Google's January 2026 spam update finished rolling out on January 22. The standard post-mortems appeared within 72 hours: link schemes punished, cloaking caught, doorway pages eliminated. All true, and all already written about by people who'd covered the same story in 2024, 2023, and 2022 with slightly different specifics.
This is not that article. What I tracked across eleven sites during the January 2026 rollout showed patterns that didn't fit the expected narrative. Some of what got hit wasn't what anyone was talking about. Some of what should have gotten hit — by all conventional wisdom — didn't move at all.
What the Update Actually Was — and What Made January 2026 Different
Google spam updates target violations of their spam policies rather than content quality broadly. The distinction matters because the remediation is different: spam violations require you to stop doing the thing that violates policy, while core update losses require you to improve the quality of what you're doing. Treating a spam action as a core update problem — or vice versa — produces months of wasted effort.
January 2026 confirmed start: January 14. Completion: January 22. Eight days. That's fast. The March 2024 spam update ran 14 days. The June 2024 spam update ran 10. The compressed timeline on January 2026 suggested to me that the targeting was more precise — not a broad sweep, but a focused action against specific patterns Google had been building classifiers for through Q4 2025.
Volatility signature compared to recent spam updates
| Update | Duration | Peak Semrush sensor | Primary targets (reported) |
|---|---|---|---|
| March 2024 spam | 14 days | 9.1 | Scaled content abuse, expired domains, site reputation abuse |
| June 2024 spam | 10 days | 7.8 | Link spam, cloaking, thin doorway pages |
| January 2026 spam | 8 days | 8.3 | Link schemes, parasite content, AI-generated press release networks (my observation) |
The peak sensor reading of 8.3 on January 16 was concentrated in specific verticals rather than spread evenly. Finance, supplement, and outdoor gear categories showed the sharpest drops. General content sites with clean link profiles barely moved.
Parasite Proximity: The Collateral Damage Nobody Documented
This is the one I didn't see written about anywhere in the first two months after the update.
One of my clients runs a legitimate B2C e-commerce site in the fitness equipment space. Clean site. No spam policies violated. Published editorial content for seven years. Strong brand. Lost 29% of non-brand organic clicks between January 14 and January 22.
I spent three weeks trying to figure out why. The answer, when I found it, was embarrassing in its simplicity.
The site had a "sponsored content" section — a small subdirectory with about 40 articles that brands had paid to have published. Nothing cloaked. Disclosed as sponsored. Editorially supervised. Standard native advertising, the kind mainstream publishers run every day. But nine of those 40 articles were from supplement brands that were themselves running aggressive link schemes and had been targeted in the January 2026 update.
The fitness equipment site hadn't done anything wrong. But it had hosted content from entities that had. And it had linked out to those entities from those sponsored posts. When Google's systems updated their evaluation of those entities, the links pointing from the fitness site to the penalized entities may have created a proximity signal that affected the fitness site's own evaluation.
I call this parasite proximity. It's not collateral damage in the legal sense — the fitness site was hosting sponsored content, which is a choice. But the mechanism is different from classic link spam because the fitness site itself was the victim, not the operator of the scheme.
The fix: we removed the nine problematic sponsored articles entirely (not noindexed — removed and 404'd), pruned the internal links pointing to those articles from other site content, and submitted a recrawl request through Search Console. Traffic partially recovered by February 11 — about 17 percentage points of the 29% loss came back. The remaining 12 points came back gradually through March, with the March 2026 core update appearing to complete the recovery once the site's overall quality signals were re-evaluated.
Signs your site might have parasite proximity exposure
- You host sponsored or guest content from third-party brands or publications
- Those third parties are in supplement, finance, gambling, or other high-spam verticals
- You accepted content before implementing strict editorial review of the linking practices of sponsors
- Your site dropped in a spam update despite having no obvious spam policy violations yourself
This is not a common situation. But it's also not hypothetical — I tracked it across three separate sites in January 2026, all in different verticals, all with the same general structure of legitimate sites hosting third-party content from entities later targeted for spam.
AI-Generated Press Release Aggregators: The Quiet Casualty
A category of site that lost badly in January 2026 and received almost no coverage: the AI-generated press release aggregation networks that had proliferated through 2024 and early 2025.
The pattern was straightforward: pull press releases from PR Newswire and Business Wire via RSS, run them through an LLM to "rewrite" them into "news articles," publish at scale on domains that looked like regional news outlets or industry trade publications. These sites had accumulated significant indexed pages — some in the tens of thousands — and had been scraping meaningful traffic from news-intent queries because they published fast and Google News had indexed several of them.
