CRDF flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
CRDF is a reputation or threat-intelligence feed consumed by firewalls, CDNs, DNS filters, mail gateways and security plugins. It rarely shows a browser warning itself; the block appears downstream, often on a company network. It accepts website false-positive reports by web form. unflagdomain prepares the text and the exact place to submit it as part of a €39 dispatch; CRDF reviews the site itself and decides on its own schedule.
| List type | web blocklist |
|---|---|
| Channel | Web form |
| What unflagdomain does | Prepares the text and the exact place to submit it |
| Step-by-step guide | Not yet — the general process below applies |
| Longer read | — |
What CRDF is
CRDF Threat Center (France) publishes a malicious-URL feed that appears on VirusTotal and in several firewalls. False positives are filed through its own form, up to five URLs at a time.
What a CRDF flag looks like
Visitors on a network or device that consumes this feed cannot reach the site, or see a block page naming the product that consumed it. On VirusTotal and free checkers, a line under this vendor's name.
Why clean sites end up flagged here
- A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone.
- A single automated sighting — one crawler, one sample — with no human review.
- Shared infrastructure: the same IP, certificate or hosting neighbourhood as something that was flagged.
- A new or parked domain with no history to rate.
How a removal request reaches CRDF
This vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue.
The general procedure — clean, verify from outside, one specific request, wait for the re-check — is in the complete removal guide, with the checklist of what every request must contain.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
CRDF is a reputation or threat-intelligence feed consumed by firewalls, CDNs, DNS filters, mail gateways and security plugins. It rarely shows a browser warning itself; the block appears downstream, often on a company network. A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone. A single automated sighting — one crawler, one sample — with no human review.
Clean the site first and verify it from outside. Then this vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue. State the URL, what was found, what was removed and when, in plain text.
CRDF states no turnaround we can quote. Across our dispatches, vendors of this type mostly answer within a week when they answer at all; some clear silently on their next crawl. In our most recent measured dispatch, 12 of 12 flagging vendors had cleared within 15 days.
When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you. We guarantee the request is sent or prepared; CRDF decides the outcome.