Hello Apple engineers and fellow developers,
Over the past few weeks I have noticed multiple reports from different developers whose legitimate websites have been classified by Safari as “Fraudulent Website Warning”, despite passing every major public security and reputation check.
My websites appear to be affected by the same issue.
Domains
https://skvoz.net
https://skvoz.org
Both domains were registered on July 15, 2026.
The Fraudulent Website Warning first appeared on July 22, 2026, only one week after registration.
Both websites are legitimate services operated by our team.
Neither website impersonates another brand, attempts to collect Apple IDs, banking credentials, passwords, or any other sensitive information through deceptive means.
Extensive verification performed
After the warning appeared, we performed a comprehensive technical and security review.
Website security
✅ No malware detected
✅ No phishing content
✅ No unauthorized redirects
✅ No suspicious JavaScript
✅ No mixed-content issues
✅ HTTPS configured correctly
✅ Valid TLS certificates
Infrastructure
DNS configuration verified
SSL certificate chain verified using OpenSSL
Server responds correctly over HTTP/2
IPv4 and IPv6 connectivity verified
Origin server behaves correctly
Cloudflare configuration was thoroughly tested during troubleshooting and ultimately removed from the production setup to eliminate it as a possible cause
Reputation checks
We verified both domains and the hosting IP address using multiple public reputation services.
Results were consistently clean.
This included services such as:
Google Safe Browsing
Google Search Console
VirusTotal
URLVoid
IP reputation databases
None of them currently report malware, phishing activity, or any other security issues.
Apple-specific actions
We have already:
submitted a Website Review request;
contacted Apple Security via reportphishing @apple.com requesting a manual review.
At the time of writing, the warning is still present.
One unusual observation
One particularly unusual observation is that both of our domains (skvoz.net and skvoz.org) received the warning independently.
These are separate domains serving different purposes, yet both appear to have been classified in the same way despite passing the same technical and reputation checks.
This made me wonder whether Apple’s reputation system may evaluate related domains or shared infrastructure together. I understand the internal implementation is not public, but I wanted to mention this observation in case it is useful during investigation.
Similar reports
While investigating this issue, I found several recent reports from other developers describing almost identical behavior.
The common pattern is remarkably consistent:
Safari displays Fraudulent Website Warning
Chrome, Firefox and Edge open the website normally
Google Safe Browsing reports the domain as safe
VirusTotal reports no malware
Google Search Console reports no security issues
valid HTTPS certificates
relatively new domains
no explanation regarding what triggered the warning
This suggests the issue may not be isolated to a single website.
Questions
I would greatly appreciate any guidance from Apple engineers.
Does Safari rely solely on Google Safe Browsing, or does Apple maintain an independent reputation database for Fraudulent Website Warning?
If Apple maintains its own reputation system, are there any documented technical signals developers should verify?
For example:
redirects
third-party scripts
TLS configuration
domain age
hosting reputation
infrastructure characteristics
phishing heuristics
machine-learning based classification
Is there any recommended diagnostic process beyond Website Review?
Approximately how long does a manual review usually take?
Why I am posting
This post is not only about my own websites.
Over the past few months I have noticed an increasing number of developers reporting what appear to be false positive Fraudulent Website Warnings affecting legitimate websites.
If there have been recent changes to Safari’s reputation or anti-phishing systems, it would be extremely helpful for developers to better understand what technical criteria should be reviewed before requesting reconsideration.
Even if the exact detection logic cannot be disclosed, any general guidance on common causes of false positives would help developers resolve issues much more efficiently.
Thank you very much for your time.
2
1
197