I tracked eight of these networks. By January 22, five had lost more than 80% of their indexed pages. One dropped from 34,000 indexed pages to 1,200 in eight days. Two survived the January update relatively intact — and those two are the interesting case, because they're showing signs of vulnerability heading into what I expect will be a June 2026 spam update.
What differentiated the survivors from the casualties? Both surviving networks had mixed AI content with what appeared to be genuine regional reporter bylines on roughly 30% of their articles. I cannot verify whether those bylines represent actual humans — the named reporters don't appear to have social media presences or bylines anywhere else. But the presence of bylined content may have been enough to avoid triggering the classifier that eliminated the pure AI-aggregated networks.
If that's what's happening — and I'm speculating here — it suggests Google's classifier for AI press release aggregation was targeting the structural pattern of the content (press release rewrites with no human byline) rather than AI involvement per se. The same caveat applies here as in the March 2026 core update analysis: AI content isn't the single variable, and treating it as such leads to wrong conclusions.
Expired Domain Redirect Contamination
This pattern has been documented before, but January 2026 produced a specific variant that deserves attention.
Classic expired domain abuse: buy a domain with existing link equity, redirect it to your money site, inherit the links. Google has been fighting this for years and spam updates regularly hit the most aggressive practitioners.
What I saw in January 2026 was different: sites that had been on the receiving end of expired domain redirects they didn't control. Specifically, sites that had old competitor domains pointed at them — either by affiliates trying to boost rankings, by past SEO vendors who'd left redirect infrastructure in place, or in one case by what appeared to be a negative SEO campaign.
One client — a legitimate SaaS company in the HR tech space — had three expired domains in the 2019–2021 vintage redirecting to their site. They had no idea these existed. A previous SEO agency had set them up as part of a "digital PR" campaign years earlier and apparently never disclosed it or cleaned it up when the relationship ended. Those redirects had been live for 4–5 years without incident.
January 2026 spam update: the site lost 23% of non-brand organic traffic in eight days.
Diagnosis: the three expired domains had been repurposed by someone else (possibly bought at auction after they expired) to serve as hubs in a link spam network targeting completely unrelated verticals. The domains now had two types of links pointing out: old links to the HR SaaS site from the legitimate "digital PR" era, and new spam links to gambling and supplement sites. When Google updated its evaluation of those domains, the HR SaaS site's association with them became a liability.
Fix: disavow the three domains, 301-verify that the redirects were no longer functioning (they were on expired hosting — they'd gone down on their own), and document the timeline in Search Console. Partial recovery by February 18, full recovery confirmed by March 10 — before the core update started.
The lesson for anyone who has ever had an SEO agency working on their site: audit your redirect ecosystem. Not just the redirects on your own domain. Find out whether any external domains are pointing to your site via redirect, and who controls them now. This is a 30-minute exercise in Ahrefs (look for redirect chains in the backlink report) and it's worth doing before a spam update does it for you.
What Should Have Died But Didn't — and What That Means
I need to be honest about the other side of this.
Two sites in my observation set during January 2026 had textbook link spam profiles — purchased links, low-quality guest posts at scale, private blog network exposure — and survived the update with minimal impact. One lost 4% of traffic. One lost nothing measurable.
I don't have a clean explanation for this. Possible factors:
The sites operate in verticals (one in home improvement, one in local restaurant reviews) with relatively low commercial competition and low attention from Google's quality review teams. Google's resources for spam enforcement are not infinite, and high-competition commercial verticals get more scrutiny than niche local content sites.
The link spam on these sites may be old enough to have been discounted rather than penalized — links Google's systems have already devalued rather than links that are actively misleading ranking signals. If the links weren't moving rankings before the update, eliminating the credit they provided doesn't produce a visible drop.
Or they got lucky. Spam updates don't catch everything on every pass. The March 2024 spam update caught things that the June 2024 update cleaned up. Survivors of one update frequently don't survive the next.
I'm raising this because the SEO discourse around spam updates tends toward determinism — "if you do X, you'll get hit." The reality is messier. Some sites with clean practices got hit in January 2026 through proximity effects. Some sites with dirty practices survived. The update was imperfect, and treating it as a binary judgement system produces overconfident conclusions.
The SIEVE Diagnostic I Use for Spam-Adjacent Sites
When a client loses traffic in a spam update and the cause isn't immediately obvious, I run what I call SIEVE — a structured audit that systematically rules out the less obvious spam-adjacent causes before assuming the site itself has a policy violation.
S — Sponsored and third-party content audit. What non-editorial content is hosted on the domain? Who published it? Do those publishers or the entities they link to have known spam associations? When was each piece published, and has the publisher's link profile changed since then?
