Sophos flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
To get a clean website reclassified by Sophos, email Sophos using the address in knowledge-base article KBA-000048894, 'Sample Submission - Non-Customer File and URL submissions'. Put the URL in the subject with hxxp:// or hxxps:// in place of http:// or https://, and in the body explain the miscategorisation and the category that should apply. Sophos accepts these from anyone but gives no feedback.
| List type | antivirus engine |
|---|---|
| Channel | Email request |
| What unflagdomain does | Sends the request for you |
| Step-by-step guide | Sophos Blocked My Website: How to Get It Reclassified |
| Longer read | Why Sophos flags clean sites |
What Sophos is
SophosLabs categorises web addresses for Sophos Firewall, Intercept X and Sophos Home. Non-customers submit a URL review by email in a documented format; Sophos states it sends no feedback.
What a Sophos flag looks like
A Sophos 'Web page blocked' page naming a category such as Malicious or Phishing & Fraud.
Why clean sites end up flagged here
- A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup.
- A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
- A verdict copied from another engine's feed, so the flag appears here days after the original source.
- A genuinely clean page that the engine's heuristics read as suspicious: obfuscated JavaScript, a login form, a redirect chain.
How a removal request reaches Sophos
This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.
The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the Sophos false-positive guide.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
Sophos is an antivirus URL-reputation system: its verdict on a domain reaches everyone who runs that product, and it surfaces through multi-engine scanners such as VirusTotal, where other products and firewalls read it. A past compromise — an injected redirect, spam pages, a phishing directory — that the engine recorded and has not re-scanned since the cleanup. A file hosted on the site (an installer, an archive) that matched a signature, which flags the URL that served it.
Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. The Sophos guide on this site has the portal, the fields and a template.
Sophos states that non-customer submissions are welcome but feedback will not be provided. No turnaround is stated. Sophos states it sends no confirmation; in practice the category changes silently, usually within a few days, and the only way to know is to re-check the lookup or a Sophos-protected client.
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; Sophos decides the outcome.