What Is Negative SEO and How to Protect Your Site
On this page
Negative SEO is any attempt to hurt a site’s search performance from the outside: floods of spammy backlinks, scraped copies of its content, fake reviews, fake requests to remove its good links, or a break-in. People do try it. On the link side, Google’s disavow help page puts it in one line: Google “works very hard to make sure that actions on third-party sites do not negatively affect a website.” So protection is less about reacting and more about readiness: know your normal link profile, watch the reports that would show a real problem, lock down the part an attacker can break, and keep dated records.
Where each tactic shows up
Each tactic leaves a trace somewhere different. Matching them up tells you where to look.
| Tactic | Where it shows up |
|---|---|
| Spam-link flood | New root domains in the Links report's "Top linking sites" and in your backlink tool |
| Manipulative anchor text | A shift in the Links report's "Top linking text" |
| Scraped copies | Search results for a distinctive sentence from your page, in quotes |
| Fake reviews | The review platforms your customers use |
| Fake link-removal requests | Good links disappearing, or a site owner asking you about a request you never sent |
| Break-in | Search Console's Security Issues report, and your server and CMS logs |
Search Console’s Links report lists top linking sites by root domain and top linking text from outside your property. It also says it shows a sample of links, and that some URLs might be omitted. Treat it as a trend line to compare over time, not a complete inventory.
Build a baseline before anything happens
An attack is much easier to see against a known normal. On a regular schedule:
- export the Links report and your backlink tool’s referring domains, with the date in the file name;
- check the Manual Actions and Security Issues reports;
- note any site changes, migrations or content cuts in a dated log.
When something odd appears later, you can show when it started and what else changed at the time. Without the baseline, a spike of spammy domains is just a scary number.
Security is the part you control
The link side is mostly Google’s to handle. A break-in is yours, and it may do direct damage to the site itself. Google’s Security Issues report groups problems into three kinds: hacked content placed on your site without permission, malware and unwanted software, and social engineering that tricks visitors. The report also says Google tries its best to keep hacked content out of its search results, which is how a compromised site can lose visibility.
The hardening list is plain:
- keep the CMS, themes and plugins updated;
- turn on two-factor authentication for every account that can change the site;
- keep tested backups you can restore from;
- serve the site over HTTPS;
- keep Search Console notifications on so a security issue reaches you fast.
Scraping: find it, then use the right channel
Search for a distinctive sentence from an important page in quotes and see where copies appear. Google’s spam policies define scraping as taking content from other sites, often through automated means, and hosting it to manipulate search rankings, and they invite reports of policy violations through a search quality user report.
Copyright is a separate channel. The same policies say that when Google receives a significant volume of valid copyright removal requests involving a site, it can use that to demote other content from that site. For a copy of your work, the legal removal route is the one that fits; a disavow file has nothing to do with duplicated content.
Keep the disavow file in the drawer
Readiness is not the same as reacting. Google’s disavow page ties the tool to two conditions together: a considerable number of spammy, artificial or low-quality links, and a manual action they caused or likely will cause. Links a stranger pointed at you don’t satisfy the second condition by themselves. Watch the Manual Actions report. If it stays clean, a spike in junk links is something to record in your log, not something to disavow.
When rankings fall, test the ordinary causes first
A drop can invite the attack story because it puts the problem outside. Before accepting it, check the Manual Actions and Security Issues reports, compare the date of the drop with known Google updates and your own changes, and look at who now ranks for the queries you lost. Those checks point at the cause more directly than a backlink export does.
Frequently asked questions
Can a competitor hurt my rankings with spam links?
Google says it works very hard to keep actions on third-party sites from harming a website, and that in most cases it can assess which links to trust on its own. Watch the Manual Actions report. That is where Google would tell you links have become a problem.
Should I disavow when I see a spike of spammy links?
Not on the spike alone. Record it with dates. Google reserves the tool for a large set of bad links that has led, or is about to lead, to a manual action.
What part of protection matters most?
Security. A break-in can do real damage, and prevention is in your hands: updates, two-factor authentication, backups and a watched Security Issues report.