A red warning page is not one warning. It is a line on a list, and the browser that shows it is reading that list out loud. Google keeps one, Google Safe Browsing, its list of dangerous sites, and Chrome, Firefox and Safari read it. Apple keeps one that Safari reads as well. Microsoft keeps one for Edge, called SmartScreen. Each list has its own way back, and a form sent to the wrong company does nothing for the list your site is on.
I opened each company’s form without sending it, and Google’s test warnings in Chrome, Firefox and Safari on my Mac. The answer first: the browser that showed the warning names the list, and the list names the way back. On Google’s list, which of the two warnings it was, deceptive or malware, decides whether Google documents a public form for it. Deceptive, which Google’s pages also call phishing, is a page built to trick visitors out of passwords or payments; malware is software that harms a visitor’s device.
Before any form, find out whether the warning is right. Google’s public status page says whether Google lists the address, and covers Google’s list only; its clean result is “No unsafe content found”. The hacked-site article reads that page line by line and has the outside checks that look for the cause. If the warning is right, clean first. The forms below are for a mistake and for a site already cleaned; a review asked for while the problem is still on the site leaves the warning where it is.
Which browser showed it? That names the list
Start with the browser that showed it, and the words on its page. In Chrome both warnings are headed “Dangerous site”: open “Details”, or ask for a screenshot with Details open, and the sentence there says phishing or malware. A paragraph each, with its way back; the detail is below.
Chrome: Google’s list. Chrome’s help page on checking a site’s connection, fetched 1 October, says of the red page: “Dangerous: Do not use this site. If you get a full-page red warning screen, the site is flagged as unsafe by Google Safe Browsing.” For a deceptive-site warning, the way back is Google’s public form, Report a Page to Google Safe Browsing, which needed no account when I opened it; for a malware warning, mistaken or not, Google’s route is in the section on a real infection. The same help page lists “Not secure” as a separate entry about the connection, so the grey label and the certificate page are a different warning with a different cause. Pages I read for this question blame the certificate; Chrome’s own page keeps the two apart.
Firefox: Google’s list. On my screen, under both warnings, Firefox printed “Advisory provided by Google Safe Browsing.” Mozilla has no form of its own. Its support page on the protection, as archived on 16 June 2026, says: “To request removal from the list of reported phishing sites, use this form provided by Google.” The same Google form.
Safari: Google’s list or Apple’s, and the warning says which. Apple’s Safari privacy page, dated 12 December 2025: “Before visiting a website, Safari may send information calculated from the website address to Google Safe Browsing and Apple to check whether the website is fraudulent or malware has been detected.” Safari’s code fills the list’s name into the warning sentence; on Google’s test page mine read “This website was reported as deceptive by Google Safe Browsing.” Read that sentence. If it names Google, the way back is Google’s, as for Chrome: the form for a deceptive warning, the re-check or review below for malware. If it names Apple, it is Apple’s review form, the form Apple’s support page links from “report an error”. One owner on Apple’s forum, in August 2026, described a warning naming Apple while Google’s status page was clean; their report, not my screen.
Edge: Microsoft’s list. One page I read says “All browsers use Google’s blacklist”; Microsoft’s page on SmartScreen in Edge, dated 8 July 2026, says otherwise: “Microsoft Defender SmartScreen is a service that Microsoft Edge uses to keep you safe while you browse the web.” Its troubleshooting page for site owners, dated 28 January 2026, names six things it weighs, among them the address’s reputation, “Newly registered domains, malicious history, hosting provider, and traffic volume”, and the certificate, “Certificate validity and protocol version”, and adds: “If a site fails these dimension checks, SmartScreen reports the site as unsafe.” As I read it, a site can be on Microsoft’s list and on nobody else’s, a new domain included. The way back is Microsoft’s feedback form, reached from Edge’s own warning page.
A line under your result in Google. “This site may harm your computer” is Google’s list too: its Safe Browsing page lists Search result messages among the places that use it.
