You own a small pile of domains — an old brand you moved away from, a couple of typo variants you grabbed so nobody else would, a name from a project that folded — and you want them all pointing at your current site. Then you read that redirecting domains is a spam signal now, that Google’s latest update torched sites for doing exactly that, and you stop with your hand on the button.
Two different things are being run together under one scary headline. One of them Google is actively penalizing. The other Google names, in its own policy, as a legitimate reason to redirect. The whole question is which one you are doing — and the line is clearer than the headlines make it sound. This is the SEO side of the parked-domain runbook and of every way to redirect on Cloudflare: the same 301, and whether Google honours it.
What Google actually went after
The thing that got hit has a name in Google’s spam policies:
Expired domain abuse is where an expired domain name is purchased and repurposed primarily to manipulate search rankings by hosting content that provides little to no value to users.
That is the play: buy a dropped domain that still carries ranking signals from its old life, point
it at your site, and inherit authority you never earned. Google’s March 2026 spam update did not
invent a rule for this — expired domain abuse was codified back in 2024 — it enforced the existing
one harder and faster. The market felt it. The advice in the expired-domain trade has visibly
moved from hunting aged domains to starting fresh ones, and the sites that leaned hardest on
authority-by-redirect are the ones that lost traffic. If the plan was to buy a stranger’s old
authority and 301 it into your rankings, that plan is done.
What Google still blesses
Now the other thing. Redirecting a domain you own to a site you own, because the two belong together, is not on any spam list. It is the opposite: Google’s own policy on sneaky redirects lists consolidating pages among the legitimate reasons to redirect, right next to moving to a new address. What makes a redirect sneaky is intent.
When examining if a redirect is sneaky, consider whether or not the redirect is intended to deceive either the users or search engines.
There is no deception in sending an old brand’s domain to that brand’s current home. The mechanics
agree: a 301 to a topically related destination still passes its signals, the way it has for
years. Where it stops working is relevance. A 301 from an unrelated domain gets treated like a
soft 404, and Google ignores the equity rather than handing it over. That is the tell for the
whole distinction — a relevant consolidation is a redirect Google honours, an unrelated authority
grab is a redirect Google declines.
Which one are you doing
The line, as a handful of questions:
| Consolidation — do it | Authority grab — dead | |
|---|---|---|
| Whose domain | yours, related to the target | bought for its old rankings |
| The link between them | same brand, product, or topic | unrelated to your site |
| What the redirect is for | keeping your own traffic and name | inheriting a stranger’s authority |
| Where it points | the page that replaces the old one | your homepage, to pass equity |
| Google’s verdict | legitimate, passes signals | expired domain abuse, or ignored |
If every answer sits in the left column, you are doing the thing Google’s policy names as fine, and the spam update is not about you.
Doing it cleanly on Cloudflare
Being on the right side of the line is most of the job. Doing it cleanly is the rest, and a few Cloudflare-specific choices keep a legitimate consolidation from reading like a lazy one.
Point each old URL at the page that replaces it, not at your homepage. A blanket redirect of
everything to the root is what muddies your anchor-text profile and looks like a link grab even
when it isn’t; where the old domain had real pages, map them to their real equivalents. The
parked-domain runbook has the Cloudflare pattern for a domain
with no server behind it — a proxied A record on 192.0.2.1 and a redirect rule — and
Bulk Redirects is where a whole portfolio lives: one
account-level list across every domain, rather than a rule per zone.
Keep it a single 301. Redirect chains — the old domain to a second domain to the site — leak
signal at every hop and are slower for the visitor, and there is no reason to build one when the
destination is fixed. One permanent hop, straight to the relevant page.
One honest aside, for the case this guide is not about: if what you actually want is to take over a dropped domain’s ranking, a redirect was always the fragile way to do it, and Google just made it fragiler. The durable version is a real site on that domain, standing on its own. That is a different project from this one, which is about domains that already belong to you.
Where this is less tidy than it looks
A domain’s past comes with it. If the name you own spent an earlier life inside a link scheme, a
301 carries that history into your site too, and a clean consolidation can still inherit a dirty
reputation — worth reading the backlink profile of an acquired domain before you wire it up.
Relevance is not binary either. A domain only loosely related to your site sits in the grey zone
where Google may pass some of the signal, all of it, or none, and no dashboard tells you which
ahead of time. The safe reading is that an unrelated 301 is a waste rather than a punishment: the
equity you hoped to move never arrives, while the redirect sits there doing nothing for anyone. The
Google policy wording here was checked on 25 July 2026.
What one setup does not give you
For a handful of domains you own, the whole job is the runbook and one Bulk Redirects list, pointed at the right pages and checked once. That is genuinely all of it, and you should start there.
At the scale where a portfolio is dozens of names funnelling into one site, the work is staying on the right side of the line continuously: every redirect relevant, every one a single hop to a live page, and none quietly turned into a chain or a homepage dump as the site changes underneath them — plus a re-check each time Google tightens the screws. That standing watch across the whole portfolio is the part 301.st runs for you. For a few owned domains, a Bulk Redirects list and the runbook are enough.