An antivirus or firewall is blocking your website.
When an antivirus, a company firewall or an internet provider blocks your website, it is reading a security vendor's list that has your domain on it. ESET shows “Access denied”, Bitdefender “Dangerous page blocked for your protection”, a FortiGate firewall “Web Page Blocked!”. Each vendor keeps its own list and its own way to ask for a review. The block page names one product; a free scan shows which other vendors list the domain, so you ask them all at once instead of one complaint at a time.
Your hosting provider found nothing and the site was never hacked? It still happens: a genuine login page read as phishing, a new domain with no history, a server shared with a bad neighbour. It is each vendor's call, and a clear review request is how you ask for it.
Free, no signup. Shows which security vendors list the domain right now.
| What people see | ESET “Access denied — the web page is on the list of websites with potentially dangerous content”. Bitdefender “Dangerous page blocked for your protection”. Sophos “Web page blocked”. Avast “Web Shield has blocked a harmful webpage”. A FortiGate “Web Page Blocked!”. Trend Micro “Website blocked”. |
|---|---|
| Where it happens | On one visitor's computer (their antivirus), across a whole office (the company firewall), or for every customer of one internet provider or mobile network that filters traffic. |
| Whose list it is | The vendor named on the block page. Firewalls and provider filters run on a vendor's list; the block page or the network's IT team can tell you which. |
| Who can lift it | That vendor, after a review request: an email or its own false-positive form. Every vendor's channel is different. |
| How long it takes | Each vendor decides on its own schedule. Firewalls and provider filters follow when their vendor's list next updates. |
| What €39 covers | A separately written request to every vendor that lists the domain and takes email, and prepared text for the ones that only take a web form. |
Our scan cannot read the website verdicts of Avast and AVG, McAfee, Malwarebytes, Microsoft SmartScreen (the red page in Edge), or DNS filters such as Quad9. If the block page names one of these and the scan comes back clean, don't pay us for it: go to that vendor's own report page, linked below.
- ESEThow to ask ❯
- Bitdefenderhow to ask ❯
- Nortonhow to ask ❯
- McAfeehow to ask ❯
- Avast, AVGhow to ask ❯
- Avira, Sophos, Dr.Webhow to ask ❯
- Kasperskyhow to ask ❯
- Trend Microhow to ask ❯
- Webroothow to ask ❯
- Fortinet (FortiGate)how to ask ❯
- Palo Alto Networkshow to ask ❯
- Forcepointhow to ask ❯
- Microsoft Edge / SmartScreenhow to ask ❯
- Any other web filterhow to ask ❯
- 01
Find out which product blocks it.
Ask a blocked visitor for a screenshot, or open the site on the network where it is blocked. The block page names the product (ESET, Bitdefender, Fortinet, Sophos…) and often the category it put your site in, such as Phishing or Malware.
- 02
Scan the domain.
The scan shows whether that product's vendor is alone or one of several that list the domain. Firewalls and provider filters run on a vendor's list, so the vendor is who you ask, not the network.
- 03
Fix the cause, or confirm there isn't one.
Hacked: remove the injected code, close the way in, rotate passwords. Never hacked: open the blocked URL from outside your own network and see what a visitor gets; a genuine login page or a new domain can be read as phishing. We don't do this step and we don't verify it.
- 04
Ask every vendor that lists the domain at the same time.
Each has its own inbox or form, wants its own wording, and decides on its own schedule. Firewalls and provider filters follow when their vendor's list next updates. This is the step we do for €39.
// step 3: cleaning a hacked website · why antivirus flags clean websites
After you pay €39, once, for this domain: we re-scan it, cache ignored, and send a separately written plain-text removal request to every vendor that takes one by email, within 48 hours and in practice within the hour, with your address as Reply-To. Form-only vendors become dashboard cards with the text prepared. If Google Safe Browsing lists the domain too, that becomes a card with the exact text for Search Console. Replies go to your inbox, not ours.
It does not clean malware. It guarantees the dispatch, not the outcome. If the scan we run right after payment finds no vendor flagging your domain, we refund the full €39 automatically. No subscription, no account.
// free scan · payment only if vendors flag you and there are requests to send
pricing · refund policy · the vendors and how each is contacted
| Day 0 | 12 vendors flagging. Payment, re-scan, 12 separately written requests sent over one hour. |
|---|---|
| Day 3 | 8 of 12 vendors no longer returned the domain. |
| Day 7 | Still 8 of 12. The same eight. |
| Day 15 | All 12 cleared. The verdicts we read were last updated on day 15, so that is the latest day by which every vendor had cleared. |
One dispatch is one dispatch: a case, not a rate. It was a false-positive flag on a site that had never been hacked, which is not the situation most people arrive here in. Vendors re-scan when they review, so a hacked site has to be clean before any of this moves. The customer's own account of that order, in his words:
“ESET flagged our client's website even though it had never been hacked. I wasn't sure whether I could trust an online service with this, but I decided to give it a try. Two weeks later, all 12 vendors that had flagged the site, including ESET, had cleared it.”
// full readings: the case study · in our September 2026 data the median flagged domain carried 11 listings, Google's among them: the report, vendor by vendor
Their antivirus, or their company's firewall, reads a list that yours doesn't. Ask for a screenshot of the block page: it names the product, and that product's vendor is who has to review the domain.
Some internet providers and mobile networks filter their customers' traffic through a security vendor's list. Ask the provider which service it uses, or read the block page. The request then goes to that vendor, not to the provider.
Yes. A genuine login page, a brand-new domain or a server shared with a bad neighbour can all be read as phishing or malware. Say in the request what the page is and why it is legitimate; that is what review requests are for.
Yes. Each vendor keeps its own list and its own review channel; there is no shared list to file once. That is the €39 part: we write and send each email request and prepare the text for the vendors that only take a web form.
Each vendor decides on its own schedule, and a firewall or provider filter follows when its vendor's list next updates. We don't promise a date. Our part, the requests, goes out within 48 hours of payment, in practice within the hour.
No. It cannot read the website verdicts of Avast and AVG, McAfee, Malwarebytes, Microsoft SmartScreen, or DNS filters such as Quad9. If the block page names one of those, use that vendor's own report page.
// related: a red warning in Chrome instead? · customers say my website is dangerous · check a web filter's category for your site