Deceptive or malware: on Google’s list, only one has a report link
Google’s list carries more than one kind of entry, and the warning’s own words say which kind. On
3 October I opened Google’s phishing test page and its malware test page, at
testsafebrowsing.appspot.com, in the three browsers on my Mac. What each showed, and whether it
offered a way to report a mistake:
| Browser | On the phishing test page | On the malware test page |
|---|---|---|
| Chrome | “Dangerous site”; under “Details”: “Let us know if you think that there’s been a mistake and that this site doesn’t pose a danger.” | “Dangerous site”; under “Details”: “Only visit this unsafe site if you’re sure you understand the risks.” No “Let us know” |
| Firefox | “Deceptive site ahead”; under “See details”: “You can report a detection problem or ignore the risk and go to this unsafe site.” | “Visiting this website may harm your computer”; “You can ignore the risk and go to this unsafe site.” No report link |
| Safari | “Deceptive Website Warning”; “If you believe this website is safe, you can report an error to Google.” | “Malware Website Warning”; a link to the status of “testsafebrowsing.appspot.com” “on the Google Safe Browsing diagnostic page”. No report link |
In Chrome the heading is the same on both; the first paragraph differs, and under “Details” the key words are “recently found phishing” against “recently found malware”. Firefox and Safari put the difference in the heading. Three browsers, one Mac, one day; Edge I did not test: Microsoft’s demonstration pages need Windows 10 or 11.
Google’s own pages draw the same line. Its page on reporting incorrect data, dated 18 September 2024, introduces the public form with “Report URLs that are currently on our phishing list but shouldn’t be:”, and Google’s help page on sites labelled dangerous says “For phishing reconsideration, request a review here.” For a malware entry, Google’s pages document no public form. What they give instead is in the section on a real infection.
If it is a mistake: the form that belongs to the list
Google’s form. Report a Page to Google Safe Browsing, opened on 1 October, signed out, asked three things: “Report Type”, required, a choice between “This page is safe” and “This page is not safe”; “URL to report”, required, already filled in when the link carries the address; and “Additional details”, optional, with a counter reading “0 / 800”. For a mistake, and for a phishing page you have since cleaned, the choice is “This page is safe”. Its own text:
Google’s form, “Report a Page to Google Safe Browsing”
If you believe you’ve encountered an unsafe page where Google Safe Browsing should be displaying a warning but isn’t, or a legitimate page where Safe Browsing is incorrectly displaying a warning, please complete the following form to notify the Safe Browsing team.
Whether “This page is safe” does anything for a malware entry, none of Google’s pages says, and I did not submit the form to find out. A form is a request, not a guarantee: nothing on the page promises a reply.
Microsoft’s form. Microsoft’s support page on SmartScreen gives the route from the warning itself: “From the warning page, select More information > Report that this site doesn’t contain threats to go to the Microsoft feedback site, and follow the instructions.” Without Edge’s warning page to start from, I opened Microsoft’s feedback form directly, with a placeholder address; the exact link Edge sends I did not see. Be ready to answer more than Google asks. The form asks you to choose “I am the owner or representative of this website and I want to report an incorrect warning about this website”, then asks for a name, an email address, a company, a street address, the purpose of the website, other affected addresses, “List all personal information collected by your website:”, a link to a privacy statement, notes and a CAPTCHA. No sign-in was asked for. What it promises:
Microsoft’s SmartScreen feedback form
Microsoft will review the information you provide. If the warning was incorrectly generated, Microsoft will remove it.
The troubleshooting page adds what happens next: “Wait for a confirmation email message from the SmartScreen Reputation Group.” Microsoft’s SmartScreen FAQ says “Once a dispute is submitted, a team of graders inspects the site in question.” No page gives a time.
Apple’s form. Apple’s support page on the warning, dated 18 March 2025: “If you believe that the website was reported incorrectly, you can report an error.” The link leads to websitereview.apple.com, titled “Request Review of Deceptive Website Warning”, which asked for a web address, required, an email address and comments, both optional, and a CAPTCHA; no sign-in. Its promise is conditional:
Apple’s form, “Request Review of Deceptive Website Warning”
If you believe your website has been incorrectly identified as a deceptive website, you can request that it be reviewed. The warning may be removed if we determine the issue has been corrected.
No time is published for this either.
If it was a real infection: clean first, then ask each list that has you
The cleanup itself is not this article; the hacked-site article’s outside checks say whether the cause is still visible, and whoever looks after the site does the rest. Once it is clean:
Google, a phishing entry. The same public form, with “This page is safe”. Google’s page on requesting a review, on web.dev, says it does two jobs:
Google’s web.dev page, “Request a review”
In addition to serving as a reporting tool for site owners who believe their page was incorrectly flagged for phishing, this report will trigger a review of phishing pages that have been cleaned to lift warnings.
