Websites

Google Safe Browsing check

See whether Google lists a site or a link for malware, phishing or unwanted software: the lists behind the red warning pages in Chrome, Firefox and Safari.

A domain checks the whole site; a full link also checks that exact page.

Questions

What does this check?

It asks Google whether the address is on its Safe Browsing lists for malware, social engineering (phishing), unwanted software, and an extended-coverage phishing list. Browsers that use Google Safe Browsing show a full-page warning for addresses on the main lists. The check never opens the site or the link.

Domain or full link: what’s the difference?

A domain is checked as the site’s address (http://example.com/), which catches listings that cover the whole site. Google can also list a single page on an otherwise clean site, so to check a specific page (for example a link from an email), paste the full link.

How fresh is the result?

A clean answer is reused for 30 minutes, and a listing is kept until the expiry time Google sends with it, so most results are minutes old. New dangerous pages can take hours to be listed, so a clean result isn’t a guarantee.

My site is listed. How do I get it removed?

Find and remove what Google flagged (the Security issues report in Google Search Console names it), fix how it got there, then choose Request Review in that report. Google says reviews take from a few days to a few weeks. See Google’s Security issues help.

Why Web Risk and not the Safe Browsing API?

Google’s free Safe Browsing API is for non-commercial use only; Google Cloud Web Risk is the version for businesses and uses the same lists. This site uses Web Risk.

Who sees the address I check?

The domain or link is sent from our server to Google. Your IP address isn’t sent and the API key stays on our server. Answers are kept for a short time under a hash of the address. Cloudflare’s request logs record the request, as the privacy page explains.

esc