SEO Hosting and Google’s AI Spam Updates: What Actually Got Penalized vs What Got Spared
SEO hosting does not cause Google penalties by itself. Google’s spam systems, including its AI based SpamBrain, go after manipulative behavior: mass produced low value pages, link spam, abused expired domains and borrowed site reputation. Where a site is hosted, or whether it shares an IP address with others, is not on that list. On May 15, 2026, Google also clarified that its spam policies apply to generative AI responses in Search, but it described that as a clarification, not a new set of rules.
We have run hosting for more than 20 years and hosted over 700,000 websites, including multiple IP hosting for people who run many sites. Here is the part that surprises people. We do not sell that product as a shield. A different IP address does not change what a page says or who links to it, so it cannot rescue a thin site, and a shared IP will not sink a good one.
A note on method. Google does not publish lists of sites it demoted or spared, so we name none, and you should be wary of anyone who does without before and after data. Everything below rests on Google’s own documentation and statements from its staff, linked as we go. Where something is our judgment, we say so.
What Did Google’s Recent AI and Spam Systems Actually Target?
They targeted behavior, not infrastructure. Google’s spam policies name specific practices, including scaled content abuse, link spam, expired domain abuse and site reputation abuse. Google’s own guidance says generative AI can help with research and structure, and treats it as a problem when it is used to generate many pages without adding value. In 2026 the change was one of scope. The same rules now explicitly cover AI answers.
Scaled content abuse
Scaled content abuse means producing many pages mainly to manipulate rankings instead of helping the people who land on them. Google introduced the name on March 5, 2024, alongside two other new policies, and it widened the older rule against spammy automatically generated content. The announcement made a point that matters today: whether content is made purely by automation is not always clear, so the policy looks at purpose.
The policy lists examples. They include using generative AI tools to produce many pages without value, scraping and reshuffling other sites’ content, stitching pages together without adding anything and creating multiple sites to hide how much content is being scaled. There is no page count that triggers it. A site with thousands of genuinely useful pages is not automatically abusing anything, while fifty near identical pages can be.
Low-value AI-generated content
Google’s guidance on generative AI content is plain about this. AI is useful for researching a topic and adding structure to original work. Using it to generate many pages without adding value for users may violate the scaled content abuse policy. The guidance asks you to focus on accuracy, quality and relevance, and suggests explaining how automation was used where that helps readers.
In practice, the pattern that reads as low value is easy to describe. The same template repeated across hundreds of pages. Claims nobody checked. No first hand information, no data, no experience, only a rewrite of what already ranks. AI is not the issue in any of those. The absence of anything new is.
Link spam and ranking manipulation
Google’s link spam policy covers links made mainly to pass ranking credit instead of helping readers. That includes buying or selling links, large scale link exchanges, automated link creation and keyword stuffed links hidden in footers. It applies to links between sites you own just as it does to links from strangers.
Link spam is also handled somewhat separately from the content focused spam updates. Search Engine Roundtable noted that the September 2026 spam update is not aimed at link spam, although Google has not said what that update does target. The takeaway is not that links are safe. It is that you cannot read one update’s date as a verdict on every policy.
Site reputation abuse
Site reputation abuse is third party content published on a trusted site mainly to borrow that site’s ranking strength. Think of a review or coupon section written by an outside company, with little oversight from the host. Google announced the policy in 2024 and enforces it mostly through manual actions.
One recent change deserves attention. On August 28, 2026, Google announced that from August 30 a manual action under this policy affects search results outside the European Economic Area but not inside it. The policy itself remains. For SEO hosting users the lesson is narrow. The policy matters if you publish other people’s content on your domain for ranking. Otherwise it is not your risk.
Expired domain abuse
Expired domain abuse is buying an expired domain and repurposing it mainly to manipulate rankings by hosting content that gives users little or no value. The goal is to ride the old name’s reputation. Google says plainly that using an old domain for a new, original site designed to serve people first is fine.
That line is the whole test, and it comes down to intent. A domain that once ran a gardening blog and now runs a thin page network about unrelated loans looks like abuse. A domain bought because the name fits a real new project does not. If you buy aged domains, be honest with yourself about which of those two you are doing.
Spam practices across traditional and AI-powered Search
On May 15, 2026, Google updated the opening of its spam policies. The definition of spam now includes attempts to manipulate generative AI responses in Google Search, and Google’s changelog says the reason was to make clear the policies cover all of Search, including AI Overviews and AI Mode. As far as we can see, Google did not publish a separate AI spam checklist. The existing policies are the guide.
