Dangerous SEO Practices · Guide

What Is the Google Spam Policy?

Most of what circulates about what search engines punish is inference. This is one of the few areas where the position is actually written down and published. This page states what is published, checked on 15 August 2026, rather than what the industry believes.

Updated: August 2026
Written by: Andrew Odgers, Managing Director
Reading time: 13 minutes
Rare, in a field built on guesswork

This Is Published, Which Makes It Unusual

Almost everything said about how search engines rank sites is inference from observation. The spam policies are different. They are written down, published by Google and available to anybody.

Why that is worth stating. It changes what a claim is worth.

In most of this subject, a confident assertion is somebody's interpretation of what they have seen. Here you can read the position yourself, which means a supplier telling you something is against policy can be asked to show you where.

What these are. Published rules, not law.

They are a private company's stated conditions for appearing in its results. That is not a legal obligation and it is not a moral code. It is the terms on which a very large source of customers operates.

Why the page carries a date. Because the source moves.

Policies get revised as practices evolve. Everything below was checked on 15 August 2026 and the review arrangement is stated in block eleven.

What this page will not do. Improve on the wording.

Where published guidance is cautious, this page stays cautious. Firming up a policy into something stronger than it says is the commonest failure in writing about this. It makes the whole account unreliable.

The areas, as published

What The Policies Actually Cover

Sixteen areas are named in Google's published spam policies for web search, checked on 15 August 2026. The names below are the published ones rather than the informal versions in common use.

Deception about what a page is. Cloaking, sneaky redirects, misleading functionality.

Content that manipulates. Doorway abuse, scaled content abuse, scraped content, thin affiliate pages, keyword stuffing, hidden text and link abuse.

Borrowed or manufactured standing. Link spam, site reputation abuse, expired domain abuse.

Compromise and harm. Hacked content, malware and malicious behaviours, machine-generated traffic.

What other people put on your site. User-generated spam, which covers comments, forum posts and profiles.

The detail worth knowing about hacked content. It hides from you specifically.

Google notes that hackers may use cloaking to make a hack harder for the site owner to detect. It also notes that injected redirects may depend on the referrer, user agent or device. Clicking your own listing in search results may redirect somewhere unpleasant while typing the address directly does not. That is why an owner can look at their own site and see nothing wrong.

The insight that makes the list usable

Policies Describe Outcomes, Not Techniques

The policies are written around what a practice does rather than how it is done. That is deliberate. It explains why looking for a specific method in the list is the wrong approach.

The clearest example. Hidden text and link abuse.

Google describes it as placing content on a page in a way solely to manipulate search engines and not to be easily viewable by a human visitor. No method is specified. The definition turns on purpose and on what the visitor can see.

Why that covers things nobody has invented yet. Purpose does not change.

A new technique with a new name still either serves the visitor or does not. Written this way, a policy from years ago covers a practice from last week without being updated.

What this means for a buyer. Stop asking whether something is on the list.

Ask what the practice is for. If the answer is that it exists to influence a search engine rather than to serve the person arriving, it is described somewhere in these policies whatever it is called.

The exception that proves the point. Paywalls are not cloaking.

Showing different things to different visitors sounds like cloaking. Google states that a paywall or content-gating mechanism is not treated as cloaking where it can see the full content behind the gate just as any person with access can, provided the flexible sampling guidance is followed. The purpose is legitimate, so the policy does not catch it.

The one that matters most commercially

Scaled Content Abuse

This describes producing many pages primarily to manipulate rankings rather than to help people. It is the policy most relevant to ordinary businesses, because it catches things done for reasons that felt sensible at the time.

The test. Purpose and value, not authorship.

The question is whether pages exist primarily to catch searches or to serve the person who arrives. Volume is the context rather than the offence, since publishing a lot is not itself a problem.

The part people get wrong. It is explicitly not about machines.

Whether a person or a tool produced the pages is not the point. Content generated at scale without judgement is described by this policy. So is content written by people at scale without judgement. The objection is to the absence of value rather than to the method of production.

What that removes. A defence people rely on.

Having a human write the templated pages does not take them outside this. Neither does editing generated pages lightly. The pages either do something for the reader or they do not.

Why templates themselves are fine. Every site uses them.

A template is a structure. The question is whether what fills it differs meaningfully between pages. That is the subject of the next block.

