SEO Glossary · Industry

White / Grey / Black hat SEO

Nobody is ever penalised for wearing the wrong hat. Google enforces documented policies, and its link rules draw exactly one line: editorially given, or intended to manipulate. The white/grey/black vocabulary survives because it encodes what the policy text leaves out, the probability of detection and the cost of being caught.

Key takeaways The essentials in 30 seconds
  • The hat taxonomy has no regulatory existence: Google’s policies describe link intent, not colours. Use the hats to price detection risk, never to argue that a tactic is legitimate.
  • Between August 2025 and June 2026 Google confirmed three spam updates and four core updates on its Search Status Dashboard, and not one of them was labelled a link spam update. Any vendor claiming a rollout « targeted paid links » is selling a story.
  • Since Google’s 14 April 2026 documentation update, spam reports can feed manual actions. Your competitor’s report is now a live enforcement path, which makes visible footprints costlier than statistical ones.
  • Google’s 15 May 2026 clarification extended spam policies to generative AI answers, so manipulating AI Overviews sits in the same policy bucket as manipulating blue links.
  • Grey tactics rarely die by penalty, they die by deprecation: FAQ rich results stopped appearing on 7 May 2026 and took an entire schema-stuffing playbook with them.
  • The professional distinction is not white versus grey, it is bounded versus unbounded: named publishers, disclosed pricing, an exit plan per link, and no single tactic carrying more than a recoverable share of the traffic.
3 questions to test your knowledge Read first, the quiz is waiting at the bottom.
List of six criteria that define a spam link under Google's spam policies: intent to manipulate, exchange of money, excessive reciprocity, large-scale link building, sponsored markup, traceability.
The line between compliant and non-compliant rests on intent and traceability, not on whether money changed hands.

A risk scale, not a morality scale

Google’s Search Essentials name two categories of link behaviour and only two: links that are editorially placed and freely given, and links intended to influence ranking. Every tactic the industry sorts into white, grey or black falls on one side of that single line. The three-hat vocabulary survives anyway, and it should, because it carries information the policy text refuses to give you: how reliably a tactic is detected, how it is punished when it is, and whether the damage is recoverable.

White hat, as a working consultant uses the term in 2026, covers what survives three simultaneous audits: the client’s legal review, a competitor’s spam report, and a core update landing the same quarter. Technical remediation, content a human would cite without being paid, coverage earned on newsworthiness. Grey hat covers tactics that breach the letter of the guidelines while being detected imperfectly and punished probabilistically: paid placements presented as editorial, insertions bought in volume inside existing articles, expired domains rebuilt to carry their historical equity forward. Black hat covers what is both against policy and adversarial to the system itself: hacked injections, cloaking, doorway networks, negative SEO aimed at a competitor’s profile, and now content shaped to poison a generative answer.

The honest position, and the one most proposals avoid putting in writing: virtually all commercial netlinking in France is grey. A link you paid for is a link intended to influence ranking, whatever the invoice line says. The rituals built around that fact, the « editorial collaboration » wording, the pretend outreach email, are theatre for the client rather than camouflage for Google. What separates a serious operation from a reckless one is not the colour of the hat, it is whether the risk is quantified, disclosed and bounded.

Four numbered steps to assess a host site: check the editorial line, independent organic traffic, its own identity, then conclude whether the outlet would exist without the links it sells.
The question that settles it: would this outlet exist if nobody bought a link from it?

How enforcement actually moved in 2026

Read Google’s own Search Status Dashboard rather than a volatility tracker and the past twelve months look like this: an August 2025 spam update that ran 26 days and 15 hours, a December 2025 core update, a February 2026 Discover core update, a March 2026 spam update that rolled out in 19 hours 30 minutes, a March 2026 core update immediately behind it, the May 2026 core update at nearly 12 days, and a June 2026 spam update lasting a bit over two days. Seven confirmed events, and not a single one labelled a link spam update.

That absence is the most useful fact of the year for anyone buying links. When a vendor explains that a rollout « targeted paid links » and that their inventory was spared, ask which confirmation they are reading. There is none. The defensible reading is narrower and less dramatic: link manipulation stayed inside the general spam-enforcement perimeter, and Google chose not to name it separately.

