// blog

Google's Spam Policies: What Actually Gets Your Site Demoted or Removed

Google's spam policies explained: 16 named categories, how SpamBrain enforces them, what Scaled Content Abuse and Site Reputation Abuse mean for your site.

By Bobby K · 

Most traffic drops have a boring explanation — a core update shuffled quality signals, a competitor got stronger, your pages lost freshness. But some drops are different. Some drops are enforcement. And the distinction matters, because you can’t write your way out of a manual action the same way you can improve your way out of a quality ranking dip.

Google’s spam policies are the enforcement layer of Search. They define what Google will demote algorithmically, flag for a human reviewer, or remove from results entirely. If you produce content at scale, buy links, run third-party monetisation on your domain, or acquired an expired domain for its authority, this article is directly about your risk exposure. The policies were last updated on 2026-05-15 — the most recent update in the entire Google Search documentation set at time of writing. Several things changed in ways that matter.

Here’s what the policies actually say, how enforcement works, and where the lines are in 2026.


Three distinct mechanisms get sites penalised. They work differently, look different in Search Console, and require different responses.

SpamBrain is Google’s AI-powered spam detection system. It runs continuously and handles the vast majority of spam enforcement automatically — no human reviewer involved. A SpamBrain action looks like an unexplained traffic drop, not a notification. You won’t get an alert in Search Console unless the algorithmic detection triggers a manual review. SpamBrain is specifically called out in Google’s spam policies documentation as the primary system, and it’s updated on a rolling basis, not just during named core updates.

Manual actions are issued by human members of Google’s Search Quality team after they’ve reviewed a site and found a clear policy violation. These show up in Search Console under Security & Manual Actions → Manual Actions. They’re explicit: the action type, the page or site scope, and a general description of what was found. Manual actions can be partial (affecting a subset of pages) or sitewide. They require a reconsideration request after you’ve addressed the violation — and that request goes to a human who reviews your work.

Legal removals are a third category, separate from spam enforcement. These handle court orders, defamation claims, child safety violations, and similar legal obligations. They’re not what most site owners are worrying about, but they’re worth naming because “Google removed my page” has three very different causes.

The practical diagnostic: if you have a traffic drop but no Manual Action in Search Console, you’re dealing with either an algorithmic ranking change (SpamBrain or core update) or a normal competitive shift. If there’s a Manual Action, you know exactly what category of problem you have.


The 16 Spam Policy Categories

Google’s documentation names 16 distinct spam policies. Most sites will never be in scope for most of them. Some are now directly relevant to normal business practices — especially content teams using AI tools and sites hosting third-party content.

Here’s the full set, with the ones that carry the most real-world risk for legitimate operators flagged:

Cloaking — Showing Google different content than users see. The deliberate version is a clear policy violation; the accidental version (misconfigured caching, A/B testing frameworks, personalisation that hides content from crawlers) is a common technical risk worth auditing.

Doorways — Pages created specifically to rank for a keyword and then redirect users somewhere else. Programmatic landing pages are not inherently doorway pages, but thin, near-duplicate pages that funnel all traffic to a single destination fit the pattern.

Expired Domain Abuse — Buying an expired domain with residual authority specifically to host affiliate or thin content, rather than continuing the original site’s purpose. If you’ve acquired a domain for its backlink profile, this policy applies to you.

Hacked Content — Spam injected by attackers (keyword stuffing in footers, redirect hijacking, hidden links in comments). You’re responsible for content published on your domain even if you didn’t put it there.

Hidden Text and Links — Text coloured to match backgrounds, zero-pixel elements, content behind layers users can’t see. CSS-based tricks that were common in 2005 and still show up in legacy templates.

Keyword Stuffing — Unnatural repetition of keywords in ways that serve no reader purpose. This includes block-lists of location/keyword variants stuffed into footers.

Link Spam (high risk) — Buying, selling, or excessively exchanging links. Covered in the next section in detail.

Machine-Generated Traffic — Automated systems sending fake traffic to manipulate engagement signals. Not a content policy but worth knowing it exists.

Malicious Practices — Malware, phishing, installing unwanted software, data harvesting without disclosure. Sitewide removal territory.

Misleading Functionality — Fake play buttons, fake download links, fake CAPTCHA screens designed to get clicks that benefit the site owner at user expense.

Scaled Content Abuse (high risk) — Producing large volumes of content that adds no original value, regardless of method. Directly addresses AI-generated content at scale. Covered in the next section.

Scraping — Taking content from other sites and republishing it with no added value. Thin aggregation, even with attribution, can trigger this.

Site Reputation Abuse (high risk) — Third-party content hosted to exploit the host domain’s authority. Covered further below.

