White hat SEO is the set of optimisation techniques that improve a site's rankings without breaking search engines' spam policies.
The expression, however, appears nowhere in Google's documentation. What does exist, and what actually decides whether you risk a penalty, is a list of spam policies with specific names, last updated on 28 August 2026. Knowing it is worth more than any label, because it includes practices almost nobody expects to find there and leaves out others that many people assume are banned.
Where the expression comes from, and why Google does not use it
The name comes from westerns: the good guys wore white hats, the bad guys black ones. On Google UK the query belongs to agencies: the first organic result is an agency that has taken the name as its brand, Whitehat SEO, and the rest of the first page is agency blogs and glossaries, one of them written in 2011 (DataForSEO, Google UK, September 2026). It is a label born inside the industry, not a recognition anyone awards.
The reference documentation is called Google Search Essentials and it has three parts: technical requirements, spam policies and some best practices. The technical requirements are minimal, so much so that Google writes that most sites meet them without ever having thought about them. The best practices are advice, and ignoring them has no formal consequence. The only part with consequences is the second one.
The practices Google calls spam, by name
There are sixteen, plus a few residual categories covering legal removals, scams and attempts to get round the policies themselves. The opposite set, what the industry calls black hat SEO, matches this list and nothing else.
| Spam policy | What Google objects to |
|---|---|
| Cloaking | Showing the search engine different content from what the user sees |
| Doorway abuse | Pages or sites created to capture similar queries and push the user elsewhere |
| Expired domain abuse | Buying a lapsed domain to exploit its reputation with new, low-value content |
| Hacked content | Pages, code or redirects added by third parties through a security flaw |
| Hidden text and links | White text on a white background, zero font size, zero opacity, text positioned off screen |
| Keyword stuffing | Filling a page with keywords or numbers out of context |
| Link spam | Links created, bought or exchanged purely to manipulate rankings |
| Machine-generated traffic | Sending automated queries to Google, for example to track rankings |
| Malicious practices | Malware, unwanted software, blocking the browser's back button |
| Misleading functionality | Promising a service or content the site does not actually provide |
| Scaled content abuse | Generating many low-value pages to rank, by any method |
| Scraping | Republishing other people's content without adding anything |
| Site reputation abuse | Hosting third-party content mainly to exploit the domain's ranking signals |
| Sneaky redirects | Sending the user to a different page from the one they asked for |
| Thin affiliation | Product pages copied from the merchant, with affiliate links inside |
| User-generated spam | Comments, forum posts and files uploaded by third parties that the owner does not moderate |
Three entries on this list are recent. Expired domain abuse, scaled content abuse and the site reputation abuse policy were announced on 5 March 2024. The last one came into force two months later, on 5 May, precisely to give publishers time to adapt.
Four places where the line is not where you think
Read in full, the document contradicts several beliefs that have been doing the rounds in courses and conference talks for years.
| Practice | Does it break the policies? | What the document says |
|---|---|---|
| Buying a link | No, if qualified | Paid links are allowed as long as they are marked with rel="sponsored" or rel="nofollow". Google writes that buying and selling links is a normal part of the economy of the web |
| Hiding text behind an accordion | No | Accordions, tabs, slideshows and tooltips are named among the elements that do not break the policies, along with text intended only for screen readers |
| Putting content behind a paywall | No | It is not cloaking if Google sees the same content as the subscriber and the site follows the Flexible Sampling guidance |
| Tracking rankings with a tool | Yes, as a rule | Scraping results for rank checking falls under machine-generated traffic and also breaches Google's Terms of Service |
The first row is worth dwelling on, because it is the one that does the most damage. The problem is not the money: it is the link that passes ranking value without declaring itself. Link building remains a legitimate activity, and Google spends half of the link spam entry explaining how to stay on the right side of it rather than banning it.
The last row is the most awkward, because it concerns a tool every agency uses, ours included. Google has never acted against anyone tracking their own rankings, but the policy is written down and that is what it says. It is the best reminder that white hat is not a clean category: it is a scale, and where you stop is decided by whoever does the work, not by the search engine.
