AdvancedLinkTraining.com logo — a free link building course by Bill HartzerAdvanced Link TrainingA resource by Hartzer.com

Toxic links and disavow: what is actually true

Junk links are the default state of publishing on the internet, not a symptom of anything you did.

The number that should recalibrate you

I have run billhartzer.com for over twenty years. In that time I have never bought a single link — not one paid placement, not one sponsored post with a followed link, not one directory submission paid for on the basis of the link. The profile is as clean in provenance as a twenty-year-old site can be.

Here is what it looks like. 22,260 referring domains. 69.3% of them — 15,421 domains — sit at Trust Flow 0, Majestic's lowest band, the score assigned to a domain with no discernible trust signal reaching it. Nearly seven in ten of the sites linking to me are junk by any authority measure you care to apply.

Every one of those 15,421 domains arrived unsolicited. I did not build them, ask for them, pay for them, or know about the overwhelming majority of them until I ran the analysis.

Sit with that for a moment, because it invalidates the premise of most link audit products on the market. If a twenty-year profile with zero purchased links is 69.3% Trust Flow 0, then a low-quality tail is not evidence of manipulation, negligence, or an attack. It is what the internet does to any site that publishes for long enough.

The other end of the same distribution makes the point from the opposite direction: only 446 referring domains — 2.0% of the profile — ever reached Trust Flow 41 or higher. That is about 22 good domains a year over two decades, from a site that publishes constantly and is reasonably well known in its field. Good links are rare. Junk links are free and automatic.

What toxic actually means

"Toxic link" is not a Google term. Google has never published a toxicity metric, never scored links on a toxicity scale, and never asked anyone to remove links on that basis. The word entered the vocabulary through SEO software vendors, where it serves a clear commercial function: a tool that assigns a toxicity score to links creates a problem that the same tool then offers to solve.

What a toxicity score actually is: a model output. A vendor takes signals it can measure — domain authority metrics, anchor text patterns, outbound link volume, hosting neighborhood, spam heuristics — and produces a number. There is no ground truth to calibrate against, because nobody outside Google knows which links Google discounts. The score is a guess, packaged with a confidence the underlying method does not support.

What is genuinely true about low-quality links:

  • Search engines discount them. A link from a scraper site or an auto-generated directory carries essentially no weight. This has been true for many years and is not controversial.
  • Discounting is not penalizing. A link worth zero and a link that costs you something are different states. The overwhelming majority of junk links are the former.
  • Google has said repeatedly that it ignores the vast majority of spam links automatically, precisely because sites cannot control who links to them. This is the only sane design: any other approach would make sabotage trivial.

So the honest translation of "you have 4,000 toxic links" is usually "you have 4,000 links a vendor's model scored badly, most of which are worth nothing and cost nothing."

Where junk links come from

Understanding the mechanism removes most of the anxiety, because once you can name the sources you stop reading them as an attack.

  • Scrapers. Sites that copy content wholesale, including your links, and republish it. One scraped article can produce hundreds of links from a single junk domain.
  • Feed aggregators and mirrors. RSS republishers, many automated, many abandoned years ago and still running.
  • Statistics and "analysis" sites. Auto-generated pages reporting on your domain, your traffic estimate, your DNS records. Each one links to you. There are thousands of them.
  • Auto-generated directories. Built by bots, populated from crawl data, monetized by ads.
  • Comment and forum spam on sites where your URL was posted by someone else, or by a bot harvesting URLs.
  • Parked and expired domains that retained old content.
  • Widget and template links that propagate one placement across thousands of pages.

None of these involve a decision by a human to endorse you, which is exactly why search engines discount them. The scale is the surprising part: a moderately visible site accumulates these continuously, forever, with no action on anyone's part. My 15,421 Trust Flow 0 domains are twenty years of that process running unattended.

What the disavow tool actually does

The disavow tool lets a site owner submit a file listing URLs or domains, telling Google to ignore links from them when assessing the site. It is a real tool with a real function, and it is far narrower than the industry treats it.

Three properties are worth being precise about.

  • It is a request to ignore, not a removal. The links still exist. Third-party tools still show them. Nothing about the linking site changes.
  • It is one-directional and blunt. Disavowing a domain discards every link from it, including any you would have wanted.
  • There is no feedback. You submit a file and receive no confirmation of effect, ever. This is what makes disavow so seductive and so unfalsifiable: whatever happens next, someone will attribute it to the file.

