Invalid traffic & fraud
Cloaking
Cloaking is showing different content to ad reviewers, crawlers or verification tools than to real users, so a harmful, fraudulent or policy-breaking ad or site slips past checks.
Ad platforms and verification vendors review ads and websites automatically. Cloaking tricks them by detecting who is looking. If the visitor appears to be a reviewer, scanner, crawler or data-center IP, it gets a clean, compliant page; if it looks like a targeted real user, it gets the real content, which might be a scam, malware, prohibited products or a junk site.
Cloaking is a core tactic in malvertising, in scam ads that impersonate celebrities or brands, and in some made-for-advertising sites and traffic arbitrage operations. It relies on the same fingerprinting techniques used by fraud detection, run in reverse: checking IP reputation, device type, geography, time of day, referrer and whether a browser looks automated.
Google's advertising policies explicitly prohibit cloaking as a form of "abusing the ad network". Detection involves reviewing ads from many vantage points, including real residential and mobile networks and genuine devices, comparing what different visitors see and monitoring for landing pages that change after approval.
Think of it like this
Cloaking is like a restaurant that serves inspectors a spotless kitchen tour and a perfect meal, while everyone else gets yesterday's leftovers.
An example
A dietary-supplement advertiser's landing page shows a harmless recipe blog to visitors from US data centers, but mobile users in Italy arriving from the ad see fake news articles and a subscription trap.
Related terms
Malvertising
Malvertising is using online ads to spread malware, scams or forced redirects, by sneaking harmful code or deceptive landing pages into ad creatives served through legitimate ad networks.
Device fingerprinting
Device fingerprinting is identifying or characterising a device from the combination of its technical attributes, such as browser, fonts, screen, graphics and network traits, instead of a stored cookie or ID.
Brand safety
Brand safety is the practice of keeping ads away from content that is harmful or universally unacceptable, such as terrorism, child abuse, hate speech or illegal activity, to protect an advertiser's reputation.
Ad verification
Ad verification is independent third-party measurement that checks whether ads were served to real people, in viewable positions, in safe and suitable environments, and in the intended geographies.
Ad fraud
Ad fraud is the deliberate faking or misrepresenting of ad impressions, clicks, installs or conversions so that someone gets paid for advertising that no real, interested human saw or did.
Sources: Google Advertising Policies: Abusing the ad network, TAG: fighting malware