I have been penalized by Google

I've been penalized by Google
Let’s look at what has actually happened

A serious drop in Google can look brutal.

On Monday, you receive hundreds of visits from search results. A few days later, the traffic has been cut in half. Pages that held stable positions on the first page are suddenly nowhere to be found among the first hundred results. The phone stops ringing. Orders decline. The curve in Google Search Console looks like the edge of a cliff.

It is easy to conclude that Google has penalized you.

Sometimes that is true. Usually, it is not.

I have seen websites whose owners believed they had been penalized when someone had accidentally added noindex to the entire site. I have seen drops caused by failed migrations, removed internal links, hacked pages and incorrect canonical tags.

I have also seen sites hit by manual actions, major algorithmic changes and systems that stopped assigning value to links that had previously supported almost all their rankings.

The result can look exactly the same in the traffic graph. The solution is completely different.

That is why I never begin by cleaning up links, rewriting hundreds of articles or building a new website. I begin by finding out what actually happened.

This is one of the hardest things you can do in SEO. In my view, most SEO consultants are nowhere close to mastering it. The reason is simple. Penalties and filters are not common enough for most consultants to get much practice.

The work can also take a long time and be difficult to evaluate along the way. A manual action can remain in place for two years, regardless of whether you have corrected the problems. Google also provides very little feedback in these situations. They consider you a crook, sort of. Their attitude has changed during the past decade, but that is still the basic position.

Sooner or later, many businesses that have suffered a manual action or filter, what they experience as a Google penalty, end up coming to me.

Over the years, I have worked with hundreds of websites affected by the problems described below. It is not impossible to learn how to deal with them. It just requires a lot of experience.

This is roughly the checklist I use when I try to save a website that Google no longer trusts.

Vertical infographic titled “Traffic crashed. Start here.” It explains how to determine whether a website received a manual action, was affected by a Google update, suffered technical errors, or lost Google’s trust. A note beside the heading says: “The drop will not fix itself. Find out why.” Another says: “Analyze before action. Always.”

The flowchart contains four numbered steps connected by downward arrows.

Step 1 is “Manual action.”

What you check: “Google Search Console, Manual Actions.”

What it usually means: “Google has reacted to something specific: links, thin content, spam, cloaking, or similar issues.”

What you do: “Read exactly what Google says. Fix the whole problem, not just a few examples. Then submit a reconsideration request.”

Time: weeks to months.

Brutality: high.

Chance of success: medium.

Side note: “Clearest diagnosis. Not the easiest fix.”

Step 2 is “Core update or spam update.”

What you check: “Does the drop line up with Google’s official update dates?”

What it usually means: “Core update: Google prefers other results. Spam update: Google trusts the method, content, or links less.”

What you do: “Compare which pages lost visibility, which competitors won, and what your site actually adds. Wait until the rollout is finished before drawing conclusions.”

Time: months.

Brutality: high to extreme.

Chance of success: medium to low.

Side note: “This is where most people underestimate how long it takes.”

Step 3 is “Technical errors.”

What you check: “Noindex, robots.txt, status codes, canonical tags, redirects, migrations, internal links, hacking.”

What it usually means: “The site may be broken rather than penalized. Often the best news you can get.”

What you do: “Review changes made before the drop. Fix indexing, redirects, links, or security problems.”

Time: days to weeks.

Brutality: low to medium.

Chance of success: high.

Side note: “Boring problem. Good diagnosis.”

Step 4 is “Filters, content, links and ads.”

What you check: “Thin or mass-produced content, doorway pages, manipulated links, too many ads, weak original value.”

What it usually means: “Google has lost trust in parts of the site or in the whole model behind it.”

What you do: “Clean up harder than you want to. Remove, merge, or rewrite weak pages. Stop relying on questionable links. Build real quality and authority.”

Time: months to years.

Brutality: extreme.

Chance of success: low to medium.

Side note: “You often do not get all the traffic back.”

The final section says: “Don’t start with panic. Start with diagnosis.”

