Most traffic drops have an ordinary explanation, but two causes in Google’s list are different in kind: a security problem on the site, and a breach of the spam policies. Both can remove traffic quickly, both have a dedicated report in Search Console, and both are checked in minutes. This article covers what Google documents about each, how to tell them from the technical and algorithmic causes, and what Google says about asking for a review. The wider list of causes is in our overview of diagnosing a traffic drop, and the technical side is in its own article.
Two mechanisms: warnings to users, and lower ranking
Google’s guide to debugging drops in Search traffic treats these as separate causes with separate effects. For security, if a site is affected by a threat such as malware or phishing, Google may alert users before they reach it with warnings or interstitial pages, which may decrease Search traffic. For spam, if a site does not comply with the spam policies, its content might rank lower or not appear at all.
The distinction matters for diagnosis. In the first case people may still be shown the site and then be warned off it. In the second, the pages may simply stop being shown. In both, the guide’s first sketch of a graph shape, a large drop from an algorithmic update or a site-wide security or spam issue, is a reminder that the chart alone does not separate them.
What the Security Issues report covers
The Security issues report groups problems into three categories: hacked content (content placed on a site without permission because of security vulnerabilities), malware and unwanted software, and social engineering (content that tricks visitors into doing something dangerous). Google says affected pages can appear with a warning label in search results or an interstitial warning in the browser.
Two details in the help page are worth knowing. First, warnings depend on browsing context, so you may not be able to reproduce one yourself; Google says to rely on the report as the source of truth for whether issues exist or have been fixed. Second, the sample URLs are not necessarily complete, and an issue can appear with no examples at all, which does not mean no pages are affected.
The spam policies describe what hacked content looks like in practice: code injection, page injection, content injection (including hidden links, hidden text or cloaking) and redirects that send some users to harmful or spammy pages. Our article on hidden links, cloaking and injected links goes into those techniques. Google also publishes a short web.dev article, Help, I think I’ve been hacked, which points to a video on how and why sites are hacked and the recovery process. The Security issues help page links further recovery steps there, and we have not relied on them beyond that.
What a manual action is, and what the report shows
The Manual actions report explains that a manual action is issued when a human reviewer at Google has determined that pages on a site are not compliant with its spam policies. Most address attempts to manipulate the search index. If a site has one, some or all of it will not be shown in results, and Google says most are ranked lower or omitted without any visual indication to the user. Google notifies the owner in the report and in the Search Console message center.
The report lists affected pages as patterns, for example a folder, or "affects all pages". Not every page matching a pattern is necessarily affected. Google also describes a narrower case: when a site is abused with third-party spam, such as in forums, guestbooks or internal search pages, the action affects only the pages with that content.
What the spam policies cover as causes of lower or no ranking
The spam policies for Google web search define spam as techniques used to deceive users or manipulate Search systems. Google says violations are detected through automated systems and, as needed, human review that can result in a manual action, and that sites violating the policies may rank lower or not appear at all. The page covers, among others, cloaking, expired domain abuse, hacked content, keyword stuffing, link spam, malicious practices, scaled content abuse, sneaky redirects and user-generated spam. It adds that Google may act against any type of spam it detects, not only the listed ones. Our articles on link building within the spam policies and AI-generated content cover two of these areas.
Telling a manual action from an algorithmic or technical cause
The routes into a lower ranking overlap, so the order of checks matters. Our reading of Google’s pages is this:
- A manual action is visible. It appears in the Manual actions report with a notification. If the report shows none, that rules out a manual action as the cause, but not spam handled by automated systems, which the debugging guide says can also lower or remove content.
- A security issue is visible. It appears in the Security issues report. Because a hack may also change pages, headers or redirects, a technical check can find the same event from another direction.
- Neither report shows anything. Then the technical causes and the algorithmic-update guidance in what to check after a Google update come next, once the drop itself has been confirmed as real.
Note that URL Inspection does not test whether a site is free of manual actions or security issues, according to Google’s help page, so a clean inspection result cannot stand in for these two reports.
Reconsideration requests as Google describes them
Both reports use the same process. Fix the issue on all affected pages, since Google says fixing only some pages will not earn a partial return to search results, and fix every issue listed if there are several. For a manual action, make sure the pages can be reached, with no login, paywall, robots.txt block or noindex. When everything is fixed, select Request review (the Security issues report calls it Request Review). Google says a good request explains the exact issue, describes the steps taken and documents the outcome.
Reviews can take several days or weeks, with link-related requests sometimes longer. Google asks that you do not resubmit before a decision, and warns that requesting a review when the issue is unfixed can lengthen the turnaround for the next request. For a recently acquired site, Google says to say so in the request.
What to confirm after the clean-up, in our reading: that the reports are clear, that the affected pages return normal responses, and that the clean-up itself did not leave a stray noindex, blocked path or broken redirect. That last point is a technical cause in its own right.
Where this fits at Cultured Digital: ruling security and spam in or out
Our SEO audit is a focused investigation that finds the cause, then says what to do first. Crawling and indexing is one of the areas an audit can cover, within technical SEO, depending on the site and the problem: see crawling and indexing. Findings reach developers as tickets with the fault, the evidence, the fix and the acceptance test. We do not promise rankings or traffic numbers. If the drop followed a launch, see what to check after a site move or release.