Three documentation changes matter more than the rollouts themselves. On 14 April 2026 Google clarified that spam-report submissions may be used to support manual action, which turns a competitor with a grudge into a functioning enforcement channel and makes a visible footprint far more expensive than a merely statistical one. If you have never read the anatomy of a penalty applied by a human reviewer rather than an algorithm, that is the document to internalise, because the recovery path is completely different. On 13 April 2026 a spam-policy section on back-button hijacking appeared, a reminder that the black-hat catalogue is still being extended in the direction of user deception. And on 15 May 2026 Google stated explicitly that its spam policies apply to generative AI responses in Search, which puts manipulation of AI Overviews and AI Mode into the same policy bucket as manipulation of the ten blue links.

The other lesson of the period is that grey tactics usually die of deprecation rather than penalty. FAQ rich results stopped appearing in Search on 7 May 2026, per Google’s own documentation updates, and an entire schema-stuffing playbook lost its payoff overnight without anyone being sanctioned. Same shape for the 15 June 2026 note that llms.txt is not required by Google Search and carries no ranking effect either way, which ended a small consulting industry before it had a chance to mature. Tactics that depend on a feature rather than on demand have a shelf life set by a product manager, not by an algorithm.

Where the grey zone actually lives in netlinking

Once you accept that paid placement is grey by construction, the useful question becomes which flavour of grey you are buying. A guest article on a real magazine with real readers, a named editor and a rate card is grey with a shallow downside: worst case, the link stops passing value. A link injected into a five-year-old post on a site whose only business is selling paragraphs is grey with a footprint, because the same pattern repeats across every client of that vendor. A network of sites built purely to link outward is grey until the day someone maps the hosting, the registrar pattern or the template reuse, at which point it becomes a single point of failure for every site it points at.

The distinction that survives audit is ownership and visibility, not tactic. When we run placements through a system where the publisher is named before you order, the client can inspect what they are buying: traffic curve, editorial history, outbound-link density, whether the site has an audience or only a metric. Nautilinks owns its French editorial media and writes them in-house, and we publish the list rather than hiding it behind a broker layer. That is not a virtue signal, it is a risk position: a network you can see is a network you can audit, and a network you can audit is one whose footprint you can actually manage instead of hoping nobody looks. The opposite model, the anonymous inventory resold through three intermediaries, is where most unpleasant surprises originate, and it is worth reading how a resale marketplace stacks its margins before assuming the price you pay reflects the risk you take.

Expired domains deserve their own line. Rebuilding an expired domain into a genuine publication, with new content and a coherent editorial line, sits at the acceptable end of grey. Restoring an expired domain’s old URLs purely to 301 them at a money site is a different bet: it works until it does not, and the failure is usually silent, a slow decay rather than a notification in Search Console. Anyone telling you the second is white hat has redefined the word.

Two-column comparison of two uses of an expired domain: relaunching a media outlet on its original topic versus buying domains in bulk and 301-redirecting them to a money page.
The tool does not decide the practice, the fit between the domain and what you do with it does.

What we see go wrong

The recurring failure in audits is not aggression, it is inconsistency. A profile that spent eighteen months at four referring domains a month and then takes forty in three weeks reads as an event regardless of the quality of those forty. The same applies to anchors: a site whose branded share collapses from most of the profile to a minority inside one quarter has changed its own baseline, and the baseline is what any classifier compares against.

Second failure, buying the metric instead of the media. A Domain Rating or a Trust Flow is a vendor’s model of a graph, not a statement about whether a page has readers. Sites engineered to score well on those models are cheap to produce and abundant, which is exactly why their price is low. If a placement costs a fraction of what an actual editorial team would charge to publish, the discount is the risk premium, made visible.

Third, the reflex disavow. Every audit season produces someone who uploads ten thousand domains after a ranking drop that had nothing to do with links. Google’s systems ignore most manipulative links rather than punishing them, and a disavow file is a blunt instrument that can remove value you were still receiving. Reserve it for a manual action or for a genuinely toxic injection campaign you can document.

Fourth, treating black hat as a spectrum extension of grey. It is not. Hacked placements, cloaked redirects and negative SEO carry legal exposure in France on top of search exposure, and no ranking gain justifies putting a client in front of a lawyer. The line here is not tactical, it is one you do not cross.

Operating the grey zone on purpose

Set a risk budget per page, not per campaign. A commercial page that generates most of the revenue can absorb far less exposure than a category page you could rebuild in a week. Concentrating the aggressive placements on the pages you can afford to lose, and keeping the money page fed by links that would survive a human review, is the single most useful allocation rule we apply.

