Skip to content

Google Named No Policy: The 16 Spam Categories Explained

Google's September 2026 spam update named no policy. Here is why that is normal, plus all 16 spam policy categories and what each means for your site.

24 Sept 20267 min read
  • Google Updates
A notebook and checklist on a desk, illustrating Google Named No Policy: The 16 Spam Categories Explained

Google's announcement of the September 2026 spam update said only that it applies globally, to all languages, and may take up to two weeks. It named no policy, which is normal for spam updates: they improve automated detection across Google's published spam policies rather than launching a new rule. That policy page currently lists 16 categories, from cloaking to user-generated spam, and this post explains each in plain terms, with what to check on your own site.

Key Takeaways

  • The Google Search Status Dashboard entry for the update (24 September 2026, 9:15am PT) contains no policy focus. That does not mean nothing changed; it means Google did not say.
  • Google's spam policies documentation lists 16 categories. A spam update is about better detection of behaviour those policies already prohibit.
  • Some categories are rarely relevant to honest sites (cloaking, hacked content). Others are easy to drift into: scaled content, thin affiliation, site reputation abuse.
  • Naming no policy is not the same as "targeting everything". Treat it as "unknown", and audit by risk.
  • Site reputation abuse has a separate change in the EEA effective 30 August 2026, as reported; see post 339.
  • Fixing a violation is worth doing even if it was not your traffic drop's cause.

Is it unusual that Google named nothing?

Not really. Google's spam updates page describes them generically: notable improvements to its automated spam detection, with the advice that sites seeing a change should review the spam policies. It gives no per-update breakdown. Search Engine Land reports the September update is the fourth announced spam update of 2026, and the September announcement is similarly short.

Whether Google could be more transparent is a fair debate, but the practical point is that the policy list is the only public map you have. I would rather audit against it than guess at rumours.

The 16 categories, in plain language

The definitions below paraphrase Google's spam policies page as of 30 September 2026. Quoted phrases are from that page.

PolicyIn one lineRisk for honest small sites
CloakingShowing search engines different content than users, to manipulate rankingsLow, unless a dev/CDN misconfiguration
Doorway abuseMultiple pages or domains funnelling users to an intermediate pageMedium (near-duplicate location pages)
Expired domain abuseRepurposing expired domains with low-value contentLow to medium
Hacked contentContent placed on your site without permissionMedium (plugin vulnerabilities)
Hidden text and linksContent "not easily viewable" by humans, placed for search enginesLow
Keyword stuffingFilling pages with keywords or numbersLow to medium
Link spamLinks created mainly to manipulate rankings, including buying linksMedium (old vendor, sponsored posts)
Machine-generated trafficAutomated queries sent to Google without permissionLow, but rank-checkers matter
Malicious practicesMalware, unwanted software, back button hijackingLow
Misleading functionalityImplying a service you do not provideLow
Scaled content abuseMany pages made mainly to manipulate rankings, not help usersHigh for programmatic/AI-assisted sites
ScrapingCopying others' content without substantial added valueMedium
Site reputation abuseThird-party content published mainly to exploit the host's ranking signalsMedium (partner/coupon sections)
Sneaky redirectsSending users to different content than they requestedLow to medium
Thin affiliationAffiliate pages copied from merchants without original contentMedium
User-generated spamSpam added through comments, forums, profilesMedium

The "risk" column is my judgement from client work, not Google data.

Grid of sticky notes representing spam policy categories
Sorting the 16 policies by likelihood for your own site takes ten minutes and focuses the audit.

Grouping the 16 into four practical buckets

Bucket 1: technical deception

Cloaking, sneaky redirects, hidden text and links, misleading functionality. These usually involve deliberate implementation, or a bug. If you use dynamic rendering, geo-redirects or A/B testing tools, check what Googlebot sees using the URL Inspection tool's live test.

Bucket 2: content at scale

Scaled content abuse, doorway abuse, scraping, thin affiliation, keyword stuffing. This is where most honest-but-sloppy sites get into trouble. The question in Google's policy language is whether pages exist "for the primary purpose of manipulating search rankings and not helping users."

