
How to Identify and Fix Google Penalties
Start by checking the "Manual actions" report in Google Search Console. If entries exist there, document every affected URL or pattern, fully fix each individual instance, and only then submit a reconsideration request with complete evidence. Submitting too hastily without solid documentation costs you valuable time, because Google reviews every request manually.
Fixing Google penalties, precisely
SEYBOLD identifies manual actions and sudden ranking drops, builds data-driven strategies, and supports the recovery of your visibility.
Request a free consultationWhat a manual action is and how it differs from algorithmic updates
A manual action arises when a human reviewer at Google determines that a website violates the spam policies. This is the key difference from algorithmic ranking drops, which happen automatically and without a case-by-case human review. Consequences range from a lower ranking for individual pages to the complete removal of the entire domain from the search index.
Google isn't pursuing punishment in the narrow sense here; it wants to keep its own search index clean. That's why lasting structural changes matter more than cosmetic fixes — a repeat manual action typically carries more weight than the first one. The "Manual actions" report in Search Console is the only reliable source for finding out the current status. Algorithmic updates leave no entry there; they only show up in traffic and ranking trends.
A clear categorization is worth doing for diagnosis, since each case group calls for a different remediation strategy:
- Link-related violations: unnatural inbound or outbound links, often from link networks or paid placements.
- Content-related violations: thin content, auto-generated text, or scraped content.
- Technical deception: cloaking, sneaky redirects, or hidden text.
- User-generated content: spam in comments, forums, or guestbooks without adequate moderation.
- Hacked content: malicious code or spam pages injected by third parties on compromised domains.
This categorization later determines which forensic evidence you need to gather for the reconsideration request.
Practical checks: using Search Console, the URL Inspection tool, and the Message Center correctly
The "Manual actions" report sits in Search Console under the Security & Manual Actions menu item. There you can see at a glance whether an entry exists at all, what kind of violation was reported, and whether the action affects the entire site or only parts of it. The Message Center additionally alerts you to new notices, so you don't miss changes.
It's important to distinguish this from the URL Inspection tool: it only confirms a page's technical indexability, but doesn't show whether that same page is being demoted in rankings due to an active manual action. The message "URL is on Google" is therefore no guarantee that the page also appears in the search results. Many site owners confuse this technical signal with content-level approval, which leads to misjudged priorities.
Proceed systematically:
- Open the "Manual actions" report and note every reported category individually.
- Check whether the notice applies site-wide or is limited to specific patterns.
- Export sample URLs or patterns from the report, wherever provided.
- Cross-check this list against your sitemap and your page directory.
- Prioritize by traffic relevance and proximity to revenue-relevant pages.
Pro tip:Write down the exact wording of every notice, since the phrasing in Search Console often already gives the decisive clue about which case group is involved.
Which pages are affected: spotting patterns and inventorying affected instances
Before you start fixing anything, you need a complete inventory. Manual actions affect either the entire domain or subdomain, individual directories or paths, or only specific single URLs. This distinction determines how broad your review needs to be.
Several techniques help with the inventory, used in parallel:
- Use Search Console's filter functions to export sample affected URLs.
- Cross-reference the findings against your current sitemap to uncover forgotten or orphaned pages.
- Check server log files for unusual crawling or access patterns that point to hacked areas.
- Check the index status of every affected URL to see whether Google is still crawling the page at all.
- Document every pattern you find with a timestamp, so the later chain of evidence stays complete.
Then prioritize by three criteria: the traffic volume of the affected pages, their importance for conversions, and their relevance to indexing the domain as a whole. An affected landing page with a high revenue share deserves more attention than a forgotten subpage with barely any visitors. Tools for an initial diagnosis, for instance from our overview of free SEO tools, speed up this cross-check considerably.
Typical causes of manual actions and forensic evidence
The most common triggers fall into clearly distinguishable case groups. Unnatural links — bought or exchanged at scale — top the statistics regularly. Alongside that, hacked or duplicated content shows up, where third parties place foreign content on your own domain. Cloaking and sneaky redirects deceive search engines and users with different content, while back-button hijacking keeps visitors from leaving the page through manipulated navigation. User-generated spam usually arises in poorly moderated comment sections or forums.
Each case group needs its own method of evidence:
- Unnatural links: a complete link export from your available tools, documented outreach attempts to have them removed.