Sneaky Redirects — Redirecting users to different destinations than Googlebot sees, or redirecting based on user-agent.

Thin Affiliation — Affiliate sites that add minimal original value and primarily republish product data from feeds. A template-heavy affiliate build with no differentiated content is the canonical example. See also thin content — the quality signal these policies formalise.

User-Generated Spam — Spam comments, forum posts, or profile pages that accumulate on sites with insufficient moderation. More relevant to open platforms than curated sites, but any site that allows public content without friction is in scope.


Scaled Content Abuse and AI: Where the Line Is

This is the policy that changed most relevantly for 2026, and the one most likely to affect content teams that have adopted AI writing tools.

Google’s spam policies documentation — updated 2026-05-15 — explicitly states that Scaled Content Abuse applies to content generated at scale using “generative AI tools or other similar tools” when that content doesn’t add value for users. The language is deliberate: the violation is not using AI. The violation is producing volume without value.

What the policy is targeting is a specific production pattern: taking a topic list, running it through a language model with a generic prompt, publishing the outputs without editorial review or differentiation, and doing it at a scale designed to occupy search results rather than inform readers. The existence of a human who pressed “Publish” doesn’t change the analysis if the editorial contribution ends there.

What the policy is not targeting: AI-assisted content where a knowledgeable author uses AI tools to accelerate research, structure arguments, or generate a first draft that they then substantially revise, fact-check, and bring genuine expertise to. The distinction is whether the content reflects real knowledge and adds original value, not whether a language model was involved in its creation.

In practice, Google’s enforcement signal is the same as it was before AI tools existed: does this page tell a reader something they couldn’t get by reading the first few results on the same query? If the answer is no for most pages in a batch, the batch is at risk under Scaled Content Abuse regardless of how it was produced.

The scale threshold is not stated in the policy — “many pages” is the language used. What matters is the combination of volume and value-per-page. A site with 200 AI-assisted pages where each one demonstrates genuine expertise is not the target. A site with 2,000 pages that are minor variations of each other, each thin, is exactly the target.


Link building remains one of the highest-signal inputs to Google’s ranking systems, which is exactly why it’s also one of the most manipulated. Google’s link spam policy covers the manipulation side.

The named practices are: buying or selling links that pass PageRank (including cash, goods, services, or cross-promotion), excessive reciprocal linking with the explicit purpose of inflating link counts, large-scale article marketing or guest post campaigns that are primarily link vehicles rather than genuine editorial contributions, and using automated programs to create links.

Private blog networks (PBNs) are the canonical link spam pattern — a constellation of sites that exist solely to link to each other or to a money site. SpamBrain’s link spam detection has been specifically cited by Google as a major investment area. Google has stated that SpamBrain continues to improve at identifying and neutralising link spam at scale.

The policy includes “excessive” link exchanges — with the word “excessive” doing real work. Exchanging links with two genuine editorial partners who have related audiences is ordinary behaviour. Running a link exchange programme with 300 sites through a shared spreadsheet is the target.

What this means for white-hat SEO: the legitimate link acquisition signals Google rewards are editorial links earned by publishing genuinely useful content, being cited in industry coverage, digital PR, and appearing as a genuine resource in roundups because someone made a genuine judgement that you belong there. None of those can be guaranteed through a link vendor.


Site Reputation Abuse: The Newer Policy Worth Knowing

Site Reputation Abuse is one of the newer named policies, and it addresses a specific growth pattern in the media and publishing space: hosting third-party content primarily to exploit the host domain’s authority for SEO benefit, rather than because that content fits the editorial purpose of the site.

The canonical example in Google’s documentation is a coupon or payday loan section on an otherwise reputable educational or news site — content that would not rank on its own domain but receives a ranking lift from being attached to a trusted host. The third-party operator benefits from the host’s authority; the host benefits from the revenue share. Google now treats this as a policy violation from the host’s perspective.

Who this affects in practice: any site that hosts third-party sponsored content sections under its primary domain, editorial partnerships where content is essentially outsourced to a partner who benefits from ranking under your domain authority, and sites that have historically sold “guest post” placements on high-authority domains as a link product.

The policy distinguishes this from legitimate editorial syndication. A news site that republishes wire copy from AP with clear attribution and for genuine editorial reasons is not the target. A personal finance site that licenses out a subfolder to a payday loan aggregator in exchange for revenue share is the target.

For content teams evaluating third-party monetisation: the question is whether the content would be hosted on your domain if it didn’t produce a ranking or revenue benefit for the third party. If the honest answer is no, Site Reputation Abuse is a real risk.