Generative AI is not black hat. Mass production is
In February 2023 Danny Sullivan and Chris Nelson published Google's official position on AI-generated content: using automation does not breach the guidelines; using it to produce content whose primary purpose is to manipulate rankings does. The principle Google has repeated for years is that it rewards quality content however it is produced, and that the same concern had already come up ten years earlier with content mass-produced by humans.
A year later the policy was rewritten precisely to remove the question of authorship. The old entry was called automatically generated content; since 5 March 2024 it has been called scaled content abuse and applies, in its own words, whether automation, humans or a combination of the two are involved. What counts is scale and value, not the tool.
Google has put a number on the effect. Elizabeth Tucker, director of product management for Search, announced that the combination of that update and previous work would reduce low-quality, unoriginal content in the results by 40%. In an update dated 26 April 2024 the same post revised the figure upwards: once the rollout was complete, on 19 April, the measured reduction was 45%.
For anyone writing with AI, the practical consequence is a single one, and it is E-E-A-T: experience, expertise, authoritativeness, trustworthiness. Google recommends adding a byline where readers would expect to know who wrote the content, and disclosing the use of AI where it would be natural to wonder how the text was made. It also added that putting AI in the byline is probably not the right choice. We have collected the available data on how AI-generated content gets indexed and ranks elsewhere.
In the EEA one policy works differently, and the UK is outside it
Since 30 August 2026 the site reputation abuse policy works in two ways, depending on where the searcher is. Google announced it on 28 August, after discussions with the European Commission.
Outside the European Economic Area, which includes the United Kingdom, a manual action has the usual effect: the section of the site in question is demoted in the results, the rest of the domain is not. Inside the European Economic Area that effect does not apply: the section can be separated in Google's systems and, over time, rank on its own, independently of the rest of the site. Google wrote that it remains concerned that an overly broad application of the DMA will stop it acting against real manipulation, and in the meantime it has opened a faster reconsideration process for European sites and the option of taking disputes to mediation with CEDR.
For a UK publisher hosting third-party sections, from voucher codes to comparison tools to sponsored features, the difference is concrete: the same page can be demoted for someone searching from London and not for someone searching from Dublin. Google lists four things it looks at in this review: how the section is presented in relation to the rest of the site, its quality, whether the author and the editor responsible are named, and whether the same content appears word for word on other sites.
How to check you are on the right side
The verdict lives in one place only: the Manual Actions report in Google Search Console. If a Google reviewer has decided that part of the site breaks the policies, a message appears there with the category concerned, and that is where you send the reconsideration request. When we take on a site in our SEO services, it is the first screen we open, before we even look at traffic data.
What confuses almost everyone is that most ranking losses do not go through there. Automated spam systems and core updates work on their own and generate no notification: a site can lose half its organic traffic with the Manual Actions report completely empty. These are two different diagnoses, and mixing them up wastes months.
One thing the industry rarely says: there is no white hat certification. Google issues no document, there is no badge, no register of compliant agencies. Anyone selling "white hat techniques only" is making a promise about their own work, not citing a status someone has verified. The only verdict that exists is that page in Search Console, and it is empty by default: empty means nobody at Google has looked yet, not that you are doing well.
White hat SEO FAQs
White hat SEO respects search engines' spam policies, black hat SEO breaks them. The line is not a moral judgement: it matches a public list of sixteen practices that Google describes by name, from cloaking to link spam.
Not in itself. Google writes that buying and selling links is a normal part of the economy of the web and does not break the policies, provided the link is marked with rel="sponsored" or rel="nofollow". It becomes link spam when it passes ranking value without declaring itself.
No. In February 2023 Google stated that appropriate use of AI does not breach its guidelines. What breaks the policies is producing many low-value pages to rank, and since 5 March 2024 the rule applies in the same way whether they were written by a machine, a person or both.
Not in Google's documents: a practice either breaks the spam policies or it does not. In industry jargon, grey hat refers to techniques that stay outside the letter of the policies but exist only to influence rankings, and which can therefore end up on the list at the next update.
Open the Manual Actions report in Google Search Console. If it is empty, you have not received a manual action. A traffic drop with that report empty is almost always down to an algorithm update or a technical problem, not a penalty.