NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
The reference

Negative SEO: what it is, and what still works

The definition, the dated evidence, and what counting 33 documented attack vectors actually shows.

The definition, and the three things it gets confused with

Negative SEO is action taken by a third party with the intention of reducing another site's visibility in search results. The third party is the whole of the definition: the owner of the target did nothing, and somebody else acted against them. Remove that element and you are describing something else - and the something elses are where nearly all the wasted money in this subject goes.

Three of them arrive described as attacks:

  • An algorithm update - a change to Google's ranking systems that moved your site relative to every other site. It has no actor and no target, and no remedy aimed at an attacker will touch it. Distinguishing the two is a comparison of dates, not a matter of opinion.
  • A manual action - a penalty issued by a human reviewer at Google, for something on your site, shown to you in Search Console under Security and Manual Actions. If that report says no issues were detected, nobody has penalized you, and most of the remediation literature does not apply to your case.
  • Technical decay - an expired canonical, an accidental noindex, a migration that dropped half the internal links, a hosting change, seasonality, or the quiet loss of a few links that were doing real work.

Worth knowing before you go looking: Google does not use the phrase. Its spam policies speak of link spam, hacked content and scraped content, never of negative SEO, so an owner who searches the documentation finds nothing and concludes the subject was never addressed. It has been, repeatedly, under other names - most of this page is those answers with their dates on. There is not, at the time of writing, even a Wikipedia article on it, which is a fair part of why a decade of folklore has gone unchallenged.

Where the term came from, and one thing I could not establish

The idea is older than the phrase. Its ancestor is Google bowling, the practitioner name for bowling a rival out of the results by aiming bad links at them, and still the most useful historical alias for the subject. It is not Google bombing, which is anchor manipulation aimed at manufacturing a ranking rather than destroying one - the two get run together constantly and they point in opposite directions.

What made a new phrase necessary was a date. Penguin launched on 24 April 2012 and demoted sites on the character of their inbound links - and inbound links are the one ranking input a stranger can add to without any access to your property whatsoever. That is the whole logic of the era in a sentence: if guilt could be inferred from links you did not place, guilt could be manufactured on your behalf. Google shipped the countermeasure the same year, the disavow tool, which exists precisely because owners had acquired links they did not want and could not remove.

Here is what I cannot tell you, and I would rather say so than invent it: who first used the phrase, or when. Archive access and general web search were unavailable to the research behind this page, so no first attestation and no coiner is claimed. What is documentable is that by mid-2012 it was ordinary trade language, used in dated material with no explanation of what it meant - an agency experiment in June 2012, a victim's running account in July 2013, trade coverage of a mass extortion email wave in 2014. One further piece of received history is left out on purpose: a story about Google softening the wording of one of its own help pages in this period circulates widely, and no archive snapshot confirming it came back. A page that argues other people's dates are wrong cannot afford a folk quotation of its own.

2012 to 2016: the window in which it demonstrably worked

Any honest account has to concede the period when the attack worked, and conceding it is what makes the rest worth reading. Three dated accounts survive from that window, and the valuable thing about them is that they disagree.

In June 2012 the agency TastyPlacement published an experiment run against a site it owned: a microsite whose domain name was itself the commercial phrase, and whose position rested on little else. Roughly 56,000 automated comment and forum-profile links were aimed at it, all carrying the same commercial anchor. The target term moved from third to second, then the site left the first page and became, in the write-up's phrase, essentially invisible; of 51 secondary terms tracked, 26 fell by an average of about nine positions. The cost and sourcing detail is not reproduced here, because it is a shopping list and serves the wrong reader.

Over the same years, from October 2012 into May 2013, Nick Ker of KerCommunications was on the receiving end of a genuine campaign and kept a running record of it, through waves climbing from a few dozen links a day to a thousand. What he published on 30 July 2013: "No 'unnatural links' warning in Webmaster Tools, rankings are nearly the same as they were back in February, traffic has also grown at around the same rate."

The third, from November 2014, is Eliav Lankri's account of roughly 600,000 spam links aimed at a jewelry e-commerce site, where a penalty was confirmed and cleared only after rounds of removal outreach and disavow submissions. It is a practitioner narrative rather than a controlled test, and the site is unnamed.

Now put the first two beside each other, because the disagreement teaches more than either alone. Same era, same class of attack, opposite results. What differed was not the weapon but what it was pointed at: a microsite whose position rested on a thin manufactured profile had nothing standing once that profile lost credibility, while an established business with an aged profile absorbed a thousand hostile links a day and did not move. The attack succeeds where there is nothing underneath the target - and that was already the rule in the years when it was most dangerous, which is the part almost every retelling omits.

Demotion becomes devaluation, and then nullification

Everything above has an expiry date on it, and the date is 23 September 2016. Folding Penguin into its core ranking systems, Google set out the new behavior in a single line:

Penguin now devalues spam by adjusting ranking based on spam signals, rather than affecting ranking of the whole site.