Separately, Google has released four spam updates in 2026 so far: March, June, August and September. The September update began on September 24 and Google said it could take up to two weeks. Google has not said which policies it targets, so check the dashboard for whether it has finished. Spam updates improve the automated systems that detect spam. They are not new rules.
Does Using SEO Hosting Automatically Put a Website at Risk?
No. Google’s published policies describe behavior, and none of them says a site is spam because of its host or its IP address. Google’s John Mueller has said several times over the years that sharing an IP address is common and not a problem for Search. The risk comes from what the sites do, such as thin duplicate content, manipulative links or networks that behave like doorways.
Hosting infrastructure versus website behavior
Think of two layers. The hosting layer decides whether your pages load, how fast and from where. The website layer decides what the pages say, who links to them and why they exist. Google’s spam policies are written almost entirely about the second layer.
That does not make hosting irrelevant. A server that is down for days stops Google from crawling your pages. A hacked server can fill your site with spam content, and hacked content is itself a spam category. So infrastructure matters through reliability and security, not through a hidden penalty for the kind of plan you bought.
Shared and dedicated IP addresses
When a site owner worried about traffic loss across sites on one IP, Mueller’s answer, reported by Search Engine Journal, was that the same IP address is really not a problem. He pointed to similar content as the more likely issue. In a separate exchange he disputed a study claiming shared IPs ranked worse, saying he knew of no algorithm that weighs other sites on the same server.
A dedicated IP has real uses. It gives you your own email sending reputation, simpler firewall rules and isolation from a neighbor’s blocklisting. Those are operational benefits. If you want your own resources, a VPS or a dedicated server is the natural step. Just do not buy one expecting a ranking boost, because nothing in Google’s documentation promises it.
Multiple websites on related infrastructure
Running several sites on related infrastructure is normal. Agencies do it, publishers do it, and so do ordinary businesses with more than one brand. What draws attention is what the sites look like next to each other. Mueller’s point was that near identical sites funnelling visitors to the same product can look like a collection of doorway sites.
Google’s scaled content abuse policy goes further. It lists creating multiple sites with the intent of hiding the scaled nature of the content. Notice what both rules turn on. It is similarity and purpose. A useful test is simple. If the other sites vanished tomorrow, would this one still make sense to a visitor? If yes, you are probably fine. If it only exists to feed the others, different IPs will not change that.
Server location and hosting configuration
We cannot point to any Google policy that treats server location as a spam signal. What location does affect is speed for your visitors, and speed is a user experience matter, not a spam matter. A site serving customers in Singapore from a distant server is slower for them. That is a good reason to pick a closer location.
We run 25 server locations worldwide, and the choice between them is usually about audience, not about search tricks. For people who need to place different sites in different regions, multi location hosting exists for that reason. Configuration matters in the same practical way. Correct redirects, working HTTPS and stable DNS are boring, and they are the things that actually keep Google able to reach you.
What Google actually evaluates beyond the IP address
Google’s documentation points at pages, links and how a domain is used. It looks at whether content is original and useful, whether links are earned or placed to manipulate, whether a domain’s old reputation is being exploited and who is publishing what on a host. Automated systems like SpamBrain look for those patterns at scale, and human reviewers can apply manual actions.
Search Essentials, Google’s baseline for every site, adds the technical side: pages must be crawlable and indexable. None of this needs your IP address to work. So when you diagnose a problem, start with the page and link layers. The IP is rarely where the answer is.
Why infrastructure alone should not be treated as proof of spam
Treating a shared IP as proof of spam would flag a huge share of the legitimate web. Shared hosting, CDN services and platforms like Blogger all put many unrelated sites on the same addresses. Mueller made that exact argument. Some Blogger sites rank terribly and others do very well on identical infrastructure.
There is an honest limit to our own argument. Infrastructure can still be a clue during an investigation. If several sites on one server dropped together, a hack or an outage is worth ruling out first. But a clue is not proof. Calling a site spam because of its neighbors gets the logic backwards, and Google’s own statements say its systems do not work that way.
Which SEO Practices Were More Likely to Get Hit by Google’s Spam Systems?
The practices that match Google’s named policies: mass produced low value content, automated content made mainly to rank, manipulative link building, expired domains reused for unrelated ranking plays, third party content published to exploit a host’s reputation, and sites created mainly to manipulate Search. We cannot hand you a list of named sites that were hit, because Google does not publish one. We can show you what the documentation describes.
Mass-produced low-value content
The classic example is the templated page set. Take one article, swap a city name or product name, and publish 400 versions. The pages exist to catch searches, not to help anyone who lands on them, and that is the pattern the scaled content policy was written for.
