What a manual action is, and what a reconsideration request is
A manual action is a penalty applied to a site by a human being at Google. The mechanism is not inferred, it is documented: Google's Manual Actions report help page says an action is issued when "a human reviewer at Google has determined that pages on the site are not compliant with Google's spam policies," and that "if a site has a manual action, some or all of that site will not be shown in Google search results."
A reconsideration request is the only channel by which a manual action is lifted. Google defines it as "a request to have Google review your site after you fix problems identified in a manual action or security issues notification." There is no second route, no appeal above it, and no escalation path.
A penalty in the ordinary sense of the word — a deliberate, targeted downgrade imposed on one site — is what a manual action is. It is not what a core update is, and the two are constantly confused because they feel identical from the traffic graph. Everything on this page depends on that distinction, and getting it wrong is the most expensive error in this entire reference.
The control only exists inside the panel
Here is the mechanical fact that resolves most of the confusion on this subject, and it is worth more than any amount of advice about how to write a good request.
The Request Review control lives inside the manual action description panel, on the Manual actions report. When there is an action, the report shows an entry that expands into a panel naming the issue type, the affected scope, and that control. When there is no action, Google's documentation says "you'll see a green check mark and an appropriate message" — and there is no panel, so there is no control, so there is nothing to file.
Three consequences follow mechanically, and none of them is a matter of opinion:
- A site owner who is convinced they have a penalty but cannot find the button has, in that moment, been given their answer. The missing button is the finding. There is no penalty.
- A reconsideration request filed through any other channel is not a reconsideration request. Text emailed to Google, posted in a forum, or submitted through an unrelated form does not enter the review queue, because the queue is fed by that control and nothing else.
- Even if such a request could be filed, it would achieve precisely nothing. There is no outstanding action for a reviewer to revoke. A favorable review of a site with a clean report changes no ranking, because nothing was suppressing the ranking to begin with.
An algorithmic drop is invisible by design: no message in the Search Console message center, no report entry, no notification, no reviewer, and nothing to reconsider. Google publishes no appeal, no form, no queue and no timeline for algorithmic re-evaluation, which happens continuously as pages are recrawled. The remedy for an algorithmic drop is not a request. It is the site.
For a suspected link attack this is the whole of the triage: open the Manual actions report first, and if it is clean, stop. The guide to removing negative SEO links covers what to do from there, which is mostly nothing.
How you are told, and how people miss being told
Google's Manual actions documentation puts it this way: "we will notify you in the Manual actions report and in the Search Console message center." Both channels route to the email address on the verified Search Console account.
That is why an unmonitored verification email recurs as a theme across this whole reference. A manual action issued to an address nobody reads is a manual action nobody knows about, and the site owner spends the next six months diagnosing an algorithm. Before anything else: confirm who is verified on the property, confirm the address is monitored, and add yourself if you are not on it.
Read the scope as carefully as the type. An action states whether it covers the whole site or a specific set of pages or URL patterns, and both the remedy and the review follow the stated scope rather than your theory of what happened.
What a manual action is commonly mistaken for: a core update, an indexing problem, a noindex or robots.txt accident, a migration with unreconciled redirects, a Search Console property change, or a security issue — which lives in a different report entirely. Confirm which report the entry is in before doing anything at all.
The action types that arise when sabotage is suspected
Google's documentation lists more than twenty action types. Do not trust any published count of them, including one you find here — the enumeration differs between renderings of the documentation. These are the ones that come up when a site owner suspects an attack, quoted verbatim:
- Unnatural links to your site — "Google has detected a pattern of unnatural, artificial, deceptive, or manipulative links pointing to your site." This is the only action type for which inbound-link work is the remedy, and the only one a third party could plausibly provoke by pointing links at you. Since Penguin 4.0 in September 2016 it is also, on Google's stated position, rare against sites that did not build the links themselves. See spam link attacks.
- Unnatural links from your site — "Google has detected a pattern of unnatural artificial, deceptive, or manipulative outbound links on your site." In a sabotage context this is the signature of injected outbound links on a compromised site. The remedy is cleaning your own pages, not disavowing anything: see hacked site injection.
- User-generated spam — "Google has detected spam on your pages submitted by site visitors. Typically, this kind of spam is found on forum pages, guestbook pages, or in user profiles." This is the action a site hosting an open comment or profile system receives when an attacker fills it, and the victim genuinely owns the problem. See blog comment spam attacks.
- Site abused with third-party spam — "Google has detected a significant portion of your site being abused with spam that violates Google's spam policies and adds little or no value to the web."
- Cloaking and/or sneaky redirects — "Your site may be showing different pages to users than are shown to Google, or redirecting users to a different page than Google saw." Frequently the first evidence an owner gets that they have been hacked, because the cloaking is aimed at Googlebot and invisible in their own browser.
- Hidden text and/or keyword stuffing — "Some of your pages may contain hidden text or keyword stuffing, techniques that are not allowed by Google's spam policies."
- Thin content with little or no added value — "Google has detected low-quality pages or shallow pages on your site."
Manual actions are not security issues, and Google keeps them in separate reports. The Manual Actions report covers, in Google's words, "manually detected issues with a page or site that are mostly attempts to manipulate our search index, but are not necessarily dangerous for users." Hacking, malware and phishing appear in the Security Issues report, which has its own Request Review flow. A compromised site can carry both at once, and each needs its own review; filing one in the other's flow accomplishes nothing.
Google's standard for a request, quoted
Reconsideration is a real documented process with a documented outcome, so nothing here should be read as skepticism about whether it works. What deserves skepticism is how often it is the right tool — it applies to a small minority of the sites whose owners believe they need it.
