Deceptive site ahead

What "Deceptive site ahead" Means

Shoppers and owners
The short answer

It means Google Safe Browsing has flagged that site as trying to trick people into handing over passwords or payment details. Do not enter anything on it. Worth knowing: current versions of Chrome now show Dangerous site instead, so if you saw the older "Deceptive site ahead" wording you are likely on an older browser or a different Chromium browser.

Seeing this on a site? Check it now.

Paste the address and we will tell you exactly which check is failing, and why. Free, and you do not have to open the site yourself.

If you were just trying to buy something

Close the tab. Do not enter a password, card number, or any personal details, and do not click through the warning.

If you arrived from an email or a text message, treat that message as suspicious too. This is exactly how phishing works: a message that looks real, sending you to a site that looks real.

If you were trying to reach a shop you actually use, do not trust the link. Search for the business yourself, or type the address in directly.

If this is your site

Your site has almost certainly been compromised, and something on it is now serving a phishing page. This is usually not something you did, it is something that was done to you.

Do not just request a review. Find and remove the problem first, or Google will simply re-flag you. Then request a review in Search Console, which is covered further down this page.

The wording changed, and most guides have not caught up

This is the part almost nothing online tells you.

Chrome used to show three different red warnings depending on the threat: Deceptive site ahead for phishing, The site ahead contains malware, and The site ahead contains harmful programs. Current versions of Chrome have consolidated all three into a single heading: Dangerous site.

Confusingly, Google's own Search Central documentation still refers to "Deceptive site ahead", so even Google is inconsistent about it. The older wording also still appears in older Chrome versions and in other Chromium-based browsers.

So both are real. If you are reading a guide that presents "Deceptive site ahead" as the only current wording, that guide has not been updated in a while.

What Chrome actually says

Under the heading, Chrome explains the specific threat. For phishing and social engineering the text is:

Attackers on the site you tried visiting might trick you into installing
software or revealing things like your passwords, phone, or credit card numbers.

The buttons are "Back to safety" and "Details". The malware and unwanted-software versions of this paragraph are worded differently, which is now the main way to tell which threat Chrome detected.

Why a site gets flagged

Safe Browsing flags a site when it detects content designed to deceive visitors. In practice that means one of these:

  • The site is a deliberate scam, built to impersonate a real business and harvest logins or card details.
  • The site was hacked and someone quietly added a phishing page to it. This is by far the most common case for a legitimate business, and owners are usually the last to know.
  • A third-party script was compromised, so the site loads something harmful it does not host itself.
  • Deceptive content such as fake download buttons or ads that impersonate system warnings.

If it is your site: how to get the warning removed

The order matters. Requesting a review before you have actually cleaned the site wastes days.

  1. 1.Verify ownership in Google Search Console if you have not already, then open Security & Manual Actions and then Security Issues to see exactly what Google found and on which URLs.
  2. 2.Check who else has access. Google specifically warns to look for unauthorised users in your Search Console property, because attackers often add themselves so they can keep control. Remove anyone you do not recognise.
  3. 3.Find and remove the malicious content. Look at recently modified files, unfamiliar admin accounts, and any third-party scripts you did not add.
  4. 4.Close the way in. Update your platform and plugins, rotate every password, and enable two-factor authentication. If you skip this you will be reinfected.
  5. 5.Request a review in the Security Issues report, and describe the fixes you made. Google asks you to explain what you did, not just to click the button.

How long the review takes

Google's own guidance is that a review can take from a few days to a few weeks. There is no way to speed it up, and re-submitting repeatedly does not help.

This is the expensive part, and it is why the clean-up matters more than the request. If Google reviews your site and the problem is still there, you start again.

Frequently asked questions

Is "Deceptive site ahead" always correct?

Usually, but not always. Legitimate sites do get flagged after being hacked, sometimes over a single injected page the owner does not know about. The warning is about what Safe Browsing found on the site, not a judgement about the business. Either way, do not enter details until it is resolved.

Why does Chrome say "Dangerous site" instead?

Chrome consolidated its three separate red warnings into one heading. Malware, phishing and unwanted software now share the wording "Dangerous site", with the explanatory paragraph underneath describing the specific threat. Older Chrome versions and some other browsers still show the original headings.

Can I safely click through the warning?

We would not. The whole point is that the page is trying to deceive you, and clicking through gives it the chance. If you need to reach the real business, search for it or type the address yourself instead.

How do I check a site without visiting it?

Use the checker above, or our free site safety check. It queries Safe Browsing for you and reports the result, so you get an answer without loading the risky page in your own browser.

My site was flagged but I cannot find anything wrong. What now?

Start with the Security Issues report in Search Console, which lists the specific URLs Google objected to. Injected content is often hidden from logged-in administrators, or only served to visitors arriving from search, so check the exact URLs Google names rather than browsing your own site.

Related errors

See all errors explained →

Stop guessing what is wrong.

Run a free check on any site and see every trust and security signal at once, in plain English.

Run a free check Browse the fixes