NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Abstract tapered column illustration representing Paid Link Framing
Link-Based AttackYour backlink profile

Paid Link Framing

Situational Works only under specific conditions, and rarely otherwise.

The only inbound link attack that survives contact with a human reviewer, because a business buying links is a thing businesses actually do.

What paid link framing is

Paid link framing is a negative SEO attack in which the attacker buys links pointing at somebody else's site, and deliberately places them where the commercial nature of the placement is plain on the page: properties with a visible "write for us" or "advertise here" price page, paid guest-post farms, and sites already known to search engines as link sellers. The anchor text is keyword-rich and commercial. The articles look like articles.

The point is not the ranking credit. The point is the appearance of intent. Every other inbound link attack manufactures noise, and noise is what spam classifiers are built to discard. This one manufactures a pattern engineered to look like a deliberate purchase by the target, so that a human reviewer at Google — or a classifier tuned to buyer behavior — concludes the target bought the links and issues a penalty accordingly.

What separates this from forum profile spam, comment spam or link farm inclusion is one word: plausibility. Nobody believes a real business bought forty thousand foreign-language forum profiles. A reviewer might well believe a real business bought sixty contextual guest-post links on marginal industry sites, because that is exactly what a large number of real businesses do, every quarter, on purpose. The attack does not have to defeat Google's filtering. It only has to be credible.

This page describes the mechanism and the defense. It names no marketplace, vendor, network or service, and gives no placement procedure.

Why this one is situational and the other link attacks are not

Most of the pages on this site conclude that an inbound link attack has been neutralized, and I write those conclusions without hedging. This page does not reach that conclusion, and the reason is specific rather than atmospheric.

Three things separate paid link framing from the rest:

  1. It aims at a human, not only at an algorithm. The manual action for unnatural inbound links is issued by a person reviewing a link profile, and a person can be persuaded by a pattern a classifier would filter.
  2. Google runs a live classifier whose stated job is to identify sites buying links, and has never described how it separates a site that bought links from a site somebody else bought links for.
  3. The reliable damage is commercial and sits outside search entirely. A framed profile turns up in agency audits, acquisition due diligence and partner reviews, and no disavow file touches it.

Against that, the case for the attack being overstated is still strong. Gary Illyes of Google said at Pubcon Florida in March 2019 that he had examined hundreds of supposed cases of negative SEO and found none where it was the genuine cause. And no case has ever been publicly documented in which a clean site received a manual action for links a third party bought on its behalf — no Search Console screenshot with the target's non-involvement established, after fifteen years of the industry asserting it happens. That absence is why the verdict here is situational rather than documented: the conditions are narrow, the reliably damaged parties are sites that were already buying links, and the reliably damaged asset is commercial reputation rather than ranking.

Google's policy is written around an act of creation

The exact wording matters more here than anywhere else on this site, because the attack is an attempt to make a business look guilty of a specifically named violation. Read what the violation is.

Google's spam policies define it as something a party does:

Link spam is the practice of creating links to or from a site primarily for the purpose of manipulating search rankings.

The buying case appears among the examples — "Buying or selling links for ranking purposes," including exchanging money, goods or services for links or for posts containing links. And there is a carve-out that most people quoting this policy omit: Google states that buying and selling links is a normal part of the economy of the web for advertising and sponsorship, and that having such links is not a violation as long as they are qualified with rel="nofollow" or rel="sponsored".

Every clause of that policy describes a practice the site owner engages in. A business that did not buy the links has not engaged in the practice. That is not an inference or a sympathetic reading — it is what the text says, and it is the defender's central argument, made from Google's own document rather than from anyone's opinion about fairness.

Google states its intent on third-party action in two places, in its disavow documentation and in its guidance on competitors and ranking, and in both the wording is that Google works very hard to prevent actions on other sites from harming a website. Very hard is not cannot. I quote it as effort, because that is what it is.

SpamBrain classifies link buyers, and the question nobody can answer

This is the most important recent development for this attack, and it cuts both ways at once.

SpamBrain is Google's machine-learning spam detection system. In the December 2022 link spam update, announced on 14 December 2022 and completed on 12 January 2023, Google extended it so that, in Google's own description quoted in trade coverage of the announcement, it "can now detect both sites buying links, and sites used for the purpose of passing outgoing links."

Read the first half of that sentence from a framed site's point of view. There is now a live classifier whose explicit job is to identify sites buying links — which is precisely the classification this attack tries to induce. That is the strongest technical argument that paid link framing has something to aim at, and it did not exist before 2023.

Now read what Google says happens next. The described outcome of the update was that rankings "may change as spammy links are neutralized and any credit passed by these unnatural links are lost." The consequence is that the links stop counting. A framed site loses ranking credit it never had in the first place, because the attacker bought the links, not the site. The classifier can be triggered; the documented result of triggering it is the loss of a value the target was never receiving.

