SEO Glossary · Algorithm

Google Spam Update

A spam update is Google retraining SpamBrain and re-running the classifier across the index: sites leaning on manipulative patterns lose visibility, everyone else mostly watches. Three shipped between August 2025 and June 2026, with rollouts collapsing from nearly a month to a matter of days, and none announced a link-spam focus. Reading them correctly matters more than fearing them.

Key takeaways The essentials in 30 seconds
  • A spam update is enforcement, not re-ranking: Google re-runs a retrained SpamBrain classifier against its written policies, and Sistrix's August 2025 data showed a losers-only pattern. If you gained during one, a competitor got removed.
  • Rollout time collapsed from just under 27 days (August 2025) to less than 24 hours (March 2026): treat spam updates as routine classifier refreshes on a two-to-three-per-year cadence and annotate every reporting window accordingly.
  • Per Google's spam policies as revised on 15 May 2026, paid placement itself is not the violation, unblocked ranking credit is: qualifying paid links with rel=sponsored or nofollow remains the defensible compliance position.
  • Enforcement energy has visibly moved to scaled content abuse and site-reputation abuse; classic purchased links are mostly devalued continuously and silently by SpamBrain, outside any named update.
  • Never attribute a September 2025 visibility drop to the August 2025 spam update without checking the num=100 measurement break: in one analysis of 319 sites, 87.7% lost Search Console impressions because scraper artifacts vanished, not rankings.
  • A genuine spam-update hit is site-wide and fast; link devaluation is invisible in analytics. If a loss does not map to a dashboard-confirmed window, the problem is usually quality, and pruning links will not fix it.
3 questions to test your knowledge Read first, the quiz is waiting at the bottom.
Three-step process to measure the effect of a spam update: record the rollout boundaries, annotate the tracking dashboards, compare the curves over symmetric windows.
The method to isolate a spam update's effect on your hosts and your targets.

What a spam update really is

Strip the label down and a Google spam update is an enforcement event, not a change in ranking philosophy. Google maintains automated spam-detection systems, SpamBrain being the one it names publicly, that classify pages and sites against its written spam policies. Those systems run continuously, but periodically Google retrains them and re-deploys the refreshed classifier across the whole index. That redeployment is what gets announced as a spam update. The distinction that matters operationally: a core update asks whether your content deserves its position, a spam update asks whether your site violates a written policy. The remediation paths are completely different, which makes diagnosing which one hit you the first practical question, not an academic one.

The lineage matters for netlinking specifically. For years, the Penguin filter was the named link-spam system; it was eventually folded into the core algorithm and shifted from demoting sites to devaluing the offending links. SpamBrain inherited and extended that logic: it neutralizes unnatural links continuously, in the background, without waiting for a named update. The consequence is uncomfortable for anyone selling link-removal panic: most purchased links Google identifies are simply ignored, silently, long before any spam update ships. An episodic spam update mostly bites at the site level, when the classifier concludes an entire domain exists primarily to spam.

The visibility data supports reading these as pure enforcement. Sistrix's assessment of the August 2025 spam update described relatively limited aggregate SERP movement but visibility losses concentrated on overtly spammy domains, a « losers rather than winners » pattern. Nobody wins a spam update directly; you inherit positions from domains that got removed. If your curves rose during one, the correct conclusion is that a competitor got caught, not that your links started working harder.

Checklist of the five checks to run on a host site before any link purchase: editorial pattern, cadence, authors, traffic stability, authority last.
In 2026, a paid link's risk is judged by the host, not the link.

The 2025-2026 cadence: three updates, shrinking rollouts

Between August 2025 and June 2026, Google shipped three confirmed spam updates, and the operational story is in the rollout durations. The August 2025 spam update, announced on 26 August 2025 via Google Search Central, was the first since December 2024. It covered all languages and took just under 27 days to finish rolling out, per Search Engine Land's completion report. Volatility was visible within roughly 24 hours for affected sites, with a second wave of movement reported around 9 September. Google disclosed no affected-query percentage and no target category.

