Unsafe-site lookup

Before your browser opens a page, it checks the address against a list of dangerous sites kept by Google. This lookup asks that same list about any address and names the kind of threat on record.

A full link works too: that exact page is checked together with the home page of its domain.

Or try mozilla.org, testsafebrowsing.appspot.com/s/malware.html

One list that most browsers consult

Since 2007 Google has kept a constantly updated list of web addresses that harm their visitors. Its crawlers find some of them, and people report others. The list is called Safe Browsing, and Chrome, Firefox and Safari all consult it before they load a page. If the address is on it, you get a full-screen red warning in place of the page, something like “Deceptive site ahead” or “The site ahead contains malware”. The only way forward is a small link tucked behind a “Details” button, and very few people go looking for it.

Being listed rarely means the owner is a criminal. Most listed sites are ordinary sites that got broken into and now carry a fake login page or a hidden redirect their owner has never seen.

What this lookup sends and what comes back

Our server sends up to four addresses to Google’s Safe Browsing Lookup API in one request: the address exactly as you typed it, then the home page of the domain as https://example.com/, https://www.example.com/ and http://example.com/. Google answers with the matches it has, each tagged with one of four threat types:

Type in the APIShown asWhat it means
MALWAREMalwareThe page installs harmful software or sends visitors to a page that does.
SOCIAL_ENGINEERINGPhishing or deceptionThe page imitates a bank, a mailbox or a store to collect passwords or card numbers, or tricks people into a download.
UNWANTED_SOFTWAREUnwanted softwareDownloads that change browser settings, add toolbars or show ads without saying so clearly.
POTENTIALLY_HARMFUL_APPLICATIONPotentially harmful applicationA mobile app that Google considers dangerous is distributed here.

One match on any of the four addresses is enough for the verdict “Flagged”. The table under the verdict shows which address matched, since one infected page deep in the site and an infected home page aren’t the same size of problem.

If your own site is flagged

  1. Get the evidence. Verify the site in Google Search Console and open Security & Manual Actions, then Security issues. Google lists sample URLs and the date it found them.
  2. Find out how they got in. The usual ways in are an outdated plugin or theme, a reused admin or FTP password, and a neighboring site on the same hosting account. Look for administrator accounts you didn’t create, .php files inside upload folders, and new rules in .htaccess. Our .htaccess explainer points out suspicious redirects.
  3. Clean or restore. A backup from before the first detection date is the fastest route. Then update everything and change every password, the database one included.
  4. Request a review from the same Search Console screen and describe what you removed. Phishing reviews usually finish within a day, malware reviews within a few days.

Don’t request the review until the cleanup is complete. A failed review makes the next one slower.

What a clean result doesn’t prove

“Not flagged” means the addresses aren’t on Google’s list at this minute. A phishing page often lives for a few hours before anyone reports it, so a brand-new scam gets through this check easily. The lookup also covers only the addresses listed above, not every page of the site, and it knows nothing about pages behind a login.

Microsoft Edge relies on a different list, Microsoft Defender SmartScreen. A site can be clean here and still be blocked in Edge, or the other way around.

To judge a link that came in a message, use this lookup and then look hard at the address itself. The lookalike character detector catches domains built from swapped letters.

Questions people ask

How do I check if a website is safe before visiting it?

Paste the address here to see whether Google has it on record as dangerous. Then read the domain name slowly, letter by letter, and compare it with the address you expected. A clean result on a domain you don’t recognize is no reason to type a password there.

Why does Chrome show “Deceptive site ahead” on my website?

Google found a page on your domain that imitates another service or pushes a misleading download. In most cases an intruder planted it. Search Console, under Security issues, shows examples of the pages involved.

How long does it take to remove the Safe Browsing warning?

Once you’ve cleaned the site and requested a review in Search Console, a phishing flag is usually lifted in about a day and a malware flag in a few days. If you don’t request a review, the flag stays until Google gets around to crawling the pages again.

Does “not flagged” mean the site is safe?

No. It means the site isn’t on this list right now. New malicious pages take time to be found, and a site can be dishonest in ways no blocklist covers, such as a store that never ships.

Is the address I check shared with Google?

Yes, the addresses go to Google’s API so it can answer. The request comes from our server, so Google doesn’t receive your IP address or anything about your browser.

How can I see what a flagged result looks like?

Google publishes harmless test pages for that. Try testsafebrowsing.appspot.com/s/malware.html, which is offered as a sample under the field.