Learn · Technical SEO · Beginner

How to check for security and spam problems after a traffic drop

Learn to check two Search Console reports that show whether Google has flagged your site as hacked or as breaking its spam policies, and how to ask for a review once fixed.

By Dean Cruddace · 30 minutes to do · Updated · Last reviewed

What security and spam problems are

Two causes of a fall in search traffic differ from the rest. A security issue means Google found your site was hacked or could harm visitors, for example through malware or phishing. A spam problem means the site breaks Google's spam policies, its rules against deceiving people or manipulating search results.

Search Console has a report for each. A manual action is applied after a person at Google decides pages break the spam policies. This guide shows how to read both reports and what to do if they show something.

Why they can reduce search traffic

Google says that if a site is affected by a threat such as malware or phishing, it may warn users before they reach it, which may decrease Search traffic. A site that does not comply with the spam policies might rank lower or not appear at all. See Google's traffic-drop guide.

What you need to check for security and spam problems after a traffic drop

  • Access to Google Search Console for the site
  • Someone who can clean the site's code and server, if a problem is found

Check for security and spam problems after a traffic drop, step by step

  1. 1

    Open the Security issues report

    In Search Console, open Security issues. At the top you will see a count of issues, or a green check mark and a message if there are none. Google groups problems as hacked content, malware and unwanted software, and social engineering. See the Security issues report help.

    You will know it worked when You can see a green check mark, or a list of issues with their categories.

  2. 2

    Read any security issue carefully

    Expand each issue to read its description and sample pages. Google cautions that the sample list is not necessarily complete, and that an issue can have no examples at all, which does not mean no pages are affected. Warnings depend on browsing context, so you may not reproduce one yourself: Google says to rely on the report as the source of truth.

    You will know it worked when For each issue you have noted its type, first-detected date and sample pages.

  3. 3

    Open the Manual actions report

    Open Manual actions. Google also notifies you in the message center. With none, you see a green check mark. Otherwise, expand each action to read its description and affected pages, listed as patterns such as a folder, or "Affects all pages". Not every page matching a pattern is necessarily affected. See the Manual actions report help.

    You will know it worked when You know whether any manual action exists, and if so its type and pages.

  4. 4

    If both are clear, keep looking

    Google says violations are found by automated systems as well as human review, so clear reports rule out a manual action and a flagged security issue, but not spam handled automatically. Read Google's spam policies and compare them with your site. The URL Inspection tool does not test whether a site is free of manual actions or security issues, so do not use it instead.

    You will know it worked when You have noted that both reports are clear and listed any policy areas to review.

  5. 5

    Fix what the report shows

    Each issue has a Learn more link with fix steps. Fix the issue on all affected pages, because Google says fixing only some earns no partial return to search results, and fix every issue listed. For hacked pages, Google advises against opening them directly in a browser; it suggests the URL Inspection tool, which shows the page as Google sees it, or command-line tools such as cURL. Some fixes need code and server skills, so find help if that is beyond you.

    You will know it worked when Each listed issue is fixed on every affected page, and you have checked an example page.

  6. 6

    Make sure Google can reach the pages

    For a manual action, Google says affected pages should not need a login, sit behind a paywall, or be blocked by robots.txt or a noindex directive. Check your clean-up left none of these. URL Inspection can test accessibility.

    You will know it worked when URL Inspection shows a fixed page can be reached with no block or noindex.

  7. 7

    Request a review

    When everything is fixed, select Request review in the report. Google says a good request explains the exact issue, describes the steps taken and documents the outcome. If you recently bought the site, say so. Do not resubmit before a decision. Reviews can take several days or weeks, and requesting one while the issue is unfixed can make the next slower.

    You will know it worked when You get a confirmation that the review is under way, and later an email with the decision.

Common mistakes when you check for security and spam problems after a traffic drop

  • Relying on a clean URL Inspection result. Google says it does not test for manual actions or security issues.
  • Fixing only some pages, or only some of several listed issues.
  • Treating the sample URLs as the full list of affected pages.
  • Resubmitting a review request before a decision.

Terms used when you check for security and spam problems after a traffic drop

Security issue
A problem Google detects, such as hacked content or malware, that could harm visitors.
Manual action
A penalty issued after a human reviewer at Google decides pages break its spam policies.
Spam policies
Google's rules against techniques that deceive users or manipulate search systems.
Social engineering
Content that tricks visitors into doing something dangerous, such as revealing confidential information.
A Security Issues or Manual Actions warning to deal with?

Describe what the report says and when it appeared. Link and authority analysis is part of the authority and link building work.

Talk to an SEO specialistAuthority and link building: analysis first →