Safe Web false positive: safeage[.]eu rated Warning (URL:Botnet) — clean site, two submissions filed, no change after 3 days

Issue abstract: Norton Safe Web rates safeage[.]eu and its www hostname as Warning, categorised as URL:Botnet. The site is clean and I believe this is a false positive. Two submissions filed on 31 August have not changed the rating.

Note: domain names are written in defanged form (brackets around the dot) because new accounts cannot post links here.

Detailed description:

I am the owner and operator of safeage[.]eu, a Dutch webshop selling mobility and daily-living aids for elderly and less-abled customers. The site runs WordPress/WooCommerce behind Cloudflare.

Alert ID: 4d352ec5c0b5/2026-08-27T09:41:51.093Z
Detection observed: 27 August 2026, 09:41 UTC

What I have already done

On 31 August I filed false-positive reports through the Norton submissions portal, separately for the bare domain and the www hostname. Both were acknowledged with the “48 business hours” message. Three days on, both still return a Warning rating.

Why I believe the site is clean

Our developer completed a full server-side audit: no malware, no backdoors, no web shells, no modified core or plugin files, no unknown administrator accounts, no unexpected scheduled tasks.

An independent Sucuri SiteCheck scan returns no malware and no blacklist entries. Google Safe Browsing reports “No unsafe content found” (checked 31 August 2026).

Of 36 reputation engines checked via aggregated scanning, only Norton, Avira and Gridinsoft flag the domain. Bitdefender, Dr.Web, Fortinet, SURBL, Spam404, PhishTank, OpenPhish and URLhaus all report nothing.

Certificate Transparency shows only five hostnames on the domain (apex, www, mail, webmail, dashboard). There are no forgotten or abandoned subdomains.

Norton Safe Web itself rates our hosting IP as safe, which suggests the classification is attached to the domain name rather than to hosted content.

One thing that may be triggering the automated rating

Our homepage opens preconnect and dns-prefetch connections to api.config-security[.]com and conf.config-security[.]com. Despite the name, these are not a security service. They are the endpoints used by the Triple Whale analytics pixel (TriplePixel), a commercial e-commerce attribution product that we license and actively use.

I can see how a heuristic would read repeated beacons to a domain called “config-security” as botnet-like behaviour. Norton Safe Web rates that domain itself as safe. If this is what is driving the classification, I would very much like to know, because it would keep recurring after any manual clearance.

Impact

A meaningful share of our customers cannot reach the shop. Our conversion rate on paid traffic roughly halved. Our customer base skews older and disproportionately runs pre-installed Norton products, so the effect on us is severe.

I am happy to provide the full audit report, server logs or any other evidence a reviewer needs, and I can supply the exact URLs privately. Any pointers on getting this escalated would be much appreciated.

Thank you.

Thomas

2 Likes

Hello @user13803
Welcome to the Norton Community!
We’ll try to call attention:
https://safeage.eu/
image

Threat name: URL:Botnet
URL: safeage.eu
Detected by: Web Shield | URL scanning
Alert ID: d1f658181781


a1ca18951b03/2026-09-02T12:26:11.254Z


a1ca18951b03/2026-09-02T12:26:11.254Z

1 Like

https://safeage.eu/


AbuseIPDB » 104.21.85.183
We resolved the domain safeage.eu to IP address 104.21.85.183
104.21.85.183 was not found in our database
This IP was reported 0 times.

1 Like

@bjm thank you, this was exactly the piece we were missing. Your distinction between a public guest submission and a verified-owner dispute explains why nothing moved after our two submissions on 31 August. Also much appreciated that you reproduced the block yourself and pulled the third-party reports.

Update: I am now a verified site owner.

Today I registered safeage[.]eu in the Norton Safe Web owner portal and completed ownership verification using the HTML authentication file method. My Sites now shows “Ownership verified” for the domain. I then used the “Re-evaluate site ratings” link in the owner dashboard and filed a fresh dispute, stating my verified-owner status.

A question, because this may be a gap in the flow.

The “Re-evaluate site ratings” link in the verified-owner dashboard opens the same public form at the submissions portal that I already used twice as an unverified guest. I did not see a separate owner dispute tab, a dispute status view, or anything that looked like a domain-wide rescan request.

Is that expected behaviour, and does the backend link the submission to my verified ownership automatically because the account matches? Or is there a separate owner dispute path I am not finding? If it really is the same single-URL form, then verified owners have no practical way to request the domain-wide rescan you describe, which seems worth flagging.

Current status, for anyone escalating this:

Domain: safeage[.]eu (and the www hostname)
Rating: Warning, URL:Botnet
Ownership: verified 2 September 2026
First dispute: 31 August 2026, more than 48 business hours ago, no status change
Alert ID (mine): 4d352ec5c0b5/2026-08-27T09:41:51.093Z
Alert ID (reproduced by @bjm): d1f658181781

The site is clean by every independent measure: full server-side audit, Sucuri reports no malware and no blacklist entries across 9 lists, Google Safe Browsing reports no unsafe content, AbuseIPDB has zero reports for the hosting IP, and only three engines out of the whole field flag the domain.

