A short explanation of a change in how browsers and search engines police the web, why it can affect a perfectly legitimate print storefront, and the simple things that keep you on the right side of it.
What’s changed
Google, Microsoft and other technology providers are increasingly using automated systems to check websites for signs of phishing, impersonation and malicious activity. This is good for internet users overall, but it means legitimate sites now have to send clearer signals about who they are, what they’re for, and why they’re asking someone to log in.
This matters most for branded storefronts: portals you run for a client, showing that client’s logo and branding, often on a subdomain of your own domain.
Why a legitimate storefront can get caught
Imagine a print portal for a big brand’s staff. It shows the brand’s logo, it lives at an address like brand.yourdomain.com, and it opens straight onto a username and password box. You know it’s legitimate. But an automated scanner sees a specific pattern:
How the four signals combine, and how enough context flips the outcome
| The signal the scanner sees | Why it looks risky on its own |
| A well-known brand’s logo | Phishing pages copy real brands to look convincing |
| A domain that isn’t that brand’s own | Impersonation sites live on look-alike or unrelated domains |
| A username / password prompt | The goal of most phishing is to harvest credentials |
| Very little explanatory text | Real services usually explain themselves; blank login pages don’t |
Put those four together with no context and, to a machine, your legitimate storefront is hard to tell apart from a site pretending to be that brand. The result can be a red “Dangerous site” or “Deceptive site” warning in the browser.
The key insight
Nothing is technically “wrong” with the storefront. The scanner isn’t reacting to a bug or a broken certificate. It’s reacting to a lack of context. Add the context, and the pattern stops looking like impersonation.
Why one flagged store can affect several
There’s a second factor worth understanding. Storefronts on related subdomains are sometimes grouped together behind a single shared security certificate, most commonly a wildcard certificate that covers every subdomain at once (for example *.yourdomain.com). When they are grouped like this, search engines can treat the whole group as one entity, so if one storefront in the group gets flagged, the warning can spread to the others sharing that certificate, even though there’s nothing wrong with them.
That’s why a single branded portal being flagged has briefly taken several other storefronts offline at once. It feels baffling from the outside, which is exactly why it’s worth knowing about. If this happens to you, Infigo Support can separate that grouping so the flag stops spreading. You don’t need to solve it yourself. If a storefront is already blocked, see My storefront shows a “Dangerous site” warning.
One flagged storefront can take down others that share its certificate, until the grouping is separated
The five things that keep you clear
All five come down to one idea: make the purpose and legitimacy of your storefront obvious.
- Make your domain descriptive.
companyprintstore.yourdomain.com says far more than company.yourdomain.com.
- Explain what the storefront is on the login or landing page, for example “This is the print ordering storefront for authorised Company employees.”
- Give context alongside the branding. Never just a logo and a password box.
- Make the relationship clear. Say who operates the store, especially when the domain differs from the brand shown.
- Review unused storefronts and domains. Disable or remove anything no longer needed.
Why this is worth doing anyway
Even setting the scanners aside, these changes make your storefronts better. Someone arriving at a clearly labelled “Company Print Ordering Storefront” has more confidence they’re in the right place before they enter their details. Clearer context means fewer confused users, fewer support questions, and a more professional first impression.
It’s fully yours to style
The examples in these guides are deliberately simple. Your login page can be fully styled to match your brand, and the explanatory message can be placed anywhere on the page. The how-to guide shows the mechanism, and the wording, look and position are entirely up to you.
Related
Search Terms
why is my storefront flagged, dangerous site, deceptive site, phishing warning, branded storefront, impersonation, search engine blocking storefront, Google Safe Browsing, SmartScreen, storefront trust, shared certificate storefronts flagged