GrowthLimit

How to Identify Toxic Backlinks Without Over-Disavowing

A decision system, audit worksheet, AI instruction, and disavow validator for evidence-based backlink cleanup.

Dennis Shirshikov
Dennis Shirshikov
GrowthLimit Founder

Published July 9, 2026Updated July 19, 2026Reviewed July 19, 2026

Direct Answer

A toxic backlink requires evidence of manipulation, hacking, hidden placement, automation, an artificial network, or another violation of Google's spam policies. A low authority score provides insufficient evidence. Most sites do not need to disavow links. Google says to consider its disavow tool only when there are many spammy, artificial, or low-quality links and those links caused, or are likely to cause, a manual action.

Use four states: keep, review, remove, or disavow. Keep legitimate editorial links. Review uncertain links. Request removal or proper rel="nofollow" or rel="sponsored" qualification when a real publisher placed a manipulative link. Disavow only when the evidence is strong, the risk is material, and removal is not realistic.

Free decision aid

Classify one link from human-reviewed evidence, then validate and download a Google-format disavow file. Nothing is uploaded or stored.

1. Classify the evidence

A recommendation is not proof that Google counts or penalizes the link.

Recommended next state

Review

Collect acquisition, placement, anchor, network, and ownership evidence before changing the link.

2. Validate a proposed disavow file

Paste one complete URL or domain:example.com per line. Comments beginning with # are ignored. Duplicate URLs covered by a domain entry are removed.

Download audit worksheet

Safety limit: this validator checks format and obvious scope mistakes. It cannot determine whether a link should be disavowed. Keep the previous file because a new upload replaces it.

The workbench runs in the browser. It does not crawl linking pages, log in to Google, upload a file, or decide that a backlink is harmful. The downloadable file remains a draft until a qualified person verifies every entry.

For a complete local audit, use the open-source Toxic Backlink Checker. It can reconcile DataForSEO with Google Search Console, Ahrefs, Semrush, Majestic, Moz, or generic CSV exports, preserve source attribution, compare each audit with the prior run, inspect representative pages, preserve an existing disavow file, and require individual approval before adding any draft entry.

Evidence-Based Decision Tree

Vendor scores identify links for investigation. Apply the decision order below to every suspicious URL or domain.

Decision tree

Evidence determines the next state

  1. 1

    Manual action?

    Use the Search Console report, not a vendor alert.

  2. 2

    Manipulation confirmed?

    Check payment, exchange, hacking, hiding, automation, or network evidence.

  3. 3

    Publisher contactable?

    Request removal or link qualification and record the outcome.

  4. 4

    URL or domain scope?

    Use the narrowest supported scope; keep legitimate links out.

No confirmed evidence → keep or review. Confirmed evidence → remove first; disavow only when justified.
Evidence classExamplesDefault state
Tool-only signalLow authority, high Spam Score, high toxicity scoreReview. Do not remove or disavow from this alone.
Contextual concernIrrelevant topic, unnatural anchor, suspicious placementReview. Inspect the page and acquisition history.
Acquisition evidencePurchased, exchanged, automated, or undisclosed placementRemove or qualify. Record the request and outcome.
Manipulation clusterRepeated money anchors across a PBN, hacked pages, hidden networkRemove or disavow. Establish URL-versus-domain scope.
Confirmed enforcementSearch Console unnatural-links manual actionCleanup and reconsideration. Follow the cited scope.

This replaces universal numeric cutoffs. Google does not publish a toxicity score, safe anchor percentage, domain-authority minimum, or link-velocity multiplier. Ahrefs, Semrush, Moz, Majestic, and other platforms calculate proprietary metrics that can produce false positives.

What to Give the Audit

Start with Google's Search Console Links report overview. It explains that the report shows links to and within a site as Google Search sees them. Add one or more commercial exports when the risk justifies broader discovery.

Provide these fields when available:

  • Linking URL and referring domain
  • Target URL
  • Anchor text
  • Follow, nofollow, sponsored, or UGC status
  • First-seen and last-seen dates
  • Data source and export date
  • Acquisition source: earned, paid, exchanged, vendor-built, migrated, or unknown
  • Page purpose and topical relationship
  • Link placement and surrounding text
  • Outbound-link pattern
  • Shared ownership, template, IP, analytics, or network evidence
  • Search Console manual-action status
  • Previous removal request and outcome

Do not upload passwords, customer data, private contracts, personal contact details, or privileged legal material to an AI system. Replace sensitive evidence with a short human-written classification.

Download the backlink audit worksheet. It includes the required columns and three example rows. Make a copy before changing classifications so the audit remains reversible.

Commercial tools expand discovery and reduce spreadsheet work. None can establish that Google counts a link, that a link caused a ranking loss, or that a disavow is required.

