“Negative SEO” usually means someone pointing junk links at your domain to try to hurt rankings. It is less common than people claim, and less effective than a real site compromise that injects spam. If you came here for Ahrefs disavow links help, start by separating external junk from on-site infection.
On WordPress, that split matters. A hacked site that manufactures its own spam pages will keep looking like “negative SEO” in Ahrefs until you clean the install.
Separate two problems
External junk backlinks. Weird domains linking to you with spam anchors. Investigate with Google Search Console and a backlink crawler such as Ahrefs (Majestic or similar also work). Document patterns. Many links can be ignored; Google already discounts obvious spam.
On-site spam or malware. Injected pages, hidden links, or redirects on your host. That is an incident, not a disavow file. Start with WordPress malware removal and SEO recovery after a hack. Signs checklist: signs your WordPress site is hacked.
If Search Console shows “Hacked content” or you see pharma/gambling pages on your domain, stop the disavow project and clean first.
How to disavow links in Ahrefs (and what Ahrefs does not do)
People search “how to disavow links in Ahrefs” because Ahrefs surfaces toxic backlinks clearly. The important detail: Ahrefs helps you find candidates. Google’s disavow tool is where you submit the file.
There is no “Ahrefs upload disavow file” button that talks to Google. Export from Ahrefs, edit the list, upload in Search Console.
Step-by-step workflow
- Confirm the site is clean. If Search Console shows hacked content or you see spam pages on your domain, clean that first. Disavowing while malware still manufactures links wastes time. Use a malware scanner and vulnerability scan on WordPress.
- Export suspicious linking domains from Ahrefs (Site Explorer → Backlinks / referring domains) or from Search Console links reports. Focus on clear spam networks and toxic backlinks you can explain, not every low-DR blog mention.
- Build a plain-text disavow list with lines like
domain:example.com for the worst confirmed spam networks. Prefer domain-level entries over endless URL lists when the whole site is junk.
- Submit the file via Google’s disavow tool for the correct Search Console property.
- Keep a copy of the list. Revisit only when new evidence appears. Do not rebuild the file weekly out of anxiety.
Domain vs URL lines (what Ahrefs users mix up)
Prefer domain: when the whole linking site is garbage. That is what most “difference in disavow URL or domains Ahrefs” searches are asking.
Example disavow file shape
# Toxic networks reviewed 2026-08-26
domain:obvious-spam-network.example
domain:another-pbn-dump.example
Save as UTF-8 plain text. Upload in Search Console under the property that matches the site (domain property vs URL-prefix property). Wrong property is a common silent miss.
How to spot toxic backlinks without panicking
Useful signals (combined, not one score alone):
- Sudden spikes of low-quality referring domains with matching spam anchors
- Foreign-language gibberish sites linking with money keywords
- Link graphs that look automated (thousands of near-identical domains in days)
- Ranking drops that line up with on-site spam in Search Console, not only new backlinks
Less useful:
- A single “toxic” score in a tool with no ranking loss
- Random directory links that have been there for years
- Competitor paranoia without evidence
When you should not bother disavowing
- A handful of random spam links with no ranking loss and a healthy site
- Links that look like normal directory or partner noise
- Anything you cannot explain as organized spam after a sober review
- Before the WordPress site is clean of injected spam
Chase malware and indexing issues harder than a vanity toxic score. Background: why website security matters for SEO.
WordPress hardening so the next mess is smaller
Link spam is annoying. A hacked site that manufactures its own spam is career-level painful.
- Keep core, plugins, and themes updated (checklist)
- Harden logins with 2FA and login protection
- Run scheduled malware and vulnerability checks
- Watch Search Console security messages
- Keep restore-tested backups
If cleanup keeps looping, hire help. Security Ninja Free covers tests and vulnerability checks; Pro adds firewall and malware scanning when you want active blocking. Free on WordPress.org or pricing.
Bottom line
Use Ahrefs to find toxic candidates. Use Google Search Console to disavow. Clean WordPress malware before you live in a disavow spreadsheet. Most “negative SEO” panic is either ignored junk or an on-site infection wearing a backlink costume.