Google Play spam malware policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Apps that send unsolicited messages or use a device as a spam relay.
This malware category concerns the messages your code sends, not repetitive store listings. Google prohibits unsolicited messaging to a user’s contacts and use of the device as an email spam relay.
What to check
Trace SMS, email, invitations, referrals, and background messaging. Check whether the user selects the recipients and intentionally approves the message, or whether a library sends it automatically.
Inspect remote command handlers and any embedded mail transport. A messaging component can act as a relay without an obvious screen in your app.
How to address the rejection
Remove automatic unsolicited sending and relay functionality. For legitimate sharing, give the user control over recipients and content before sending. Remove dependencies that use the device to distribute unrelated messages.
Test onboarding, contact import, and idle behavior with a clean account. Document the path that previously sent messages and show the corrected interaction. If the notice instead concerns mass-produced apps or affiliate traffic, check the separate Spam policy.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Spam malware Checked 22 September 2026