It lists six actions:

Define the drop.
Check manual actions.
Compare update dates.
Rule out technical errors.
Review quality, links and content.
Decide how brutal you need to be.

The closing statement reads: “The hard part is not finding the problem. The hard part is accepting what has to go.”

My investigation normally follows four steps

  1. I check whether the website has received a manual action in Google Search Console.
  2. I compare the drop with the dates of Google core updates and spam updates.
  3. I investigate whether technical errors could have caused the drop.
  4. I examine issues that may have caused Google’s automated systems to value the site less.

The order matters. I prioritise the checks based on how easy they are to perform and how easy the problem is to correct.

Checking for a manual action is simple. Google tells you about it in Search Console. A filter involving the kinds of problems historically associated with Panda or Penguin is much harder to identify and much more painful to repair.

Do not spend months rebuilding your content if the real problem is a forgotten WordPress setting.

Start by defining the drop

A Sistrix Graph showing a steep drop, can often be interpreted as a penalty but that is far from certain
There are 4 main areas I check when I see a steep drop in rankings

Sistrix is one of my favourite tools for investigating a website that has crashed.

Before I look for the cause, I want to know what has actually declined.

It is not enough for someone to tell me that traffic has fallen. I want to know when the decline began, how quickly it happened and which parts of the website were affected.

A drop can mean that

  • the entire site has lost visibility
  • a specific directory has disappeared
  • particular page types have declined
  • commercial searches have fallen while informational searches remain stable
  • positions are stable but the click through rate has decreased
  • the number of indexed pages has collapsed
  • branded searches still work while generic searches have disappeared
  • traffic has shifted between web search, images, video, news or Discover
  • market demand has decreased even though positions remain unchanged

I therefore compare data from several sources.

Google Search Console shows clicks, impressions, queries, pages and average positions. The analytics platform shows what is actually happening on the website. An external ranking tool can help determine whether the site has lost search visibility or whether the main change is in traffic.

Choosing the correct comparison period also matters.

An online retailer can experience a dramatic decline after Christmas without anything having changed in Google. A company selling heat pumps will see different search demand in July than in January.

Do not only compare the week after the drop with the week before it. Compare it with the same period during the previous year and check whether demand for the most important searches has changed.

The more precisely you can describe the drop, the easier it becomes to identify its cause.

Check for manual actions

Message on manual action in Google Search Console
If someone at Google has taken manual action against your site a message will show up in Google Search Console

When someone at Google has taken manual action against your website, Google informs you through Search Console.

You are also told, often in rather vague language, what must be corrected before the site is welcome back.

The first thing I do is open Google Search Console and go to the Manual actions report.

A manual action means that a human reviewer at Google has decided that the website, or parts of it, violates Google’s rules. The action can affect individual pages, a section of the website or the entire site.

This is the easiest type of Google problem to diagnose. Google tells you that the action exists and identifies the kind of violation it has found.

That does not mean it is easy to repair.

Google can take manual action for issues including

  • unnatural links pointing to the site
  • unnatural links from the site
  • thin content with little or no added value
  • hidden text and excessive keyword use
  • cloaking and deceptive redirects
  • pure spam
  • user generated spam
  • spam published on the site by third parties
  • misleading structured data
  • hidden images
  • unexpected mobile redirects
  • back button hijacking

Google can also take specific actions that affect visibility in Google News and Discover.

When the report shows no manual action, you have not received one. You may still have been affected by Google’s automated systems, but you should not submit a reconsideration request.

Reconsideration requests are for manual actions.

How to repair a manual action

Begin by reading exactly what Google says.

Do not try to solve the action you believe you have received. Solve the action that is actually shown in Search Console.

You then need to identify the full extent of the problem.

When the action concerns thin pages, improving three obviously weak articles while leaving five hundred similar pages untouched is not enough. When it concerns outgoing links, you need to examine the entire pattern, not only the link Google happened to mention as an example.

Google explicitly states that the problem must be corrected on every affected page. A partial cleanup does not produce a partial return to the search results.

