July 4, 2026

Google Blacklisted My Site — Now What? A Step-by-Step Recovery Guide

Finding out your site has been blacklisted is a uniquely stressful moment — visitors are seeing warnings, your search traffic may have dropped, and it’s not always obvious what to do first. Here’s a clear, step-by-step way to approach recovery.

Step 1: Confirm the blacklist status and reason

Start by checking Google Safe Browsing directly, and check Google Search Console if you have it set up, since it often shows the specific pages and issue type Google flagged. Different blacklists (Google, Norton, McAfee SiteAdvisor, and others) sometimes flag independently, so it’s worth checking more than one source to understand the full scope.

Step 2: Isolate the site before doing anything else

If possible, put the site in maintenance mode or restrict public access while you investigate. This prevents further spread of any malicious code and stops additional visitors from being exposed while you work on the fix.

Step 3: Find and remove the actual malicious code

This is the step people most often get wrong — deleting a suspicious file or plugin without finding every injection point, backdoor, and modified core file. A proper cleanup checks theme files, plugin files, the database, .htaccess rules, and uploads directories, since malware frequently plants more than one way back in.

Step 4: Update everything and rotate credentials

Update WordPress core, every theme, and every plugin to the latest version, since outdated software is how most infections start in the first place. Then change all passwords — WordPress admin accounts, hosting/FTP/SFTP access, and database credentials — since compromised sites often have exposed credentials.

Step 5: Request a review from the blacklist provider

Once you’re confident the site is genuinely clean, submit a review request through the relevant tool (for example, the Security Issues report in Google Search Console). Reviews typically take anywhere from a few hours to several days, and submitting before the site is actually clean can result in a rejected review and a longer wait to try again.

Step 6: Put monitoring in place so it doesn’t happen again

A blacklisting is almost always a symptom of an underlying gap — an outdated plugin, weak credentials, or no firewall. Once you’re delisted, ongoing scanning and monitoring is what actually prevents a repeat, rather than just reacting the next time something goes wrong.

Dealing with a blacklist warning right now? Start with a scan to see exactly what’s flagged.
Run a Free Audit
Worried your own site might have gaps like this?
Run a Free Audit