Why Does My Website Say "Deceptive Site Ahead"?

"Deceptive site ahead" is a full-page red warning Chrome shows when Google thinks something on your website is trying to trick visitors. It doesn't have to mean you did anything wrong. It usually means someone else put content on your site, or something you embedded from another company has gone bad. It can be fixed, and once the cause is gone you ask Google to check again.
Why does my website say "Deceptive site ahead"?
Because Google's Safe Browsing system has decided at least part of your site is engaged in social engineering, meaning content that tricks people into doing something dangerous online. Google's page on social engineering names the two main kinds: phishing, where a page pretends to be someone trustworthy to get personal details out of people, and deceptive content that gets visitors to share a password or download something they'd only take from a source they trusted. When Chrome spots that, it shows the "Deceptive site ahead" page instead of yours.
The person reporting it to you is usually a customer who tried to book, saw red and rang instead. That's the good outcome. Others may just leave.
Is it the same as the "Not secure" warning?
No, and the fixes are nothing alike. "Not secure" is a small label next to the address, and it's about how the connection is set up. Our guide to the 'Not secure' warning and what causes it covers that one. "Deceptive site ahead" blocks the whole page, and it's about what's on the page. A site can have a perfectly good padlock and still be flagged as deceptive.
Has my website been hacked?
Possibly, but it isn't the only explanation. Google's Security Issues report help page describes hacked content as anything placed on your site without your permission because of a weakness in it, and that is one route to a deceptive page. Someone gets in, perhaps through an out-of-date plugin or a reused password, and quietly adds a fake login page or a page pretending to be a bank.
The other route catches owners out because nobody broke in. Google's social engineering page says embedded social engineering content is a policy violation for the host page, and it lists ads, images and other third-party resources as places it can come from. So an ad slot, a widget or a booking plugin from another company can get your page flagged even though every word you wrote is fine.
How do I find out what Google flagged?
Look in the Security Issues report in Google Search Console. It's Google's free tool for site owners, and the report lists what it found along with example pages where it found it. If you've never used Search Console, the first step is verifying that you own the site, which whoever built or hosts it can usually sort out.
You can also put your address into Google's Safe Browsing site status check, which shows whether Safe Browsing currently considers a site unsafe. It won't tell you which file is to blame, so the Search Console report is still the place to work from.
How do I get the warning removed?
Clean up every issue the report lists, then press Request Review in the same report. Google says to do that only once everything listed is fixed on every page, not one page at a time. The order runs like this:
- Read the example pages. They show where the problem is, which tells you whether you're looking for added pages, altered files or something embedded.
- Remove the deceptive content. Delete any pages you didn't create, and take out or replace any ad, widget or embed that's serving the bad content.
- Close the way in. If the site was hacked, a clean-up without updating the software and changing every password can end with the same pages coming back.
- Request a review. Say plainly what you found and what you changed.
Google emails you when it receives the request and again when the review is complete. Its help page says a review can take from a few days to a few weeks, so plan for the warning to stay up for a while even after the site is clean.
Who should fix it?
Whoever looks after the site's files, which for most small businesses means the web company, the freelancer who built it or the hosting company. Pulling malicious code out of a site is a job for someone who can see the files and knows what normal looks like. Your part is getting it started quickly and making sure the review request goes in once the work is done.
A message like this is ready to copy and send:
"Google Chrome is showing a 'Deceptive site ahead' warning on our website. Can you check the Security Issues report in Search Console, remove whatever it lists, find out how it got there and close that gap, then request a review? Please tell me what you found and what you changed, and let me know when the review request has gone in."
If nobody answers, or the site was built by someone who's since disappeared, that's a sign of a bigger problem with who controls your site. Our guide to whether your website is secure enough covers what a small site needs looking after so this doesn't come round again.
What should you do next?
Send the message today, and tell customers another way to reach you while the warning is up. Once you're through it, the wider list of things that quietly break a small site sits in the guide to fixing your website and getting found. And if the honest answer is that nobody is really looking after your site, ByRender's care plan from £69 a month covers hosting, security, backups and edits. Send us your details and we'll show you a preview before you pay anything.
Frequently asked questions
Should I tell customers to click past the warning?
No. You don't yet know what the flagged page does, and asking people to ignore a security warning is the exact habit the warning exists to break. Point them to your phone number, your Google Business Profile or your social pages until the review comes back clean.
I never set up Search Console. Can I still see the report?
Yes, once you prove you own the site. Google's own instructions start with verifying ownership in Search Console, and whoever built or hosts the site can normally do that for you.
Can I just move to a new domain to get rid of it?
It's tempting, but if the cause is something hidden in the site's files or an ad you've embedded, it travels with the site. You'd lose whatever the old address had built up and quite possibly end up flagged again. Clean it and ask for a review instead.