Your reconsideration request should explain

  • what was wrong
  • how the problem arose
  • which parts of the website you reviewed
  • what you removed or changed
  • how you made sure the same problem would not happen again
  • what evidence shows that the work has been completed

Do not try to convince Google that its reviewers misunderstood everything while leaving the problem in place.

A good reconsideration request focuses more on what you have done than on why you believe you deserve your traffic back.

How long a reconsideration takes

Google states that reconsideration can take several days or weeks. Cases involving links can take longer.

The removal of a manual action does not mean that your old rankings will automatically return.

When your previous rankings depended on links that Google has now stopped counting, you have lost the power those links provided. Once the manual action is removed, the site can compete normally again, but the removed link signals do not reappear.

This is an important distinction.

You can repair the penalty without repairing the traffic.

Compare the drop with Google updates

Google as an unreliabvle judge - Core Update vs Spam Update
Google can be a bit unreliable, up one date, down another

The timeline is your best friend. Compare the drop with the dates of spam updates and core updates.

When there is no manual action, I compare the decline with Google’s official dates for core updates and spam updates.

Google constantly makes smaller changes that are never announced. A few times each year, it launches broader changes known as core updates. Google also announces spam updates when it makes more substantial changes to the systems used to identify manipulation and spam.

A drop during one of these periods does not prove that the update caused it.

It is still a strong indication of what I should investigate.

Core updates

A core update is not a penalty aimed at a particular website.

Google describes core updates as broad changes to the way search results are evaluated. A page that moves down has not necessarily done anything forbidden. Google may simply have started preferring other results.

That is an important but frustrating distinction.

A manual action comes with a message and a named violation. After a core update, you can lose 80 percent of your traffic without receiving any clear explanation.

I begin by checking whether the decline really coincides with the rollout.

Google recommends waiting until the update is complete and then waiting at least another week before making a proper comparison. You can then compare one week after the update with one week before it began.

While waiting, I look for patterns

  • Which page types have declined?
  • Which competitors have taken the positions?
  • Do the winning pages contain more useful information?
  • Do they satisfy the search intent better?
  • Has the site produced large amounts of similar content?
  • Is there a clear publisher with relevant experience?
  • Is the information correct, current and sufficiently detailed?
  • Does the website offer independent value, or does it mostly repeat what already exists elsewhere?
  • Is it easy to understand who is responsible for the content?
  • Has the website become unfocused or lost its clear subject area?

I am not looking for a magic factor.

Core updates are broad. A major drop is rarely explained by a single heading, a specific word count or one technical metric.

Spam updates

Google’s systems for detecting spam are always active. When Google makes larger improvements to these systems, it may announce a spam update.

SpamBrain is one of the systems Google uses to detect spam.

When the decline coincides with a spam update, I investigate the entire method behind the site.

I look for issues including

  • content produced at scale without sufficient value
  • doorway pages targeting very similar searches
  • expired domains used to exploit old authority
  • third party content published to exploit the strength of the host website
  • cloaking
  • hidden text
  • manipulated links
  • mass produced pages with minor variations
  • copied or rewritten content without an original contribution
  • hacked content
  • deceptive functions or redirects

A website that violates Google’s spam policies can rank lower or disappear from search results entirely.

It may take months before Google’s automated systems recognise that the website is following the rules again.

When the links stop working

A decline caused by links can be particularly difficult to explain to a site owner.

Assume that a website has ranked because of a large number of links that Google previously valued. A spam update then improves Google’s ability to identify and neutralise those links. The website drops.

You can clean up the links and stop using the method. That does not mean the old positions will return.

The ranking benefit created by spammy links cannot be recreated simply by correcting the problem.

You do not necessarily have a remaining penalty. You have lost an advantage that Google no longer intends to give you.

To return, you must build the authority the website was missing in the first place.

It worked differently in the past.

Almost every link counted until Google concluded that manipulation was involved. Then the hammer came down and the site lost all its traffic.

Today, links that Google considers manipulative or low quality are more often ignored. This frequently happens continuously, although it can still arrive as a surprise.

