NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Guide series

Negative SEO recovery, when recovery means five unrelated jobs

Before anything can be undone, it has to be established what was done - because the five things people call an attack have almost nothing in common except the traffic graph.

Recovery is not one job, and treating it as one is the expensive mistake

Negative SEO recovery is the work of restoring a site's search visibility after third-party interference, and the first thing it requires is knowing which of several unrelated problems you actually have. The phrase covers five different jobs with five different remedies, five different clocks and five different definitions of finished. They share a symptom — traffic fell — and almost nothing else.

That is not a pedantic distinction. It is the distinction that decides whether the work has any chance of helping. Cleaning injected files does nothing about a hijacked canonical. Reclaiming a canonical does nothing about a flooded review corpus. A disavow file does nothing about any of them, and does something mildly harmful about most. The single largest waste of money in this subject is not overpriced remediation; it is correctly executed remediation aimed at a problem the site does not have, which is indistinguishable from good work right up until it fails to change anything.

Recovery is also the half of the subject where the commercial incentive runs hardest against the reader, and that includes mine. Recovery is what I am paid for. A page on a recovery practice's site that told every visitor they needed recovery would be worth nothing, so read what follows with the appropriate suspicion and check the primary sources it points at.

The five shapes, and how to tell which one you are in

An intervention here means any deliberate act intended to change what search engines count toward your site — a removal, a disavowal, a takedown notice, a reconsideration request, a rebuild. Each shape below calls for a different intervention, and the first calls for none at all.

  • Nothing was done to you. By a wide margin the commonest finding. The fall dates to an update, a deployment, a tracking change or a shift in demand, and the spam links somebody found afterward were always there. There is nothing to recover from, and every intervention available can only subtract.
  • Something is on your own site. Injected pages, injected outbound links, content served to a crawler and not to a browser, a redirect that fires conditionally. This is a security incident that happens to have search consequences, and it is the one shape where search engines act against the victim — correctly, because your server is serving the spam. Recovery means a complete cleanup, closing the entry point, and then asking for a review.
  • Something in the index points somewhere else. A canonical or redirect hijack, where Google has been persuaded that another host is the authority for your content. Recovery means reclaiming the index's answer to that question, and the evidence is unusually clean, because Google will tell you which URL it selected.
  • Something on a platform surface changed. An edited business listing, a review flood, a copyright removal filed against your URLs. Recovery here runs entirely through the platform's own process, on the platform's own timetable, with no search-side lever at all.
  • Inbound links only. Hostile links exist, nothing else is wrong, and the manual actions report is clean. The correct action is to export the evidence, date it, keep watching, and stop.

Sorting yourself into one of those five is not a preliminary. It is the majority of the work, and it is done with the first-party reports rather than with a backlink product. Where the sorting itself is the problem, that is the subject of detection rather than of this page.

Establish, then act - and why the order is not negotiable

Every recovery runs in the same sequence regardless of which shape it turns out to be: establish what happened, establish what it touched, then remediate in the order the finding dictates. Reversing that has three specific costs, and they compound.

Interventions here are asymmetric. Most of what a suspected victim can do subtracts something. A disavow file discards signal permanently enough that Google publishes no timeline for getting it back. A crawler block discards traffic. A rewritten page discards whatever it was ranking on. When every available move can only reduce, moving before the diagnosis is a wager with no upside.

Acting destroys the evidence. Cleaning a compromised site removes the record of the compromise, and the compromise is the part with the most law behind it. Where speed and preservation genuinely conflict — the site is live and damaging customers — an image taken before the cleanup resolves it in minutes and costs nothing.

Acting inside an open window manufactures a false story. If something is remediated while a ranking update is still rolling out, whatever happens next gets attributed to the remediation. That is how recovery case studies are produced, in this industry and in others, and it is why the same interventions keep being sold after they stop working. Google's own advice is to wait a full week after an update completes before drawing conclusions from Search Console, and the reason is exactly this: a half-applied change read as a finished one is a wrong reading that then gets acted upon.

For link attacks, the correct action is usually none

This is the section most readers arrive for, and the answer is the one nobody is selling. If hostile links have appeared and the manual actions report is clean, the indicated response is to record what you found and leave it alone.