Google's own guidance has grown steadily more discouraging over the years, to the effect that most sites should never use it. That direction of travel is informative. The tool was introduced in the aftermath of Penguin, when a great many sites had genuinely built bad links and needed a way to renounce them. The situation it was designed for is far less common now.

The two cases where disavow genuinely applies

There are two, and they are narrow.

Case one: you have a manual action for unnatural links. This is visible in Google Search Console. Not a ranking drop you are attributing to links — an actual message, in the Manual Actions report, naming the problem. In that case a human reviewer has looked at your profile and decided something. Disavow is part of the reconsideration process, and it should be paired with genuine removal attempts and an honest account of what happened.

Case two: you, or someone acting for you, actually built the links. A previous agency ran a private blog network. A prior owner bought placements. Someone on your team spent a year on paid guest posts with exact-match anchors. In that situation there is a real set of links with real provenance, and disavowing that specific set is a defensible way to renounce it — particularly ahead of a reconsideration request or a due diligence process.

Note what both cases have in common: you can name the links and explain how they got there. That is the test. If you cannot say who built a link and why, you almost certainly should not disavow it.

Everything else — a scraper tail, a spam directory sending 2,000 links, a competitor you suspect of something, a tool flagging 30% of your profile as toxic — falls outside both cases.

Why most disavow files do more harm than good

This is the part that costs people rankings, and I have seen it repeatedly.

The false positive problem is severe. Disavow files are usually built from a tool's flagged list, and those lists over-flag by design. Legitimate small sites, personal blogs, niche forums, non-English domains and anything with a low authority score routinely get caught. Every one of those you disavow is a real endorsement you have thrown away, permanently and invisibly.

Domain-level entries multiply the damage. Most files use the domain: directive because it is faster. That discards every link from the domain, including future ones. Disavow a publisher because one syndicated copy of an article looked spammy, and you have written off that publisher forever.

You cannot measure the outcome. There is no report showing what the file did. So the file gets bigger over time — someone adds to it each quarter, nobody ever removes anything, and after three years the site is ignoring thousands of domains for reasons nobody documented.

It substitutes for the actual work. Time spent classifying junk is time not spent earning the 22 good domains a year that actually move things. That is the real cost, and it never shows up in a report.

My position, stated plainly: if you do not have a manual action and you did not build the links, do not file a disavow. The expected value is negative. The junk is already discounted, the tool gives you no feedback, and the false positives are permanent.

If you have inherited a file and cannot establish why any of it is there, the defensible move is usually to remove the entries you cannot justify and monitor — not to keep adding. Module 8 covers manual actions and the reconsideration process in detail.

Questions

Are toxic links real?

Low-quality links are real; "toxic" as a scored category is a vendor coinage. Google publishes no toxicity metric and has said for years that it ignores the vast majority of spam links automatically, because sites cannot control who links to them. The practical distinction: those links are usually worth nothing, which is not the same as costing you something.

Should I disavow spam links I did not build?

Almost never. On a twenty-year profile where not one link was ever bought, 69.3% of 22,260 referring domains sat at Trust Flow 0 — 15,421 junk domains that arrived unsolicited. That is the normal state of a site that publishes. Disavowing an unsolicited tail achieves nothing measurable and risks discarding legitimate links caught as false positives.

When does disavow actually apply?

Two cases. First, you have a manual action for unnatural links showing in Search Console — an actual message, not a ranking drop you are attributing to links. Second, you or someone acting for you genuinely built the links, and you can name them. The common test is provenance: if you cannot say who built a link and why, do not disavow it.

Can a competitor hurt me by pointing bad links at my site?

Negative SEO of that kind is far harder than the industry folklore suggests, because search engines already discount the link types an attacker can produce at volume. Any other design would make sabotage trivial. If you believe you are being targeted, monitor rather than react, and look for a manual action before assuming links are the cause of any change.

I inherited a large disavow file. What should I do with it?

Establish provenance first. If the file was built from a tool's toxicity flags rather than from links someone actually built, most of it is unjustifiable and some of it is probably discarding real endorsements. The defensible move is to remove entries you cannot explain and monitor, rather than continuing to add. Do not treat an inherited file as evidence that something was wrong.