Emsisoft flagged my website — how removal works

CATALOG ENTRY VERIFIED 2026-09-21

// ANSWER

Emsisoft is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. It accepts website false-positive reports by email request. unflagdomain sends that request for you as part of a €39 dispatch; Emsisoft reviews the site itself and decides on its own schedule.

Emsisoft at a glance
List typeantivirus engine
ChannelEmail request
What unflagdomain doesSends the request for you
Step-by-step guideNot yet — the general process below applies
Longer read

What Emsisoft is

Emsisoft's Web Protection and Browser Security extension block URLs from Emsisoft's own host list; false positives are reported to its lab.

What a Emsisoft flag looks like

A block inside the antivirus or its browser extension when a visitor opens the site, and a 'Malicious' or 'Phishing' line under this engine's name on VirusTotal and the free checkers that re-display it.

Why clean sites end up flagged here

  • A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
  • A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
  • A verdict copied from another engine's feed, so the flag appears here days after the original source.
  • A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.

How a removal request reaches Emsisoft

This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.

The general procedure — clean, verify from outside, one specific request, wait for the re-check — is in the complete removal guide, with the checklist of what every request must contain.

What unflagdomain does for this vendor

When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.

This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.

// EMSISOFT FAQ
  • Emsisoft is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.

  • Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. State the URL, what was found, what was removed and when, in plain text.

  • Emsisoft states no turnaround we can quote. Across our dispatches, vendors of this type mostly answer within a week when they answer at all; some clear silently on their next crawl. In our most recent measured dispatch, 12 of 12 flagging vendors had cleared within 15 days.

  • When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; Emsisoft decides the outcome.

// OTHER ANTIVIRUS ENGINES WE COVER