What To Do If You Think You’ve Been Hit

Before taking any remediation action, establish which type of enforcement you’re dealing with.

Check Search Console first. Go to Security & Manual Actions → Manual Actions. If there’s an entry there, you have a manual action, you know the scope (partial vs. sitewide), and you know what Google’s team flagged. This is the better diagnostic position: explicit, documented, fixable.

If there’s no manual action but you have a significant traffic drop, you’re likely dealing with an algorithmic action from SpamBrain or a broad core update. These are not distinguished in Search Console — both show up as traffic changes without any notification. The diagnostic process here is comparing your drop date to Google’s public update timeline, which Google maintains in its search status dashboard.

Algorithmic vs. manual actions: different response paths. A manual action requires you to address the specific violation, document what you changed, and submit a reconsideration request through Search Console. A human reviewer reads it and responds — typically within a few weeks. An algorithmic demotion doesn’t have a reconsideration request path; you address the underlying quality or spam signal and wait for the next crawl and index cycle to reflect the change.

For link spam actions specifically: Google has stated that link disavowal via the Disavow Links tool in Search Console remains a valid remediation step for sites that have acquired unnatural links they can’t get removed manually. Submitting a disavow file is not an admission of guilt but a practical tool. Use it after a genuine attempt to get links removed by contacting the linking sites directly.

The recovery timeline expectation: manual action reconsiderations, if accepted, typically resolve within days to a few weeks of Search Console confirming the action has been lifted. Algorithmic recovery follows core update cycles, which have historically been quarterly but can vary. Recovery is not immediate even after the violation is addressed — Google needs to recrawl and reprocess affected pages.

If you’re investigating a possible Google penalty and can’t clearly identify the cause from Search Console data and update timing, a technical audit of the site against the 16 named policies is the structured next step. Most recoverable violations involve content quality (Scaled Content Abuse, Thin Affiliation), link profiles (Link Spam), or recent structural changes (Expired Domain Abuse, Sneaky Redirects).


Want to Scale Content Without Crossing the Lines?

Staying inside Google’s spam policies while scaling content output is not a theoretical challenge — it’s a production operations challenge. The policies are public. The hard part is building an editorial process that consistently produces genuine value at a pace that moves the needle, and knowing when a specific content category or acquisition strategy has crossed into enforcement territory.

If you want to grow organic traffic without building a liability, the Growth Program is how we work with you on it — mapping your current content operation against real quality and policy risk, and building the kind of consistent signal that makes Google’s spam team’s job irrelevant.


Frequently Asked Questions

What is the difference between a Google algorithm penalty and a manual action?

An algorithmic demotion — enforced by SpamBrain — happens automatically, without notification, and doesn’t appear in Search Console. A manual action is issued by a human reviewer, appears under Security & Manual Actions with a description, and requires a reconsideration request. Both cause traffic drops; only the manual action tells you explicitly what the problem is.

Does AI-generated content violate Google’s spam policies?

Not automatically. Google’s Scaled Content Abuse policy targets content produced at high volume without adding genuine value — the AI-generation method is one named example, not the defining criterion. AI-assisted content where a knowledgeable author substantially revises, fact-checks, and contributes real expertise is not the target. Volume of near-identical, low-value pages is the target, regardless of how they were produced.

How do I know if I have a Google manual action?

In Google Search Console, open Security & Manual Actions in the left sidebar and click Manual Actions. If there are none, the page says so explicitly. If there is an action, you’ll see the type (e.g., “unnatural links to your site”), its scope (sitewide or partial), and the date it was issued.

What is Site Reputation Abuse and who does it affect?

Site Reputation Abuse covers hosting third-party content primarily to benefit from your domain’s authority rather than for genuine editorial reasons — for example, a payday loan section on a reputable news site. It affects publishers, media sites, and anyone monetising by hosting third-party content. The test: would that content exist on your domain without the benefit to a third party?

Can I recover from a Google spam penalty?

Yes, but the path depends on the enforcement type. Manual actions recover by addressing the violation and submitting a reconsideration request — Google’s team reviews it and lifts the action if satisfied. Algorithmic actions (SpamBrain) recover when Google re-crawls and re-evaluates your site after you’ve fixed the underlying signals; there’s no reconsideration request, and recovery follows Google’s crawl cycle.

← Back to Blog

// related services

Put this into practice

// ready to put it all together?

Founder-led SEO.
No dashboard theater.

Book a call →

// or send a message

Tell us
about your site.

Drop your URL and we’ll give you an honest read — no pitch, no obligation. Prefer to talk live? Book a call →

// 30 min · intro, founder-to-founder

Book a call