Negative SEO: What a Real Attack Looks Like in the Data
· Royking Niba
Negative SEO is a third party deliberately building or manipulating signals against your site in the hope of triggering a demotion or a manual action. Google’s public position, across its spam policies and its guidance on the disavow links tool, is that its systems are built to ignore manufactured links rather than punish the site they point at, and that disavowing is a narrow, advanced action scoped to a manual action or the reasonable expectation of one. In my experience that position is broadly right, and most sites that believe they were attacked were instead ranking on links they should never have had. Real attacks do happen, they leave a recognisable signature, and the signature is what you should be reading, not the number of new referring domains.
I say this as someone who used to build the exact thing attackers buy. At Blue Window Ltd I ran the full private network lifecycle: expired domain acquisition, content recovery out of archive.org, site restoration, and the ongoing quality monitoring that keeps a network from collapsing. I know what that output looks like from the inside, including the parts that are expensive to hide and the parts nobody bothers hiding. That is the lens I bring to every backlink audit now.
The argument almost nobody makes: attacker economics
A link network that Google actually values is slow and expensive to build. You are buying aged domains with real history, restoring them so the recovered content matches the domain’s original topic, hosting them apart from each other, and monitoring them for months so the footprint does not converge. That effort only makes sense if the payoff is your own rankings.
Nobody spends that on a competitor. An attacker buys the cheap tier, because the whole point of the exercise is that it is cheap. The cheap tier is precisely the tier Google’s systems already discount, which is why a great many attacks land as nothing at all. When someone tells me they were hit by negative SEO and the drop was severe, my first thought is not “who did this”, it is “what were you already relying on that stopped working”.
The signature of manufactured links
Manufactured links betray themselves on four axes. Any one of them can appear innocently. All four at once, inside the same cohort of domains, is not a coincidence.
1. The anchor text is too tidy
Real backlink profiles are dominated by boring anchors: your brand, a bare URL, the page title, “here”, “this guide”, and a long tail of one-off phrases that nobody would ever choose deliberately. Manufactured cohorts come off a spreadsheet, so the distribution is far too even. You see a small set of commercial or off-topic phrases repeating in near-equal proportion across dozens of unrelated domains, often pointed at pages that could not plausibly attract links on their own.
The clearest tell is a mismatch of vertical or language. Pharmaceutical, adult, loan or casino anchors arriving at a site in none of those categories were not written by a human who read your page.
2. The velocity has no cause
A genuine link spike has a source event and a decaying tail. Something got published, or picked up, or aggregated, and the links arrive in a curve that fades over weeks. A manufactured spike is flat-topped and causeless: a large block of domains inside a few days, all pointing at a handful of URLs, then silence. It matches a job queue, not a news cycle.
3. The hosting and registration footprint converges
This is the axis I trust most, because it is the one I know is hardest to fake. Keeping a network’s infrastructure genuinely diverse costs money every month and gets no return until something goes wrong, so cheap operations skip it. Resolve the linking domains and look for convergence: the same handful of autonomous systems, adjacent IP ranges, one registrar, one privacy service, shared nameservers, registration or renewal dates clustered inside the same window, the same certificate issuer, identical WHOIS shape.
A normal profile of two hundred domains scatters across dozens of hosts. That is the baseline. Convergence is the anomaly.
4. The linking pages are built around the link
Open twenty of them and read. Manufactured pages are written outward from the anchor: a consistent word count, filler prose with no specific claims, no author with a history, no comments, no updates. They are usually orphaned, absent from the navigation, unlinked from anywhere else on their own site, reachable only through the sitemap. The outbound block is the giveaway, because your site sits in a list next to targets that share no audience with you.
