ESET flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
ESET takes website false-positive reports by email to its Research Lab, at the address documented in ESET knowledge-base article KB141. Put 'Domain whitelist' followed by the blocked domain in the subject line, list the complete blocked URLs and say why it is a false positive, in plain text with no other links. ESET says to follow up if it is not resolved within three days.
| List type | antivirus engine |
|---|---|
| Channel | Email request |
| What unflagdomain does | Sends the request for you |
| Step-by-step guide | ESET Blocked My Website: How to Report a False Positive |
| Longer read | Why ESET flags clean sites |
What ESET is
ESET's URL reputation is used by ESET's consumer and business products and by its LiveGrid cloud. Website reports go to the ESET lab by email in a documented format.
What a ESET flag looks like
An ESET 'Access denied — the web page is on the list of websites with potentially dangerous content' or a phishing block inside the browser.
Why clean sites end up flagged here
- A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
- A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
- A verdict copied from another engine's feed, so the flag appears here days after the original source.
- A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.
How a removal request reaches ESET
This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.
The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the ESET false-positive guide.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
ESET is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. The ESET guide on this site has the portal, the fields and a template.
No fixed turnaround. KB141 says to send a follow-up if the issue is not resolved within three days and the matter is urgent. Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; ESET decides the outcome.