Dates of major Google updates

Updates all the time - But what caused the drop
Did you know Panda and Penguin were Googles first AI in the search results. Nothing is new under the sun.

I use Google’s official status dashboard when comparing a traffic decline with updates. It shows both the start date and the length of each rollout.

The following updates are particularly relevant for websites analysing a decline during the past few years.

2026

Core updates

  • March core update: 27 March to 8 April 2026
  • May core update: 21 May to 2 June 2026

Spam updates

  • March spam update: 24 to 25 March 2026
  • June spam update: 24 to 26 June 2026

2025

Core updates

  • March core update: 13 to 27 March 2025
  • June core update: 30 June to 17 July 2025
  • December core update: 11 to 29 December 2025

Spam updates

  • August spam update: 26 August to 22 September 2025

2024

Core updates

  • March core update: 5 March to 19 April 2024
  • August core update: 15 August to 3 September 2024
  • November core update: 11 November to 5 December 2024
  • December core update: 12 to 18 December 2024

Spam updates

  • March spam update: 5 to 20 March 2024
  • June spam update: 20 to 27 June 2024
  • December spam update: 19 to 26 December 2024

Use these dates as support for the diagnosis, not as proof.

When the decline began on the same day as a core update, the connection is interesting. When the developers also launched a new site structure, removed old redirects and changed the JavaScript setup, you still need to investigate the technical changes.

Look for technical errors

Technical errors are often the best news you can receive after a major decline.

They can be expensive and difficult to correct, but at least they are concrete. You do not need to understand how Google evaluates the entire website. You need to find the error, repair it and make sure Google can crawl and index the correct pages again.

The simplest approach is often to trace every change made on or shortly before the date of the decline.

A failed deployment is more common than an actual Google penalty.

I begin by checking whether Google can still access the website.

Indexing

I check issues including

  • whether important pages have received noindex
  • whether robots.txt blocks Googlebot
  • whether pages return the correct status codes
  • whether canonical tags point to the wrong URLs
  • whether the sitemap contains the correct pages
  • whether Google chooses different canonical URLs from those specified by the website
  • whether large numbers of pages have disappeared from the index
  • whether important pages depend on JavaScript that Google cannot render as intended
  • whether login systems, firewalls or security software block Google
  • whether the domain or protocol has changed without proper redirects

The Page indexing report and the URL inspection tool in Search Console are central to this investigation.

Search Console can also reveal security problems and issues involving structured data.

Migrations

Many dramatic declines begin with the words:

We only launched a new website.

During a migration, URLs can change, internal links can disappear, redirects can be configured incorrectly and content can accidentally be removed.

The new site can look better to users while becoming far more difficult for Google to understand.

I compare the old and new structures

  • Do all important pages still exist?
  • Does each old URL redirect to the closest relevant new URL?
  • Have many pages been redirected to the home page?
  • Have headings, text and internal links disappeared?
  • Have important pages moved several clicks deeper into the site?
  • Do old domain versions still exist?
  • Have parameters and filters created new duplicates?
  • Do removed pages return the correct status codes?

A migration error can cause a rapid and very clear decline. It can also develop gradually as Google crawls more of the new URLs.

Internal links and navigation

Google needs links to find pages and understand how they relate to the rest of the website.

When a redesign removes links to important categories, those categories can lose visibility even when the pages still exist and remain indexed.

The same thing can happen when links are implemented using technology Google does not interpret as ordinary links, or when large parts of the navigation break.

I do not only check whether the page exists. I check whether the website still treats it as important.

Hacking and spam

A hacked website can suddenly contain thousands of pages about pharmaceuticals, casinos, fake support services or other subjects that have nothing to do with the domain.

These pages are not always visible in the ordinary navigation. Google can still discover them and allow them to affect its evaluation of the site.

Check the Security issues report in Search Console, server logs, new user accounts, unexpected files, altered templates and indexed URLs you do not recognise.

Removing the visible spam pages is not enough.

