Grey Hat, Black Hat and Parasite SEO
what it is, how it gets caught and what happens to the people who do it.
Level 7 documents grey hat, black hat and Parasite SEO from the position of the person defending a site, not the person running the technique. Every lesson describes what a tactic looks like from the outside, which signal exposes it, and what it has cost the people caught doing it. None of the ten lessons explains how to build anything.
The reason to write this down is practical. When you inherit a project, most of the first month goes into working out what the previous agency did, and that job is impossible if you cannot recognise a bought link profile, a doorway template or a media subfolder rented out to a third party. The same applies when a site loses rankings overnight and nobody can say whether it was a core update, an algorithmic spam demotion or a manual action. Without the vocabulary of spam, the diagnosis stays guesswork.
Google publishes a spam policies page listing named policies, among them scaled content abuse, site reputation abuse and expired domain abuse. That page is the reference document for this entire level. Google also separates algorithmic spam demotion, which arrives without any notice, from a manual action, which is reported to the site owner in Google Search Console. The two are diagnosed differently and recovered from differently, and a large part of this level is learning to tell them apart.
Almost no free course covers site reputation abuse honestly, because doing so means naming large publishers who rent out subfolders. That is exactly why it is covered here. An auditor who cannot name the practice cannot spot it on the site that just landed on their desk.
What this level covers
- Recognising a manipulated link profile during an audit: anchor text patterns, shared hosting footprints and template overlaps that expose a PBN.
- Telling a core update drop apart from an algorithmic spam demotion and from a manual action reported in Google Search Console, and knowing what evidence each explanation demands.
- Identifying Parasite SEO and site reputation abuse on somebody else’s domain, or worse, on your own: rented sections, ghost bylines and content unrelated to anything the host publishes.
- Detecting cloaking, doorway pages and sneaky redirects by comparing what a browser receives with what is served to Google’s crawler.
- Putting a number on the risk before a client or a manager proposes a shortcut: what gets lost, for how long, and which part of the loss never comes back.
- Deciding on evidence when a competitor’s spam is worth a report to Google and when reporting it is wasted effort.
Where the line between grey hat and black hat actually sits
The line is drawn by intent to manipulate rankings, not by how effective a technique is or how much risk the operator accepts. Google defines the boundary through its spam policies, and a practice falls inside them when its main purpose is to deceive the ranking systems or the user. Whether a technique still works is not the test. It is a statement about today’s detection, and detection does not stand still.
Grey hat is usually described as the zone where Google’s policies say nothing explicit. In a real audit that zone is far narrower than it sounds. Buying an editorial mention, paying for a review with a followed link, dropping in an unmarked sponsored block: all of that lands under paid links, which is a named policy rather than an ambiguity. What genuinely stays grey is different in kind: internal linking aggressiveness, how many listing pages a site generates, how far a template gets reused across projects. Those are judged by degree, not by category.
The useful question for classifying a borderline case is not whether Google will catch it. It is this: if somebody at Google read the project’s own internal documentation, would an honest description of the tactic read as manipulation? A team that has to hide how it acquires links has already answered. The test needs no tools, survives a meeting, and ages better than any list of techniques.
Algorithmic demotion and manual actions are two different diagnoses
Google separates algorithmic spam demotion from a manual action, and that separation changes the auditor’s work completely. A manual action appears in the relevant report in Google Search Console, names the policy that was breached, and allows a reconsideration request once the problem is fixed. An algorithmic demotion appears nowhere. The site simply performs worse and there is no message to read.
The common mistake is treating every drop as a penalty. Most are not. Before reaching for a spam explanation, rule out the boring causes: a template that started emitting noindex, a canonical changed during a redesign, a robots.txt block, a migration with badly mapped redirects. Only once the technical side is clean does it make sense to look at the link profile and the domain’s history.
When the spam hypothesis survives, the evidence to gather is specific. Pin down the exact date of the drop, whether it hit the whole domain or one directory, whether the lost traffic came from brand or generic queries, and whether anything is waiting in Google Search Console. A second-hand domain adds one more mandatory question: what was this site before? Expired domain abuse is a named policy, and history travels with the domain.
