What anchor text poisoning is
Anchor text is the clickable wording inside a link - the words a linking page chooses to describe the page it points at. Search engines have always used it as a description supplied by a third party, on the reasoning that what other people call your page is evidence about what your page is.
Anchor text poisoning is a link attack with a payload. Rather than merely pointing junk at a target, the attacker controls the wording and fills it with terms chosen to misclassify the site being linked to. The classic payloads are pharmaceutical, adult, gambling and counterfeit-goods terms, together with exact-match commercial keywords repeated at implausible volume.
Two different outcomes are being attempted, and conflating them is the most common analytical error on this subject:
- Topical misclassification. Flood a URL with anchors from a disreputable category and hope the engine's understanding of that URL shifts, or that it is filed with the neighborhood those words belong to. This is what most people mean today, and it is the weaker of the two.
- Over-optimization framing. Manufacture an inbound profile with an implausibly high share of exact-match commercial anchors, so the target looks like a site that bought links. This was the real threat between 2012 and 2016.
The fear people arrive with, and what supports it
Almost everyone who searches for this subject arrives with the same sentence: my backlinks say viagra, or casino, or worse, and I am about to be classified as that kind of site. It is a reasonable fear from the outside. It is also the version of the claim with the least evidence behind it.
Searching Google's published material and the leaked internal documentation, I found no primary or documented support for topical transfer - no source, in either place, describing a mechanism by which a third party's pharma anchors cause a target to be understood as a pharmacy. Google's spam policies address links created by or for the site that benefits, and say that "Sites that violate our policies may rank lower in results or not appear in results at all." They do not describe anchors imposed by strangers being charged to a target.
What Google does say about strangers is in the disavow documentation in Search Console Help, and it is blunt: "Google works very hard to make sure that actions on third-party sites do not negatively affect a website." That is not a promise, and it is not a guarantee of anything. It is a statement of engineering intent, published by the party that has to implement it, on the page site owners in this exact situation are most likely to open.
What the documented mechanism actually does
The clearest evidence on the question - can anchors on a link that gets ignored still hurt me? - comes from Google's internal Content Warehouse API documentation, published to a public code host in March 2024. In the module describing anchor statistics, the field badbacklinksPenalized is documented as: "Whether this doc is penalized by BadBackLinks, in which case we should not use improvanchor score in mustang ascorer."
Read that slowly, because it is the mechanism. The documented consequence of bad backlinks is that the system stops using the anchor score. Not that it applies a negative one. The poisoned anchors are withdrawn from the calculation rather than counted against the URL they point at.
That changes the shape of the damage entirely. The upper bound is the loss of whatever benefit your legitimate anchors were providing. That is a real cost, and on a page whose ranking leans on how other sites describe it, it can be a noticeable one. But it is a bounded, symmetrical cost, and it is a completely different thing from the outcome people fear. A withdrawn signal is not an inverted signal.
The caution here is not a formality. Documentation proves a field exists; it does not prove the field is consulted when a result is ranked, and some of its neighbors are marked deprecated. The reading above is mine, drawn from a field description rather than from anything Google has said out loud.
Why a crude payload is the easy case
The same leaked corpus describes the detection side, and it describes a comparison rather than a blacklist. The anchor spam module carries trustedTotal ("Total number of trusted sources for this URL"), trustedMatching ("Number of trusted anchors with anchor text matching spam terms"), phraseFraq ("Spam phrases fraction of all anchors of the document") and spamProbability ("Predicted probability of spam").
That is the shape of a classifier that measures suspect anchors against the anchors arriving from trusted sources for the same URL. If a business has a substantial body of trusted inbound anchors and not one of them contains the injected terms, the injected terms stand out as an anomaly attached to an event.
Paradoxically, the more outrageous the payload, the more reliably it is caught. Pharma or adult anchors pointed at a plumbing supplier are close to the easiest case such a classifier will ever see, because the divergence between the trusted anchors and the spam anchors is total. The genuinely difficult attack is the subtle one: plausible exact-match commercial anchors inside the target's own vertical, which look exactly like links the target might have bought. The payload that frightens people is the one that fails; the payload nobody worries about is the one that works.
