NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Detecting an attack

The six symptoms people read as an attack, and what each one usually is

Every symptom below has a duller explanation that is more likely than sabotage. Here is the duller one first, then the observation that separates the two.

The list Google publishes, and what is missing from it

Google maintains a page whose entire purpose is to explain why a site's search traffic falls: Debug Google Search traffic drops, last updated 10 December 2025. It names seven causes - algorithmic updates, technical issues, security issues, spam policy violations, seasonality and changing interests, site migrations, and reporting glitches.

Sabotage by a third party is not on that list. Be exact about which argument that is. It is not Google denying hostile links get built; the disavow documentation says separately that Google "works very hard to make sure that actions on third-party sites do not negatively affect a website," which concedes they happen. The absence means something narrower and more useful to you this morning: among sites that lose traffic, sabotage is rare enough that the page Google wrote to triage them does not spend a paragraph on it.

So every symptom here runs in one order - innocent explanations, then the attack explanation, then the discriminator that separates them. That is not politeness toward whoever you suspect. It is arithmetic. Read the attack explanation first and you will find evidence for it, because every site on the web has some spam links, some unindexed pages, and a competitor who moved up this month.

One more frame from the same page, and it is the most under-used diagnostic in the subject. Google illustrates four shapes of drop, captioned "Large drop from an algorithmic update, site-wide security or spam issue," "Seasonality," "Technical issue across your site, changing interests," and "Reporting glitch." The outline of the curve carries more information than the depth of it. A cliff on one day is a discrete event; a ramp over two weeks is a rollout; a repeating sawtooth is a season.

Symptom one: the rankings fell overnight

Innocent, in order. A confirmed ranking update landed that day - and Google's published update history carries a completion date as well as a launch date, so reading only the launch column is how people conclude "that was weeks ago, this must be something else" while a rollout is still running. A deployment: a template change that dropped canonical tags, a staging noindex shipped live, URLs changed without redirects. A robots.txt edit - or, worse and less obvious, a robots.txt that stopped answering, because Google "requests this file frequently, and if the request doesn't return either a valid file (either populated or empty) or a 404 (file does not exist) response, then Google will slow or stop crawling your site until it can get an acceptable robots.txt response." A 500 there, thrown by a firewall or a bot-blocking product installed because an attack was suspected, suppresses crawling site-wide. It is this subject's cleanest case of the defense causing the feared damage. Then an expired certificate, invisible in a browser holding a cached session.

Attack. Narrow: a hacked-site injection, a canonical or 302 hijack pointing the index at another host, or a Safe Browsing flag after a malware injection. Every one is a change to your own site or to how Google resolves it - not a link aimed at you from outside. A pure inbound link campaign does not produce a one-day cliff, because discovery, reprocessing and consequence are not same-day events.

Discriminator. Date the fall to the day, check that date against the update history, open the Manual actions report, then ask what you changed that week. That last question resolves more suspected attacks than any backlink tool ever has. The dating procedure is attack or algorithm update.

Symptom two: referring domains spiked

Innocent, in order. The tool discovered links; it did not witness their creation. Third-party indexes crawl in batches and plot discovery dates, so a vertical line is frequently the vendor's crawl schedule rather than an event in the world - the leading source of false alarms in the subject. Then scraper republication, which copies your outbound links and often links back, producing junk referring domains with no attacker behind them. Then syndication, a press pickup, or your own campaign going live. Then domain-level noise: an expired-domain network re-pointing, a directory dump, a theme footer credit propagating.

Attack. A deliberate spam link run, link farm inclusion, PBN pointing, or a comment and forum run. These are real and they are purchased. They are also, on current evidence, mostly consequence-free - which is a different claim from saying they do not happen.

Discriminator. Not the domain count. Search Console, Links, External links, Top linking text. A spike with an ordinary anchor distribution - brand names, bare URLs, "click here" - is noise. A spike concentrated on commercial-exact or off-topic anchors is anchor text poisoning. Distribution is the signal; volume is not. Two limits Google states on that report: it is a sample, "not a comprehensive list of every link on your site," and it "doesn't specify if a link is marked as nofollow," so follow status cannot be read from it at all.