Google's standard is short and testable. A good reconsideration request "does three things":
Explains the exact quality issue on your site.
Describes the steps you've taken to fix the issue.
Documents the outcome of your efforts.
And the completeness requirement, which is the sentence most often ignored: "Fix the issue on all affected pages. Fixing the issue on just some pages will not earn you a partial return to search results."
On timing, Google states that "most reconsideration reviews can take several days or weeks, although in some cases, such as link-related reconsideration requests, it may take longer than usual to review your request," and that "you will be informed by email when we receive your request, so you'll know it is active." The recovery time guide collects those figures with the others Google publishes, and notes where it publishes none.
Filing repeatedly: what is documented, and what is not
Google's instruction is explicit: "Please don't resubmit your request before you get a decision on any outstanding requests."
What is documented is that resubmitting while a request is pending does not accelerate a review and that Google asks you not to do it. What is not documented, and must not be asserted as though it were: Google publishes no stated penalty, ban, rate limit or blacklist for repeated filing, and no data exists on whether repeat filers are reviewed more slowly. Anyone telling you there is a documented sanction is asserting more than the record supports, and on a subject where people are frightened that is worth correcting rather than repeating.
The honest statement is narrower and still decisive. Repeated filing buys nothing, contradicts Google's stated instruction, and spends the one opportunity a site has to make its situation legible to a human reviewer on a case that reviewer has already rejected.
The real cost is easier to overlook. A rejected review means the fix was incomplete. Filing again without changing anything reproduces the rejection exactly. The loop that keeps sites suppressed for months is almost always fix-partially, file, get rejected, file again — not any adverse action by Google.
The procedure, in order
- Confirm the action exists and read its exact type and scope. If the report is clean, stop here.
- Read Google's spam policies for Google web search for the specific violation cited. The spam policies are Google's published rules for what may not appear in its index, and the request has to answer the policy that was actually named rather than the one you assume was meant.
- Find every affected page, not a sample. Partial fixes do not earn partial reinstatement, in Google's own words.
- Fix it. For an inbound-link action: remove what can be removed, then disavow the documented remainder using the disavow file. For an injected-content or outbound-link action: clean the site and close the entry point. For user-generated spam: delete the spam and fix the system that admitted it.
- Make the evidence visible to a reviewer. Fixed pages must not require a login, sit behind a paywall, or be blocked in robots.txt. Blocking the affected directories before the review is a common self-inflicted wound: it hides the fix exactly as well as it hid the problem.
- Write the request to the three-part standard. The exact issue, named in Google's vocabulary, without arguing about whether it was fair. What you did, specifically and countably — dates, URL counts, what was removed, what was disavowed and why the remainder could not be removed. The outcome, with evidence a reviewer can check in minutes: a linked sheet of every URL and its status, a dated outreach log, the contents of the disavow file pasted in. Then one short paragraph on what prevents recurrence. Google's own example wording from the security track sets the tone — "I removed the 3rd-party code that was distributing malware on my website and replaced it with an updated version of the code" — concrete, past tense, checkable.
- File once and wait for the decision.
- If rejected, treat it as information about the fix, not about the request. Find what was missed before filing again.
What does not help: arguing that a competitor caused it, because the reviewer's question is whether the site is now compliant and not who is to blame; attaching a vendor's toxicity report, which is an opinion Google did not ask for; disavowing without filing the request, because the disavow alone never lifts an action; and emailing Google outside the reports, which reaches no queue.
There is no appeal beyond this, and that is the honest answer
A manual action is Google's editorial judgment about its own index. There is no regulator to appeal to, no form beyond the reconsideration request, and no legal theory in the United States under which a site is entitled to a ranking. That is worth stating plainly, because a great deal of money is spent by people looking for a door that is not there.
Where a third party's conduct caused the situation, the recourse runs against that party rather than against Google — the litigated theories, with their elements, are on the spam link attack page. Bing operates its own webmaster tooling with its own review channels, and a Google reconsideration has no effect there; I have not verified Bing's current documentation in this pass and will not describe its process on that basis.
Frequently asked questions
I think I have a Google penalty but I cannot find the Request Review button. What now?
You have your answer. The control exists only inside a manual action panel, so if the Manual actions report shows a green check mark there is no panel, no button and no action. Whatever caused your traffic loss was not a manual action, and no request of any kind will reverse it. Date the drop in Search Console Performance and compare it against announced Google updates before doing anything else.
Can I file a reconsideration request if I do not have a manual action?
Mechanically, no — the submission control does not exist outside an action panel. And if it did, it would achieve nothing: there is no outstanding action for a reviewer to revoke, so a favorable review would change no ranking. This is the single most common wasted action in negative SEO recovery.
How is a manual action different from an algorithmic drop?
A manual action is issued by a human reviewer, appears in the Manual actions report, and generates a message in Search Console and an email. An algorithmic drop produces none of those: no entry, no message, no reviewer, no queue and no appeal. Both look identical in a traffic graph, which is why the report rather than the graph is what decides it.
A competitor pointed spam links at me. Should I say that in the request?
Say it in one sentence at most, and spend the rest of the request on evidence. The reviewer's question is whether the site is compliant now, not who is at fault. A request that argues the case rather than documenting the fix reads, to someone working a queue, like a request with nothing to show.
Will filing repeatedly get my site banned or deprioritized?
Google publishes no sanction of that kind — no ban, no rate limit, no documented slower queue — and claims to the contrary are unsourced. What Google does state is that you should not resubmit before you get a decision on an outstanding request. Repeated filing buys nothing, and a rejection is information that the fix was incomplete rather than a reason to send the same case again.