Most SEOs still mentally model link penalties as a manual action workflow: someone at Google reviews your site, sends a message in Search Console, and you file a reconsideration request. That model was roughly accurate until 2022. It is not accurate now.
SpamBrain — Google’s AI-based spam detection system, first deployed around 2018 but significantly expanded in 2022 and again in 2024 — doesn’t flag your site for human review in most cases. It adjusts the weight assigned to individual links algorithmically, often before those links have passed meaningful equity anyway. The manual action is increasingly a last resort for the clearest cases of manipulative link networks, not the primary enforcement mechanism.
What SpamBrain Actually Classifies
SpamBrain operates as a multi-class classifier, not a binary spam/not-spam filter. Google has confirmed it can detect sites that are used to buy links and sites that pass links to third parties — both sides of a paid link transaction simultaneously. That’s the part most link builders underestimate.
The signals it draws on include link velocity patterns relative to site age and topical history, the linking site’s own spam score, anchor text distribution anomalies across the receiving domain’s full link profile, and co-citation patterns — whether sites that link to you also tend to link to a cluster of other sites with similar spam characteristics. None of these are novel ideas. What changed is the scale and the speed at which they’re evaluated.
One concrete implication: buying ten links from ten different “niche relevant” sites that happen to be part of the same private blog network does not produce ten independent signals. SpamBrain’s graph-level analysis groups those sites together before your domain even enters the picture. The equity from those links doesn’t get neutralized after the fact; it never really accumulates.
Why the Disavow File Is Less Useful Than It Used to Be
Here’s something that cuts against a lot of standard advice: for most sites, spending significant time building and maintaining a disavow file is lower ROI than it was five years ago. Not zero ROI. Lower.
SpamBrain is already discounting links it classifies as manipulative. If it’s doing that correctly, disavowing those same links adds nothing — you’re disavowing equity Google wasn’t passing anyway. The residual case where disavow still matters is a manual action triggered by links SpamBrain missed, or a profile so aggressively toxic that even partially-discounted links are dragging your domain-level quality score down. Both exist, but they’re edge cases relative to the volume of routine “bad link” panics you see in SEO forums.
The more important intervention is upstream: stop acquiring links that pattern-match to what SpamBrain is trained on. Which means understanding the features it’s likely using.
The Features That Actually Pattern-Match to Spam
Google hasn’t published SpamBrain’s feature set. But between Gary Illyes’ conference talks, the 2022 link spam update documentation, and watching what actually survived the March 2024 and August 2024 core updates, a few patterns are clear enough to act on.
Anchor Text Mismatch at Scale
Exact-match commercial anchors pointing to a page that isn’t the most authoritative result for that query — from sites with no organic reason to use that specific phrase — read as engineered. The issue isn’t using exact-match anchors ever. It’s having a distribution where commercial exact-match anchors are proportionally high relative to brand, naked URL, and natural phrase anchors. SpamBrain doesn’t look at one link; it looks at what the full profile distribution implies about whether the links were acquired naturally.
Velocity Spikes Without Corresponding Authority Events
A site that earns 200 links in a month because a study it published went viral has a velocity spike with a corresponding event. A site that earns 200 links in a month from guest posts and paid placements doesn’t — and the pattern of where those links come from (similar DA ranges, similar content templates, similar anchor text) compounds the signal. SpamBrain’s graph analysis clusters those sources even if you thought you were diversifying.
Linking Site Topical Incoherence
A link from a site that covers twelve unrelated verticals — travel, finance, pets, home improvement, cryptocurrency — to a SaaS tool for SEO practitioners is topically incoherent. These sites exist specifically to sell links. Google has said since at least 2012 that PageRank flows through topically related sites more effectively, and SpamBrain operationalizes this by treating topically incoherent linking sites as higher-probability spam sources regardless of their raw authority metrics.
What This Changes About Link Acquisition Strategy
Link building in 2026 needs to be evaluated against what survives SpamBrain’s classification, not what shows up in Ahrefs. Those are not the same list.
Links more likely to survive: editorial links from sites where the surrounding content is topically adjacent to yours, where the anchor text is a natural phrase rather than a target keyword, and where the linking site has genuine traffic and engagement signals. The bar for “genuine” is whether Google’s own quality classifiers — which feed into SpamBrain’s source scoring — would rate the site as a real publication. A blog with five posts all published on the same day in 2024, no bylines, and no author history is not a real publication regardless of its domain authority score.
Higher risk than most people price in: links from sites in link marketplaces even when labeled “editorial,” links from sites with template-based content, and links acquired through systematic guest post outreach at scale where the content is interchangeable. The last one is where I see the most rationalization — “we’re adding real value with the content” — but SpamBrain is evaluating the network-level pattern, not the content quality of any individual post.
Manual Actions Still Exist. Here’s When They Actually Happen.
Manual actions for unnatural links are now largely reserved for cases where the manipulation is overt enough that algorithmic adjustment isn’t sufficient — or where a competitor or third party flags the site and a human reviewer confirms the pattern. Large-scale private blog networks operated by the same entity sometimes still trigger manual actions, particularly when ownership signals are obvious. But the idea that you’ll get a Search Console warning before your rankings move is backwards. The ranking adjustment typically comes first, from SpamBrain, and the manual action (if it happens at all) comes later.
If you’re auditing a link profile and using the presence or absence of manual actions as your primary risk signal, you’re looking at the wrong thing.
One Thing Worth Testing
Pull your referring domain list and segment it by linking site topical relevance to your core subject matter — not just domain authority. Check what percentage of your linked-to pages are receiving exact-match commercial anchors from sites in unrelated verticals. If that percentage is high and your rankings have plateaued despite a growing link count, SpamBrain discounting is a more likely explanation than the content or technical issues most audits default to examining first.
The disavow file is not the fix. The mechanism behind why bad links don’t work anymore — graph-level classification running before equity flows — is the thing worth sitting with. It changes where the work should actually go.