You must also close the security vulnerability, change the affected passwords and make sure the attacker has not left another way back in.

Investigate algorithmic filters and demotions

SEO-steroids, grow fast. Die Hard.
Programmatic SEO has been the new fad but there are great risks with it.

Did you know that Panda was Google’s first attempt to use AI in the search results?

There is nothing new under the sun.

Once manual actions and technical errors have been ruled out, the more difficult part begins.

I still sometimes use terms such as Panda and Penguin when explaining these types of problem. They are useful because many people in SEO recognise them.

You should not imagine them as two separate filters that Google starts at particular times and later switches off.

The underlying issues remain part of Google’s broader systems.

Panda broadly concerned thin, weak and mass produced content. Penguin concerned manipulated links and unnatural link patterns.

Google’s systems have developed, but websites can still lose visibility because of the same fundamental problems.

Weak content

I look for content that exists to cover a search phrase rather than to help a person.

Today, this often results from programmatic SEO. It worked differently in the past, but this has become a service people sell, and it is producing victims.

The trap is easy to fall into.

Every new article gives the website an opportunity to appear for one or more additional search terms. The results often appear to move upwards. Every day looks slightly better.

It is a kind of steroid treatment for SEO. The site becomes bigger and stronger every day until its heart gives out.

After that, the website is more or less dead.

Weak content can include

  • hundreds of local pages where only the place name changes
  • categories containing nearly identical information
  • thin affiliate pages without original analysis
  • automatically generated text without editorial review
  • summaries of other sources without independent insight
  • old articles that are no longer correct
  • pages where advertising is the main content
  • long articles that still fail to answer the question
  • notes and fragments published as finished articles
  • internal search result pages indexed at scale

The problem is not automatically solved by writing more words.

Sometimes the page needs to become better. Sometimes several pages need to be combined. Sometimes the page must be removed.

Google describes removal as a last resort and recommends first trying to improve content that can be saved.

Manipulated links

I investigate both the links and the strategy behind them.

A pattern can matter more than an individual link.

One hundred links using commercial anchor text from irrelevant pages are different from a natural mixture of branded links, editorial mentions and relevant references.

I examine factors including

  • how quickly the links appeared
  • which websites they come from
  • whether the same networks keep recurring
  • whether the content surrounding each link has a real purpose
  • whether the anchor text is unnaturally exact
  • whether the links were bought, exchanged or mass produced
  • whether the website links out using the same manipulative methods
  • whether previous rankings depended on a small number of questionable links

A disavow file is not my first response when a website declines.

A major drop is not proof that links need to be disavowed. I first need to understand whether a real link pattern exists and whether the website risks, or has already received, a manual action.

Too much advertising

Ads above the fold was a common name for Google’s system targeting pages where advertising occupied so much space that users had difficulty finding the main content.

The underlying question remains relevant.

When I open the page, I want to see whether users can immediately understand what it is about and access the content.

When the screen is initially covered by full screen advertisements, cookie notices, newsletter prompts, app promotions, video players and several advertising blocks, the website has created an obstacle between the visitor and the information Google sent them to find.

That does not mean one advertisement automatically causes a penalty.

It means the actual usefulness of the page needs to be evaluated, particularly on mobile devices.

Doorway pages

Doorway pages are created to capture many similar searches and send users towards the same underlying destination.

A common version consists of hundreds of pages for different places, services or combinations where the content is essentially identical.

Another version uses several domains or subdomains that appear different but lead to the same company and offer.

These setups can work for a long time.

That does not make them safe.

When Google begins evaluating them differently, the decline can be severe because such a large share of the traffic was built on the same method.

Determine the real cost of recovery

The cost of repairing a Google problem is not determined only by how far the website has fallen.

It depends on what created the rankings in the first place.

A forgotten noindex directive may take minutes to correct. A failed migration can require several days of technical work. A content problem affecting tens of thousands of pages can require months of analysis, rewriting and removal.

A website whose authority was built on links Google has stopped valuing may need to rebuild much of its credibility from the beginning.

I usually divide the work into four levels.