And the part no cleanup vendor volunteers: even a confirmed hostile spike is usually harmless. Announcing Penguin 4.0 on 23 September 2016, Google wrote that it "now devalues spam by adjusting ranking based on spam signals, rather than affecting ranking of the whole site." A nullified link confers nothing, which is exactly why it costs nothing.

Symptom three: pages fell out of the index

Innocent, in order. The site: count was never a measurement: in Google's words the operator "doesn't necessarily return all the URLs that are indexed under the prefix specified in the query," results are "not always exhaustive," and it is designed primarily for search users, with site owners pointed at URL Inspection instead. Then ordinary housekeeping - "Alternate page with proper canonical tag," "Page with redirect," and the two that alarm owners most while meaning least, "Crawled - currently not indexed" and "Discovered - currently not indexed." Then your own directives: robots.txt, noindex, 404, 5xx, soft 404, 403.

Attack. Three vectors genuinely remove pages: a fraudulent DMCA takedown stripping specific URLs, a canonical or redirect hijack, and removal after a security flag on a compromised site. A fourth, weaponized spam reporting, is folklore - reports do not deindex sites on demand.

Discriminator, and it is the decisive one on this whole site. Inspect an affected URL and read Google-selected canonical, documented as "the page that Google selected as the [canonical] URL when it found similar pages on your site." If that field names a domain you do not own, stop reading symptom lists: that is Google stating in the first person that it treats another host as the authority for your content, and nothing in any backlink product comes close to it evidentially. Read User-declared canonical beside it, then Indexing allowed and Crawl allowed, which catch the self-inflicted cases in seconds. The default result "is not a live test" - it reflects the last indexed version - so run the live test too, or you will not know whether the fault still exists.

Symptom four: the brand SERP changed

Innocent, in order. Google rewrites titles and snippets routinely and unilaterally, so a changed title is editorial behavior rather than damage. Sitelinks are algorithmic and fluctuate; they are not a setting you lost. Knowledge panels follow the sources underneath them - encyclopedia edits, structured data, business feeds - and move with no attacker involved. And a core update can reweight the brand query, letting a directory or a review aggregator sit above your homepage.

Attack. This is the symptom where attacks are most often real, because the surfaces accept third-party input by design: suggested edits or a false closure flag on the Business Profile, review flooding, hostile pages built to rank on your name, and brand mention spam.

Discriminator. The Business Profile is the only surface in this subject with an edit history, which makes it the only place an attack leaves an author-attributed record. Check pending suggested edits and the change log first. Everything else here needs the slower discipline of dated screenshots, which is why periodic brand SERP capture is one of the few line items in monitoring that earns its keep.

Symptom five: traffic fell but rankings did not

The most diagnostic symptom on the page, because it excludes almost every vector by construction. If positions have not moved, no ranking signal was affected - whatever happened did not happen in the ranking.

Innocent, in order. A tracking change: a consent banner, a tag manager edit, a new analytics property, server-side tagging, a bot-filtering rule. This is the most common cause by a wide margin and always the first thing to check; Google names reporting glitches among its own causes and gives them a shape of their own. Then the fact that Search Console counts clicks from Google while analytics counts sessions on your server - they never reconcile, and the gap widens when consent or blocking changes. Then feature encroachment: impressions steady, position steady, clicks down is the signature of an AI overview, a shopping unit or a local pack appearing above you. Then seasonality, compared year over year rather than month over month.

Attack. Thin. CTR manipulation is what people reach for, and the evidence does not support treating click behavior as a lever an outsider can pull. A crawler flood degrading response times can cost conversions without costing a single position - real, if unglamorous.

Discriminator. Put Search Console clicks, which are Google's own count and immune to your tracking, beside analytics sessions for the same window. Clicks flat and sessions down means measurement, not search. Clicks down while impressions and position hold means the results page changed shape around you.

Symptom six: the server slowed, or the logs exploded

Innocent, in order. A legitimate crawler surge after a sitemap change, an image CDN misconfiguration, a plugin update, a real traffic event, or faceted navigation generating a combinatorial explosion of crawlable URLs. The last is self-inflicted and very common.

Attack. Crawler overload, or requests forged as Googlebot.