The candid application, which implicates us

Which Is A Live Risk For Anybody Publishing At Scale

A set of pages built to a shared template with the trade or the town swapped is exactly what the previous block describes. This agency produces trade and town pages at volume, so this is our risk as much as anybody's.

The related policy. Doorway abuse.

Google describes doorway abuse as sites or pages created to rank for specific, similar search queries. Note that it covers sites as well as pages, which catches the practice of spreading templated material across several domains.

The check that is actually available. Measure your own overlap.

You can compare your own pages against each other and establish how much of each is genuinely different. This is a real, mechanical check that any business publishing to a template can run. Almost nobody does.

What we found when we ran it. Pages that failed.

We have run that check across our own work and reworked pages that failed it. We do not publish the figures, because they came from client specific work. A number without its context would be misleading rather than useful.

What passing looks like. Something that exists nowhere else.

Genuine local detail, real coverage information, things true of that place and not of the next one. If a page cannot carry that, the page should not exist, which is the same conclusion reached in what is black hat SEO.

Recent, increasingly visible

Site Reputation Abuse

This covers third party content published on a site in order to take advantage of that site's standing. It has become considerably more visible as established publishers have let out space on their domains.

What the arrangement looks like. A section that does not belong.

A well known publication carrying commercial content unrelated to its subject, produced by somebody else, ranking on the strength of the host rather than its own merit.

Why the host is exposed. Their standing is the asset being spent.

The publication is lending the thing that makes it valuable in exchange for a share of somebody else's revenue. Several have found that arrangement cost them more than it earned.

Why the tenant is exposed. Nothing is theirs.

Positions held by somebody else's standing end when the arrangement does. Whatever was spent bought a tenancy rather than an asset.

Why this matters to an ordinary business. It gets sold to you.

Placements on recognisable publications are offered as a service. They sound like a bargain. Ask whose standing is doing the work and what happens to your position when that section is removed.

Buying a name for what it used to be

Expired Domain Abuse

Buying a domain that has lapsed and repurposing it to benefit from its former standing rather than to continue what it did. Named in the published policies alongside the two above.

What the practice relies on. Inherited reputation.

A domain that has been referenced by other sites over years carries something. Buying it and putting unrelated commercial content on it is an attempt to acquire that history without having earned it.

What makes it abuse rather than commerce. The mismatch.

Buying an expired domain is not itself a problem. A business acquiring a domain relevant to what it does, then continuing something recognisably related, is doing something ordinary. The policy addresses buying a name purely for its past.

Where a normal business meets this. Being sold a shortcut.

It is offered as a way to skip the years a new site would take. The pitch is that the domain already has standing, which is true and is exactly the thing the policy names.

The question to ask. Would you buy it if it were new.

If the only reason to want a particular domain is what somebody else built on it, that is the practice being described.

Named here, covered properly elsewhere

Link Spam

Link spam is one of the named policy areas and it is the one most businesses encounter directly, through the offers that arrive by email. It is covered in full on its own page rather than repeated here.

What the policy addresses. Links intended to manipulate.

The category is defined by purpose rather than by mechanism, consistently with block three. Whether money changed hands, whether it was an exchange and whether anybody wrote an article around it are details. The question is what the arrangement was for.

Why it sits in this list at all. Links are meant to be evidence.

A link records that somebody chose to point at you. Manufacturing that choice removes the information the link was carrying, which is why the policies treat it as a form of deception rather than as a technicality.

What a business actually needs to know. Two things.

Whether the offers in their inbox are worth taking, then whether the links already pointing at them are a problem. The answer to the first is almost always no and the answer to the second is almost always also no.

Where that is dealt with. Its own page.

Including the position on toxic link reports and on disavowing, in what is link farming in SEO.

Two routes, with an enormous difference

What Happens When A Policy Is Breached

A breach may be responded to automatically or by a person. Which of the two you are dealing with decides everything about what recovery involves. It is the distinction the rest of this cluster is built around.

The automated route. Silent.

A system responds and nothing is announced. There is no report, no stated reason and nobody to appeal to, which is why businesses in this situation invent explanations.

The manual route. Announced.

A person reviews the site, applies an action and you are notified with a stated reason and a defined scope. That is set out in what is a Google manual action.

Why the difference is not academic. Opposite work.

A manual action means removing something and demonstrating it is gone. An automated response following a broader change means improving the site and waiting to be reassessed. Doing the first when the second was needed is how a year gets spent badly.

