
If you run a website with any real authority, open your backlink report and you will eventually find a wall of ugly, spammy domains you never asked for. Most of it is harmless. A small part of it is an actual attack. This article shows you how to tell the two apart in about 30 seconds, then what to do about each, using a real coordinated attack we caught pointing 99 junk domains at dennisyu.com in a single month.
Who this is for: business owners, agency operators, and anyone running a personal-brand or local-service site who has seen scary backlinks in Ahrefs or Google Search Console and wondered whether to panic. The short version is freeing: you can safely ignore almost all of it, and the small part you cannot ignore has a calm, specific response. Read on and you will never lose an afternoon to spam links again.
Separate the noise from the attack
Ninety percent of the “toxic” links in any established profile fall into two harmless buckets. Learn to recognize them and the real signal jumps out.
Bucket one: background noise. Every site that has existed for a few years collects junk automatically. Scraper directories, coupon sites, and throwaway domains copy your listing without asking. On dennisyu.com these go back to 2013 and include domains like prolinksdirectory.com, globalseodirectory.com, and a wave of near-empty .pw domains. It accumulated slowly, from all over the world, for a decade. It never moved the rankings, and Google never acted on it.
Bucket two: link sellers advertising themselves. Some spam is just a sales pitch. You can read the intent right in the domain name: buy-quality-backlinks, 99backlinksbuy.com, topratedbacklinks.com, buytopqualitybacklinks.com. These are vendors dropping a link so their own brand shows up in your report, hoping you will panic and buy their “cleanup” service. They are annoying, not dangerous. Do not buy anything.
See the real attack we caught
Here is what bucket three looks like with the numbers attached. Starting on June 21, 2026, a network began dropping links on dennisyu.com at a rate of several per day and did not stop. By July 19 it had added 99 fresh junk domains, peaking at nine in a single day.

The domains share a fingerprint. They live on disposable .store and .shop extensions, carry keyword-stuffed names, and each drops exactly one link. Here is a real sample straight from the report, with the exact timestamps:
| Referring domain | Ahrefs DR | First seen (UTC) |
|---|---|---|
| editorial-link-outreach-pro-and-high-da-systems.store | 22 | Jul 19, 22:54 |
| outrank-hq-legendary-white-hat.store | 34 | Jul 19, 04:30 |
| do-follow-traffic-surge-and-link-velocity-syndicate.store | 23 | Jul 18, 10:15 |
| grand-link-baron-league.store | 34 | Jul 16, 22:20 |
| link-baron-innovative-press-release-house.store | 34 | Jul 13, 00:52 |
| seoexpress-niche-edit-group.store | 34 | Jul 07, 22:01 |
See how the network is built
Behind the burst sits a simple, cheap machine. Someone registers hundreds of disposable domains in bulk, spins up thin auto-generated pages, and scatters your URL across footers, sidebars, and fake directory listings.
Notice the DR column above. Several of these sit in the low 30s, which is a deliberate trick. The operator inflates a vanity metric so the link looks respectable at a glance in a tool. Underneath, the pages have no readers, no real content, and no reason to link to you.
Understand what it actually does to your rankings
This is where most advice gets it wrong. Google has devalued rather than punished spammy links since the Penguin 4.0 update in 2016, and its SpamBrain system now neutralizes manipulative link patterns automatically, at scale.
In plain terms, Google ignores most of this junk before it ever touches your rankings. It rarely penalizes a clean-history site for links it never built, because it weighs intent and the real authority signals behind a well-built entity and E-E-A-T, not just the raw link pattern.
Google’s own Search Advocate, John Mueller, put the tool in its place this way: “The disavow file is a tool, not a religion. Most sites don’t need it, but that’s not all sites.”
So do not panic-disavow, and do not pay anyone who tells you to. Watch for real impact instead of reacting to a scary-looking chart.
Detect it with the right monitoring
You cannot defend what you cannot see, so the first move is simple visibility. Pull your referring domains in a backlink tool, filter for the spam flag, and sort by the date each link first appeared.
That single view surfaces an attack immediately: a wall of same-shaped domains, all first seen within days of each other, exactly like the chart above. Track the rate of new toxic domains week over week so you know whether the campaign is growing or fading.
Pair that with two free signals. Check Google Search Console for any manual-action warning, and watch your organic traffic for a real, sustained drop. If both stay quiet, the attack is noise, not damage.
Respond without overreacting
Match your response to the evidence. For a concentrated, obvious attack like this one, a disavow file is reasonable insurance, especially if you are uncertain about your link history or want a clean paper trail. We built one for both properties and keep it on hand as insurance.
Build the file by listing the bad sources one per line at the domain level, then upload it once in the Google Search Console disavow tool for each property. If Search Console rejects the upload because your site is a Domain property, here is the two-minute fix. Keep it updated as new junk arrives, and re-upload on a schedule rather than chasing every single domain by hand.
Reserve the disavow for three situations: a confirmed manual penalty, a real history of paid or manipulative links, or a concentrated spam pattern where you are genuinely unsure. Outside of those, monitoring beats reflexive action every time. If the attack is paired with fake reviews or a smear, that is a different fight, and we walk through it in the anatomy of a smear campaign and in how AI defends your reputation.
Harden the target, not just the links
Backlink spam rarely travels alone. The same people probing your reputation often probe your website, so an attack on your links is a good prompt to lock down the site itself. This is not theoretical for us either. Wordfence blocked login attacks on this domain from Iran, Bulgaria, and India in the same week the backlinks spiked.
The most important lesson we learned the hard way: update the components bundled inside other plugins. A standalone plugin auto-updates, but a copy of it packaged inside a custom plugin does not, and it quietly goes stale. An outdated bundled copy of one popular field plugin was the exact hole an attacker used to inject a hidden admin on one of our sites. The standalone version now sits patched and current; the bundled copy is the one you have to check by hand.
Then do the basics that stop most WordPress compromises. Review your administrator accounts and remove anyone you do not recognize, because an unexpected admin is how most break-ins begin. Turn on two-factor authentication for every admin, rotate passwords, enable auto-updates, and keep a malware scanner running with alerts routed to an inbox someone actually reads. Strong links protect your rankings; a hardened site protects everything behind them.
Protect your search presence the calm way
A coordinated spam attack is built to make you flinch. The professional move is to sort the noise from the real signal, disavow as insurance when the evidence calls for it, and harden the site so the next probe finds nothing open. If your published work names names the way ours does, expect to make enemies, and expect some of them to try this. It still does not work.
This is the kind of brand-defense work we run across the Spotlight network of local-service sites and for the clients whose websites we manage. Want the same backlink-and-security check on your own site? Get a quick audit — the exact review our agents run, powered by the skill files on our Content Factory floor.