The argument rests on published primary sources rather than on temperament. Google's disavow documentation states its criteria as two conditions joined by and: a considerable number of spammy, artificial or low-quality links, and a manual action those links have caused or are likely to cause. A clean report fails the second condition outright. The same page calls the tool an advanced feature, says most sites will not need it, and warns that incorrect use can potentially harm your site's performance in Google Search results. Google structured its own instructions so that deciding whether the file is necessary comes before creating one.

Behind that sits the mechanism. The Google Search Central Blog — Google's official channel for announcing changes to its ranking and spam systems, and the place where the dates on this subject are established — recorded on 23 September 2016 that Penguin had entered the core algorithm and that spam was thereafter devalued rather than charged against the whole site. The December 2022 link spam update on the same channel described spam links as nullified outright. A link that confers nothing also costs nothing, and there is no state to recover from.

John Mueller, a Search Advocate at Google and one of the small number of named staff who answer public questions about ranking systems, has said the same thing more bluntly and against Google's own commercial interest in appearing responsive. On 12 May 2020 he said that negative SEO is not the reason the disavow tool exists and that he could not recall a case where a site had needed one for it. On 31 January 2023 he described the businesses on both sides of that trade — the agencies building the links and the agencies charging to disavow them — as making things up and cashing in on people who do not know better, and recommended spending the time building the site up instead.

One honest counterweight, because a page that quotes only the reassuring half of the record is a sales page written backwards. Google's own qualification is that where its systems cannot isolate the spam from anything legitimate — a site whose entire profile is indistinguishable from spam — trust in that site can be lost. That describes a site with nothing genuine to protect, not an established site under attack. The full argument, including why no removal-outreach success rate exists anywhere, is in removing negative SEO links; the file itself, its format and its failure modes, is in the disavow file guide.

What recovered means, and the two things it is not

Recovery has an ambiguity in it that costs people months, and it is worth resolving before any clock is started.

Eligibility is not position. A manual action being revoked restores a site's eligibility to rank. It does not restore a ranking, and nothing in Google's documentation promises that it will. The same applies to a security warning lifting, a copyright removal being reversed, or a disavow list being incorporated. Each of those is a discrete event with an observable end. Ranking is not an event; it is a continuous reassessment with no queue and no completion notice.

A remedy is not a re-evaluation. Mixing the two produces the estimates that make this subject unmanageable — a published review window with an invented recovery window added to it, presented as a single number. The sum inherits the accuracy of the invented half. Google publishes review times for several scenarios and publishes nothing at all about how long visibility takes to return or whether it returns. Where I have no figure, the correct thing to say is that there is no figure, and how long recovery takes collects the published timelines beside the gaps.

There is also a mechanical fact that settles more confusion than any advice about writing a good appeal: the control that submits a reconsideration request exists only inside a manual action panel. If the report shows no action, there is no panel, no control, and nothing for a reviewer to reverse. An owner who cannot find the button has been given the answer. Manual actions and reconsideration requests covers what the process does when it is genuinely the right one.

Where recovery is real work, and what it consists of

Three of the five shapes involve substantial remediation, and it is worth being concrete about what that means, because the honest version and the sold version differ.

A compromised site. Preserve first — an image, the logs, the current state — then find every affected file rather than a sample, close the way in, rotate the credentials that were in scope, and only then request a review. A review that finds anything left behind fails, and a failed review buys you the whole waiting period a second time. Repeated failed reviews are the single largest driver of long recoveries, and they are self-inflicted. Make the fixed pages crawlable while you are at it: blocking the affected directories before a review hides the fix exactly as well as it hid the problem.

A hijacked canonical or redirect. The remediation is on your side of the line more often than owners expect — self-canonicalization, one hostname answering, an accurate sitemap, being crawled promptly — plus removal pressure on the offending host. Being the version Google reaches first is the most effective defense available to a victim, and it is unglamorous configuration work rather than a legal instrument.

Copied content. Establish which URL Google selected before anything else, because most reports of a copy outranking an original do not survive that check. If the copy costs nothing, it deserves nothing. If it does cost something, a notice to the host removes the content and a request to the search engine removes the results, and those are different outcomes that get conflated constantly. Recovering from content scraping sets out the order, including the misrepresentation exposure that an overreaching notice carries.