- Hacked content: a Wayback Machine comparison of the page before and after the incident, server logs with a timestamp of the attack.
- Cloaking: screenshots of the content served to Googlebot compared with the user-facing view.
- User-generated spam: export lists of the removed comments along with a moderation log.
- Back-button hijacking: code snippets of the removed scripts with a change date.
For link-related violations, the Search Console help on the disavow process states: removing links takes priority, and the disavow tool is only meant as a supplement when removal isn't possible. Simply uploading a disavow list without documented outreach attempts does not count as a complete fix. After the upload, processing by Google can take several weeks, which you should factor into your timeline.
Pro tip:Always collect evidence in its original format — a PDF export or a screenshot with a visible date — because documentation created after the fact looks less credible when Google reviews it.
If the affected link profile spans several hundred questionable domains, or the origin of the links stays unclear, an external forensic review is worth it. Our guide to backlink analysis shows which patterns point to coordinated spam campaigns.
Concrete remediation steps and documentation before the reconsideration request
Each case group calls for specific technical measures. For link-related violations, first remove as many unnatural links as possible directly at the linking domains, and use the disavow tool only for links that can't be removed. For hacked content, fully clean up the malicious code, change any compromised credentials, and check all files for remaining backdoors. If a noindex tag was mistakenly set, remove it and confirm correct indexability via the URL Inspection tool.
Documentation before the reconsideration request should fully cover the following points:
- A complete list of all originally affected URLs or patterns.
- Screenshots or exports showing the state before and after the fix.
- Communication logs with third parties, for example when requesting link removal.
- A timestamp for every action taken, so the sequence remains traceable.
- An updated sitemap containing only cleaned, indexable pages.
- Confirmation that Google can technically access every relevant page — no login wall and no blocking noindex left in place.
After uploading a disavow list viaGoogle Search Console, processing by Google can take several weeks, which means you should schedule this step early, before submitting the reconsideration request.
Before submitting, a staging validation is worthwhile: check on a test environment whether all fixes are actually live before you file the request. Our on-page and off-page checker helps uncover any remaining technical issues before submission, such as directories accidentally blocked in robots.txt.
The reconsideration request: what Google wants to see, and how to avoid rejection
The reconsideration request, which you submit directly through the "Manual actions" report, needs to include three elements: a clear description of the original problem, a complete list of the resolved instances, and evidence for every fix carried out. Google also expects an assessment of what preventive measures will stop future violations.
Typical rejection reasons can be avoided:
- Incomplete remediation, because individual patterns or subdomains were overlooked.
- Missing or vague evidence, for example without timestamps or without specific URLs.
- A repeat request filed too soon, without anything new having changed since the last rejection.
Experienced SEO practitioners stress that a successful request has to credibly show that structural changes rule out future violations; according to SISTRIX, surface-level fixes are often not enough. A proven structure for the request starts with the problem description, followed by the list of fixes, the evidence, and a short paragraph on the preventive measures introduced.
Pro tip:Write the request factually and specifically, skip the justifications, and put the focus on what you changed, not on why the violation happened.
Timelines, status messages, and handling rejected reviews
Reconsideration requests usually take a few days to weeks, and often significantly longer for link-related cases, because Google reviews the completeness of the link cleanup more closely. Search Console shows the status per instance: Pending, Passed, Failed, or Other, each with notes on which URLs still show issues.
When you get a Failed notice, proceed systematically:
- Carefully review the hints Google provides about remaining instances.
- Cross-check these against your original inventory list to find overlooked patterns.
- Carry out the necessary fixes and document them again.
- Only then submit a new, well-substantiated request.
Repeated submissions without new evidence tend to delay the process rather than speed it up, since every review is done manually and needs time accordingly.
Diagnostic path: manual action vs. algorithmic ranking drop
Not every ranking drop is a manual action. A clear diagnostic path helps narrow down the cause quickly:
- First check the "Manual actions" report in Search Console: an entry there is the clearest signal.
- If there's no entry, cross-reference the timing of the ranking drop with known Google update periods.
- Run a backlink analysis to spot sudden unnatural link patterns.
- Check logfiles and crawl frequency for anomalies that point to technical rather than content-related causes.