Parasite SEO and site reputation abuse
Parasite SEO means publishing on somebody else’s high-authority domain to borrow its reputation, usually in sections the host does not edit. Google covers this on its spam policies page as site reputation abuse. The most visible form is the rented subfolder: a newspaper or magazine hands a directory to a third party who publishes commercial content with no connection to the publication’s editorial line.
From the outside it is recognisable by a handful of tells. The subfolder does not share a template, a byline style or a tone with the rest of the site. The authors have no track record outside that section. Internal linking into the directory from the main navigation is thin or absent. And the subject matter has nothing to do with what the publisher covers the rest of the time.
This matters to an auditor in two directions. Outward, it explains why an irrelevant domain outranks genuine specialists on commercial queries. Inward, it is inherited risk: plenty of publishers signed these deals without the search team being told, and the exposure surfaces in the audit rather than in the contract. The lesson on the August 2026 European carve-out documents the territorial exception attached to this policy.
The signal that exposes each technique, and what it costs
This table condenses the level into audit form: what you are looking at, which evidence exposes it, and what has followed when Google acts. Treat it as the checklist to run over any project arriving with a questionable history.
| Technique | Signal that exposes it | What it costs when caught |
|---|---|---|
| PBNs and link networks | Several domains sharing a template, a registrar, an IP range and near-identical anchor text all pointing at one site | The links stop passing value and the receiving site can pick up a manual action for unnatural links in Google Search Console |
| Unmarked paid links | Blog sections carrying followed links into industries unrelated to the publication, posted in bursts | The purchased links lose their value, and a manual action can reach both the seller and the buyer |
| Cloaking | A difference between the HTML served to Google’s crawler and the page a normal browser receives | Affected pages are removed from Google’s index, and recovery is slow even after the cloaking stops |
| Doorway pages | Hundreds of near-identical pages that swap only a city name or query variant and funnel to the same destination | Algorithmic demotion across the whole set of pages and, in clear cases, a manual action |
| Parasite SEO and site reputation abuse | A subfolder with no editorial relationship to the host domain, authors with no history, and no links from the main navigation | The affected section stops ranking and the host domain puts the reputation of the rest of the site at risk |
| Scaled content abuse | A publishing volume the declared team could not produce, repeated structure, and no first-hand information anywhere | Low-value pages are dropped from the index and trust in the whole domain falls |
| Expired domain abuse | A second-hand domain whose current content has nothing to do with whatever the archives show it used to be | The inherited link history stops counting and the domain loses precisely what was paid for |
| Back button hijacking | The browser’s back button fails to return the user to the search result they came from | A breach of a named spam policy, with the corresponding demotion of the pages involved |
The 10 lessons in this level
- Black Hat, Grey Hat, White Hat: Where the Line Actually Is
- Google’s 18 Spam Policies, Explained One by One
- Parasite SEO: How It Works and Why Google Hunts It
- Site Reputation Policy: The August 2026 European Carve-Out
- PBNs and Link Networks: Anatomy of a Detection
- Cloaking, Doorways and Sneaky Redirects
- Scaled Content Abuse: The Line Between Scaling and Spamming
- Back Button Hijacking: The 2026 Spam Policy
- Spotting Black Hat in Your Competition (And Whether to Report It)
- The Real Risk Calculation: What You Lose When You’re Caught
How to work through this level
Work through this level with a domain in front of you, not with notes. The goal is not to memorise a list of techniques. It is to come out with an audit habit you apply to every project you take on.
- Start with lessons 1 and 2, in order. Without the line drawn properly and Google’s spam policies read, the rest of the level turns into anecdotes.
- Pick a real domain you can inspect, ideally one you inherited or a competitor, and apply each lesson to it as you read.
- Record every finding with its evidence: the URL, the screenshot, the date. A suspicion without evidence cannot be defended in front of a client.
- Check the manual actions report in Google Search Console on every property you manage. It takes two minutes and closes an entire hypothesis.
- Finish with lesson 10 and convert your findings into numbers: how much traffic depends on the pages at risk, and how long recovery would take.
The output of this level is your own audit template, short and repeatable, that you can run over any domain in an afternoon. If you finish holding a list of tactics instead of that template, the level has not done its job. When you are done, go back to the complete free SEO course and carry on with the next level.