Document every placement as if you will have to defend it: publisher, date, anchor, page, cost, and whether the link is removable. Grey positions become dangerous when they are undocumented, because you cannot unwind what you cannot list. This is also why knowing what a placement actually costs before you price the risk matters more than negotiating a discount: an opaque price hides an opaque inventory.

Finally, change what you measure. Pew Research, in a study published on 22 July 2025 covering 68,879 real Google searches from 900 US adults, found that when an AI summary appeared users clicked a traditional result on 8% of visits versus 15% without one, and clicked a source cited inside the summary on 1%. Whatever the exact transfer to French SERPs, the direction is clear enough: a share of the payoff from any ranking tactic, white or grey, now lands as a citation rather than a click. Judging a netlinking programme purely on positions, while the answer layer absorbs the query, will make a working programme look dead and a dead one look fine. Track branded demand, qualified conversions and citation presence alongside rankings, and pick your hat with the arithmetic in front of you rather than the vocabulary.

Put it into practice?

Nautilinks operates an owned network of editorial media. In-house written articles, transparency disclosures respected, anchor mix calibrated.

See pricing → Buy backlinks service
BD
Benoit Demonchaux Founder · Nautilinks

Founder and operator of Nautilinks. Edits and writes the site's editorial glossary, as well as the content published across the Nautilinks network of editorial media.

Frequently asked questions

Is buying links black hat or grey hat?

Grey, and calling it anything else is dishonest. A paid link is a link intended to influence ranking, which is what Google’s policy prohibits, but detection is imperfect and enforcement is probabilistic. What moves the risk is not the payment, it is the footprint: a named publisher with real readers and a disclosed rate is a different exposure from an anonymous inventory resold through brokers, where the same pattern repeats across hundreds of buyers and one investigation reaches all of them.

Did any 2026 update specifically target paid links?

No confirmed one. Google’s Search Status Dashboard lists spam updates in August 2025, March 2026 and June 2026, plus four core updates, and none was labelled a link spam update. Link manipulation stayed inside general spam enforcement. Treat any vendor claim that a specific rollout hit paid links, and spared their inventory, as marketing rather than fact, because Google published nothing that supports it.

Does the hat vocabulary still mean anything with AI answers in play?

More than before, because the surface widened. Google clarified on 15 May 2026 that its spam policies apply to generative AI responses in Search, so content engineered to manipulate an AI Overview sits in the same policy bucket as classic ranking manipulation. The practical consequence is that the black-hat catalogue now includes answer-layer poisoning, while the grey zone in netlinking is unchanged: paid editorial placement, with the same detection economics as last year.

How much of a profile can be grey before it becomes a liability?

There is no published threshold, and anyone quoting one is inventing it. The workable rule is recoverability: no single tactic or vendor should carry a share of your traffic you could not rebuild within a quarter. Concentrate aggressive placements on pages you can afford to lose, keep the revenue pages fed by links that would survive a human review, and keep a removable-link list so you can unwind a position instead of discovering it during a manual action.

Should we disavow grey links preemptively?

Almost never. Google’s systems ignore most manipulative links rather than penalising the target, and a disavow file removes value you may still be receiving, with no undo on a useful timescale. Reserve it for a documented manual action or for an injection campaign you can actually evidence. In audits, the preemptive disavow is far more often the cause of a decline than the cure for one.

Why do grey tactics keep dying without any penalty?

Because most of them depend on a SERP feature rather than on demand. FAQ rich results stopped appearing in Search on 7 May 2026 and a whole schema-stuffing practice lost its payoff with nobody being sanctioned. Same for the 15 June 2026 clarification that llms.txt has no ranking effect. A tactic whose value comes from a product decision has a shelf life set by a product manager, which is a good reason to weight your programme toward links and content that would matter even if the feature vanished.

Quiz

Test your knowledge

Quiz: White / Grey / Black hat SEO

1/3

Between August 2025 and June 2026, how many Google updates were confirmed as link spam updates on the Search Status Dashboard?

Newsletter

GEO + SEO analyses and network case studies, in your inbox

Once or twice a month at most. No filler. One-click unsubscribe.

By subscribing you agree to receive our emails. See our privacy policy.