The strange story of EiM’s LinkedIn block
I'm Ben Whitelaw, the founder and editor of Everything in Moderation*. I'm standing in for Alice in this week's Trust & Safety Insider while she's on a well-earned holiday.
I've been meaning to write about today's topic for more than two years. It's a slightly strange and, at times, technical account of a takedown incident that bears little significance in the grand scheme of things.
However, many T&S won't have experienced being on the receiving end of the systems that they build, buy or help enforce. And I learnt a lot about the potential pitfalls of automated moderation systems, users' limited redress mechanisms and often obscured supply chain of safety decisions.
Drop me a line if if you've experienced something similar or if this raises questions inside your own team. In honour of my T&S Insider co-writer, here we go! — Ben
The moderation newsletter gets moderated
What happened
It was a typical week. I had just sent a new edition of Week in Review and, as I often do, I went to LinkedIn to post about it to whoever the algorithm would deign to show it to. Except this time, no dice. LinkedIn showed a “cannot display preview” warning and said I should try another link.

Odd. I hadn't changed anything on the site and didn’t see why that would be the case. I had posted dozens of (let’s be honest) anodyne updates about my niche newsletter many times before without issue.
One possible explanation was that EiM had written about child sexual abuse material or the content policies of, say, OnlyFans or Pornhub. Perhaps that was enough to trigger an automated system or lead a disgruntled subscriber to report me to an email service provider? But the edition in question led on the US Supreme Court and previous editions were about the Digital Services Act, the Oversight Board and Taylor Swift. Hardly controversial.
So, I reached out to LinkedIn via its case management page to ask what was happening.
‘Contact our browsing partner’

Credit to LinkedIn, a support agent came back to me within a few hours and tried to replicate the issue. After a bit of back and forth in which I tried different browsers, cleared my cache, and disabled various extensions, it was escalated to LinkedIn’s internal research team. Then, a breakthrough.
One of its partners, VirusTotal, had apparently blacklisted the everythinginmoderation.co domain for reasons that were not apparent. VirusTotal is an intelligence service headquartered in Spain that provides signals to companies about whether a domain, file or IP address could be malware. It was bought by Google in 2012 and is now part of Google Security Operations, a subsidiary of the search giant.
To clarify: it wasn’t LinkedIn that said my domain was dangerous, but a third-party company that I had never heard of and that wasn’t even a content moderation vendor in the way most EiM subscribers would understand. But that was where I went next.
On 7 March, I contacted VirusTotal, which explained that it “only aggregates data from a variety of vendors” and produces “no verdicts of our own”. I was asked to rescan the EiM domain and then reach out to a list of vendors if I believed there was a false positive.

Either I was too enraged about the situation to follow instructions, or the rescan didn't yield anything because I reached out again, wondering what the problem was. The message came back: speak to a company called CyRadar. At which point, the story became more interesting.