v152 · suspicious site warnings
What a page can observe
The answer is nothing, and an answer like that has to be earned. Every plausible place a verdict might be exposed is checked here, with controls that prove the checking works — because "I looked and did not find it" is only useful from someone who can demonstrate they would have.
Places a verdict could have been
| candidate | present? | reads as | note |
|---|---|---|---|
| Not checked yet. | |||
The two control rows are the point of the exercise. One names something that certainly exists and one something that certainly does not, so a table of absences means something rather than being the shape a broken probe would also produce.
Things this is not
| mechanism | present? | what it actually reports |
|---|
Every one of these is real and useful, and none of them will ever mention Safe Browsing. They report your page's own policy violations back to you — a different question, asked by a different party, about a different thing.
Why the absence is the design
A detectable warning is a defeatable warning. A page that could read the verdict could change its behaviour when it is being watched — show benign content to a flagged load, keep the deceptive flow for everyone else — and the signal would be worth less than nothing, because it would now also be a reliable way to detect the safety system.
The same argument rules out an opt-out, and it is the reason the operational path runs through an account you have to prove you own rather than through an API. That is slower on purpose.