A customer writes to you: "I tried to open your site, but my browser showed a red screen and said the site was dangerous." You open the site on your own computer. Everything is fine, and the homepage is the same as yesterday.
You reply that the fault was probably on their computer. It probably was not. The red screen is not a fluke, and it is not your host having a bad day. It is Google's list of dangerous addresses. Usually your address is on it; sometimes it is the address your site sent the visitor on to.
This article is about that list: who keeps it and who reads it, why the owner is the last to hear, how to check for yourself and how to get off the list. And, at the end, what we check ourselves and what nobody can see from the outside.
A list most browsers read
Google Safe Browsing is Google's list of web addresses it considers dangerous. Pages end up there for spreading malware, for trying to trick visitors out of passwords or card details, or for offering unwanted software to download.
Chrome is not the only reader. Firefox and Safari use the same list, Gmail checks the links in your mail against it, and Google Search checks its results. By Google's own account it protects more than five billion devices. If your address is on the list, this is not one browser's whim: the warning reaches most of your visitors, because most of the major browsers read the same list.
And now the most important sentence in this article. Many of the sites on the list do not belong to people with bad intentions. Google itself writes that among the dangerous sites it finds every day are many perfectly ordinary sites that somebody broke into. Being on the list does not mean you are the one to be afraid of. Usually it means somebody is using your site.
What the visitor sees
In Chrome it is a full red page headed "Dangerous site". Your site does not show behind it. The biggest button, "Back to safety", takes the visitor back, and the only way forward is under "Details", through a small link that reads "Visit this unsafe site". Few people click it. Who would, when the browser itself says the site is unsafe?
In search the warning is quieter, but the effect is the same. One of two lines can appear under your result. Google's English help pages put them like this: "This site may harm your computer" and "This site may be hacked". The first means malware and comes together with the browser warning. The second means Google judges that somebody has changed your pages or added spam pages to your site. Neither one is a verdict on what you wrote. Both are about what somebody else put on your site.
A full-page warning can also come from an expired certificate, but in Chrome that page is white, with a red triangle. It is a different fault and a different door: the certificate warning is about the lock, "Dangerous site" is about the content. Who to call for which screen is set out in the article on a website that is down.
Why the owner finds out last
An intruder does not want you to see them. Their whole business depends on your site carrying on working and nobody repairing it. That is why much of today's malware is built to show itself only to chosen visitors.
- To someone arriving from search, not from a bookmark. You open your site from the address bar. The customer comes from Google and sees a different page.
- To the search crawler, not to a person. Spam links and foreign-language titles are shown only to Google's crawler, so that they reach the search results. A person sees a clean page.
- To everyone except the logged-in owner. If you are logged in to your site's admin, you are skipped. You are the one visitor to whom the site always looks clean.
The 2026 report from Patchstack, a security firm that focuses on WordPress, describes the same thing: the dominant malware families hide themselves so that security scanners and site owners often see a clean page. You check and everything is fine, because you are checking exactly the way the intruder counted on.
Why anybody attacks a small site at all, and what a broken-into site otherwise looks like, is written up separately. One conclusion matters here: if you want to know what Google thinks of your site, do not look at the site. Ask Google.

How to check for yourself
Three checks, all free and all Google's own.
The Transparency Report. Google has a public page where you can type in any address, and it answers whether it currently considers it dangerous. Search for the phrase "Google Safe Browsing site status". It is the fastest answer to whether your customer saw right, and you can ask it about somebody else's site too. If your own address comes back clean but the customer saw a warning, ask them what address was in the browser's address bar: it may be the place your site sent them on to.
Search Console. If your site is verified in Search Console, you will find a security issues section there. Google calls it the place the definitive answer comes from. It says what Google found and on which page. It is also where Google writes to you itself: a verified owner gets an email. If you have not connected Search Console, you will hear about it from your customers.
This is the moment to ask yourself: whose name is that account in, and whose inbox does its mail go to? If it belongs to the developer whose contract ended three years ago, the warning goes to them. Who owns your website and every account connected to it is a story of its own.
Search your own name as a stranger would. On a phone, logged out, with your company name. Look for a line under the result that you never wrote. How to search your own name through a stranger's eyes is written up too.
How to get off the list
You cannot get off the list by asking. The only way off is a clean site, and Google checks that for itself.
Do not just delete what you can see. The visible spam is the consequence. If nobody knows how they got in, it is likely to come back. According to the security firm Sucuri's 2023 data, nearly half of the sites it cleaned had at least one backdoor, and more than half of the infected databases held an admin account that did not belong there. Neither is visible from the homepage.
Close the door. Update everything that is out of date, change every password and go through the user accounts you do not recognise. Do it in one go and finish it. Google's guidance is plain that every issue has to be fixed on every page: a half-clean site does not win back half the trust.
Request a review. In Search Console's security issues section there is a button to request a review. Write down what was wrong and what you fixed. Google says a review takes from a few days to a few weeks. Do not send a new request before the previous one has an answer.
One rule is worth knowing before you hurry. Google's help warns that requesting a review before everything is fixed can slow down the next review or even get the site marked as a repeat offender. A repeat offender can only request a new review after 30 days. A quick half-clean-up is therefore not quick. It is simply the first of two attempts.
What we check ourselves
WebAdmin's site check asks the Google Cloud service Web Risk whether the address of a site's homepage is on Google's list of dangerous sites. Web Risk is a service any company may use, and we use it on the same terms as everyone else: this is not a partnership, and Google has not reviewed or endorsed our check.
The rest is our own check. It reads the homepage as the server hands it to our request, and looks there for the known signs of a break-in: loader code from known malware families, hidden blocks of links, and a Japanese title on an Estonian page. On WordPress, Magento, Joomla and Drupal it asks for the homepage twice more, once with a request that looks like a search crawler and once as an ordinary browser, and compares the answers. It also asks for a few well-known addresses where a configuration file, a log or a backup is sometimes left public by mistake, so that we can tell the owner if anyone can read it. We never store any secrets found there. Every request is an ordinary page request: we do not log in, fill in forms or try passwords.

