Affiliate chats are increasingly reporting Chrome's "red screen" on gambling PWA domains: a domain lives for a few hours, then visitors see the full-screen "Deceptive site ahead" warning and traffic to it drops to zero. Google has made no separate statement about PWAs, but back in the summer the company explained in detail how Chrome now catches push-notification abuse — through service-worker analysis, automatic permission revocation and sending limits. Here is what is known officially, why PWA funnels are getting hit and what to do when a domain has already "gone red."
What is happening
The scheme in question is a classic gambling funnel: a landing page posing as a mobile game or utility offers to "install the app" (in reality a PWA shortcut on the home screen), asks for notification permission, then drives users to a casino with bonus pushes and "system" messages. Media buyers report that such domains now get the Safe Browsing red warning faster than before — sometimes within the first hours of a campaign. That timing can't be verified independently, but the trend matches what Google has said about Chrome's new protections.
What Google has said officially
In August the Chrome Security team published a post on its "multi-layered defenses" against abusive notifications. The key numbers and mechanics:
- 7 billion notifications a day. That is how much Chrome on Android cut unwanted notifications by in the first quarter of the year.
- Automatic permission revocation. Chrome switches off notifications from sites the user hasn't engaged with recently and from sites that repeatedly receive warnings as suspicious. Users can restore permissions in Safety Hub.
- Detecting site networks. Google explicitly mentions "advanced behavioral detection" that identifies networks of sites coordinating abusive notifications — including through service worker activity. That hits the "many domains, one broadcast" setup directly.
- A 1,000-messages-per-minute cap. Firebase Cloud Messaging throttles domains that send too much: above the limit the server returns HTTP 429, and repeat offenders get stricter limits until their behavior improves.
- One-tap unsubscribe and a new permission prompt on Android — it is easier for users not to subscribe and easier to leave.

Chrome's push-spam defenses in numbers, per Google (chart labels in Russian)
The red screen and the push filter are two different things
Two Google mechanisms are often lumped together as one "ban," and it matters to separate them:
- The abusive notifications policy has been in force since Chrome 86. Google's crawler subscribes to a site's pushes itself, evaluates their content with Safe Browsing (fake system messages, links to malware, tricking users into granting permission), and if the site violates the rules, the owner gets an email in Search Console and at least 30 calendar days to fix it. After that Chrome shows a "quieter" permission prompt that almost nobody accepts, and blocks the request automatically for repeat offenders. There is no red screen here.
- The full-screen "Deceptive site ahead" warning is Safe Browsing acting against social engineering: a page pretends to be another service or tricks users into doing something they would only do for a trusted site. A "game" landing page that actually leads to a casino, and pushes in the style of "your device is infected," fit that definition. The warning is shown to all visitors immediately, with no grace period.
That is why a gambling PWA gets the red screen rather than the quiet prompt: the problem isn't the volume of pushes, it's that the page masquerades as something it isn't.
What it means for affiliates
- The economics of standard PWA builders break down. If a domain gets the warning hours after launch, the clicks you paid for are wasted and the subscriber base you collected loses value — Chrome revokes the permissions.
- Domain networks no longer save you on their own. Google looks for coordination through service-worker behavior, not just complaints about a specific address. Identical sending code across dozens of domains is a signal in itself.
- Separating the landing domain from the push domain is worth it at least so that a ban on one doesn't kill the other. But if the notification content breaks the rules, Safe Browsing will reach the second one too.
- Quiet PWAs live longer. The fewer "system" phrasings and bonus promises in the pushes, and the closer the manifest and interface are to what the landing page claims, the fewer triggers for detection.
How PWAs fit into a funnel and when they still make sense — in our article on PWA in affiliate marketing.
The domain is already red: what to do
- Check the status. Google's Transparency Report has a Safe Browsing site status check, and Search Console has a Security Issues report that states the reason (social engineering, malware, etc.).
- Remove the cause. As long as the domain still hosts a deceptive landing page, redirects or pushes with fake messages, a review request is pointless.
- Request a review in Search Console. According to affiliate media, removal takes anywhere from a few hours to 1–3 days.
- For a gambling funnel this usually isn't an option. Cleaning a casino landing page until it "isn't misleading" means killing the conversion rate. In practice buyers just switch domains and rebuild the funnel rather than fight for the old one.
News on Google, Chrome and traffic sources in our Telegram channel.
FAQ
Has Google officially blocked PWAs for gambling?
No. There has been no separate statement about PWAs. Google described Chrome's new defenses against abusive notifications, while the red screens on gambling PWAs are Safe Browsing acting against deceptive content.
Why does Chrome show "Deceptive site ahead" on my PWA landing page?
Most often because of social engineering: the page poses as a game or utility but leads to a casino, or the pushes imitate system messages. The exact reason is shown in the Security Issues report in Search Console.
How many pushes does Chrome allow?
Firebase Cloud Messaging caps problematic domains at 1,000 messages per minute; above that the server returns HTTP 429.
Can the red screen be removed?
Yes, if you remove the violation and request a review in Search Console. For a casino funnel that usually means reworking the landing page, so in practice the domain is more often simply replaced.
What happens to the collected push subscriber base?
Chrome automatically revokes permissions from sites flagged as suspicious and from sites the user hasn't engaged with for a long time. A base from a banned domain quickly loses its value.
Sources: Google Security Blog (Chrome Security post on defenses against abusive notifications), Chromium Blog (abusive notifications policy, Chrome 86), Google Safe Browsing help, Help Net Security, reports in affiliate media and chats.