What is worth knowing about severity. It varies.

The published material describes effects ranging from lower ranking to omission from results. We give no figure for any of it, because none is published and any number would be invented.

The limit of this whole subject

Policies Are Not The Whole Picture

A great deal of poor practice breaches no stated policy and simply does not work. A page can be entirely compliant and entirely useless. Compliance is a floor rather than a standard.

What compliance actually buys you. Not being removed.

It means you are eligible to compete. It says nothing about whether you will. Treating the policies as a strategy produces sites that are permitted rather than chosen.

What breaches nothing and still fails. Most of the internet.

Pages that answer a question worse than the alternatives. Sites nobody can navigate. Content written for an industry rather than a customer. None of that is prohibited and none of it works.

Why this belongs on the policy page. To stop it being misread.

A business that reads these policies carefully can conclude it is doing everything right while its site serves nobody. The policies describe the floor of acceptable behaviour. Being above the floor is not an achievement.

The more useful question. Better than the alternatives.

Whether somebody arriving on your page is better served than they would have been elsewhere. That is a harder standard than any policy and it is the one that decides outcomes, per what is thin content in SEO.

Stated on the page, not buried

Keeping This Current

Everything on this page describes published guidance that changes. Every other page in this section points here rather than asserting policy independently, which makes this the page most likely to date and the one where it would matter most.

When it was checked. 15 August 2026.

Every policy area, wording and position stated above was verified against Google Search Central on that date.

How often it gets rechecked. Quarterly, plus after any announced change.

Policy areas have been added within the last two years, so quarterly is the minimum sensible interval rather than a formality.

Who is responsible. Andrew Odgers.

Named rather than assigned to the business, because a review owned by nobody in particular is a review that stops happening during a busy quarter.

What to do if you spot a discrepancy. Believe the source.

If what you read in the published policies differs from what is written here, the published policies are correct and this page is out of date. Tell us and we will fix it.

Website migrations

Ask them
to show you
where it says so.

A review that checks your site against what is actually published rather than against what somebody believes. Including the overlap check on your own pages, which almost nobody runs. We will tell you plainly if we find nothing worth changing.

What a risk review covers:

Policy alignment Page overlap check Location page test Link profile review Inherited risk check Manual action check Content value review Findings you can act on

A risk review is a one-off piece of work rather than a monthly service, so it is scoped against the size of the site and how much history it carries.

The full guide series

Every guide.
One practice.

Black hat, grey hat, link risk, thin content, the spam policies, negative SEO, manual actions, algorithmic penalties, how to check for one and how to recover from one.

Questions people ask

The Spam Policies, Briefly

Where can I actually read these policies?
They are published by Google on its Search Central documentation, under spam policies for web search. That is unusual in this field, where most claims about what search engines punish are inference from observation. It also means a supplier telling you something is against policy can be asked to show you where it says so.
Are location pages for different towns against policy?
It depends entirely on what is on them. We build these ourselves, so it is our risk too. Google describes doorway abuse as sites or pages created to rank for specific, similar search queries. It describes scaled content abuse as producing many pages primarily to manipulate rankings rather than to help people. A page carrying genuine local detail that exists nowhere else is not that. A template with the town swapped is.
Does it matter whether AI wrote the pages?
Explicitly not. Scaled content abuse turns on whether pages exist primarily to catch searches rather than to serve the person arriving. Content generated at scale without judgement is described by the policy. So is content written by people at scale without judgement. Having a human write templated pages does not take them outside it.
How do I check my own site against this?
For scaled content, compare your own pages against each other and establish how much of each is genuinely different. It is a real mechanical check that any business publishing to a template can run. Almost nobody does. We have run it across our own work and reworked pages that failed. More broadly, ask what each practice is for rather than whether it appears on a list.
Is showing different content to different visitors always cloaking?
No. This exception is rarely mentioned. Google states that a paywall or content-gating mechanism is not treated as cloaking where it can see the full content behind the gate just as any person with access can, provided the flexible sampling guidance is followed. The policies are written around purpose, so a legitimate reason for the difference matters.
If we follow all of this, will we rank?
No, which is worth being clear about. Compliance means you are eligible to compete rather than that you will. A great deal of poor practice breaches no policy and simply does not work: pages answering a question worse than the alternatives, sites nobody can navigate, content written for an industry rather than a customer. The policies describe a floor. Being above it is not an achievement.