What is domain spoofing in advertising?
Domain spoofing is when a seller misrepresents where an ad will run, labelling cheap or fraudulent inventory as a well-known premium website so advertisers pay premium prices. The bid request claims to be, say, a major news site, but the ad actually appears on a junk site or to a bot. ads.txt, sellers.json and ads.cert were built largely to stop it.
In real-time bidding, buyers decide what to bid based on the domain declared in the bid request. Domain spoofing exploits that trust: a fraudster rewrites the domain field, or runs a fake site whose ad calls impersonate a real one. The app and CTV equivalents are app spoofing and device spoofing.
The main defense is supply-chain transparency. With ads.txt, a publisher lists every company authorized to sell its inventory; buyers can refuse bids from sellers not on the list. sellers.json and the supplyChain object reveal every hop between buyer and publisher, and ads.cert adds cryptographic signing. None is perfect, but together they made large-scale spoofing of premium domains much harder than it was in the Methbot era.