ESET flagged my website — how removal works

CATALOG ENTRY VERIFIED 2026-09-21

// ANSWER

ESET takes website false-positive reports by email to its Research Lab, at the address documented in ESET knowledge-base article KB141. Put 'Domain whitelist' followed by the blocked domain in the subject line, list the complete blocked URLs and say why it is a false positive, in plain text with no other links. ESET says to follow up if it is not resolved within three days.

ESET at a glance
List typeantivirus engine
ChannelEmail request
What unflagdomain doesSends the request for you
Step-by-step guideESET Blocked My Website: How to Report a False Positive
Longer readWhy ESET flags clean sites

What ESET is

ESET's URL reputation is used by ESET's consumer and business products and by its LiveGrid cloud. Website reports go to the ESET lab by email in a documented format.

What a ESET flag looks like

An ESET 'Access denied — the web page is on the list of websites with potentially dangerous content' or a phishing block inside the browser.

Why clean sites end up flagged here

  • A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
  • A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
  • A verdict copied from another engine's feed, so the flag appears here days after the original source.
  • A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.

How a removal request reaches ESET

This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.

The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the ESET false-positive guide.

What unflagdomain does for this vendor

When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.

This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.

// ESET FAQ
  • ESET is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.

  • Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. The ESET guide on this site has the portal, the fields and a template.

  • No fixed turnaround. KB141 says to send a follow-up if the issue is not resolved within three days and the matter is urgent. Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.

  • When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; ESET decides the outcome.

// OTHER ANTIVIRUS ENGINES WE COVER