ToolUseful forImportant limit
Semrush Backlink AnalyticsFinding referring domains, anchors, new and lost links, and link-pattern candidates for a manual auditSemrush metrics are vendor signals. Verify each proposed action manually.
Ahrefs Site ExplorerLarge backlink index, new and lost links, anchors, referring domains, filters, and link-pattern investigationDomain Rating and filters describe the Ahrefs index; they do not prove a Google penalty.
Moz Link ExplorerSpam Score, Domain Authority, anchor text, linking domains, and new or lost linksMoz states these are its own metrics. Treat Spam Score as triage evidence.
MajesticFresh and historic backlink indexes, Trust Flow, Citation Flow, topical relevance, link context, and network inspectionFlow metrics support comparative research and have no status as Google thresholds.
LinkResearchToolsSpecialized link-forensics and penalty-recovery workflows for large or high-risk profilesComplexity and cost are difficult to justify for routine monitoring without a material risk event.

A practical stack is Search Console plus one commercial index. Add a second commercial index only when coverage gaps could change a high-stakes manual-action or network decision. Export raw data from every source; do not rely only on a dashboard label.

Audit Workflow

Audit workflow

One evidence trail from export to monitoring

  1. 01

    Export

    Combine Search Console with a commercial index and date every source.

  2. 02

    Normalize

    Deduplicate by referring domain without losing page-level evidence.

  3. 03

    Review

    Inspect page purpose, anchor, placement, acquisition, and network patterns.

  4. 04

    Act

    Keep, review, request removal, or prepare the narrowest defensible disavow.

  5. 05

    Monitor

    Track manual actions, new domains, rankings, qualified leads, and revenue.

Every changed state needs an owner, evidence sentence, review date, and reversible record.
  1. Export links from Search Console and the selected paid tools. Put the source and export date in each file name.
  2. Normalize referring domains, linking URLs, targets, anchors, attributes, and dates.
  3. Deduplicate repeated sitewide links without deleting the page-level evidence.
  4. Separate known earned links, known paid or exchanged links, vendor-built links, and unknown links.
  5. Review page purpose, topical fit, anchor, placement, outbound links, ownership, and acquisition history.
  6. Group related domains only when shared evidence supports a network conclusion.
  7. Assign keep, review, remove, disavow URL, or disavow domain. Write one evidence sentence for every action.
  8. Send removal requests only to legitimate, contactable publishers. Do not pay link-extortion sites.
  9. Validate the proposed file against the current disavow file. A new upload replaces the previous file.
  10. Have a second person review every disavow entry and every domain-level decision.
  11. Upload through Google's Disavow links tool only when Google's stated conditions are met.
  12. Monitor manual-action status, new referring domains, ranking pages, qualified leads, and organic revenue for 30 to 90 days.

Worked Audit Example

Linking pageEvidenceStateNext action
Relevant trade publication with a branded anchorReal author, real article, logical citation, no paymentKeepRecord as legitimate; take no cleanup action.
Thin directory with a branded anchorWeak site, but no manipulation or network evidenceReview or ignoreCheck scale and acquisition source; do not disavow from low metrics alone.
Paid roundup using an exact-match money anchorInvoice or vendor record, no sponsored qualificationRemoveAsk for removal or rel="sponsored"; document the response.
Hacked page containing an injected paragraphUnrelated text, compromised page, repeated injection patternDisavow URLRequest removal if practical; use page scope if the rest of the domain is legitimate.
PBN cluster built by a prior vendorShared ownership and templates, repeated commercial anchors, no editorial purposeDisavow domainPreserve evidence and exclude every legitimate domain before export.

The outcome cannot be inferred from authority alone. A small publication can be legitimate. A high-authority domain can contain a paid, hacked, or hidden link.

AI can normalize exports, find duplicates, group patterns, summarize page-level evidence, and prepare a review queue. It cannot verify every live page without access, establish causation, know whether Google counts a link, or authorize a disavow.

Give the AI:

  1. The audit worksheet or CSV export
  2. The audited domain
  3. The export source and date
  4. Search Console manual-action status
  5. Known paid, exchanged, or vendor-built campaigns
  6. A human-reviewed evidence note for every high-risk candidate
  7. The current disavow file, if one exists
  8. The exact output schema requested below

Copy this instruction and replace the bracketed values:

You are assisting with a backlink audit for [AUDITED DOMAIN].

Inputs:
- Backlink CSV exported from [SOURCES] on [DATE]
- Google Search Console manual-action status: [NONE OR EXACT MESSAGE]
- Known acquisition history: [EARNED / PAID / EXCHANGED / VENDOR / UNKNOWN]
- Existing disavow file: [ATTACHED / NONE]
- Human evidence notes: [COLUMN NAME OR ATTACHMENT]