Be fair to templates, though. A set of location pages can be legitimate if each one carries real, specific information: actual addresses, local prices, staff, photos. The test is whether a visitor from one city would get the same page as a visitor from another. If the only difference is the word in the title, expect trouble.
Automated content created primarily for rankings
Automation by itself is not forbidden. Google’s guidance accepts AI as a tool for research and structure. What puts a site at risk is a pipeline that generates pages, publishes them without a human check and exists mainly to rank. Think unreviewed output, invented facts and keyword stuffed text that reads fine to a machine and badly to a person.
An AI assisted workflow can land on either side of the line. A writer who uses a model to draft, then adds original testing, corrects errors and removes padding, is making a page for people. A script that pushes 200 untouched drafts a day is not. The tool is the same. The purpose and the editing are different.
Manipulative link building
Link spam covers links built mainly to pass ranking credit. Buying them, swapping them at scale, generating them with software and loading footers with keyword anchors are all in that family. Networks of sites that exist mainly to link to one another to pass credit are a link scheme too.
This is where the hosting question gets a firm answer. If a network of sites links to itself to manipulate rankings, putting the sites on different IP addresses does not make the links natural. The link pattern is what gets evaluated. We say this clearly because it is the misconception we most want to correct. Multiple IPs are an operations tool, not a way to hide a relationship.
Expired domains reused for unrelated ranking manipulation
The risky version is specific. Someone buys a domain because it has backlinks, then puts unrelated, thin content on it to inherit that reputation. Google calls that expired domain abuse. It is also a practice that tends to be spotted quickly, because the topic of the old links and the topic of the new content do not match.
If you do buy an aged domain, ask three plain questions before you publish. Does the new site fit the old domain’s topic? Is the content original and useful? Would you still want this site if the domain had no backlinks at all? Three yeses make it a normal project. Any no is a warning.
Third-party content published to exploit site reputation
This one catches businesses by surprise, because it often starts with a good intention. A trusted site opens a section for an outside company’s reviews, coupons or comparison pages, takes a fee and gives the content little editorial oversight. The section then ranks because of the host’s reputation, not its own merit.
Google’s policy focuses on content produced with little or no oversight by the host. Content the host closely edits and stands behind is treated differently. If you run partner sections or guest hubs, a clear editorial process is your protection. It is cheaper than recovering a section after a manual action.
Multiple sites created primarily to manipulate Search
Creating many sites with the same content or the same funnel is covered twice. The scaled content policy lists creating multiple sites to hide scaled content, and Mueller’s doorway comment shows the same instinct: a collection of near duplicates all pushing visitors to one destination. Spreading the sites across hosts and IPs is exactly the behavior those rules anticipate.
Ask one question of any network you run: what would a visitor lose if a sibling site disappeared? If the honest answer is nothing, the sites are doing real work. If the answer is that the other sites would lose their traffic, you have built a funnel. The table below sums up this section. Notice the final column, because it is the point of the article.
| Practice | Google policy | Does hosting setup change the verdict? |
| Mass produced pages | Scaled content abuse | No. Similar pages stay similar on any IP. |
| Automated content for ranking | Scaled content abuse | No. The editing and purpose decide. |
| Links to pass ranking credit | Link spam | No. The link pattern is evaluated. |
| Expired domain for thin content | Expired domain abuse | No. Intent and topic mismatch decide. |
| Outside content on a trusted host | Site reputation abuse | No. Oversight decides. |
| Many sites built to funnel visitors | Scaled content abuse, doorway abuse | No. Splitting IPs does not remove similarity. |
What Types of SEO Hosting Websites Can Remain Unaffected?
Sites with genuinely useful pages and a setup that serves a real purpose. Google does not publish a list of sites it spared, so we cannot name any. What we can say is that nothing in the policies penalizes independent sites, real business portfolios, agencies hosting client sites or AI assisted content with real added value, and a hosting arrangement alone does not change that.
Independent websites with genuinely useful content
A single site with original, useful pages is the baseline case. It can sit on ordinary shared web hosting and nothing in Google’s policies treats that as a problem. The things that protect it are the pages themselves: accurate, specific and written for someone with a real question.
One honest caution. Staying clear of the policies does not guarantee stability. Search Engine Roundtable’s report on the September update notes that any update can cause collateral movement. If a good site dips, treat it as a signal to investigate, not as proof of a violation, and not as proof that you are safe either.