Discriminator. Read the host status section of Crawl stats before any graph, because it separates "my server is failing" from "something is hitting it." Google documents three states there: robots.txt fetching, which shows the failure rate for those requests during a crawl; DNS resolution, which shows when your DNS server did not recognize the hostname or did not respond; and server connectivity, which shows when the server was unresponsive or returned an incomplete response. Any of the three red around the drop date is a technical finding, and a technical finding outranks every link theory in the room.

Then verify the user agent instead of believing it. Verifying Googlebot has two documented methods: a reverse DNS lookup on the accessing address, confirming it resolves to googlebot.com, google.com or googleusercontent.com, followed by a forward lookup confirming it returns the same address; or matching the address against Google's published ranges. Anything failing both is not Googlebot, whatever its user-agent string says - and that is the whole of the spoofed Googlebot question.

What is not a sign, however alarming it looks

  • Referrer spam in analytics. It appears in your reports, never in the index, and has no ranking effect at all.
  • A toxicity or spam score rising. Vendor-invented metrics with no counterpart inside Google. John Mueller of Google, writing publicly on 31 January 2023 about the businesses on both sides of that trade, put it as bluntly as anyone there ever has: "That's all made up & irrelevant. These agencies (both those creating, and those disavowing) are just making stuff up, and cashing in from those who don't know better." What those scores can and cannot see is set out separately.
  • The last day or two of a Search Console chart. Google: "The newest data can be preliminary, meaning it's still being collected and might change in the next few hours." A cliff at the right-hand edge of the graph is often incomplete collection.
  • A falling site: count, for the reason given above.
  • A competitor overtaking you on one keyword. Google's own analogy for core updates is a list of top restaurants: "restaurants that move down aren't necessarily 'bad'; there are just other restaurants that make your top 20."

The mistake that manufactures attacks

One error produces more false diagnoses than all the others combined: reading the symptom backwards. Traffic falls, so you open a link tool, so you find spam - every site has some - and the found thing becomes the cause. Nobody was auditing those links the week before, so nothing establishes that they are new, that Google counted them, or that they relate to the fall at all.

What follows is worse than the mistaken diagnosis. Disavowing on suspicion, when Google says the tool "can potentially harm your site's performance in Google Search results" if used incorrectly and that "most sites will not need to use this tool." Filing a reconsideration request with no manual action outstanding, which spends a channel on a case containing nothing to reconsider. Blocking crawler ranges in a panic. Naming a competitor publicly, which converts a suspected SEO problem into a real defamation exposure. Acting inside a rollout window, when Google advises waiting a full week after a core update completes.

The discipline that prevents all five is free: establish what happened before deciding who did it. The ordered version of that is how to check for negative SEO.

Frequently asked questions

My rankings dropped overnight. Is that an attack?

Usually not, and a calendar answers it faster than a backlink tool. Date the fall to the exact day, check it against Google's published update history, check the Manual actions report, then list what changed on your own site that week. The attack shapes that do produce a one-day cliff are hijacks and hacked-site injections, and both show in URL Inspection within minutes.

A tool says I have hundreds of toxic backlinks. Should I worry?

A toxicity score is a vendor's model of how a link looks to that vendor's crawler. Google publishes no such metric and exposes none in Search Console, and its documented behavior since 2016 is to devalue spam links rather than charge them to the site they point at. The score rising is evidence about the model. Acting on it with a disavow file is how a non-event turns into self-inflicted damage.

How quickly would a real attack show up?

It depends on the vector, which is what makes the question useful. Changes to your own site - injected pages, injected redirects, a hijacked canonical - can register within a crawl cycle. Inbound link campaigns cannot, because discovery and reprocessing spread over weeks. If the fall was instantaneous, links are the least likely explanation rather than the most.

Search Console shows no manual action. Does that rule out a penalty?

It rules out the only thing Google calls one. A manual action is issued by a human reviewer and reported in that report and in the message center, so a clean report means no person at Google has acted against your site. It does not rule out an algorithmic reassessment, which leaves no entry anywhere and is what a core update does. The two get conflated constantly, and the remedies are not the same.

Can a competitor get my pages removed from Google?

Three routes genuinely remove pages, and each leaves a trace. A fraudulent copyright takedown strips specific URLs and appears in public takedown records. A canonical or redirect hijack makes Google prefer another host's URL, and shows in the Google-selected canonical field. A security flag on a compromised site removes content and appears in the Security issues report. Spam reports do not deindex sites on demand.

Top