Google, a malware entry. Google’s Safe Browsing FAQ says: “We periodically check sites on our list to see if they are still infected.” No time is given for “periodically”. The same page adds: “Our accuracy rate is very good, but you can submit your site for a malware review by following the instructions here”. Besides Google’s own re-check, the review behind that link is the one route Google documents for a malware entry:
- Prove you own the site: the web.dev page lists “Verified ownership of your site in Search Console” first.
- Be sure the cause is gone. Google’s help page: “Be sure that the problem is truly fixed before requesting a review; if the problem still exists, you will only prolong the period of time that your site is flagged as problematic.”
- “Visit the Security Issues report for your site and select Request a review.”
Google’s pages do not agree on whether a review is needed at all. The web.dev page: “You must request a review from Google to have your page or site unflagged as dangerous or possibly deceptive to users.” Google’s help page on sites labelled dangerous, quoted in the hacked-site article, says a flag its systems placed on their own clears when Google next reads the fixed site.
Firefox. Mozilla’s page covers both cases in one sentence: “If you own a site that was attacked and you have since repaired it, or if you feel that your site was reported in error, you can request that it be removed from the lists.” The only form it points to is Google’s, and only “to request removal from the list of reported phishing sites”.
Microsoft and Apple. Microsoft describes its form only for a warning shown in error and names no other route for a cleaned site. Apple’s form, quoted above, is written for a corrected site.
What the timings mean
Every number Google publishes has a condition attached. Several of the pages I read for this question give times that no company behind a list gives: “a few hours to a few days”, “usually takes 24-72 hours”, “within a day or two” and “approximately 10 business days”. What the three companies publish:
- Google, review time. The web.dev page: “Phishing reviews take about a day to process.” Review time, for phishing only; the page carries no usable date of its own.
- Google, removal time. The same page: “If Google finds that your site is clean, warnings from browsers and search results will be removed within 72 hours.” As I read it, the 72 hours starts after the clean verdict, so the two numbers add rather than overlap.
- Google, the general expectation. Google’s help page on sites labelled dangerous: “Note that it can take several days for your fix to be verified by Google and any labeling to be removed.”
- Google, a site flagged again. Its repeat offenders policy, dated 10 December 2025: “Repeat Offender status persists for 30 days, after which the website owner will be able to request a review.”
- Google’s periodic re-check, Microsoft, Apple. No time published.
A quote is not a promise either. “About a day” is what Google wrote about its own process, not a clock you can hold anyone to.
How to know it is gone, browser by browser
Check in the browser that showed the warning, after the cleanup, on the same address the visitor had.
Chrome. The address opens, with no red page and no red “Dangerous” label in the address bar. Google’s status page should agree, but it covers Google’s list only: a clean result there says nothing about Apple’s or Microsoft’s.
Firefox. The same, with one allowance. Mozilla’s support page says: “These lists are automatically downloaded and updated every 30 minutes or so when the Phishing and Malware Protection features are enabled.” As I read it, a Firefox can run about half an hour behind Google’s list, so a warning still there minutes after Chrome stopped showing it is not yet a verdict.
Safari. If the warning is still there, read its sentence again: it names Google or Apple, and the two lists clear separately. Apple’s form, quoted above, does not promise removal.
Edge. Microsoft’s own image of the warning reads “This site has been reported as unsafe”; gone is that page not appearing, and its troubleshooting page says to wait for the confirmation email from the SmartScreen Reputation Group. That is Microsoft’s description; I did not see it.
To see each warning without risk: Google’s test pages at testsafebrowsing.appspot.com, Mozilla’s
at itisatrap.org/firefox/its-a-trap.html, Microsoft’s at demo.smartscreen.msft.net, which needs
Windows 10 or 11 with Edge. They are built to be flagged; after the cleanup, your own address should
open with none of these pages.
The part worth remembering
The browser that showed the warning names the list, and each list has its own way back: on Google's, as I read its pages, a public form for a deceptive warning, and only a re-check or a review for malware. Where that list has a form for your warning, send it there, with the address as the visitor saw it.
Koval SEO Console reads the public pages of your site and explains each finding in plain words, with the evidence beside it, then answers fixed, not fixed, or couldn't confirm when you check again.
Check my site