What a negative SEO claim actually alleges
“Negative SEO” is not a term of art with a fixed meaning, which is the first problem in any matter that uses it. Stated carefully, the claim is that a third party did something to or about the claimant's website that degraded its visibility in search results, and that the third party did it deliberately.
That breaks into three quite different factual theories, and they do not have the same evidentiary strength. The first is an inbound link campaign — mass acquisition of low-quality links pointing at the target. The second is content interference — scraping and republication designed to create duplication, or scaled generation of pages that mimic the target. The third is intrusion — injected pages, injected links, injected redirects, or cloaked spam served from the target's own domain after a compromise.
The third theory is the strongest and the one most often overlooked in favor of the first. Intrusion leaves first-party records, produces a dated Google notification, involves conduct that is independently actionable, and can be demonstrated deterministically. A link campaign leaves none of that on the target's side. Separating the theories early is worth doing, because the discovery each one needs is different and the causal problems each faces are different.
Link spam campaigns and what Google's policy actually covers
Google's spam policies enumerate what counts as link spam, and the list is useful in these matters because it is the vocabulary the platform itself uses. It covers buying or selling links, including exchanging money, goods or services for links and sending a product in exchange for a post containing one; excessive link exchanges and partner pages that exist only for cross-linking; automated programs or services that create links; requiring a link as part of a contract or terms of service; text advertisements and text links that do not block ranking credit; advertorials and native advertising where payment is received for articles containing links that pass credit; low-quality directory and bookmark links; keyword-rich, hidden or low-quality links embedded in widgets; widely distributed footer and template links; and forum comments with optimized links in the post or signature. Paid links are permitted where they carry a rel="nofollow" or rel="sponsored" attribute, which is an attribute in the link markup telling Google not to pass ranking credit.
Notice what that list is for. It describes conduct by a site seeking to benefit itself. Applying it to a campaign aimed at harming someone else requires an inference the policy does not make, and a defendant will say so. The policy is still worth citing, because it establishes that the pattern observed is recognized spam rather than an ordinary link profile, but it does not establish who built it or that the target was penalized for it.
Injection, cloaking, and the part that is demonstrable
Where a site has been compromised, the evidence is far better. Search Console's Security Issues report names the mechanisms in its own language: code injection, where malicious code such as redirects or cryptomining is added; content injection, where spammy links or text are added to existing pages; URL injection, where new pages are created on the site containing spammy words or links; and malware. It also covers deceptive pages, deceptive embedded resources, harmful downloads and possible phishing on a login page.
Each entry is a dated, first-party, platform-generated record, which is exactly what a link-campaign theory lacks. Google states that most security reviews take several days or weeks, and that link-related requests may take longer, so the reinstatement timeline is itself documented.
Cloaking is the delivery mechanism that keeps injected content invisible to the site's own operators: the injected pages serve spam to the crawler and the ordinary page to a browser. Google defines cloaking as presenting different content to users and search engines with the intent to manipulate rankings and mislead users. Detection is deterministic and easy to put in front of a fact-finder: request the same URL with a crawler user agent, verified against Google's published crawler ranges, and with an ordinary browser user agent, and compare the responses. Google's URL Inspection tool performs a version of the same test and produces a record inside the claimant's own account.
Google's stated position, and how it has changed
This is contested ground and the page is more useful if it presents the change over time rather than a conclusion.
Before 22 May 2012, Google's published help material said, in substance, that there was almost nothing a competitor could do to harm a site's ranking or have it removed from the index. From that date, the wording changed to say instead that Google works hard to prevent other webmasters from being able to harm a ranking or have a site removed. The change is documented in contemporaneous trade reporting; anyone relying on the exact prior wording should pull the archived Google page for the relevant date rather than quote the secondary account.
Google's later position, expressed through its link spam systems, is that detected spam links are handled by discounting them so they pass no ranking credit, rather than by penalizing the site they point at. That framing matters enormously to a claimant, because it means the platform's own account of its mechanism does not produce the harm the claim asserts.
Against that, Google continues to maintain “Unnatural links to your site” as a live manual action type, described as Google having detected a pattern of unnatural, artificial, deceptive or manipulative links pointing to the site. A manual action is a human decision recorded in the claimant's own Search Console with a date. Where one exists, there is a first-party record of Google acting on the links. Where none exists, the causal chain rests entirely on inference, and that is the ordinary case.
The disavow file as a document
This is the point most worth making in a negative SEO matter and it is almost never made. The disavow file is not just a remediation tool. It is a dated, party-authored document, and it behaves in discovery like any other.
Start with the mechanics, because they drive the evidentiary consequences. Google's own warning is that this is an advanced feature that should be used with caution, and that used incorrectly it can harm a site's performance in Search. Google states that in most cases it can assess which links to trust without additional guidance, so most sites will not need the tool at all. The format is one URL or domain per line, with a domain: prefix to cover an entire domain, as a plain text file, with a limit of 100,000 lines including blanks and comments and a maximum of 2 MB. Processing takes weeks, as Google recrawls and reprocesses the pages. And critically, uploading a new file replaces the previous list entirely.
That last mechanic is what makes the file probative. Because each upload overwrites the last, prior versions exist only in the party's own records — local copies, an agency's file share, email attachments, ticket systems, version control. Those are discoverable, and they are the only way to reconstruct what the party believed about its own link profile at each point in time. A file uploaded three weeks after a campaign began establishes contemporaneous knowledge of it. The absence of retained prior versions, where a preservation duty had attached, is a separate problem.