Restored expired domains have their own tell: the recovered content is thematically stranded, sitting on a domain whose old inbound links point at a subject the current pages no longer cover.
| Axis | Manufactured cohort | Normal messy profile |
|---|---|---|
| Anchor text | Small set of commercial or off-topic phrases, evenly distributed, often wrong vertical or language | Brand, bare URLs, page titles, “here”, plus a long tail of unrepeatable one-offs |
| Velocity | Flat-topped burst over days, no identifiable source event, then nothing | Spikes tied to a publication or pickup, with a decaying tail over weeks |
| Hosting and registration | Few ASNs, adjacent IP ranges, one registrar, shared nameservers, clustered creation dates | Scattered across dozens of hosts, registrars and dates with no pattern |
| Linking page | Orphaned, uniform length, no author history, outbound block of unrelated targets | Sits in navigation, internally linked, has comments, edits, an author, a reason to exist |
| Target URLs | A few pages, often ones with no natural link appeal | Spread across the site, weighted to genuinely useful pages |
| Overall feel | Too consistent | Genuinely random, including plenty of junk |
Note the last row. Real profiles contain a lot of rubbish: directories, scrapers, forums, dead blogs, aggregators. Rubbish is not evidence of an attack. Uniformity is.
What more than 200 manufactured domains looked like in practice
One backlink audit I ran surfaced more than two hundred manufactured referring domains on a single client profile. Nobody had to squint at that data. The cohort separated itself the moment I sorted the full referring domain export by first-seen date and put the infrastructure fields next to it.
The method, which I now run as a script rather than by hand, is dull and repeatable. Export every referring domain with its first-seen date, its anchors and its target URL. Resolve each domain to its host and its registration record. Fetch each linking page and record its length, its internal link count and its outbound targets. Then group, and look for rows that agree with each other. Manufactured domains agree with each other far more than real ones ever do, and once the cohort is isolated you read all four axes at once instead of arguing about individual links.
Here is the part people skip. Proving a cohort was manufactured does not tell you who manufactured it. Those two hundred domains were built by somebody, and the only honest next question is whether anyone on your side, at any point, including an agency three contracts ago, ever paid for links. That question is answered by asking, by reading old invoices and by looking at whether the cohort points at pages you were actively trying to rank. An attacker aims at your money pages because that is where the damage is. So does the agency you hired to rank them. The infrastructure looks identical. The intent does not, and intent is not visible in the data.
This is why I treat a manufactured cohort as the start of a toxic backlink investigation rather than the conclusion of a negative SEO one.
Why a spike in referring domains proves nothing
Referring domain counts inflate for reasons that have nothing to do with anybody attacking you. A single link on a syndicated page reproduces across every site that carries the feed. Scrapers copy pages that already link to you. Statistics, WHOIS lookup, “site worth” and SEO report subdomains generate a page per domain and link out automatically. Parked and expired domains get resold and re-crawled. None of that is an attack and none of it is worth a minute of your attention.
There is also an ordering illusion that catches almost everyone. You looked at your backlink profile because traffic dropped. You found links you had never noticed, because you had never looked. Then you assumed the links caused the drop. Test that assumption directly: line up the first-seen dates of the cohort against the day the traffic moved. In most cases the drop comes first, or the two are weeks apart, or the drop lands squarely on a date the Search Status Dashboard and the Search Central blog already explain.
A count answers nothing. Dates and patterns answer everything.
The attacks that have nothing to do with links
Link attacks get the attention, but the non-link forms are the ones I see actually cause measurable harm, because they exploit your own site’s weaknesses rather than trying to overpower Google’s filters.
Scraped and duplicated content
Someone republishes your pages at scale. The realistic risk is not a penalty, it is canonical confusion, and it only bites when your own signals are weak: no self-referencing canonicals, thin pages, poor internal linking, or content already duplicated across your own parameter URLs. Fix your side, using Google’s guidance on consolidating duplicate URLs, and scrapers stop mattering. Chasing takedowns while your own canonicals are broken is the wrong order of work.
