Fortinet flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
To clear a Fortinet FortiGuard false positive, look the URL up in the FortiGuard Web Filter Lookup at fortiguard.com/webfilter. If a FortiGate blocks the site under the wrong category, click Request a Review and submit the Web Filter Classification Rating Request. If VirusTotal lists Fortinet as malware or phishing, use the Malicious URL Appeal Form instead. Both forms are free and need no account.
| List type | antivirus engine |
|---|---|
| Channel | Web form |
| What unflagdomain does | Prepares the text and the exact place to submit it |
| Step-by-step guide | Fortinet FortiGuard False Positive: How to Get a Site Reclassified |
| Longer read | — |
What Fortinet is
FortiGuard is Fortinet's threat-intelligence service behind every FortiGate firewall. It keeps two separate verdicts: a web-filter category (what kind of site this is) and an antivirus 'malicious URL' rating; each has its own review form.
What a Fortinet flag looks like
A FortiGate 'Web Page Blocked!' page naming the category, shown to users on a network behind a Fortinet firewall.
Why clean sites end up flagged here
- A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
- A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
- A verdict copied from another engine's feed, so the flag appears here days after the original source.
- A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.
How a removal request reaches Fortinet
This vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue.
The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the Fortinet false-positive guide.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
Fortinet is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
Clean the site first and verify it from outside. Then this vendor takes website reports only through its own web form, usually with a CAPTCHA and sometimes an account, so a person has to submit it. The form is the only path into its review queue. The Fortinet guide on this site has the portal, the fields and a template.
The FortiGuard Web Filter Lookup page says reviews are generally processed and updated within 24 hours. The Malicious URL Appeal Form states no turnaround. Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
When a scan shows this vendor flagging your domain, your dashboard gets a prepared card for it: the vendor's form, the exact URL, and the text to paste. You submit it; the vendor replies to you. We guarantee the request is sent or prepared; Fortinet decides the outcome.