I — Inbound redirect map. What external domains are currently redirecting to this site? Who owns those domains now? What else do those domains link to? This requires a backlink tool audit filtered for redirect links specifically.
E — Entity association check. Is this site named, cited, or linked in content from known spam networks? Not as a target of those links, but as a referenced source — sometimes spam content references legitimate sites in a way that creates association signals.
V — Vendor and agency history review. What SEO work was done on this site by previous vendors? Are there link building campaigns that weren't properly documented? Are there domain purchases or redirect setups from 2–5 years ago that are still live?
E — External content signals. Is the site's brand name being used on third-party sites in ways that could create spam associations? Affiliate abuse, fake review sites, doorway pages that reference the brand without authorization?
SIEVE doesn't tell you whether a site has a self-inflicted spam problem. It tells you whether there are environmental factors contributing to a spam update loss before you waste time on internal remediation that won't fix an external cause.
Two Things the Spam Update Discourse Gets Consistently Wrong
Contrarian take 1: Disavow files are overused as a response to spam updates
Every spam update produces a wave of practitioners recommending disavow files as the primary response. I've done this myself, and I admitted in the March 2026 core update article that I did it wrong on at least one site. The instinct is understandable: spam update loss, backlink profile looks questionable, disavow seems responsive.
But most disavow recommendations I see are for links that Google's systems have already devalued — links that weren't contributing to rankings before the update and whose removal changes nothing. Filing a disavow for links that aren't helping you is pointless. Filing a disavow for links that are helping you is counterproductive. The only situation where a disavow file does useful work is when you have links that were actively manipulating rankings and those links are now creating a manual action or algorithmic penalty — and even then, fixing the source is usually more valuable than filing the disavow.
For January 2026 specifically: if your loss was from parasite proximity or expired domain contamination, a disavow file addresses the wrong part of the problem. You need to remove the content or document the external circumstances, not file a list of domains with Google.
Contrarian take 2: Spam updates and core updates are not as distinct as Google implies
Google presents spam updates and core updates as separate systems targeting separate problems. In practice, the sites I tracked through both January 2026 and March 2026 showed overlap that suggests the systems interact more than the public framing implies.
Sites that lost ground in January's spam update and didn't address the underlying issue saw compounded losses in March's core update. Sites that fully resolved their spam-adjacent issues before March 5 saw those pages re-evaluated positively in the core update. The systems appear to share signals — a site's spam history doesn't disappear when the spam update ends and stay invisible to the core update system. The quality evaluation is continuous.
This matters practically because it means the window between a spam update and the next core update is active remediation time, not a waiting period. Eight weeks between January 22 and March 5. That's enough time to fix a sponsored content problem, clean up a redirect ecosystem, and get recrawled before the next round of quality signals are computed.
How January Set Up March 2026
The relationship between January's spam update and March's core update was tighter than any previous spam-to-core sequence I've tracked.
Sites that resolved January spam issues by mid-February had seven weeks for Google to recrawl and update their quality signals before March 5. Of the three sites in my set that resolved January issues quickly, all three held or improved in the March core update. Of the two sites that were still mid-remediation when March started, both saw continued declines.
This is a small sample and I won't overinterpret it. But the pattern aligns with what we know about how Google's systems work: quality signal updates happen on recrawl cycles, not at fixed points in time. Fixing a problem early means it gets incorporated into the quality evaluation sooner. Waiting means you carry the old signal into whatever update comes next.
The outdoor gear site I described in the March 2026 core update forensics article was mid-remediation when March started. The January spam loss wasn't fully resolved. The March update hit the already-weakened site and drove a further decline. Whether the March loss was a continuation of the spam penalty or an independent core quality evaluation, I can't say with certainty. But the timing suggests the two are related.
If there is a June 2026 spam update — and based on the pattern, there probably will be — the two surviving AI press release networks I mentioned earlier are the ones I'm watching most closely. They've had five months to get caught. If June doesn't get them, I'll revise my model for how Google classifies AI-generated content at scale in news contexts.
Data sourcing note: Traffic figures in this article are from Search Console and Ahrefs, tracked January 14 through March 31, 2026 across eleven sites in active management. Indexation figures for press release aggregators come from site: operator checks recorded on January 22 and compared to January 13 baselines. All client situations are described with identifying details changed to protect confidentiality.
Related on this site: March 2026 core update forensics | Product reviews retirement and what changed for affiliates | AI Overviews 2.0 CTR impact across 47 sites
External reference: Google Search spam policies documentation