Legitimate multi-site business portfolios
Plenty of real businesses run several websites. A company might have one site per brand, per country or per product line, each with its own audience, its own content and its own customers. Nothing about that is manipulation.
What keeps it legitimate is that each site earns its place. Different products, different copy, different reasons to exist. The moment the sites become near copies of each other, or the only purpose of one is to link to another, the portfolio starts to look like the doorway pattern Mueller described. Ask whether you would still run each site if search engines did not exist.
Agencies managing separate client websites
An agency hosting forty client sites is running forty separate businesses. Each has its own owner, content and audience. Hosting them in one account, or spreading them over several IPs, is an operations decision. If you bill and manage clients through reseller hosting with WHMCS, that is simply how the job works.
The risk for agencies is not the hosting. It is shared tactics. If the same article template, the same link source or the same AI pipeline runs across every client, the sites can start to resemble a network. Keep each client’s strategy specific to that client, and your portfolio looks like what it is.
Websites using AI-assisted content with human-added value
Google’s guidance does not ban AI content. It says generative AI can help with research and structure, and it asks that the work meet its spam policies and Search Essentials. So the practical question is what a human adds. Original testing, firsthand experience, checked facts and a clear point of view are the usual answers.
Where it helps readers, say how automation was used. Google suggests that for content that is automatically generated. A simple review step also helps: one person reads every page, fixes errors and deletes anything padded before it goes live. That step is dull, and it is what separates an assisted page from an automated one.
Sites using multiple hosting environments for legitimate operational reasons
There are many ordinary reasons to use more than one server or IP. A staging copy, a CDN in front of production, a second region for faster delivery, failover for uptime, or a separate address for sending email so one site’s mailing does not hurt another’s reputation.
That last one is a good example of an operational use. Email reputation is tied to sending IPs, which is why a service like MailChannels corporate email matters for deliverability. None of these setups says anything to Google’s spam systems. They are engineering choices, and they stay engineering choices as long as the content on top is honest.
Websites following Google’s Search Essentials
Search Essentials is Google’s baseline: the technical requirements, the spam policies and the key best practices. A site that meets them is eligible to appear in Search. Google does not promise a particular ranking, and nobody can honestly promise that for it.
That is a useful way to read this whole article. Follow the essentials, stay inside the spam policies and your hosting setup is not the thing that decides your fate. If a drop does happen, you will at least know that you did the checkable things right, and that narrows the search for the cause.
How Can You Tell Whether a Ranking Drop Came From Spam or Hosting?
Work through the evidence in order. Check Search Console for a manual action or security issue, match the drop date to Google’s update dates, compare which pages and queries lost visibility, review your own content and link changes, and rule out server problems. If sites on the same server moved together, suspect infrastructure. If only the thin or manipulated sites moved, suspect content and links.
Checking Google Search Console
Start with the Performance report. Compare a period before the drop with an equal period after it, and use the same days of the week. Look at impressions, clicks and average position separately. They tell different stories.
If impressions and positions held but clicks fell, the cause may be how results are displayed, not a demotion. AI answers on the results page can change click behavior without changing where you rank. If impressions and positions both fell, a ranking change is more likely. Then check the date against the Search Status Dashboard to see whether a spam update was rolling out.
Reviewing manual actions and security issues
Open the Manual actions report. If a human reviewer applied an action, Search Console tells you, names the problem and lets you request reconsideration after you fix it. Then open the Security issues report, because hacked content falls under the spam policies too.
An empty report is useful but not conclusive. Google does not send a notice for algorithmic demotions, which come from automated systems like SpamBrain. So no manual action means the cause is either algorithmic or unrelated to spam. It does not mean the site is clean. If the report shows an action, read the description closely, because it names the policy and often the affected section, and that narrows your fix list immediately.
Comparing affected pages and queries
Export the pages and queries that lost the most visibility, then group them. Did the losses concentrate in one template, one folder or one batch published around the same time? A concentrated drop in a templated section points toward scaled content. A broad drop across everything, including brand searches, looks more like a technical or demand problem.
Look at the winners as well. Pages that held or gained on the same site are your best comparison. If they share traits that the losers lack, such as original data or real author detail, that tells you what Google’s systems may be rewarding. It is a hint, and you should treat it as one.
Checking content and link changes
Build a change log. When did you publish in bulk? When did a template change? When did an AI pipeline go live, or a link campaign start? A drop that follows a batch of 300 new pages by three weeks is a different case from a drop with no changes before it.
Check backlinks for sudden growth in the same period, especially from sites you own or from pages with keyword heavy anchors. You will not always find a smoking gun. When you do, write it down with dates, because it will matter if you later ask for reconsideration.