Rules:
1. Never classify a link as toxic from authority, traffic, language, TLD,
   Spam Score, Toxicity Score, Domain Rating, Trust Flow, or another vendor
   metric alone.
2. Do not claim that Google counts a link, that a link caused a ranking loss,
   or that a disavow will improve rankings.
3. Preserve every source row. Normalize URLs and domains in separate columns.
4. Deduplicate exact links, but report sitewide and network patterns separately.
5. Use only these states: KEEP, REVIEW, REMOVE, DISAVOW_URL,
   DISAVOW_DOMAIN.
6. KEEP requires a plausible editorial or navigational purpose and no confirmed
   manipulation evidence.
7. REMOVE requires confirmed paid, exchanged, automated, hidden, or otherwise
   manipulative placement on a legitimate contactable site.
8. DISAVOW_URL requires strong page-level evidence and a reason not to apply the
   decision to the whole domain.
9. DISAVOW_DOMAIN requires repeated, domain-wide manipulation evidence. Never
   infer domain scope from one bad page.
10. If evidence is missing, conflicting, inaccessible, or tool-only, use REVIEW.
11. Do not invent page content, ownership, contact status, or acquisition history.
12. Compare proposed entries with the existing disavow file. Flag additions,
    removals, duplicates, and URL entries already covered by domain entries.

Return:
A. An executive summary with record counts and explicit data limitations.
B. A table with: linking_url, referring_domain, target_url, anchor_text,
   source, evidence, state, confidence, required_human_check, recommended_action.
C. A domain-pattern table showing the rows supporting each proposed cluster.
D. A removal-outreach queue, excluding fake or extortion contact paths.
E. A proposed disavow list, separated into URL and domain entries.
F. A final list of every decision that still requires human approval.

Do not produce a final upload-ready disavow file until a human confirms each
DISAVOW_URL and DISAVOW_DOMAIN row.

Run the instruction on a copy of the export. Manually open a sample from every proposed cluster and all domain-level disavow candidates. If the AI cannot cite the input row and evidence behind a decision, return that row to review.

Removal Request Template

Subject: Request to remove or qualify a link

Hello,

The page below links to our website:

Linking page: [URL]
Target page: [URL]
Anchor text: [ANCHOR]

Please remove the link or add an appropriate rel="nofollow" or
rel="sponsored" attribute.

Thank you.

Record the request date, recipient, response, change, and verification date. Do not threaten a publisher or claim that a link is illegal merely because it is unwanted.

Disavow File Rules

Disavow file anatomy

Validate scope before upload

  1. #

    Comment

    # Reviewed 2026-07-19 — documents why the entry exists.

  2. U

    Single URL

    https://example.com/hacked-page/ limits scope to one confirmed page.

  3. D

    Whole domain

    domain:spam-network.example applies to every URL on that host.

  4. R

    Replacement

    A new upload replaces the prior file; keep the previous version.

No wildcards. One entry per line. Do not include your own domain. Verify every entry manually.

A valid file is UTF-8 or 7-bit ASCII, ends in .txt, contains one URL or domain per line, and uses # for comments. Google documents a maximum file size of 2 MB and 100,000 lines. Domain entries use the exact form domain:example.com.

# Reviewed 2026-07-19
# Confirmed hacked pages and link-network domains

https://legitimate-site.example/hacked-page/
domain:spam-network.example

Use URL scope when one confirmed page is the problem and the rest of the domain may be legitimate. Use domain scope only when the evidence supports the entire domain. Do not use wildcards. Do not include the audited site's own domain.

Google warns that the disavow tool is advanced and can harm performance if used incorrectly. Uploading a new list replaces the existing list. Download and preserve the current file before changing it.

Manual Actions Change the Workflow

Check the Manual Actions report. Only an entry in this report establishes a Google manual action. If the report cites unnatural links:

  1. Read the exact scope and examples.
  2. Audit the cited pattern across the full profile.
  3. Remove or qualify manipulative links where possible.
  4. Document attempts, outcomes, controls, and remaining disavow decisions.
  5. Submit a reconsideration request only after the violation and repeated pattern are corrected.

Monitoring and Completion Criteria

For a stable small site, review new referring domains quarterly. For an active PR or outreach program, review monthly. During a manual-action recovery or sustained spam attack, review weekly until the pattern and enforcement state stabilize.

The audit is complete when:

  • Every source and export has a date
  • Every changed link has an evidence sentence
  • Tool-only flags remain in review
  • Legitimate editorial links are excluded from removal and disavow queues
  • URL-versus-domain scope has a written basis
  • A second person has reviewed the proposed disavow list
  • The prior disavow file is preserved
  • Removal requests and outcomes are recorded
  • Search Console manual-action status is recorded
  • Monitoring has an owner and next review date

Track business outcomes separately: ranking pages, qualified organic visits, leads, assisted conversions, and revenue. A change after cleanup does not prove that a specific backlink caused the original movement.

Primary Sources

Final Rule

Evidence clusters determine backlink risk. Fear and proprietary scores provide insufficient support for action. Keep legitimate links. Review uncertainty. Remove confirmed manipulative placements when a real publisher can act. Disavow only the narrowest justified scope, preserve the prior file, and require human approval before upload.

Use one call to test fit.

Growth Limit checks whether the page topic connects to a real organic-acquisition constraint before proposing work.