The contents can also cut against the party that authored them. A disavow list naming domains the party itself paid for is an admission that it paid for links. I would expect any competent opposing counsel to request the full version history early, and I would expect the request to be productive more often than not.
Attribution to a beneficiary, and why it usually fails
Separate what can be shown from what cannot, because conflating them is how these opinions get excluded.
Typically establishable. That the campaign existed — through link index snapshots with first-seen dates, archived copies of the linking pages, registration records for the linking domains, hosting address and network clustering, shared analytics or advertising identifiers across the network, and shared registrant data or registration bursts. Its timing, from first-seen dates and archived snapshots. And its shape: anchor-text distribution, acquisition velocity, and the distribution of top-level domains and languages.
Typically not establishable. Who paid for it. Spam link services are commodity products bought anonymously, registration data is routinely privacy-shielded, and payment happens off-platform. Also not establishable: authorship inferred from benefit. A competitor whose rankings improved during the campaign is not thereby its author, and an opinion resting on that inference is post hoc reasoning that will be named as such. And finally, that the target's loss came from the links rather than from a concurrent core update running in the same window — the update dates are public and dated, so this is checked, not argued.
Attribution does sometimes succeed. It succeeds where the same operational fingerprint appears on both sides: identical hosting, a shared registrant, a reused template, an agency that serviced both parties, or discovery that produces the purchase records. That is a documents case with technical support, not a search-data case, and a report should say so rather than dress up the inference.
What a defensible opinion in this area looks like
The honest shape of an opinion here is narrower than the complaint usually is, and stating the limits explicitly is what makes the remainder usable.
- Describe the campaign as observation. Volume, first-seen dates, anchor distribution, network characteristics, and archived evidence of the linking pages, each with its source and capture date.
- Establish whether Google acted. A manual action, a security issue, or neither. This is a yes-or-no question answered from the claimant's own account, and it changes the case entirely.
- Address the alternative causes directly. Overlay the dated record of algorithm updates on the traffic series. If the inflection sits inside an update window, say so.
- Treat attribution as a documents question. Report the technical fingerprints and stop where the inference would begin.
- Preserve the disavow history. Both sides' versions, with dates, before they are overwritten.
An expert who states in the report that attribution could not be established, and explains precisely why, is considerably harder to impeach than one who reaches for it. The primary references are Google's spam policies, its disavow documentation, and its manual actions report.
Frequently Asked Questions
Can negative SEO actually harm a website's rankings?
Google's account of its own systems is that detected spam links are discounted so they pass no ranking credit, rather than causing a penalty against the site they point at. That makes the causal claim difficult on the platform's own documentation. Google nonetheless still maintains a manual action for unnatural links pointing to a site, so human action on inbound links does occur. Whether it occurred in a given matter is answerable from the claimant's own Search Console, and that answer usually determines whether the claim is viable.Is a disavow file discoverable in litigation?
It is an ordinary business record and there is no obvious basis to treat it otherwise. It is more probative than parties expect, for a structural reason: each upload replaces the previous list entirely, so Google does not retain earlier versions. Prior versions exist only in the party's own files, email, ticket systems or version control. Those versions show what the party believed about its own link profile on each date, and a list naming domains the party paid for is an admission that it bought links.Can an expert identify who launched a link attack?
Rarely from search data alone. What is establishable is that a campaign existed, when it began, and what it looked like structurally, using link index first-seen dates, archived copies of linking pages, registration records, hosting and network clustering, and shared identifiers. What is not establishable is who paid for it, because these are commodity services bought anonymously with shielded registration and off-platform payment. Attribution succeeds where documents connect the parties, or where the same operational fingerprint appears on both sides.What is the difference between a link attack and a hacked site?
A link attack originates outside the claimant's infrastructure and leaves no record inside it. An intrusion originates inside it and leaves several: Search Console's Security Issues report names code injection, content injection, URL injection and malware, each as a dated first-party entry. Injected content is frequently cloaked, meaning spam is served to crawlers while ordinary content is served to browsers, which is detectable by requesting the same URL with different user agents and comparing responses. The intrusion theory is the stronger of the two.What should be preserved when a link attack is suspected?
Dated exports from at least two link indexes, captured promptly, because first-seen dates and link inventories change as those indexes recrawl. Archived copies of representative linking pages. Search Console messages, the manual actions report state, the security issues report state, and Performance exports before the sixteen-month window rolls. Every version of the disavow file with its upload date. Registration and hosting records for the linking domains. Server logs. Waiting is costly here, because much of the third-party evidence is not retained by anyone.Does a competitor benefiting from the attack prove they caused it?
No, and offering that inference is one of the faster ways to lose an opinion. A competitor whose visibility improved during the same period is not thereby the author of the campaign, and characterizing the correlation as proof is post hoc reasoning that opposing counsel will name as such. Search results are close to zero-sum on any given query, so someone always gains when a site loses. Attribution needs an independent link: shared infrastructure, shared registrant data, a common vendor, or produced records.How does a defendant usually respond to a negative SEO claim?
By attacking causation before attribution. The strongest defense arguments are that Google's documented handling of spam links is discounting rather than penalizing; that no manual action exists in the claimant's own account; that the traffic inflection aligns with a dated core update rather than with the campaign; and that the claimant made concurrent changes to its own site. Each of those is checkable against public or first-party records, which is why a claimant's expert is better served addressing them in the report than in a deposition.Published