What changed, and when
In 2012 Penguin ran as a periodic filter. It demoted a site and held it demoted until the next refresh, which could be a year away, and anchor ratio was among its strongest inputs. That combination made anchor poisoning genuinely dangerous: an attacker could move a ratio, and the target was stuck with the consequence on Google's release schedule rather than its own.
Penguin 4.0 ended that. On 23 September 2016 Google announced Penguin had become part of the core algorithm and stated the change in one sentence: "Penguin now devalues spam by adjusting ranking based on spam signals, rather than affecting ranking of the whole site." It added that Penguin's data now refreshes in real time, "so changes will be visible much faster, typically taking effect shortly after we recrawl and reindex a page." The recovery clock stopped being a release schedule and became a crawl cycle. That wording is quoted from two independent trade transcriptions published the same day as Google's post, whose body does not render to a plain fetch.
On 14 December 2022 Google extended SpamBrain, its machine-learning spam system, to link spam, stating that when "our systems nullify spammy links, the link credit that was previously generated is lost." Each change reduced the attacker's leverage over anchor ratios. The leak reflects the same posture: demotedStart and demotedEnd are documented as the start and end dates of a demotion period. What is described is a window that closes, not a mark on a domain.
The one experiment that isolates anchor text
On 7 June 2012 the agency TastyPlacement published a test against its own exact-match-domain microsite, pointing roughly 52,000 comment and forum-profile links at it, all carrying the same exact-match commercial anchor. The primary term first rose from third to second, then the site went "off the front page and essentially invisible"; of 51 secondary terms, 26 fell by an average of about nine positions. Their cost and source detail is deliberately omitted here, because it is a shopping list.
Three things about that experiment cut toward the current verdict rather than away from it. It ran in 2012, four years before site-level demotion for link spam ended. The target was a thin microsite with essentially no trusted anchor baseline. And the payload was exact-match commercial anchors in the site's own vertical - the subtle attack, not the crude one readers fear. The experiment that worked is not the attack that is usually described.
Set against it, in the same era: from October 2012 to May 2013 Nick Ker documented a live attack on his established firm's own site that escalated to 1,000 links a day aimed at his commercial terms, and reported on 30 July 2013 "No 'unnatural links' warning in Webmaster Tools, rankings are nearly the same as they were back in February." Same era, same class of attack, opposite result, and the variable was the target rather than the attack. I located no documented case after 2016 of anchor poisoning producing measured ranking loss on an established site - an absence of evidence found, not a proven negative.
Poisoned anchors, or a hacked site?
These two present identically to a non-specialist and demand opposite responses, so settle it before anything else.
- Run a site: search on your own domain for the injected terms. If the pharma or gambling words appear on your pages, you have a compromised site, not an anchor attack, and it is a far more urgent problem. Read Search Console Security Issues for the same reason.
- Search Console, Links, then Top linking text. This is the report that matters and the one to open first. It lists the wording most used to link to your site, and a real profile is dominated by your brand, your domain, and neutral phrases like "click here" and "read more." Foreign commercial, adult or pharmaceutical phrases in that list are the signature of the attack.
- Search Console, Security and Manual Actions. "No issues detected" means no human reviewer at Google has penalized you.
- Top linking sites and the exportable "Latest links" sample, for which domains supplied the anchors and when they arrived.
Commonly mistaken for anchor poisoning: a hacked site injecting spam pages; a core update; a scraper network republishing your pages with your own anchors intact; an expired domain in your niche that used to host spam; and ordinary long-tail anchor noise, which every genuine profile carries.
How it is undone, and the counter-move that makes it worse
- Rule out a compromise with the site: search and Security Issues.
- Check for a manual action - a penalty applied by a human reviewer at Google and shown to you in Search Console. If there is none, no penalty has been issued.
- Record the anchor distribution now, with dates, before it changes. Backlink indexes overwrite; your export does not.
- Do nothing, in most cases. The documented behavior is that poisoned anchors are demoted and withdrawn from scoring, and nothing you can do accelerates a process already running.