Fake review campaigns
Two versions exist and they need different responses. A flood of fake one-star reviews damages your local visibility and your click-through rate, and is handled through the platform’s reporting process. A flood of fake positive reviews is the more dangerous one, because it is designed to make your profile look bought and to put your review rich results at risk. Document the burst, report it, and do not respond by soliciting a counter-wave of reviews from people who never bought from you.
Forced crawling of parameter URLs
This is the one I would use if I were attacking a site, and it is the one people check last. The attacker links to, or simply hammers, thousands of generated URLs on your domain: tracking parameters, faceted filter combinations, and above all your internal search endpoint with spam queries in it. Your server obligingly renders a unique page for each. Crawl budget drains into infinite variants, thin near-duplicates enter the index, and if your search results pages are indexable you end up hosting somebody else’s spam under your own domain.
Your server logs settle this in an hour, which is why logs are worth more than any backlink tool during an investigation. The fix is your own configuration: noindex on internal search results, canonicals on parameter variants, and a robots policy that reflects what you actually want crawled.
What to do, in order
Work this sequence top to bottom and do not jump ahead. Every step you skip makes the later steps guesswork.
- Date the drop precisely. To the day, by page, by query and by country. A drop that is one market or one template is a different problem from a sitewide drop.
- Check the manual actions report. The manual actions report settles the largest question in one click. A manual action is a human decision you are told about and can appeal. Nothing there means nothing was decided about you by a person, which changes the entire shape of the work. My full sequence for both cases is in my guide to Google penalty recovery.
- Compare the date against known updates. The status dashboard and the Search Central blog cost you five minutes and frequently end the investigation.
- Separate lost rankings from lost clicks. Stable positions with falling clicks is a SERP layout or intent change, not an attack.
- Now, and only now, export the links. Sort by first-seen date, isolate the cohort that arrived around the drop, and run it against the four axes above.
- Check the non-link vectors. Index coverage, duplicate and parameter URLs, server logs, review platforms.
- Fix your own side first. Remove what you control, repair canonicals and crawl policy, and improve the pages that lost ground against Google’s guidance on helpful content.
- Disavow last, if at all.
The disavow file belongs at step eight, not step one, and people find that genuinely uncomfortable. The reason is mechanical. Disavowing removes nothing, produces no confirmation, and is invisible in every third-party tool, so it gives you no feedback loop. Upload one as a guess and you have learned nothing, while introducing a file that quietly outlives the person who made it, still suppressing links nobody remembers listing. Google’s own documentation is explicit that this is an advanced feature for a narrow case, and I treat that framing as literal. I use it at domain level, against an isolated cohort I can characterise, when there is a manual action for unnatural links or a well-founded expectation of one. The mechanics, and the mistakes I keep having to undo, are in my breakdown of what a disavow file actually does.
When to do nothing at all
Doing nothing is an active decision and often the correct one. I close an investigation with no action when:
- The manual actions report is clean and the drop lines up with a documented update. That is a quality and relevance problem wearing an attack costume.
- The new domains fail the signature test. Scattered hosting, varied anchors, ordinary junk. That is weather, not an attack.
- Links arrived and rankings did not move. Links that did nothing on arrival will not activate later.
- The pages that dropped were ranking above their weight and lost ground to obviously stronger results.
- I cannot state the mechanism. If I cannot explain in one sentence how these specific links produced this specific drop, I do not have a case, I have a coincidence with a story attached to it.
Restraint is cheap and reversible. Panic is neither. Across the recoveries I have run, which add up to more than eight million organic visits returned to clients, the damage I have had to undo was more often caused by the emergency response than by whatever prompted it: mass disavows, deleted pages, redirects fired at guesses.
The short version
Negative SEO is real, rare, and identifiable. It looks like uniformity where there should be randomness: tidy anchors, causeless velocity, converging infrastructure, pages built outward from a link. It does not look like a big number in a backlink tool. Read the signature, date the drop, check for a manual action, fix your own side, and keep the disavow file in its box until you can describe exactly what it is for.