Negative SEO is any action taken by someone else to make a site lose rankings on Google: spam links pointed at it, copies of its content, fake reviews, made-up copyright complaints, break-ins on the server. The best-known form, link spam, has worked far less since 2016 than most articles suggest. The others still work.
While we were preparing this article, visilay.com was receiving a wave of links from spam domains: 408 new referring domains between 1 August and 5 October 2026, 377 of them in the last eleven days. We use those numbers to show what something many people would call an attack looks like from the inside, and what you should do about it. Spoiler: almost nothing.
What counts as negative SEO, and what doesn't
The term is used for three different things, and mixing them up leads to bad decisions.
Negative SEO in the strict sense targets someone else's site. It's different from black hat SEO, which is manipulation done on your own site to climb the rankings, and from the penalty a site brings on itself by buying links (we cover that in our guide to Google penalties). It's also different from so-called reverse SEO, which pushes unwanted results about a name or a brand further down the page: that's online reputation management, not an attack on a competitor.
In the UK, demand is small and uneven. According to Google Ads data pulled through DataForSEO, "negative seo" averages 40 searches a month, with a peak of 110 in September 2025, and "negative seo attack" gets 10. The first page of Google UK that answers it is old: of the nine organic results we read on 10 October 2026, two are from 2012 (SEObook, with the title "Yes, Negative SEO Techniques do Work on Google", and Search Engine Journal), one from 2014 (Net66, a Manchester agency), one from 2023 and one from 2024. Only one, by Landingi, was updated in 2026, and the first result is a Reddit thread from a site owner whose traffic dropped "practically overnight".
What a link spam wave looks like: the visilay.com data
The numbers come from the DataForSEO backlink index, queried on 5 October 2026 for the domain visilay.com. In the first seven months of 2026 the site gained between 0 and 11 new referring domains a month, 28 in all. Then the pace changed.
| Period | New referring domains | Notes |
|---|---|---|
| January-July 2026 | 28 | 0 to 11 a month |
| August 2026 | 11 | about one every three days |
| 1-24 September 2026 | 20 | first signs from 18 September |
| 25-30 September 2026 | 153 | between 18 and 35 a day |
| 1-5 October 2026 | 224 | peak of 71 on 4 October |
| Total 1 August-5 October | 408 | 90% of the 452 current referring domains |
The profile of those 408 domains is more interesting than the count.
| Feature | Domains | Out of 408 |
|---|---|---|
| Cheap extensions (.store, .space, .online, .site, .shop, .website, .link, .info, .xyz) | 376 | 92% |
| DataForSEO spam score of 55 or more (0-100 scale) | 312 | 76% |
| The word "checker" in the domain name | 232 | 57% |
| The word "backlink" in the domain name | 86 | 21% |
| Links marked nofollow | 8 | 2% |
| Italian .it domains | 0 | 0% |
The names say almost everything: dachecker, seocheckerfreetool, buypbn, casinobacklinks. They're networks of auto-generated pages that create a listing for every domain analysed or sold, often to sell link packages in turn. Who's behind them we don't know, and you don't need to know to decide what to do.
A warning about the most eye-catching number: spam score is a proprietary DataForSEO metric, like the "toxicity score" in other tools. Google doesn't read it. We use it here to describe the domains, not to say what Google thinks of them.
For a site in this position the right response, by the criteria Google has put in writing, is to do nothing: no disavow, no removal requests. What needs watching is elsewhere, and we get to it below.
Why link spam usually does nothing
In September 2016 Google announced that Penguin had become part of its core algorithm and that from then on it would devalue spam links rather than demote the whole site receiving them. That change took most of the force out of link-based negative SEO.
The second piece came in December 2022. With the link spam update, rolled out from 14 December 2022 to 12 January 2023, Google said it was using SpamBrain "to neutralize the impact of unnatural links on search results".
The official documentation on the disavow links tool is explicit: "In most cases, Google can assess which links to trust without additional guidance", so most sites don't need to use it. On the same page Google writes that it "works very hard to make sure that actions on third-party sites do not negatively affect a website".
Google's people have been saying the same for years. John Mueller, asked on Reddit in November 2022, replied that he would ignore those links: if competitors are competent they won't build you links, and if they're incompetent the links won't have any effect (the exchange is reported by Search Engine Journal). Gary Illyes, in an interview from May 2024 reported by the same publication, said he had received "hundreds, literally hundreds of examples of alleged negative SEO", and that none of them really was.
