Google Play spam malware policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that send unsolicited messages or use a device as a spam relay.

This malware category concerns the messages your code sends, not repetitive store listings. Google prohibits unsolicited messaging to a user’s contacts and use of the device as an email spam relay.

What to check

Trace SMS, email, invitations, referrals, and background messaging. Check whether the user selects the recipients and intentionally approves the message, or whether a library sends it automatically.

Inspect remote command handlers and any embedded mail transport. A messaging component can act as a relay without an obvious screen in your app.

How to address the rejection

Remove automatic unsolicited sending and relay functionality. For legitimate sharing, give the user control over recipients and content before sending. Remove dependencies that use the device to distribute unrelated messages.

Test onboarding, contact import, and idle behavior with a clean account. Document the path that previously sent messages and show the corrected interaction. If the notice instead concerns mass-produced apps or affiliate traffic, check the separate Spam policy.

Messages this guide can help with

Spam malware; Spam malware policy violation; Spam malware rejection; Spam malware denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access