Skip to main content
Skip to main content
All posts

Google made back button hijacking a spam violation. Check your funnel.

On April 13, 2026 Google gave site owners two months of warning before enforcement. Aggressive conversion tactics your agency installed years ago may now be a demotion risk.

Andrew Bethel avatarAndrew BethelApr 21, 20265 min read

Growth teams inherit tactics. Somebody installed an exit-intent stack in 2021, it lifted a conversion rate by a fraction of a point, and nobody has looked at it since.

It is time to look.

The policy#

On April 13, 2026, Google expanded its spam policies to make "back button hijacking" an explicit violation of the malicious practices policy.

Google's definition: it occurs when a site interferes with browser navigation and prevents a user from using the back button to immediately return to where they came from. Instead, "users might be sent to pages they never visited before, be presented with unsolicited recommendations or ads, or are otherwise just prevented from normally browsing the web."

The consequence is stated plainly: pages doing this "may be subject to manual spam actions or automated demotions." Google published the policy two months in advance of enforcement to give owners time to fix it.

Google also noted this was never allowed — inserting deceptive pages into browser history has always violated Search Essentials. What changed is that it is now named, and Google says it has "seen a rise" in the behavior.

Why a marketing company is writing about a spam policy#

Because this one hides inside the conversion stack, not the SEO stack. The usual suspects:

  • History-injection scripts that push an interstitial when back is pressed
  • "Wait, don't go!" offer pages that replace the previous page in history
  • Funnel builders and landing-page platforms with a back-button-offer feature enabled by default
  • Third-party retention or survey widgets that manipulate history.pushState
  • Legacy affiliate or quiz funnels nobody owns anymore

None of these are labeled "spam" in the vendor UI. They are labeled "exit recovery."

"Inherited tactics need an owner and a review date, or you hear about them from a demotion."

Andrew Bethel — COO, Perfectus Labs

The compounding risk#

A demotion here is not just a lost ranking. In an answer-engine world, demotion is disqualification: models draw disproportionately from sources that search systems already trust. A manual action against your domain removes you from the pool that gets summarized, cited, and recommended.

You are risking your entire AI-answer presence to recover a small percentage of abandoning traffic. That trade was never good. It is now clearly bad.

What to do this week#

  1. Inventory it. Ask your web team and every landing-page vendor a direct question: does anything on our domain modify browser history or intercept the back button? Get it in writing.
  2. Test it manually. Open your top ten landing pages from a search result, press back, and confirm you land exactly where you started. Test mobile separately.
  3. Kill it, do not tune it. There is no compliant version of preventing a user from leaving.
  4. Replace the intent. If exit recovery was earning real revenue, rebuild it with methods Google is not policing: faster pages, a genuinely useful offer above the fold, follow-up email, and remarketing.

Our position#

Perfectus Labs does not ship dark patterns, and BookedSolid does not include them. Not because we are pious about it, but because conversion tactics that borrow against domain trust always come due — and in 2026 the interest rate is your visibility inside AI answers.

Build a funnel that would survive being described accurately to your buyer. That is the same standard the machines are now applying.


Source: Google Search Central, Apr 13 2026.