The March 2026 spam update inverted that profile: launched on 24 March 2026, completed on 25 March, less than 24 hours end to end. Google called it a standard spam update, and Search Engine Land's reporting noted that link spam and site-reputation abuse were outside its scope. That detail matters: if you saw movement on 24-25 March 2026 and blamed your link profile, you were arguing against the published record. The June 2026 spam update ran from 24 to 26 June per Google's Search Status Dashboard, again global, again all languages, again with no category disclosed.

Two readings of the shrinking timelines. The generous one: Google's spam infrastructure has matured to the point where redeploying a retrained classifier is a fast, routine operation rather than a multi-week sweep. The more cynical one, which we lean toward: sub-24-hour rollouts suggest these are increasingly refreshes of existing detection rather than new capability, and the announcement is as much a deterrence signal as a technical milestone. Either way, the practical cadence has settled at two to three spam updates a year after an eight-month announcement gap, which means every quarterly reporting window now plausibly contains one. Annotate accordingly.

What Google actually polices in 2026

The reference document is Google's spam policies page, last revised on 15 May 2026. Its link-spam section is blunt: any link created primarily to manipulate rankings qualifies, with explicit examples that read like a netlinking vendor catalogue. Buying or selling links that pass ranking credit. Excessive link exchanges. Automated link creation. Low-quality directories. Keyword-rich anchors stuffed into guest posts and press releases. Footer and template links distributed across sites. Forum comments with optimized anchors. None of this is new doctrine, but the May 2026 revision consolidates it with unusual precision.

The nuance most commentary skips: paid placement itself is not prohibited. The policy's requirement is that ranking credit be blocked, meaning paid links should be qualified with rel=sponsored or nofollow. That is the defensible compliance position for advertorials, affiliate placements and paid digital PR in 2026. Whether a followed paid link gets you penalized or merely devalued is a separate question, and from what we see in audits, devaluation is the overwhelmingly common outcome, but the written policy line is unambiguous.

The bigger doctrinal shift of 2025-2026 sits on the content side. The policy explicitly covers scaled content abuse, defined by volume and intent rather than production method: generative-AI pages become a violation when large volumes of unoriginal pages exist primarily to manipulate rankings while serving little user value. It covers site-reputation abuse, third-party content parked on an established domain to borrow its ranking signals, and circumvention through fresh subdomains, subdirectories or sites. It also states that the policies apply to attempts to manipulate generative-AI responses in Google Search, not just classic blue links. If your risk model for spam updates is still limited to your paid links, it is five years out of date: the enforcement energy has visibly moved to scaled low-value content and parasite hosting.

Two-column comparison: the core update reassesses the relevance of the whole index and redistributes rankings, the spam update rolls out a detection model that removes spammy sites from the game.
Two update families that do not do the same job in the SERPs.

Reading a hit correctly: annotation before attribution

The most expensive mistake we see after a spam update is attribution without annotation. Before touching your link profile, establish three things: the exact update window from Google's Search Status Dashboard, whether a core update was running in an overlapping window, and whether your measurement itself broke.

That last check is not paranoia. In September 2025, Google disabled the num=100 results parameter that rank trackers relied on, and a September 2025 analysis of 319 websites, widely circulated in the SEO trade press, reported that 87.7% of them lost Search Console impressions and 77.6% lost unique ranking terms in that window. The mechanism was scraper-generated deep-result impressions disappearing, not user traffic vanishing. Any site that read its September 2025 impression drop as a spam-update penalty was chasing a ghost: the tail of the August 2025 spam update and the num=100 removal overlap almost perfectly, and one of the two is a measurement break, not a ranking event.

Then diagnose on clicks over symmetric before-and-after windows, never on impressions alone. A genuine spam-update hit is typically site-wide, fast (movement within about 24 hours of rollout start, per Search Engine Roundtable's August 2025 reporting), and does not recover when you refresh a few pages. Devaluation of specific links, by contrast, shows up as nothing at all in your analytics: the pages those links were supposed to support simply fail to move. If you cannot tie a loss date to a dashboard-confirmed spam window, the honest conclusion is usually that a core update reassessed your quality, and pruning links will not fix it.

