"Suspected deceptive pages": a possible social engineering flag
This issue means your site "has been flagged for potentially containing content that tricks visitors into doing something dangerous." The wording is softer than the Deceptive pages issue: Google says Safe Browsing warns users before pages that may display deceptive content, where the firm version covers pages that consistently do. The definitions are the same: pretending to be a trusted entity, or pushing visitors to do something they would only do for one.
So you may be dealing with a real but intermittent scam, such as one that only shows to some visitors, or a legitimate page that looks enough like a scam to raise suspicion. Either way the steps are the same: confirm, fix, and request a review.
Do not assume the softer wording means a softer outcome. Browsers using Safe Browsing can still warn visitors while the flag stands, and a warning page costs you almost every visitor who sees it. Treat the issue with the same urgency as a confirmed one, and check the report's first-detected date against recent changes on the site, such as a new ad partner, plugin or landing page.
Why a page might only be suspected
Two very different situations lead here.
Intermittent deception. Hacked sites often show scams conditionally: only on mobile, only to visitors from certain countries or search engines, only once per visitor, or only when a rotating ad slot serves a bad creative. Safe Browsing may see it some of the time.
Legitimate pages that look like scams. Things that commonly trip the filter on WordPress sites:
- A "Download" button styled as a Windows or macOS dialog, or a fake progress bar.
- A login page that copies a well-known provider's branding, for example a "Sign in with" screen built by hand instead of using the provider's official button.
- A support page for your own product that says "Your computer may be at risk, call now".
- Payment or account pages on a domain that does not match the brand shown.
- Aggressive countdown or "virus detected" style marketing copy.
The second group are your own design choices, which makes them easy to fix.
Checking each example URL
Open every example in URL Inspection and view both the mobile and desktop screenshots, as Google suggests. Then load it a few times in a clean browser profile on a phone and on a computer, with no ad blocker, arriving from a Google search. Note anything that:
- Imitates the browser, operating system or another company's interface.
- Asks for a password, card details or a phone call.
- Starts a download or asks the visitor to install something.
- Appears only sometimes.
If something appears that you did not put there, treat the site as compromised and work through Hacked: Code injection. If it comes and goes with ads, look at deceptive embedded resources.
Redesigning pages that look deceptive
For legitimate pages, remove the resemblance rather than arguing about intent:
- Use plain buttons that say exactly what they do: "Download invoice (PDF, 120 KB)".
- Use official sign-in buttons and libraries from identity providers, not hand-drawn copies of their logos.
- Keep payment and login on your own domain, with your own branding, over HTTPS.
- Drop alarmist copy that sounds like a security warning.
If, after checking, you are confident the page is not deceptive and nothing third-party on it is either, Google offers a way to report a Safe Browsing classification error. The Security issues report links to it from the issue details. Hydrogen SEO does not influence Safe Browsing classifications; it controls titles, descriptions, schema and similar metadata, none of which trigger this.
Filing the request
When the examples and similar pages are fixed, select Request Review in the Security issues report. Explain which of the two situations applied:
The flagged page /download/ used a button styled like a Windows
dialog and a fake progress bar. We replaced it with a plain labelled
button and a file description. No third-party scripts load on this
page. We found no signs of compromise (core and plugin checksums
verified, no unknown admin users).
The review normally takes a few days, and can run to a few weeks, according to Google. Warnings remain until then. If the page is flagged again later, the design probably still resembles something Safe Browsing associates with scams, so compare it with the list above.
Common questions
What is the difference between Deceptive pages and Suspected deceptive pages?
Both use the same definition of deceptive content. Deceptive pages covers pages that consistently show it; Suspected deceptive pages covers pages that may show it, so the evidence is less certain.
Can a legitimate page be flagged as suspected deceptive?
Yes. Pages that imitate system dialogs, copy another brand's login, or use scam-like warnings can be flagged even if you meant no harm. Redesigning them usually resolves it.
Should I report the flag as an error?
Only after checking the page thoroughly, including ads and embedded content. If nothing is deceptive, Google provides a way to report a Safe Browsing classification error.