I remain convinced the likely trigger is the Triple Whale analytics pixel, which beacons to api.config-security[.]com and conf.config-security[.]com. Those are legitimate first-party tracking endpoints for a commercial attribution product we license, but the domain name is unfortunate and a botnet heuristic could easily latch onto it. If a reviewer can confirm or rule that out, it would prevent this from recurring after any clearance.

Meanwhile a meaningful share of our customers still cannot reach the shop. Any manual escalation would be very welcome.

Thank you.
Thomas

2 Likes

Hello @user13803
fwiw ~ my understanding:

1 Like

https://safeage.eu/klantenservice

Threat name: URL:Botnet
URL: www.safeage.eu
Detected by: Web Shield | URL scanning
Alert ID: 69e411f79c3c

image


4ad495ab0c91/2026-09-02T16:06:39.928Z

4ad495ab0c91/2026-09-02T16:06:39.928Z

https://safeage.eu/winkelwagen/
147c47c49209/2026-09-02T16:23:50.126Z

https://safeage.eu/mijn-account/
13604fb14667/2026-09-02T16:24:35.383Z

1 Like

https://safeage.eu
288ed91671f4/2026-09-03T11:55:35.596Z
7dd9e916d069/2026-09-03T12:34:57.124Z

https://safeage.eu
05bf95be5c34/2026-09-03T17:31:11.839Z

https://safeage.eu
b01b1332d7b3/2026-09-03T20:45:58.907Z

Update — day 11, still rated Warning (URL:Botnet), requesting Norton staff review

Posting an update on this thread, and asking whether a Norton staff member can take a look.

Current status (checked 4 September 2026, 09:09 CEST):

  • safeage.eu — rating b (Warning), category URL:Botnet
  • www.safeage.eu — rating b (Warning), category URL:Botnet
  • Control check on google.com in the same API call returns g, so the measurement itself is reliable
  • The site itself is up and serving normally (HTTP 200)

What has been submitted so far:

  • Three false-positive submissions: two on 31 August, one on 2 September
  • Site ownership verified through Safe Web since 2 September
  • Alert IDs: 4d352ec5c0b5/2026-08-27T09:41:51.093Z and d1f658181781
  • The Warning first appeared around 24 August 2026

No change in rating in the 11 days since, and no response to any of the submissions.

Evidence the site is clean:

The site has been fully audited by our developer — no malware, no backdoors, no shells. Sucuri and Google Safe Browsing both report clean. The hosting IP shows zero abuse reports on AbuseIPDB, as bjm confirmed earlier in this thread. Norton, Avira and Gridinsoft are the only engines still flagging the domain; every other engine we have checked reports it clean. We have not been able to find anything on our side that would justify a URL:Botnet classification, and no specific URL or indicator has been provided to us that we could act on.

Business impact: this is a live webshop. Roughly one in five visitors cannot reach the store, and conversion on paid traffic has halved since the Warning appeared. Every day the classification stands has a direct commercial cost.

My request: could a Norton staff member please pick this up for a manual review? The automated dispute path has now been tried three times over 11 days from a verified site owner without any result. If there is a specific URL, script or indicator behind the URL:Botnet classification, please share it — we will remediate immediately. Happy to provide scan results or any other evidence needed.

Thanks in advance.

1 Like

Hello @user13803
We’ll try to call attention – again:

Curious, I need Norton VPN IP address to reach safeage.eu

via my residential IP = ERR_CONNECTION_RESET
browser successfully knocked on the door and a connection actually started—but mid-handshake, a machine abruptly slammed the door in your face by firing back a **TCP RST (Reset) packet.

  • Without the VPN: You approach as a US residential customer. The guard looks at your home IP, remembers the site has an active “Botnet” alert due to that Triple Whale tracking script, and immediately throws a punch—slamming the door in your face with that TCP Reset packet (ERR_CONNECTION_RESET).
  • With the VPN: You approach dressed as a corporate data center server. The guard notes your Norton IP, assumes you are a legitimate business tool or remote employee, and lets you pass without hesitation.

++++++++++++++++++++++++++++++++++++++++++++++++

fwiw ~ as per AI

AI sourced content may make mistakes

fwiw ~ as per AI

AI sourced content may make mistakes

Hi @user13803

Thank You for reporting the issue on Norton Community. The reported url is now resolved as False Positive. Could you please check now?

Thanks !

1 Like

https://safeage.eu



Note: I still need Norton VPN IP address to reach safeage.eu
Testing in new Private Mode window and still getting ERR_CONNECTION_RESET
the block is network-based, my browser cache is innocent