Between those two readings sits a question that no source answers. Google has never described whether the classifier attempts to distinguish a site that bought links from a site that was framed, or how it would. Not in the announcement, not in the documentation, not in any staff comment I have found. Anyone who tells you the classifier definitely does make that distinction is guessing, and so is anyone who tells you it definitely does not. I am not going to resolve it by asserting one side. It is the single largest unknown on this page and it belongs stated as such.

The lost-trust hedge, 1 November 2021

The strongest published statement supporting a non-mythical verdict on any link attack came from John Mueller of Google in a Search Central video question-and-answer session on 1 November 2021. He said that for the most part Google tries to recognize and ignore problematic links, and then added the condition that matters:

If our systems recognize that they can't isolate and ignore these links across a website, if we see a very strong pattern there, then it can happen that our algorithms say well we really have kind of lost trust with this website...

That is reported by Search Engine Land, and Mueller has separately said on X that where Google's systems cannot find useful signal after filtering spam, its algorithms can end up being skeptical about the site overall.

Give that its weight and no more. Two conditions govern it, and both are stated in the sentence itself. The links have to be hard to isolate, and the pattern has to be very strong across the site. Paid link framing is the one attack in this category where both conditions can plausibly be met, because the placements are on real sites, in real articles, in ordinary English, and they are not distinguishable by format from links a business legitimately earned. That is the opposite of a forum profile run, which is templated, marked ugc and trivially isolable.

What the hedge does not say is equally important. It does not describe a penalty, a manual action, or a demotion for links a site did not create. It describes a loss of confidence in a site where spam is effectively the whole recent signal. The case it fits is a site with almost no legitimate link acquisition, where purchased links dominate everything Google has recently seen. That is a narrow site profile, and it has never been publicly demonstrated on a site whose links were attacker-placed.

The manual action, and why its remedy assumes you are guilty

The mechanism this attack aims at has a specific shape, and a defender should know it exactly.

In Search Console, under Security and Manual actions, the relevant entry reads: "Google has detected a pattern of unnatural, artificial, deceptive, or manipulative links pointing to your site." Three properties of that mechanism matter here.

  • It is issued by a human. Google describes enforcement as detecting policy-violating practices through automated systems and, as needed, human review that can result in a manual action. A person reads the profile.
  • It is visible. The site owner is told, in writing, in the manual actions report. Any claimed penalty that does not appear there is not a manual action. That single fact resolves most framing panics in about ninety seconds, and it is the first thing to check.
  • Its documented remedy assumes the site owner did it. Google's guidance is to make a good-faith effort to remove the links first, then disavow what cannot be removed, then file a reconsideration request documenting the removal effort.

That third property is the real harm surface of this attack, and it is not a ranking effect. A framed site has to prove a negative — that it never bought links — inside a process designed for sites that did, and the process asks for evidence of removal work rather than evidence of innocence. Nothing in it has a field for "somebody did this to me."

One historical note, because older articles will mislead you. Google previously issued a partial variant of this action, described in trade coverage as impacting links rather than the site. That variant does not appear in Google's current manual actions documentation, which lists a single "Unnatural links to your site" entry. Whether Google retired it or merely stopped documenting it is not established, so treat older two-tier explanations as historically accurate and currently unreliable.

Recognizing framed placements

What makes this attack plausible also makes it detectable: the placements are too consistent to be editorial.

  • They do not look like spam. Start there. Real-looking sites, coherent English, contextual placement inside a genuine-looking article. Then open the linking site's own menu and look for a visible "sponsored post", "write for us" or "advertise" page. Sites that sell placements advertise that they sell placements.
  • First-seen dates cluster. Genuine editorial links accrete unevenly across years. A framing campaign appears as dozens of links across a few weeks, from unconnected domains, in one repeated format — a short article carrying one contextual link.
  • Anchor text is over-weighted to exact-match commercial phrases, far beyond anything an editorial pattern produces. This is the fingerprint most visible in a backlink tool's anchor report.
  • The links are followed. Sample them. What a placement seller is selling is the followed link, so uniform followed links across dozens of obviously commercial sites is itself the pattern.
  • Nobody can account for the articles. Framing campaigns generate copy about your industry that you never commissioned. Being unable to name who wrote a piece that links to you is evidentially useful later, so record it now.
  • Referral traffic is near zero. These links are placed for machines, not readers. A "guest post" that sends no humans is a tell.

The single most common innocent explanation, by a wide margin, is that an agency or contractor did buy links at some point and current management does not know. Rule that out before concluding anything. Also consider affiliate and syndication links, press-release distribution the communications team ran, and partner links negotiated years ago.