We check the public websites of many Estonian companies, whether or not they are our clients. There are two reasons and we state both: the owner finds out last, and the work such a finding calls for is the work we sell. If you would rather we did not check your website, let us know and we will leave it out from then on.
When a site is on Google's list, we tell the owner that this is Google's assessment rather than ours, and show them how to verify it with Google directly. When we find signs ourselves, we say what we saw and where, and if it is only a suspicion, we say that too. We publish no such site's name and no count of how many there are. If you want to know what we saw on your site, write to us.
And the limit we always state. The check looks for signs of malware on the homepage only, and reading a site from the outside does not see into the server: a backdoor waiting among the files stays hidden, and so, sometimes, does what an intruder shows only to chosen visitors. When our check finds nothing, that means we saw no signs, not that the site is clean. Google says the same about its own list: some dangerous sites are missed and some safe ones end up on it by mistake.
We sell upkeep and still say: check for yourself
We sell website management, but this article teaches you to check for yourself. The one does not rule out the other.
All three checks described above are free and take less than an hour between them. Upkeep does not replace them, because upkeep does not make any site invulnerable. Nothing does. Upkeep makes it less likely that a door is left open, and if something happens anyway, there is somebody who knows where to start. But the Search Console account has to be in your name and its mail has to reach you, whoever keeps your site in order.
Make one check today
Open Google's Transparency Report page today and type in your address. It takes a minute. If the answer is clean, that is good news: Google does not consider your site dangerous today. It is not proof that all is well on the site, and not a promise for tomorrow.
Then look at whether your site is in Search Console and whose inbox its mail goes to. If the answer is "I don't know", that is a more important finding than the first. If the red screen ever appears, the difference is whether you hear about it from Google or from a customer.
Frequently asked questions
Google Safe Browsing is Google's list of web addresses it considers dangerous: pages that spread malware, try to trick visitors out of passwords or card details, or offer unwanted software. Chrome, Firefox and Safari use the list, as do Gmail and Google Search, so most visitors to a listed site see a warning instead of the site. Many listed sites do not belong to people with bad intentions; they are ordinary sites that somebody broke into.
Usually because your address is on Google's list of dangerous sites, and that usually means somebody has broken into your site and added something to it. Sometimes the listed address is instead the one your site sent the visitor on to. Check on Google's Transparency Report page whether the address is currently listed, and look in Search Console's security issues section for exactly what Google found. An expired certificate warning is a different fault: in Chrome that page is white, and the fix goes through your host.
Because much malware is built to show itself only to chosen visitors. It may appear only to visitors arriving from search, only to the search crawler, or to everyone except the logged-in owner. The owner, meanwhile, usually opens the site from a bookmark while logged in. So the site looks clean to the owner while a customer sees a warning or ends up somewhere else. That is why looking at your own site is not a check: ask Google itself, through the Transparency Report page or Search Console.
Only with a clean site. First find out how they got in, because if you delete only the visible spam, it comes back. Then update everything out of date, change the passwords, remove unknown user accounts and fix every issue found on every page in one go. After that, request a review in Search Console's security issues section and describe what you fixed. Google says a review takes from a few days to a few weeks, and requesting one before everything is fixed can make the wait longer still.
No. A clean answer says only that Google does not currently consider your address dangerous. Google itself says its list is not perfect: some dangerous sites are left off it and some safe ones land on it in error. A check from the outside cannot see into the server either, such as a backdoor among the files, and does not always see what an intruder shows only to chosen visitors. A clean answer is good news for today, not proof that all is well on the site.
Read next

Nothing happens to a website nobody touches, for a long time, and then everything happens at once. A walk through that time: what ages, what breaks quietly, and what your customer sees before you do.