Left Click

Flagged for malicious software?

Almost every legitimate business that gets this has been hacked rather than caught. That matters, because the two situations are different policies with different remedies, and appealing through the wrong one fails no matter how good the appeal is.

No cost. A straight answer within one business day on which of the two you are in.

Read the notice carefully

Two policies, and the difference decides where you appeal.

Malicious software and compromised sites are separate policies. Most pages about this treat them as one thing, which is why so many appeals go to the wrong place.

Compromised site

Your code was altered by someone else

Google defines a compromised site as one whose code has been manipulated to benefit a third party without the owner's knowledge, usually harming visitors. A hacked site with an injected script, redirect or skimmer is this.

It is the common case for legitimate businesses, and it is enforced differently from the deliberate policy. The remedy runs through Google Search Console and Safe Browsing rather than the Google Ads appeal form: clean the site, then appeal to have the domain removed from the Safe Browsing threat list.

Google states that once that process completes successfully, the site or landing pages should automatically be re-enabled to serve ads. That is unusual and it is worth knowing, because it means the Google Ads appeal is not always the thing standing between you and running again.

Malicious software

Google believes the harmful behaviour is intended

This covers software that harms or gains unapproved access to a device or network, forced redirects to infected destinations, and ads built to steal credentials from the page they appear on.

Google classes violations of this policy as egregious, which means suspension on detection with no warning and no strike sequence.

Legitimate businesses do land here, usually because the compromise was severe or long-running enough to look deliberate. The appeal has to establish that it was not, with evidence of the compromise and of the cleanup.

Not sure which policy your notice names?

Get it reviewed

Before you do anything else

Four things that keep a malware flag in place.

  1. 01

    Appealing in Google Ads before Safe Browsing is clear

    For a compromised site the remedy runs through Search Console, with an appeal to remove the domain from the Safe Browsing threat list. Submitting a Google Ads appeal while the domain is still listed argues with a system that is not the one holding you.

  2. 02

    Cleaning only what you can see

    Google assesses the ad, the landing page and everything the page loads: scripts, iframes, content delivery networks, third-party forms, and any redirect that follows. One compromised third-party script is enough to keep the flag in place after the visible site looks fine.

  3. 03

    Assuming a clean scan means clean

    Google's own guidance notes that its Safe Browsing tool might not catch everything and is a starting point rather than a verdict. A single scan returning nothing is not evidence that the compromise was found.

  4. 04

    Restoring from a backup and stopping there

    If the entry point is still open, the injection returns, often within days. A second flag on the same domain is a materially harder conversation than the first.

If one of these has already happened, the case is harder but not over.

Get it reviewed

How this works

The process we go through

01

The questionnaire

Six questions about the notice and what changed in the business before it arrived. Answered within one business day with a read on the likely cause and whether it is worth pursuing.

02

Account access

If it is worth pursuing, read-only access to the account and a look at the site. The real cause is rarely the one the advertiser expects, and it is not visible from outside.

03

Root cause and remediation

What actually triggered it, what has to change on the account and the site before an appeal can succeed, and the evidence to submit alongside it.

04

The appeal

Drafted and submitted once the account is genuinely ready for re-review, then managed through to the decision.

Get it reviewed

Six questions. A straight answer on whether it comes back.

The notice you received and what changed in the business before it arrived are usually enough to identify the cause. No account access needed to answer these, and you get a reply within one business day.

The cause is usually a change, not a campaign.

A reply within one business day, from me. No cost, no obligation, and if it isn't worth pursuing you'll be told that plainly.

Prefer email? rob@leftclick.co.nz

Rob Kramers, Left Click
Rob KramersLeft Click

Nineteen years in search marketing. Eight of them running my own agency, sold in 2021. Four years managing seven-figure United States advertising accounts in consumer credit, a category Google scrutinises hardest.

In that industry, compliance, suspensions, disapprovals and verification reviews are a frequent occurrence and a condition of operating.

You deal with me directly, from the first reply through to the decision.

In search marketing, in-house, agency and freelance
19 years
In regulated categories, where policy review is routine
9 years
Same time zone, one person, no account managers
NZ & AU

Questions

Questions and answers.

Can you guarantee reinstatement?

No. Google decides. What can be committed to is an honest read on whether the case is arguable, a correctly identified root cause, and an appeal built around the actual detection rather than around fairness.

How do I tell which of the two policies I am in?

In Google Ads, filter policy details for compromised site. Google sometimes names the compromised domains it detected, which is both the confirmation and the start of the fix. If that filter returns nothing and the notice names malicious software, you are in the other one.

Being hacked was not my fault. Is that a defence?

Not on its own. It changes which policy applies and therefore the route and the urgency, but Google's position is that the end result for the user is the same either way. The appeal has to show the compromise was found, removed, and the entry point closed.

My developer says the site is clean.

That is worth testing rather than trusting. Google's check covers everything the page loads, including third-party scripts, content delivery networks and embedded forms, and it follows redirects. A site can be clean in the sense your developer means and still fail.

Will my ads come back automatically?

For a compromised site, Google states the site or landing pages should automatically be re-enabled to serve ads once the Safe Browsing removal process completes successfully. If they do not, something in the chain is still flagged.

Should I set anything up to catch this earlier?

Yes. Google Search Console can send email notifications for security issues on your property. Most businesses find out from a suspension rather than from the notification, and the notification is free.