I keep a plain-English test for teams: for each page template, name the specific user need it serves that no other page on the site does. If you cannot, consolidate or add real substance.

Bucket 3: authority games

Link spam, expired domain abuse, site reputation abuse. These all involve borrowing authority: buying it, inheriting it, or renting your domain's to others. If you sell "guest posts" to anyone, run a sponsored section or host a partner's programmatic pages, review them now.

Bucket 4: security and abuse

Hacked content, malicious practices, user-generated spam, machine-generated traffic. Mostly hygiene: update plugins, moderate comments, lock down forms, and avoid automated scraping of Google results in violation of its terms.

What a "no policy named" update means for your audit

Because Google gave no hint, prioritise by exposure:

  1. Look at what changed on your site in the last year. New page templates, content batches, partnerships.
  2. Look at your biggest Search Console losers since 24 September (after the rollout ends) and ask which bucket they belong to.
  3. Sample, do not boil the ocean. Review 20 URLs per suspect group and read them as a stranger would.

A quick scoring method

For each page group score 0 to 2 on three questions: does it exist mainly for search, is the content mostly unoriginal, and does it rely on third-party authority or links? A group scoring 4 or more goes to the top of the fix list.

Where AI content fits

Google's scaled content abuse policy is about intent and value, not tools. A team using AI to draft, then adding real expertise, sources and editing, is in a different position from a site that publishes thousands of near-identical pages. I do not claim to know how Google's systems weigh this; I only note that the written policy targets the purpose, and I audit accordingly.

Editor reviewing printed article drafts with pen marks
Human editing and original substance are the difference between helpful content and scale for its own sake.
  • Site reputation abuse: as reported, a policy change in the European Economic Area took effect 30 August 2026. Details are in post 339. I have not verified the specifics against Google's primary announcement for this post, so check before acting.
  • Rank trackers: google.com/goto redirects, as reported, are rolling out and may affect scrapers. Machine-generated traffic is itself a listed policy, so use approved data sources where possible.

What to do if your audit finds something

Fix it, document it, and resist immediate claims of recovery. Google's documentation says improvement may follow as its systems learn over months that the site complies, and that for link spam, changes may not bring improvement because the value of those links is already discounted.

What I tell clients

Whatever the update named, the policies are the same ones you should have been meeting. When I worked on organic growth for Masai School, we made pages for real learner questions, and that discipline is the safest defence I know: if a page has an obvious human reason to exist, an update aimed at manipulation is far less likely to matter to it.

FAQ

Did Google name a policy for the September 2026 spam update?

No. Its status dashboard entry says the update applies globally and to all languages and may take up to two weeks, with no policy focus given.

How many spam policies does Google list?

Sixteen categories on its spam policies page as of 30 September 2026, from cloaking through user-generated spam.

Is scaled content abuse the same as AI content?

No. The policy addresses producing many pages mainly to manipulate rankings and not to help users, whether written by people, automation or both.

Which policy is easiest to violate accidentally?

In my experience, thin affiliation, near-duplicate location pages (doorway-like) and site reputation abuse via third-party sections. Hacked content is the other accidental one, through outdated plugins.

Only if you have a genuine link-spam problem you cannot remove. Google notes that spammy links' benefits may already be discounted, so disavowing is not a general cure.

Can user comments cause a spam problem?

Yes. User-generated spam is a listed category. Moderate comments, use nofollow or ugc attributes where appropriate, and remove spam.

How do I check for cloaking?

Use Search Console's URL Inspection live test to view what Googlebot sees, and compare it with what a normal browser sees. Investigate any difference that is not just personalisation you can explain.

Will fixing violations bring rankings back?

Possibly, over time. Google says improvement may follow as its systems learn over months that a site complies. There are no guarantees or set timeframes.

Where can I read the full policy?

On Google Search Central's spam policies page. Read the current version, since Google may revise it.

CTA

If you would like help mapping your site against these policies, I would be happy to talk. I have 4+ years of marketing experience in organic growth, SEO and content strategy for edtech and startup teams. See my work and reach me via the contact form at https://younusfardeen.in.

Verified as of 30 September 2026 against Google's spam policies page and Search Status Dashboard. Not legal advice.