There's also third-party data. Ahrefs writes in its guide to negative SEO that the page of its backlink checker is linked from "over a million spammy pages" and still gets an estimated 133,000 organic visits a month. The figure is Ahrefs' own and covers one page, but the mechanism it describes doesn't depend on the country.
The best-documented case we found points the other way, and it's from 2015, before Penguin 4.0. An Italian fashion magazine site, described by the Italian agency I'm Evolution, had received a manual action for unnatural links after its pages were cloned on compromised domains: about 600,000 inbound links, and traffic down from 3,000-4,000 organic visits a day to a few dozen. The manual action was lifted seven days after the reconsideration request. Today the same pattern would be largely devalued automatically; it's still useful because it shows the one scenario where disavow really helps.
The attacks that still work
The risk has moved from links to other channels. This is our assessment, attack by attack, of how much each one can hurt a site today.
| Attack | What it hits | Real risk today | Where you see it first | First move |
|---|---|---|---|---|
| Break-in (injected spam, redirects, hidden pages) | Index, security, user trust | High | Search Console, Security and Manual Actions | Clean-up, updates, review request |
| Fake reviews on your Google Business Profile | Local pack and conversions | High for local businesses | Profile notifications | Report to Google, public reply, keep records |
| False copyright complaints | URLs removed from results | Low but fast | URLs disappearing from the index | Counter-notice to Google |
| Content copied by other sites | Duplicates, wrong canonical | Low | Searching for a sentence in quotes | Removal request, correct canonical |
| Fake link removal requests | Loss of good links | Low | Lost links in the backlink report | Tell the sites that link to you |
| Aggressive crawling, hotlinking, DDoS | Speed, server resources | Medium on small hosting plans | Server logs | CDN, firewall, rate limits |
| Mass link spam | Rankings | Low | Backlink report | Ignore it; disavow only in the cases Google describes |
A break-in is still the most effective attack
A hacked site can end up with spam pages indexed under its name, redirects to other domains, or text hidden from users and shown to Googlebot, which is a form of cloaking done by someone else. Google's spam policies class all of this as hacked content, and the problem belongs to the site hosting it, even though it didn't write it.
On WordPress sites the usual way in is a plugin. According to the Patchstack report published in 2026, 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025: 91% in plugins, 9% in themes, just 6 in core. For heavily exploited vulnerabilities, the weighted median time to the first exploit is 5 hours. These are global figures, but a vulnerable plugin doesn't know which country it's installed in. What to check is in our guide to website security.
A subtler variant targets canonical tags: anyone who can edit them can tell Google that the main version of a page lives somewhere else. How that signal works is explained on our page about the canonical URL.
Fake reviews hit businesses that live on local search
For a restaurant, a practice or a shop, twenty one-star reviews in a week move more customers than any link spam. Google says that in 2025 it blocked or removed over 292 million reviews that broke its policies and more than 13 million fake Business Profiles, and that it is stepping up action against people who demand payment to remove fake one-star reviews. These are worldwide figures: Google doesn't publish UK data. In the UK it has made extra commitments, which we cover in the section on the law.
How much reviews weigh in local rankings we measured in a test on 24 local pack listings in Italy. How the three local rankings work is covered in our guide to local SEO.
Made-up copyright complaints
Copyright offers a weapon that bypasses the algorithms: if Google accepts an infringement complaint, the URL is removed from the results and only comes back after a counter-notice from the site owner. Google has taken people who abused this to court. In Google LLC v. Nguyen Van Duc and others, the federal court for the Northern District of California granted a default judgment on 27 September 2024 that bars the defendants from submitting copyright complaints based on false claims.
How to tell whether a drop comes from an attack
It almost never does, so the order of the checks matters. This is the one we recommend.
- In Google Search Console open Manual actions and Security issues. If both are empty, a link attack that has penalised you can be all but ruled out.
- Compare the date of the drop with the Google Search Status Dashboard. A drop that coincides with a core update is almost always about the algorithm update, not a competitor.
- Look for pages you didn't write: in the page indexing report and with a site: search followed by typical spam words (pharma, casino, loans). If you find any, the problem is a break-in. How to read that report is in our guide to indexing.