- Assess the content quality of the affected pages against competitors.
If the report shows no entry, much of the evidence points to an algorithmic effect, which calls for a different approach than a manual action. If, on the other hand, several indicators appear at once — say, a ranking collapse alongside unusual link patterns — an external forensic review is usually the faster path to clarity.
A forensic audit checklist drawing on SEYBOLD experience: evidence, process steps, and templates
SEYBOLD works on ranking drops and Google penalties using a data-driven, forensic approach built on complete evidence documentation and structural countermeasures. The goal isn't just fixing the acute problem, but also preventing repeat violations through durable process changes.
A forensic review typically covers the following areas:
- Link forensics to identify coordinated spam patterns in the backlink profile.
- Wayback Machine comparisons to place manipulated or hacked content in time.
- Server log analysis to uncover unusual crawling or access patterns.
- Access-rights checks on CMS logins to close off entry points for hacking incidents.
- Moderation reviews for user-generated content, to catch future spam early.
- Staging validation before every reconsideration submission, to rule out remaining technical errors.
Handling reconsideration requests correctly requires a clear, structured evidence file with a list of URLs, screenshots, timestamps, and communication logs. Agencies frequently add process and quality-assurance measures to this file that lower the risk of a repeat violation.
Lasting visibility doesn't come from quickly patching a symptom, but from consistently removing its cause — Ralf Seybold
When external help with manual actions makes sense
In-house teams handle plenty of simple cases on their own — removing individual spam comments, for instance, or submitting a missing sitemap. But once the scope grows, say hundreds of affected links or several domains affected at once, in-house handling quickly becomes a resourcing question. Complex cases with unclear link origins or deeply nested hacking traces also often demand more forensic experience than a marketing team can bring to bear on the side.
Agencies typically deliver three things in such cases: systematic forensics to clarify the cause, coordinated link-removal campaigns with documented outreach attempts, and precise drafting of the reconsideration request along with follow-up monitoring. There are agencies with many years of experience in visibility management that have helped develop their own standards under DIN SPEC 33461 to structure forensic reviews in a traceable way.
Support with forensics and reconsideration
When fixing a manual action demands more than a single afternoon, it's worth looking at specialized support. A forensic audit, for example, is offered in the price range of €1,500 to €5,500 one-time, which targets root causes and delivers the evidence documentation needed for the request.
On top of that, a full visibility audit starting at €3,000 one-time helps identify structural weaknesses beyond the acute action. For ongoing protection against risky link patterns, link risk management is available as a fixed part of the service offering, and anyone who wants to keep an eye on their own visibility across multiple answer systems will find a corresponding offer in monitoring across multiple answer systems.
- Forensic audit for root-cause clarification and evidence documentation.
- Visibility audit for structural safeguarding after the cleanup.
- Link risk management for ongoing protection of the link profile.
- Workshops for building in-house expertise, such as the Technical SEO Workshop.
If you need support assessing your case, start with an initial conversation via our services overview.
Sources
For further reading on your own, it's worth going straight to Google's documentation, which is updated regularly and forms the binding basis for every review.
- "Manual actions" report - Search Console Help
- Spam Policies for Google Web Search - Google Developers
FAQ
How do I check whether a manual action is in place?
Open the "Manual actions" report in Google Search Console under the Security & Manual Actions menu item. If there is no entry there, no active manual action is in place, and a ranking drop has a different cause, such as an algorithmic update.
How long does processing a reconsideration request take?
Processing typically takes several days to weeks, and often significantly longer for link-related cases, because Google checks the completeness of the fixes closely. Repeated submissions without new evidence do not speed up the process.
Can I lift a manual action myself?
A manual action is not lifted by technical fixes alone, but only after a successful reconsideration request submitted through the "Manual actions" report. This requires fully resolving every reported instance, along with evidence.
What is the difference between a manual action and an algorithmic ranking drop?
A manual action appears as a specific entry in Search Console and is based on a human review against the spam policies. An algorithmic ranking drop leaves no entry there and shows up only in traffic and ranking trends around known update periods.
Is removing links enough, or do I also need to use the disavow tool?
According to Google, removing links takes priority; the disavow tool is only meant as a supplement when direct removal isn't possible. Simply uploading a disavow list without documented outreach attempts does not count as a complete fix.