What to do, starting with an uncomfortable question

  1. Establish whether the business actually bought links. Ask every current and former agency, contractor and marketing hire, in writing, and keep the answers. This is awkward and it goes first, because the entire remediation path forks here and a defense built on a false premise collapses at exactly the worst moment.
  2. Check the manual actions report before touching anything. With no manual action outstanding, the correct action is usually none. Google's disavow guidance states that "in most cases, Google can assess which links to trust without additional guidance, so most sites will not need to use this tool."
  3. Preserve evidence immediately, dated. Search Console link exports, archived copies of the linking pages including their sponsored-post price pages, hosting and registration records, and the first-seen timeline. Sellers take pages down. This evidence has a short life and it is the foundation of both a reconsideration request and any legal claim.
  4. If a manual action exists, disavow and document. This is the one attack class where a disavow file is clearly appropriate, because Google's stated condition is met: a considerable number of artificial links that have caused, or likely will cause, a manual action. Make a genuine removal attempt first, because Google asks for evidence of one, and keep the correspondence.
  5. File the reconsideration request with the framing argument made explicitly and evidenced. State the first-seen clustering, the absence of any commercial relationship, the written vendor attestations, and the removal effort. Do not simply assert innocence. Reviewers read that assertion constantly and it carries no weight on its own.
  6. Handle the commercial surface separately, because it is a different problem with a different fix — see below.

What does not help: disavowing pre-emptively with no manual action; a link-detox subscription; filing a reconsideration request with nothing outstanding; buying countervailing links to dilute the profile, which converts a false accusation into a true one; and naming a suspected competitor publicly before counsel has looked at the evidence.

The damage no disavow file fixes

In my experience the framed link profile does its real work outside Google entirely, and this is the part clients are least prepared for.

A backlink report showing dozens of paid guest posts gets pulled by an acquirer's analyst during due diligence, by a platform partner during a compliance review, and by the next agency the business talks to. None of those readers has your first-seen dates, your vendor attestations or your side of the story. They see purchased links and price the risk accordingly. Losing a deal that way is a genuine cost with no search component at all, and no disavow file addresses it, because a disavow file is invisible to everyone except Google.

The fix is documentary rather than technical: a dated, written link-profile report the business can hand to a counterparty, setting out when the links appeared, that no commercial relationship exists with the sites, what the vendors attested to, and what was filed with Google and when.

On legal recourse, be realistic. I located no published decision, indictment or regulatory action arising from links bought by a third party to frame a target; the theories below are what counsel reaches for, and none has been carried to judgment on these facts. Lanham Act section 43(a), 15 U.S.C. section 1125(a), is the federal frame, and standing under it is governed by Lexmark Int'l, Inc. v. Static Control Components, Inc., 572 U.S. 118 (2014), decided 25 March 2014, which requires an injury to a commercial interest in reputation or sales flowing directly from the deception and drops any requirement that the parties be direct competitors — which matters here, because whoever placed the links is frequently not a competitor at all. The hard half is proximate cause: the injury has to flow from consumer deception, and a framed link profile mostly deceives a spam classifier and a due-diligence analyst rather than a buyer. State-law tortious interference, defamation where the placements assert false facts, and state deceptive trade practices statutes are the alternatives. All of them need a defendant a court can reach, and most targets cannot name one.

Frequently asked questions

I got an "Unnatural links to your site" manual action and I never bought a link. What now?

Before anything else, ask every current and former agency, contractor and marketing hire, in writing, whether links were ever purchased. Discovering mid-reconsideration that someone did is the worst possible sequence. Then archive the linking pages, including any sponsored-post price pages they publish, before you request removals — succeeding at removal destroys the proof you need. Make a documented removal effort, disavow what survives, and file a reconsideration request that sets out the first-seen clustering and the vendor attestations rather than simply asserting innocence.

Why is this rated situational when the other link attacks on this site are called neutralized?

Because it is the only one that is plausible. A reviewer looking at sixty contextual guest-post links on marginal industry sites sees something a great many real businesses genuinely do, which is not true of forty thousand forum profiles. It also aims at a human decision rather than only at a filter, and Google now runs a classifier explicitly aimed at sites buying links without ever describing whether it separates buyers from framed targets. Those are narrow conditions, but they are real ones, and none of the other inbound link attacks has them.

Can Google tell that someone else bought the links?

Nobody outside Google knows. Google has never described how SpamBrain distinguishes a site buying links from a site somebody else bought links for, or whether it attempts to. Anyone claiming a definite answer in either direction is guessing. What is documented is the outcome Google describes when the classifier fires: the links are neutralized and their credit is lost, which for a framed site means losing value it never received.

Should I disavow paid links I did not order?

Only against an outstanding manual action, and then with documentation. This is the one attack class where Google's stated condition for the tool is genuinely met. With no manual action outstanding, a disavow file does nothing useful and Google warns it can harm a site's performance in search if used incorrectly. Check the manual actions report first, every time.

How exposed am I if my company did buy links a few years ago?

Considerably more exposed than a company that never did, and that is the single strongest condition under which this attack works. The attacker's purchases blend into a genuine pattern, and a reviewer has no way to separate them. It is also why the first step is asking rather than assuming — a defense that says "we never bought links" and turns out to be wrong does more damage than the attack.

Top