Sucuri flagged my website — how removal works
CATALOG ENTRY VERIFIED 2026-09-21
When Sucuri SiteCheck says a site is blacklisted, read which list it names. SiteCheck also shows Google Safe Browsing, McAfee, ESET, PhishTank, Yandex and Opera, and each of those needs its own request. Only a Sucuri Labs listing is Sucuri's own. Report that one by email to Sucuri's Research / Labs address, which is listed on Sucuri's contact page, with the URL and evidence the site is clean.
| List type | web blocklist |
|---|---|
| Channel | Email request |
| What unflagdomain does | Sends the request for you |
| Step-by-step guide | Sucuri SiteCheck Says My Site Is Blacklisted: How to Clear It |
| Longer read | Why Sucuri flags clean sites |
What Sucuri is
Sucuri's SiteCheck scanner shows other vendors' blocklists alongside Sucuri Labs' own list, which appears on VirusTotal. A SiteCheck 'blacklisted' result must be read vendor by vendor before anything is reported to Sucuri.
What a Sucuri flag looks like
A 'Site is Blacklisted' banner on sitecheck.sucuri.net, and 'Sucuri SiteCheck' as an engine line on VirusTotal.
Why clean sites end up flagged here
- A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone.
- A single automated sighting — one crawler, one sample — with no human review.
- Shared infrastructure: the same IP, certificate or hosting neighbourhood as something that was flagged.
- A new or parked domain with no history to rate.
How a removal request reaches Sucuri
This vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when.
The exact portal, the fields it asks for, a template and the reasons requests get rejected are in the Sucuri false-positive guide.
What unflagdomain does for this vendor
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent.
This is one of 133 vendors in the catalog. A scan shows which of them flag a domain right now; the €39 dispatch covers every one that does.
Sucuri is a reputation or threat-intelligence feed consumed by firewalls, CDNs, DNS filters, mail gateways and security plugins. It rarely shows a browser warning itself; the block appears downstream, often on a company network. A URL on the domain was seen distributing malware or hosting a phishing page, and the feed keeps the entry until its next crawl finds it gone. A single automated sighting — one crawler, one sample — with no human review.
Clean the site first and verify it from outside. Then this vendor accepts a website false-positive report by email at an address it publishes in its own documentation. The message must be plain text, come from an address at the affected domain or a contact the vendor can verify, and state the URL, what was found, what was removed and when. The Sucuri guide on this site has the portal, the fields and a template.
No stated turnaround for Sucuri Labs blacklist reviews. Not measured per vendor yet. In our most recent measured dispatch, all 12 flagging vendors had cleared within 15 days.
When a scan shows this vendor flagging your domain, a separately written plain-text request goes out to it in the dispatch, with your address as Reply-To, so the vendor's answer lands in your inbox. If the address bounces, another working contact is looked for and the request re-sent. We guarantee the request is sent or prepared; Sucuri decides the outcome.