Two words carry it. Demotion means a site is pushed down because of the links. Devaluation means the links are taken out of the calculation and whatever else the site has is scored as before. The attacker's theory requires the first; Google's stated behavior from that day is the second, and no version of the theory survives the substitution. You cannot frame somebody with evidence the court declines to admit. The same announcement made Penguin's data refresh in real time, "typically taking effect shortly after we recrawl and reindex a page," ending the long wait for a scheduled refresh that used to hold a site down after its cause was dealt with.

A note on sourcing, because this is the most consequential quotation on the site. Google's blog pages are assembled in the browser rather than served as text and did not return through the tooling behind this research; the wording came from two trade transcriptions published the same day, and the announcement is linked so anyone relying on it reads the original rather than my copy.

Detection then moved upstream. On 14 December 2022, announcing that year's link spam update, Google named the system doing the work - "SpamBrain is our AI-based spam-prevention system," now able to "detect both sites buying links, and sites used for the purpose of passing outgoing links" - and described the outcome: when Google's systems "nullify spammy links, the link credit that was previously generated is lost."

Everything turns on that verb. A nullified link confers nothing, and something that confers nothing also costs nothing: it is subtracted from the ledger rather than entered on the wrong side of it. That is not a promise of safety, and Google has never made one - it is a description of an architecture, and the architecture is why the classic attack mostly fails.

What Google publishes today, and how to read it

The FAQ Google publishes on why a site's position in the results changes says:

We work really hard to make sure that competitors can't negatively affect other sites' rankings.

Its recommended action for an inbound link you do not want is to contact the owner of the linking site - not to disavow it, not to report it. Search Console help repeats the position twice more in near-identical words, once on the disavow documentation, where Google "works very hard to make sure that actions on third-party sites do not negatively affect a website," immediately followed by "most sites will not need to use this tool."

Read the hedge, and do not let anyone read it to you as a guarantee. "Work really hard to make sure" is a statement of engineering intent, not immunity. Google has not claimed immunity, and quoting these sentences as a promise misrepresents them as surely as pretending they were never written.

The uncomfortable quotation belongs here too, because omitting it would be the folklore in reverse. In May 2020 John Mueller, who answers site owners' questions publicly in Google's Search Advocate role, said the disavow tool does not exist for this problem and that he "honestly can't recall a situation where a site ever needed to do a disavow for that." But in a Google video reported on 1 November 2021 he described ignoring as the first-line behavior and then named the fallback: "if we see a very strong pattern there, then it can happen that our algorithms say well we really have kind of lost trust with this website." That sentence is why the honest verdict on link attacks is situational rather than myth, and the conditions under which it bites are set out below.

Counting 33 attack vectors, and the pattern in the count

Every attack profile on this site reaches its own verdict from its own sources, before any of them are read together: documented threat, situational, or largely neutralized. Counted at the time of writing, across 33 documented vectors, they fall out as ten documented threats, sixteen situational, and seven largely neutralized.

The distribution is mildly interesting. What sits inside the columns is the finding, and it is the reason this site exists. Sort the ten documented threats by what the attacker actually has to do, and they fall into three groups and no others:

  • Compromise of the victim's own infrastructure - hacked-site injection, malware and blacklisting, crawler overload. Here Google does act against the target's domain, and it is right to: the spam genuinely is being served from that domain. In Google's spam policies, the category is hacked content, described there as "any content placed on a site without permission, due to vulnerabilities in a site's security." No algorithm is being fooled. Its output is accurate, which is exactly the problem.
  • Abuse of a platform's own complaint, edit or review process - Business Profile hijacking, false closure reports, fake reviews, forged copyright takedowns, trademark complaint abuse, defamation aimed at the results page. Each fires a legitimate process on a false input. Nothing algorithmic stands in front of them, because no ranking system is involved anywhere in the chain.
  • A crime against the owner rather than the site - link removal extortion, where the threat about links is largely hollow and the extortion is entirely real and has been prosecuted.

Not one of the ten is a link-based ranking manipulation. The count runs the other way with the same consistency: every one of the seven verdicts of largely neutralized is a link or click-signal attack - 302 hijacking, blog comment spam, CTR manipulation, forum profile spam, link farm inclusion, link velocity spikes, sitewide footer links.

So the finding is not that the fear is imaginary. It is this: negative SEO did not stop being real. It stopped being about links. What works now is security compromise and platform abuse; what has stopped working is link spam. The trade's vocabulary, its anxieties and most of its paid remedies are still aimed at the 2013 threat model, which is why so much is spent on link cleanups by people whose actual problem is an unclaimed Business Profile, an unpatched content management system, or a competitor filing forged takedown notices.

