How to Recover from a Negative SEO Attack

On this page

Before you build a disavow file, disprove the attack. Most suspected negative SEO is not actually harming the site. Google’s link systems neutralize the vast majority of spam links automatically, and a clean Manual Actions report in Search Console means there is no formal penalty to recover from. So the disciplined first move is to test the attack hypothesis against three alternatives: the timing of the drop, the pattern of which pages fell, and whether a competitor simply got better. Real recovery, when there is genuinely something to act on, is documentation plus a domain-level disavow plus DMCA for scraped content. More often the higher-leverage fix turns out to be improving stale content, not fighting links you imagined were the cause.

Verify before you react

Start in Search Console under Security & Manual Actions. If there is no manual action listed, Google has not penalized your site, full stop. An algorithmic shift and a human penalty are different things, and only the penalty produces a notification here. A blank report rules out the scenario most people fear when they say “negative SEO.”

Next, line up the timing. Pull the date your traffic dropped and compare it against three timelines: the date any suspicious links appeared, the dates of known Google updates, and your own deploy and content-change log. A drop that aligns with a confirmed algorithm update or a site change you made is almost certainly not an attack. A spam-link spike that predates or postdates the drop by weeks is unlikely to be the cause.

Then read the pattern. A site-wide, uniform decline points toward a domain-level signal. A decline confined to specific pages or a section points toward content or a competitor on those exact queries, not a link attack on the whole domain. The shape of the loss narrows the cause before you touch a single link.

These three checks take an hour and they reorder your whole response. People who skip them spend weeks exporting backlink profiles, scoring “toxic” links with third-party tools, and assembling enormous disavow files in response to a drop that a manual-actions check, a timing comparison, and a pattern read would have explained in minutes. The reason to disprove first is economic: the disavow work is slow, low-yield, and frequently moves nothing, while the actual cause is usually sitting in plain view in the timing or the competitor SERP. Resist the pull of the attack narrative long enough to run the cheap diagnostics, and most of the time you will not build a disavow file at all.

The usual real cause

In the majority of “we’ve been attacked” cases, the actual driver is mundane: a competitor improved their page, earned links, refreshed their content, and overtook you, or your own content went stale and slid. Diagnose the competitor delta directly. For the queries that lost ranking, look at who now ranks and what they have that you do not. This is unglamorous and it is usually the answer. The attack narrative is appealing because it externalizes the problem, but the data rarely supports it.

Targeted or just industry noise

If you do find a pile of spammy backlinks, ask whether they point only at you or at many sites in your vertical. Spam networks blast links across whole industries; finding your domain in one does not mean you were singled out. Industry-wide spam is far more common than a precision attack on a single competitor. A genuinely targeted hit, where the spam links almost exclusively to you, is rare, and even then Google’s systems likely already discount the links. The distinction matters because it sets your expectation: untargeted industry spam is background noise Google handles, not a wound to heal.

If you decide to act

When evidence genuinely warrants action, work in this order.

Document everything first. Screenshots, dates, exports from your link tools, and a written timeline. This record is what a future reconsideration request would rest on if a manual action ever did arrive, so build it now while the data is fresh.

Disavow at the domain level for clear spam. Add whole domains rather than picking individual URLs when a domain is unambiguously a link farm, scraper, or auto-generated junk site. Keep the file conservative and update it periodically rather than treating it as a one-time purge. Understand what disavow actually is: a suggestion to Google to ignore those links, not a command that removes anything, and its effect is essentially unmeasurable because Google may already be ignoring the same links. Because algorithms like SpamBrain neutralize most spam automatically, disavow is rarely necessary at all and Google positions it as a last resort for sites that have, or suspect they have, an unnatural-links problem. Do not expect it to move rankings; treat it as hygiene.

Handle other vectors on their own terms. Content scraping is the most common one that genuinely matters, because a thief who republishes your article can, in rare cases, get their copy indexed or ranked over yours. Your first defense is structural: make sure your originals self-canonicalize so Google has a clear signal of which URL is authoritative, and that your pages are crawled and indexed promptly so yours is the version Google sees first. Monitor where copies appear by searching distinctive sentences from your content.

Most scraped copies never outrank the original and need no action. When one actually does outrank you, that is the trigger to file a removal request through Google’s legal and copyright process, which is the correct channel for copied content; disavow does not apply, because the problem is duplication, not a bad link pointing at you. Document the original publication date and URL when you file, since the claim rests on you being the source.

Fake reviews, fake business listings, and hacking are separate problems with their own remediation paths and none of them are solved by anything in your link file. If you suspect a site compromise, the Security Issues report in Search Console is where that surfaces, and the fix is cleaning and securing the site, not disavowing links. Keep these vectors mentally separate so you apply the right tool to each rather than reaching for the disavow file as a universal remedy.

Priority order

Fix content first, disavow as hygiene second, monitor third. The reason follows from everything above: the disavow probably will not move what Google already ignores, while the stale-content or competitor-improvement cause is usually what is actually driving the loss. Spend the first hour disproving the attack and reading the competitor delta, then put your effort where the data points. If a real manual action ever does appear, you will already have the documentation and the disavow in place to support a reconsideration request, but until then the recovery work that pays off is the content work, not the link war you were tempted to fight.

Frequently Asked Questions

Rarely. Google’s link-spam systems are built to ignore most spam links automatically, so pointing junk links at a site usually does nothing. Before assuming an attack worked, check Manual Actions (a clean report means no penalty), align the drop timing with updates and your own changes, and look for a competitor who simply improved. The cause is usually not the links.

Only as conservative hygiene, and only when you can evidence clear spam. Disavow whole domains for unambiguous link farms and scrapers, keep the file tight to avoid disavowing legitimate links, and do not expect a ranking change, because Google likely already discounts those links. It is a last-resort tool, not a routine recovery step.

Sources

Disavow links to your site, Search Console Help: https://support.google.com/webmasters/answer/2648487

Spam policies for Google web search (link spam), Google Search Central: https://developers.google.com/search/docs/essentials/spam-policies

Manual Actions report, Google Search Central: https://support.google.com/webmasters/answer/9044175