Ad tech stocks
TEAD0.55▲ +8.59%186013.51▲ +7.48%PSKY9.90▼ -4.16%SAX36.86▲ +3.95%MNTN10.55▲ +3.74%OMC76.17▲ +3.45%WPP387.90▲ +3.14%INUV0.58▲ +2.97%TRU62.86▲ +2.85%DSP12.63▲ +2.60%CCO2.40▲ +2.34%IHRT2.06▼ -2.14%APP284.30▼ -2.11%CDLX2.88▼ -2.04%PUB96.44▲ +2.03%SCOR4.59▼ -2.03%RDDT145.32▲ +2.02%STGW8.30▲ +1.97%APPS11.30▲ +1.80%ZETA32.07▲ +1.58%NFLX68.55▼ -1.49%035420191200.00▼ -1.29%4755681.70▼ -1.26%BABA108.85▲ +1.22%AZRN0.82▼ -1.20%U41.40▲ +1.15%HAVAS17.85▲ +1.13%SIRI25.59▼ -1.12%LFTO15.65▼ -0.95%CPNG13.76▼ -0.83%SNAP5.44▲ +0.74%DEC24.82▲ +0.73%BIDU87.46▲ +0.68%NEXN9.05▲ +0.61%OUT27.58▼ -0.61%AAPL331.05▼ -0.59%PUBM18.84▲ +0.59%VER12.15▲ +0.58%47511238.50▲ +0.57%SPOT489.81▲ +0.50%META728.66▲ +0.48%TTD12.22▲ +0.45%24331308.00▲ +0.38%SST2.61▼ -0.38%GOOGL342.87▼ -0.35%TBLA3.37▲ +0.30%0700431.00▼ -0.23%CRTO15.23▲ +0.23%IBTA39.31▼ -0.23%SFOR46.10▲ +0.22%PINS18.93▲ +0.21%RAMP37.59▲ +0.20%PERI8.71▲ +0.17%CART43.09▼ -0.07%DV13.48▼ -0.04%MGNI25.25▼ -0.04%SNOW339.48▼ -0.03%43243564.00▲ +0.03%ROKU152.31▲ +0.02%ILLM0.65▲ 0.00%WBD30.95▲ 0.00%
Ticker byClearTrust

ads.txt, sellers.json & schain

How a buyer checks that the seller really is allowed to sell a site’s ads, and why it defeats domain spoofing.

ads.txt, sellers.json & schain

1/6
▤news.examplepublisher✓ads.txtwho may sell me⇄SSPseller ID 1234▦sellers.jsonwho 1234 is◎DSPthe buyer!Spooferclaims to be news.example★Verified pathbuy with confidence
1
The publisher declares its sellers

news.example posts a public file, ads.txt, listing every company allowed to sell its ads and the account ID it uses, marked DIRECT or RESELLER.

  1. The publisher declares its sellers: news.example posts a public file, ads.txt, listing every company allowed to sell its ads and the account ID it uses, marked DIRECT or RESELLER.
  2. A bid request arrives: The DSP receives a request “for news.example”, sent by SSP account 1234, with a SupplyChain object listing every hop it passed through.
  3. Check 1: is this seller authorised?: The buyer checks news.example/ads.txt: is SSP account 1234 listed? If not, the request is unauthorised and is not bought.
  4. Check 2: who is account 1234?: The SSP’s sellers.json names the business behind 1234 and whether it is the publisher itself or an intermediary. Hidden sellers are a warning sign.
  5. A spoofer tries the same trick: A fraudster sends requests claiming to be news.example from its own junk site. This is domain spoofing. Its seller ID is not in news.example’s ads.txt.
  6. Only verified paths get bought: Requests whose seller, ads.txt entry and schain all line up get bought; the spoofed ones fail. Simple public files closed one of the biggest fraud loopholes of the 2010s.

Step by step

  1. The publisher declares its sellersnews.example posts a public file, ads.txt, listing every company allowed to sell its ads and the account ID it uses, marked DIRECT or RESELLER.
  2. A bid request arrivesThe DSP receives a request “for news.example”, sent by SSP account 1234, with a SupplyChain object listing every hop it passed through.
  3. Check 1: is this seller authorised?The buyer checks news.example/ads.txt: is SSP account 1234 listed? If not, the request is unauthorised and is not bought.
  4. Check 2: who is account 1234?The SSP’s sellers.json names the business behind 1234 and whether it is the publisher itself or an intermediary. Hidden sellers are a warning sign.
  5. A spoofer tries the same trickA fraudster sends requests claiming to be news.example from its own junk site. This is domain spoofing. Its seller ID is not in news.example’s ads.txt.
  6. Only verified paths get boughtRequests whose seller, ads.txt entry and schain all line up get bought; the spoofed ones fail. Simple public files closed one of the biggest fraud loopholes of the 2010s.

Read the full lesson