Kaspersky flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
To clear a Kaspersky false positive on a website, look the URL up on the Kaspersky Threat Intelligence Portal (opentip.kaspersky.com). If you disagree with the verdict, click 'Submit to reanalyze' on the results page, enter your email and explain what the site is and why the detection is wrong. Kaspersky's knowledge base describes this process and states no turnaround.
| List type | antivirus engine |
|---|---|
| Channel | Email request |
| What unflagdomain does | Sends the request for you |
| Step-by-step guide | Kaspersky Flagged My Website: How to Report a False Positive |
| Longer read | Why Kaspersky flags clean sites |
What Kaspersky is
Kaspersky Security Network rates URLs for Kaspersky's products and the Kaspersky Protection extension. Its Threat Intelligence Portal (OpenTIP) shows the current verdict and takes re-analysis requests.
What a Kaspersky flag looks like
A Kaspersky 'Dangerous URL' or 'Phishing link detected' block in the product or the browser extension.
Why clean sites end up flagged here
- A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
- A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
- A verdict copied from another engine's feed, so the flag appears here days after the original source.
- A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.
How a removal request reaches Kaspersky
This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.
The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the Kaspersky false-positive guide.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
Kaspersky is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. The Kaspersky guide on this site has the portal, the fields and a template.
No stated turnaround. Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; Kaspersky decides the outcome.