A limited technical error

This is the best case.

The problem is clear, such as an incorrect block, broken redirects or canonical tags pointing in the wrong direction.

Once the problem has been fixed, Google may need to crawl the pages again.

The cost can be limited when the website is small and the problem is simple. On a large online retailer with millions of URLs, even a seemingly simple error can become expensive.

A manual action

You need to complete a full cleanup, document the work and wait for Google’s review.

The cost depends on the action.

A few incorrect outgoing links may be easy to fix. A manual action involving thin content on a large website can require a complete review of the entire publishing model.

A quality problem

When a core update has revealed that the site no longer matches the standard of its competitors, there is rarely a quick technical solution.

You may need to improve editorial processes, remove old pages, combine overlapping content, hire real experts, create better images, collect original data and make it much clearer who is responsible for the information.

This is often expensive because the problem does not exist only on the website.

It exists in the way the company produces content.

Lost link signals

This can be the most expensive situation.

When the website previously ranked because of links that no longer count, you need to replace their effect with real authority.

That can require better products, better content, digital PR, original research, industry relationships and resources that other people genuinely want to reference.

You cannot clean your way back to link authority that Google has already stopped giving you.

You cannot replace it with more of the same method you used before. You need to build genuine authority.

One method that worked in the past, sometimes and often only temporarily, was redirecting the entire website to a new domain.

At first, filters did not follow the redirect. Later, they began following after a while.

I have carried out these redirects several times, with mixed results depending on the underlying problem.

One case involved an enormous gambling website that lost tens of millions in revenue after my client bought it. When I reviewed the site, I found that every single link was rubbish.

We redirected everything and received another three weeks in the search results.

That may sound pathetic, but it generated a few million. The redirect produced a good return.

We also began cleaning up the links, but the traffic never returned to its previous level.

Until a few years ago, many spammers used redirects to escape penalties and filters.

They did not build bad links directly to the website they wanted to rank. They built them to a separate domain that redirected into the main site.

When the penalty arrived, they dropped the domain that had received the links. The main website was once again clean from the rubbish.

How quickly traffic can return

After a technical error, improvements may begin appearing once Google has crawled and indexed the pages again.

This can happen quickly on an active website and more slowly on a site Google rarely visits.

After a manual action, you must first wait for reconsideration. That can take days or weeks. The pages must then be evaluated again by the ordinary systems.

The rankings do not have to return to their previous level.

There may also be a fixed time limit, such as six months or two years. In that situation, no corrective action changes the waiting period. The positions can only return afterwards, provided the website meets the requirements at that point.

After improvements following a core update decline, it can take several months for Google’s systems to learn that the site consistently produces useful and reliable content.

In almost every case, you need to wait until the next core update, or sometimes the one after that, before being allowed back into the warmth.

After a spam update, the systems may need months or years to determine that the site now follows the rules.

That makes the work difficult to evaluate.

You can make the correct change today and still see no clear result next week.

Document every significant action. Record what changed, which URLs were affected and when the change was published.

Otherwise, you will be sitting there several months later with ten simultaneous initiatives and still have no idea which one worked.

Do not start repairing before you have a diagnosis

Don't start fixing before you have a diagnosis

The most common response to a major decline is panic.

Someone changes every heading. Someone else removes half the website. A third person uploads a disavow file containing every link they do not recognise.

The developer changes the structure while the content team begins rewriting hundreds of articles at the same time.

After that, it becomes impossible to know what caused the decline or which change affected the result.

Work in the correct order

  1. Confirm what has actually declined.
  2. Check the Manual actions report.
  3. Compare the decline with Google’s official updates.
  4. Rule out technical errors.
  5. Review content, links, advertising and other possible quality problems.
  6. Formulate a clear hypothesis.
  7. Prioritise the changes that solve the underlying problem.
  8. Document what you do.
  9. Give Google time to process the changes.
  10. Evaluate the correct pages and searches, not only the total traffic of the website.

Doing one hundred things immediately may feel better.

It is still worse than doing the right thing first.