check — is in the complete removal guide, with the checklist of what every request must contain.

What unflagdomain does for this vendor

When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you.

This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.

// CRDF FAQ
  • CRDF is a reputation or threat-intelligence feed consumed by firewalls, CDNs, DNS filters, mail gateways and security plugins. It rarely shows a browser warning itself; the block appears downstream, often on a company network. A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone. A single automated sighting — one crawler, one sample — with no human review.

  • Clean the site first and verify it from outside. Then this vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue. State the URL, what was found, what was removed and when, in plain text.

  • CRDF states no turnaround we can quote. Across our dispatches, vendors of this type mostly answer within a week when they answer at all; some clear silently on their next crawl. In our most recent measured dispatch, 12 of 12 flagging vendors had cleared within 15 days.

  • When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you. We guarantee the request is sent or prepared; CRDF decides the outcome.

// OTHER WEB BLOCKLISTS WE COVER