What lengthens a recovery, almost always from the inside

Long recoveries are rarely long because Google is slow. They are long because the clock kept being restarted. In rough order of how much time they cost:

  1. Requesting a review before the fix is complete, or before it is crawlable.
  2. Resubmitting while a request is open, which Google explicitly asks people not to do and which accelerates nothing.
  3. Treating a rejection as a verdict on the request rather than as information about the fix, and refiling the same case unchanged.
  4. Remediating inside an update window, then having to redo the analysis once the rollout finishes.
  5. Disavowing in bulk at domain level from a tool export, which discards earned links on a vendor heuristic and is not practically reversible.
  6. Waiting for a completion event that does not exist, because the thing being waited for is a ranking rather than a decision.

Against that, what genuinely shortens elapsed time is unglamorous: fix completely, make the evidence checkable in two minutes, file once, and do nothing where nothing is wrong. No expedited channel into any review queue exists, and no practitioner — including me — can promise that rankings, traffic or revenue return. What can be promised is that the work is described honestly and that the parts with no evidence behind them are labeled as such.

The recovery that is not a recovery

The hardest conversation in this work is with an owner whose diagnosis comes back clean. Traffic fell, the fall is real, the money lost is real, and the finding is that nobody did anything to them. The instinct is to keep looking until something is found, and something always is, because every site has spam links and a competitor who improved.

What that owner needs is not a remediation. It is the recognition that a ranking loss with an ordinary cause has an ordinary remedy — better pages, a faster and cleaner site, links earned rather than defended — and that no cleanup restores traffic a cleanup did not cost. The sentence worth writing down: if the drop lands on a day Google confirmed an update and the rest of the market moved with you, nothing was done to you, and paying anyone to clean up your links will not bring the traffic back.

Working in search since 1996, the pattern I keep meeting is that the sites which genuinely lost something to a third party had first lost control of something small — a stale login, an abandoned extension, a DNS record nobody could explain. The sites that merely received a pile of junk links carried on ranking. That is the whole of the recovery frame, and it is also the argument for spending the budget on prevention rather than on protection from the thing that mostly does not work.

Frequently asked questions

How do I recover from a negative SEO attack?

By first establishing which of five unrelated problems you have. If your own site is serving injected content, recovery is a security cleanup followed by a review request. If the index prefers another host for your pages, it is a canonicalization fix. If a platform surface was edited, it is that platform's process. If hostile links appeared and nothing else is wrong, recovery consists of documenting them and doing nothing. The remedies do not overlap, so the sorting step is not optional.

Thousands of spam links appeared. What should I do?

Check the manual actions report first. If it reads no issues detected, you fall outside Google's own criteria for the disavow tool, which require both a considerable volume of spammy links and a manual action they have caused or are likely to cause. Export the referring domains with their first-seen dates, store the file with its date intact, and leave the links alone. Google's documented behavior since 2016 is to devalue this material rather than charge it against the site it points at.

Will a reconsideration request undo an algorithmic drop?

It cannot, and mechanically it cannot even be filed. The submission control exists only inside a manual action panel, so a clean report means there is no panel and no button. Even if there were, a favorable review would change nothing, because no action is suppressing the site. An algorithmic reassessment leaves no entry, no message and no queue, and the remedy for it is the site rather than a request.

How long should recovery take?

Google publishes review windows for several scenarios - several days or weeks for a reconsideration review, a few days to several weeks for a security review, and 72 hours for a browser warning to lift once a site is confirmed clean. It publishes nothing whatever about how long rankings take to return, or whether they return to where they were. Any specific recovery figure you have been quoted came from the person quoting it, not from a search engine.

Can recovery be guaranteed?

No, and a guarantee is the clearest signal to walk away. Whether a site regains a position depends on continuous reassessment that nobody outside Google can inspect, on what competitors did in the interval, and on whether the loss had a third-party cause in the first place. What can be committed to is the diagnosis, the remediation and an honest account of what the evidence supports - not an outcome inside somebody else's ranking system.

My rankings fell and the diagnosis came back clean. Now what?

Then the loss is real and the attacker is not, and the useful response is the ordinary one: improve the pages, fix what is slow or broken, and earn links rather than defend against them. This is the least welcome answer in the subject and the most common correct one. Buying a cleanup for an update-shaped drop tends to produce a false success story months later when the next update restores some visibility, which is how ineffective remedies keep their reputations.

Top