Ad tech stocks
TEAD0.59▲ +16.13%CDLX2.69▼ -8.33%PSKY9.54▼ -7.70%186013.51▲ +7.48%U43.30▲ +5.78%APPS11.60▲ +4.50%APP278.01▼ -4.28%STGW8.45▲ +3.81%RDDT147.51▲ +3.56%ZETA32.45▲ +2.79%OMC75.62▲ +2.70%MNTN10.43▲ +2.56%TRU62.66▲ +2.51%SFOR44.85▼ -2.50%CCO2.41▲ +2.50%LFTO15.42▼ -2.41%CART43.95▲ +1.92%PUBM19.09▲ +1.92%WPP382.90▲ +1.81%INUV0.57▲ +1.79%NFLX68.36▼ -1.76%DSP12.52▲ +1.71%ILLM0.66▲ +1.54%GOOGL338.81▼ -1.53%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%SIRI25.54▼ -1.31%035420191200.00▼ -1.29%4755681.70▼ -1.26%SPOT493.33▲ +1.22%AZRN0.82▼ -1.20%AAPL329.05▼ -1.19%IHRT2.13▲ +1.19%MGNI25.54▲ +1.09%ROKU150.66▼ -1.06%BIDU85.99▼ -1.01%PUB95.34▲ +0.87%SNAP5.45▲ +0.83%IBTA39.73▲ +0.82%SST2.64▲ +0.76%SNOW341.49▲ +0.57%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%TBLA3.35▼ -0.45%RAMP37.69▲ +0.44%META728.04▲ +0.39%24331308.00▲ +0.38%TTD12.21▲ +0.29%OUT27.68▼ -0.25%0700431.00▼ -0.23%PINS18.93▲ +0.19%NEXN9.02▲ +0.17%DEC24.68▲ +0.16%PERI8.68▼ -0.12%CRTO15.21▲ +0.07%CPNG13.88▲ +0.04%DV13.48▼ -0.04%43243564.00▲ +0.03%WBD30.94▼ -0.02%BABA107.54▲ 0.00%VER12.08▲ 0.00%
Ticker byClearTrust

Invalid traffic & fraud · also called Site misrepresentation, URL masking

Domain spoofing

Domain spoofing is misrepresenting the website where an ad will run, so that inventory from a low-quality or fake site is sold to advertisers as if it came from a premium publisher.

The short answer, from the AdTech Sumo glossary

In programmatic buying, the bid request tells buyers which site the ad slot is on. Domain spoofing is lying in that field. A junk site, or a server full of bots, claims to be a well-known newspaper so buyers bid premium prices. Methbot, exposed in 2016, spoofed hundreds of thousands of URLs, including many belonging to big-name publishers.

Spoofing happens in several ways: a fraudulent seller writes a false domain into the bid request; a tag is loaded inside a hidden frame so the real page is concealed; or malware on a user's device injects ads into a legitimate site's pages. The MRC IVT guidelines classify domain misrepresentation as SIVT.

The industry's main response is supply-chain transparency. ads.txt lets a publisher list the companies authorised to sell its inventory, so buyers can reject sellers not on the list. sellers.json and the supplyChain object reveal who is in the path, and ads.cert adds cryptographic signing. Verification vendors also compare the declared domain with where the ad actually rendered. The app equivalent is app spoofing.

Think of it like this

It is like selling cheap sparkling wine with a forged Champagne label: the buyer pays for the famous name and gets something else entirely.

An example

A buyer sees 50 million daily bid requests claiming to be from a top UK news site, whose own ads.txt shows it only authorises eight sellers. Requests from 30 other seller IDs are spoofed and blocked pre-bid.

Related terms

Sources: IAB Tech Lab ads.txt and app-ads.txt, IAB Tech Lab sellers.json, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)