For a netlinking operation, the doctrine is boring, and that is the point. What survived the three 2025-2026 rollouts is what looked defensible before them: links placed in real editorial media with their own audience and editorial line, moderate velocity, diversified anchors, and content on both ends that reads as journalism rather than filler. What died is industrial: link farms, expired-domain shells reanimated as link dispensers, scaled AI microsites, parasite subfolders on rented authority.

This is why the structure of your link sources matters more than any metric threshold. A marketplace aggregating thousands of anonymous third-party sites cannot guarantee what any of them will look like to a retrained classifier next quarter; the risk is opacity itself. Operating media in-house inverts that: at Nautilinks, the French editorial media we run in-house went through all three 2025-2026 windows without a site-level event, which we attribute less to cleverness than to the fact that each site is a functioning magazine first and a link host second. The catalogue view that shows exactly which media would host your link exists for the same reason: spam risk accumulates where you cannot see.

Tactically: qualify obviously commercial placements, keep the followed editorial ones defensible on their own merits, resist the reflex to disavow after every announcement, and annotate the dashboard the day Google's status page confirms a window. A spam update should be a non-event for you. If it is not, the problem predates the update.

Put it into practice?

Nautilinks operates an owned network of editorial media. In-house written articles, transparency disclosures respected, anchor mix calibrated.

See pricing → Buy backlinks service
BD
Benoit Demonchaux Founder · Nautilinks

Founder and operator of Nautilinks. Edits and writes the site's editorial glossary, as well as the content published across the Nautilinks network of editorial media.

Frequently asked questions

Does a spam update penalize purchased links, or does Google just ignore them?

Mostly the latter. SpamBrain neutralizes unnatural links continuously, outside any named update, so a purchased link Google identifies typically stops passing value silently. A spam update matters when classification escalates to the site level, treating the domain itself as spam. That is why the observable symptom of link devaluation is nothing in your analytics, while a genuine spam-update hit is a fast, site-wide visibility loss aligned with a dashboard-confirmed window.

How do I separate a spam-update hit from a core update when the windows overlap?

Start with Google's Search Status Dashboard timestamps for both update types, then compare symmetric before-and-after windows on clicks. A spam classification tends to be site-wide, near-immediate and indifferent to content refreshes; a core-update loss is usually more graded across templates and query classes and responds to quality work over months. If the loss date does not align with a confirmed spam window, work the quality hypothesis first.

Should I disavow after losing visibility in a spam update?

Almost never as a first move. Disavow is meant for cases involving manual actions or a likely one, and links the algorithm has already devalued gain nothing from being disavowed. Panic disavowing after an update mostly risks cutting links that were still passing value. Diagnose first: confirm the window, rule out measurement breaks, and only consider disavow if the profile contains patterns you would not defend in a reconsideration request.

Did the March 2026 spam update change anything for link builders?

No. Search Engine Land's reporting stated that link spam and site-reputation abuse were outside the scope of the March 2026 update, which Google described as a standard spam update and completed in less than 24 hours. Its real significance was operational: rollouts that once took 27 days now finish overnight, so attribution windows are tighter and post-update analysis has to be more precise about dates than it used to be.

Do Google's spam policies apply to AI Overviews and other generative results?

Yes. The spam policies page as revised on 15 May 2026 states that the policies cover attempts to manipulate generative-AI responses in Google Search, alongside ordinary web results. The same revision frames generative-AI content through the scaled content abuse lens: production method is irrelevant, volume and intent are what qualify a violation. The accurate risk label in 2026 is scaled low-value content, not AI content as such.

Why did so many sites lose impressions in September 2025 if the spam update had already finished its main wave?

Because measurement broke at the same time. Google disabled the num=100 results parameter in September 2025, and an analysis of 319 websites reported 87.7% losing Search Console impressions and 77.6% losing unique ranking terms as scraper-generated deep-result impressions disappeared. That is a reporting artifact, not a ranking loss. Any post-mortem of that period has to separate the two events before blaming the August 2025 spam update.

Quiz

Test your knowledge

Quiz: Google Spam Update

1/3

What was the striking difference between the August 2025 and March 2026 spam updates?

Newsletter

GEO + SEO analyses and network case studies, in your inbox

Once or twice a month at most. No filler. One-click unsubscribe.

By subscribing you agree to receive our emails. See our privacy policy.