- Disavow narrowly, and only where Google's own two-part test is met: a considerable number of spammy links AND a manual action those links have caused or likely will cause. Both, not either. Disavow domains you have actually examined, not everything a vendor scores as toxic.
- Dilute rather than subtract. Because the mechanism compares your anchors against trusted sources, the durable defense is a larger body of legitimate anchors, not a longer disavow file.
The counter-move to avoid is the intuitive one: building exact-match anchors of your own to rebalance the ratio. That manufactures precisely the over-optimization pattern the attacker was trying to fake, which is to say it creates a real violation to cure an imagined one. Buying anchor toxicity scoring is the same error with an invoice attached: the score is a vendor's own invention, and the action it exists to recommend is the one you should be slowest to take.
Legal and platform recourse
Google provides no report channel for an anchor attack. The disavow tool is a request to ignore, not a complaint, which leaves ordinary civil and criminal law - and the theory that fits this vector is not the one a victim reaches for first.
"The defendant damaged my rankings" is the hardest claim to run, because it requires proving what Google's systems did in response to the links, and that evidence sits inside Google where a private plaintiff cannot reach it. The theories that avoid that problem are aimed at the words themselves. Anchor text is published text about a business, and it can be wrongful as published text whatever a search engine did with it: defamatory statements about a named person or business are analyzed as publication, against whoever published them; anchors that use another party's trademark to confuse or tarnish sit under the Lanham Act, 15 U.S.C. section 1125(a), with state consumer-protection statutes traveling alongside, which have to be matched to the forum where the harm is alleged.
Where the attack arrives with a payment demand, it becomes a law enforcement matter, and there the record is concrete: in United States v. William Laurence Stanley (N.D. Tex.) a self-described black hat search engine optimizer pleaded guilty to one Hobbs Act extortion count on 22 December 2015 and was sentenced on 5 January 2016 to 37 months in federal prison plus restitution, per the Justice Department's announcements. Carry the caveat: Stanley's conduct was threatening to publish disparaging content and fake reviews, not building links, so it is evidence that this class of conduct is prosecuted rather than a precedent about anchor text, and the figures come from press releases rather than the judgment. Where the attack turns out to be a hack, the Computer Fraud and Abuse Act, 18 U.S.C. section 1030, is engaged, because unauthorized access occurred - which is not true of link-pointing alone. No decided case holding an anchor-text campaign unlawful is cited here, and none should be assumed.
Frequently asked questions
My backlinks have adult anchor text. Will Google decide my site is adult?
I found no primary or documented evidence for that outcome, in Google's published material or in the leaked internal documentation. The mechanism that is documented does the opposite: bad backlinks cause the anchor score to be set aside rather than reversed. A crude, obviously foreign payload is also the easiest case for a classifier that compares your suspect anchors against your trusted ones.
Should I disavow links because of their anchor text alone?
No. Legitimate sites link with odd wording constantly, and Google's stated criteria require a manual action, not an unpleasant-looking report. Google warns the tool "can potentially harm your site's performance in Google Search results" if used incorrectly and that "most sites will not need to use this tool." Anchor text on its own is not a reason.
Should I build branded anchors to fix my anchor ratio?
Building genuine links because they are worth having is always fine. Building anchors specifically to move a ratio is not: it manufactures the over-optimized profile the attacker was trying to fake, and unlike the attacker's links, yours are attributable to you. Dilution through real coverage works. Ratio engineering creates the violation.
The spam terms are showing up on my own pages, not just in links. What now?
Stop treating it as a link problem. Spam terms appearing on your own URLs means your site is compromised, and that is an intrusion to be contained, cleaned and closed off before anything about anchors matters. Check Search Console Security Issues, then get the site cleaned and the entry point found.
How long does an anchor demotion last?
The leaked internal documentation describes a demotion period with a documented start date and end date, which suggests a window that closes rather than a permanent mark. Since Penguin became real-time in September 2016, changes have been described by Google as taking effect shortly after a page is recrawled and reindexed. Neither is a promise of a timeline, and I would not give you one.