- Open the server logs and see who is crawling what. Spikes of requests on the same file or on URLs with made-up parameters are a sign of crawling abuse.
- Only at the end, look at the backlinks. A wave like the one visilay.com received is background noise as long as the previous checks are clean.
If none of these steps explains the drop, the cause is almost certainly something else: we've put the usual suspects in order in our guide to a website traffic drop and in the one on why a site doesn't show up on Google.
Disavow: when it helps and when it does damage
Google sets two conditions, and both must apply: "a considerable number of spammy, artificial, or low-quality links" pointing to the site, and links that "have caused a manual action, or likely will cause a manual action". A wave of "checker" domains on a site that has never bought links doesn't meet the second.
Disavowing isn't neutral. In its article on "toxic backlinks", Ahrefs reports the case of a user who lost 60% of their traffic after disavowing the links a tool had flagged as toxic, and a test of its own in which a disavow temporarily lowered traffic, which recovered once the file was removed. Disavowing in bulk means risking throwing away the links that count too. Which links still carry weight is covered in our analysis of link building.
What UK law says
A caveat first: we aren't lawyers, and what follows is a pointer, not legal advice. The references are to the law of England and Wales unless stated otherwise.
- Getting into someone else's site without permission is unauthorised access to computer material under section 1 of the Computer Misuse Act 1990, punishable by up to two years in prison on indictment. In England, Wales and Northern Ireland you report it to Report Fraud, the police service for cyber crime and fraud (0300 123 2040 if an attack is in progress); in Scotland you call 101.
- False statements that damage a business can be defamation, but for a company the bar is high: under section 1(2) of the Defamation Act 2013, harm to a body that trades for profit isn't "serious harm" unless it has caused or is likely to cause "serious financial loss". It's a civil claim, not a criminal one.
- Since 6 April 2025 the Digital Markets, Competition and Consumers Act 2024 bans submitting or commissioning fake consumer reviews, publishing reviews in a misleading way and offering services that facilitate either (Schedule 20, paragraph 13). It isn't a criminal offence, but the CMA can enforce it directly, with fines of up to £300,000 or 10% of turnover, whichever is higher (section 182).
- Google has made specific commitments for the UK. Under undertakings accepted by the CMA on 24 January 2025, UK businesses found boosting their ratings with fake reviews get a warning on their Google profile and can have reviews switched off, and people who repeatedly post fake reviews for UK businesses have their reviews deleted and are barred from posting new ones, wherever they are based.
There's no specific law on link spam, and above all there's almost never a way to prove who created it. For break-ins and fake reviews, on the other hand, it pays to keep records straight away: dated screenshots, log extracts, copies of the reviews before they disappear.
Frequently asked questions
Yes, but it has changed shape. Google has devalued spam links since 2016, with Penguin 4.0, and neutralised them with SpamBrain since 2022. Break-ins, fake reviews on your Google Business Profile and false copyright complaints still work.
Rarely. Google says that in most cases it can work out on its own which links to trust. The risk is mainly for sites that already have a history of bought links or a manual action for unnatural links.
No, unless two conditions apply together: there are a lot of links, and they have caused, or are likely to cause, a manual action. A bulk disavow based on a tool's score can strip value from good links too.
It depends on the attack. Check Manual actions and Security issues in Search Console first, then indexed pages you didn't write, then the server logs, and only at the end the backlinks. Tracing the author is almost impossible with link spam, easier with fake reviews and break-ins.
It depends on the technique. Hacking a site is an offence under the Computer Misuse Act 1990. False statements that damage a business can be defamation if they cause serious financial loss. Since April 2025 the DMCC Act 2024 bans commissioning or submitting fake reviews, with CMA fines of up to 10% of turnover. There's no specific law on link spam.
The damage a site does to itself
In our view the most harmful negative SEO today is the kind a site does to itself after opening a backlink report full of red flags: disavow files thousands of lines long, removal requests sent to good sites, weeks spent chasing domains like the ones linking to us right now. In the UK "toxic backlinks" gets more searches than "negative seo" (70 a month against 40, Google Ads data via DataForSEO, 10 October 2026), and those waves feed a small market in "toxic link" audits: the score that makes them look serious is calculated by a tool, not by Google. If the drop is real and the cause doesn't turn up with the five checks above, it's the kind of diagnosis we do in an SEO audit and in our SEO service.