That tally is my own reading of the documented evidence, reached one vector at a time. It is not a survey of the field and I do not offer it as consensus - the industry has an obvious commercial reason to prefer the older answer, and the counting is the part of this page I would want checked first.

Where link attacks still have teeth

Stating the exceptions is not a hedge on the section above; omitting them would be the same dishonesty pointing the other way. The residual risk is narrow and it has one structural cause: devaluation protects you in proportion to what remains after the spam is discarded. Where little remains, little protects you.

  • A new or thin site with few genuine inbound links, where discarding the hostile ones leaves too little to score. That is the microsite in the 2012 experiment, and it is still the exposed population.
  • A site already carrying a manual action, where hostile links add to a finding that exists rather than having to create one.
  • A site whose own profile is partly manufactured, so an attacker's links merge with real violations and cannot be isolated. That is Mueller's 2021 case precisely, and it means the sites most at risk from a link attack are the ones that bought links themselves.
  • Bing and smaller engines, which have made no equivalent public statements and should be checked on their own terms rather than assumed to behave as Google says it does.
  • Local businesses, where the exposure is usually not the website at all. The review stream and the Business Profile are where the damage lands, and neither is protected by anything in this section.

If you think it is happening to you

The order matters more than any individual step, because the first two end most cases and everything after them is wasted effort until they are done.

  1. Open the Manual actions report first. "No issues detected" means no human at Google has penalized your site, and the entire manual-action path, reconsideration requests included, is irrelevant to you. Most skipped check, most decisive one. Then Security Issues, where a hacked-content problem appears - and hacked content is in the category that genuinely works.
  2. Compare the date of the drop against the record of confirmed Google updates. A fall landing on a core or spam update is an update; the full triage sequence covers the canonical, indexation, link and log checks that follow, and the platform surfaces a local business has to check separately.
  3. Document before anything changes - referring domains, the review stream, the profile edit history, the Search Console messages, all with dates. A claim runs on contemporaneous records; a tool's view of the web this afternoon is not evidence of last month.
  4. With no manual action and no security issue, the right action on hostile inbound links is usually nothing. The published criteria for the disavow tool are two conditions joined by and, not or: a considerable number of spammy links, plus a manual action those links have caused or are likely to cause. Most people who reach for it meet the first condition and fail the second, and disavowing on suspicion is how most of the real damage in this subject gets done.

Where I get called in is the part between the panic and the invoice: establishing whether anything was done to a site at all, and if so which category it falls in. A good share of that work ends with me telling someone nothing happened to them and no cleanup is warranted. Nobody can promise a recovery here, and the legal routes are thinner than most victims expect.

Frequently asked questions

Is negative SEO real, or something SEO companies invented to sell services?

Both, and the halves need separating. Attacks on other people's search visibility are documented, prosecuted and ongoing: false closure reports, forged copyright notices, review attacks and site compromises all happen to real businesses. What has largely stopped working is the specific thing the industry sells protection against - pointing spam links at a competitor. Google's stated behavior since 23 September 2016 is to devalue those links rather than charge them to the site they point at, and no comparably documented case since then of spam links measurably damaging an established site turned up in this research. The threat is real; the popular model of it is a decade out of date.

Can a competitor get my site penalized by pointing spam links at it?

Against an established site with a genuine, aged profile it is very difficult, and no documented case of it succeeding since 2016 surfaced in this research. Where the target is new and thin, or under a manual action already, or leaning on links it bought itself, it remains possible - not because hostile links are charged to you, but because once they are discarded there may be too little left to rank. The defense in all three cases is the same and unglamorous: a legitimate profile substantial enough that discarding the spam leaves plenty.

My rankings fell overnight. How do I tell sabotage from an update?

By date, before anything else. Find the day traffic actually moved in the Search Console Performance report, then check that day against the list of updates Google has confirmed. If the two coincide, the update is your answer, however many new links appeared that week - coincidence in time is the most common reason this gets misdiagnosed. If the date matches nothing, check Manual actions and Security Issues next, then the canonical and indexation status of the pages that lost most.

Why does Google never use the phrase negative SEO?

Because it is not a mechanism. Google's documentation is organized around what was done - link spam, hacked content, scraped content - rather than around who intended what, and the same conduct is described identically whether you did it to yourself or someone did it to you. The practical effect is that searching for the term returns nothing and people conclude the subject is unaddressed. Search for the mechanism instead of the motive and it is covered extensively.

Should I buy a service that monitors my backlinks for toxic links?

Watching your own link profile is sensible, and Search Console reports it at no cost. Paying for a toxicity score is a different proposition: no vendor's score corresponds to anything inside Google's systems, and its practical output is a recommendation to disavow, which on a site with no manual action is the most damaging thing an unaffected owner can do to itself. Spend the attention where documented attacks land instead - the Business Profile, the patch level of the content management system, and the inbox where a warning would arrive.

Top