Reviewing server availability and technical errors
Open the Crawl Stats report in Search Console and check host status: whether Google could fetch your robots.txt, resolve your DNS and connect to your server. Look at the share of 5xx responses and average response time around the drop. Then compare with your own uptime monitor and server logs.
If outages lasted days, crawling can fall off and visibility with it. Short blips usually matter far less. Reliability and backups are the unglamorous side of hosting, and they are why we publish a comparison of reseller features covering security and uptime. A site that is always reachable removes one whole class of explanation.
Separating correlation from causation
Timing alone proves little. The September update may take up to two weeks, and Mueller said it was likely to take longer than earlier ones, so volatility inside that window is hard to pin on one cause. Rankings also moved before the announcement. Be careful about blaming a rollout for a drop that began earlier.
Run one test that helps. Look at unrelated, healthy sites on the same server or IP. If hosting were the cause, they should have moved with the problem site. If they did not, the cause lives in the affected site. This is a hint and not a proof, and you may never get certainty, because Google does not explain algorithmic decisions. Aim for the most likely cause, and fix that.
How Should SEO Hosting Users Adapt to Google’s AI-Driven Search Environment?
Build around user value. Publish original, useful pages, audit anything made at scale before it goes live, link only where an editor would, watch each site on its own and treat hosting as a reliability tool. That advice is the same for AI Overviews and AI Mode as for ordinary results, because Google says the same spam policies apply to both.
Prioritizing original and useful content
Add one thing to every page that does not exist anywhere else. Your own test results. A screenshot from your own setup. A number from your own data. A quote from a person who did the work. AI systems summarize what already exists, so original material is what gives a page a reason to be cited or clicked.
This is also the cheapest protection against the spam policies. A page with first hand information is very hard to mistake for mass produced filler. If you cannot say what a page adds, it probably should not be published.
Auditing scaled content before publication
If you publish at scale, add a gate. Read a sample of every batch, not only the best pages. Compare pages side by side for near duplicate passages. Check names, dates, prices and claims against a source. Reject anything that you would not defend to a customer.
Keep a record of what you reviewed and who approved it. If a batch fails the check, improve it or leave it out. Publishing weak pages and hoping nobody notices is the pattern the policy describes, and it is far cheaper to hold a batch back than to repair a whole section later.
Maintaining natural and editorially justified linking
Use a simple rule. Would you place this link if search engines did not exist? If the answer is yes, because it helps a reader, it is editorially justified. If the only reason is to pass strength, it is the kind of link Google’s policy targets.
That includes links between your own sites. Cross linking can be useful when the sites are truly related and the link helps a visitor. Sitewide footer links with keyword anchors across a dozen domains do not. When in doubt, remove the link and see if anything is lost for the reader.
Monitoring multiple websites independently
Give every site its own Search Console property, its own analytics view and its own uptime monitor. Treating a portfolio as one blob hides the signal. If one site drops and nine hold, you know where to look. If all ten drop together, you know to check shared causes like a server or a template.
Set alerts for sudden changes in clicks, indexed pages and server errors. Keep your change log per site. This is the same evidence you need for diagnosing a ranking drop, and it costs very little to keep while things are going well.
Using hosting infrastructure for reliability rather than ranking manipulation
Here is what multiple IP hosting is honestly good for. Isolating sites so one neighbor’s blocklisting does not touch the others. Keeping separate sending reputations for email. Giving each project its own address for firewall and monitoring rules. Placing sites close to their visitors. All of that is about reliability and control.
What it is not good for is hiding relationships or rescuing weak pages. Google evaluates pages, links and purpose, and no IP address changes those. If a vendor promises ranking power from IP diversity alone, treat that promise with suspicion, including ours if we ever made it. We do not.
Building SEO strategies around user value and search intent
Start from the question behind each query. Simple factual queries may be answered directly on the results page, so a page that only restates a fact has less to offer. Pages that earn the click tend to offer depth, a decision aid, original data or a tool.
Measure what matters to the business, not just impressions. Track conversions, leads and returning visitors, because visibility can shift while value holds. Build for the person with the problem, keep the policies in view and let the hosting do its quiet job. One practical habit helps here. Review your top ten pages every quarter and ask what a visitor can do or learn there that an AI summary cannot give them. Strengthen the weakest answer first.
If you run several sites and want separate IP addresses for isolation, email reputation or monitoring, see our multiple IP SEO hosting. Use it for reliability and control, and keep the ranking work where it belongs, in the pages.