Ad tech stocks
TEAD0.60▲ +17.40%CDLX2.69▼ -8.67%PSKY9.52▼ -7.80%186013.51▲ +7.48%U43.15▲ +5.42%APP276.19▼ -4.90%LFTO15.29▼ -3.20%STGW8.38▲ +2.95%MNTN10.46▲ +2.85%APPS11.40▲ +2.75%SFOR44.85▼ -2.50%RDDT145.90▲ +2.43%ZETA32.33▲ +2.41%CCO2.40▲ +2.30%NFLX68.02▼ -2.25%OMC75.26▲ +2.21%TRU62.39▲ +2.08%INUV0.57▲ +2.02%WPP382.90▲ +1.81%DSP12.51▲ +1.62%GOOGL338.65▼ -1.58%ILLM0.66▲ +1.54%SIRI25.48▼ -1.53%AAPL328.26▼ -1.43%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%BIDU85.69▼ -1.36%SST2.58▼ -1.34%CART43.69▲ +1.32%035420191200.00▼ -1.29%4755681.70▼ -1.26%PUBM18.96▲ +1.23%SPOT493.31▲ +1.22%AZRN0.82▼ -1.20%ROKU150.64▼ -1.08%IHRT2.12▲ +0.95%TBLA3.33▼ -0.89%PUB95.34▲ +0.87%IBTA39.73▲ +0.84%NEXN8.93▼ -0.83%PINS18.75▼ -0.71%BABA106.92▼ -0.57%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%META729.03▲ +0.53%MGNI25.38▲ +0.48%SNAP5.42▲ +0.46%OUT27.64▼ -0.40%24331308.00▲ +0.38%TTD12.13▼ -0.37%RAMP37.65▲ +0.35%0700431.00▼ -0.23%PERI8.68▼ -0.17%DEC24.68▲ +0.16%CRTO15.21▲ +0.07%WBD30.93▼ -0.06%SNOW339.72▲ +0.05%CPNG13.87▼ -0.04%DV13.48▼ -0.04%43243564.00▲ +0.03%VER12.08▲ 0.00%
Ticker byClearTrust

Lesson 4 of 8 · 9 min read · intermediate

This lesson counts towards the ClearTrust Invalid Traffic & Ad Fraud certificate. Enrol with your email to record your progress and scores.Get certified, free

Spoofing: fake websites, apps and devices

Spoofing sells cheap or fake inventory under a premium name. Learn domain, app and device spoofing, and how ads.txt, sellers.json and schain fight back.

Programmatic advertising runs on labels. A bid request tells buyers which website or app the ad will appear on, what kind of device the viewer has, and roughly where they are. Buyers bid more for premium labels: a major newspaper, a top streaming app, a smart TV. But for years nobody checked whether the label was true. Spoofing is lying on the label.

It is like selling tap water in bottles printed with a luxury brand's logo. The buyer at the wholesale market only sees the label, pays the luxury price, and never tastes the water. Spoofing works for the same reason: in an automated auction, the bid request is the label and nobody tastes the water until much later, if ever.

Three kinds of spoofing

Spoofing targets whatever label commands the highest price.
TypeWhat is fakedReal-world example
Domain spoofingThe website name in the bid request, so a junk or non-existent site poses as a premium publisherMethbot (2016) spoofed 6,111 premium domains
App spoofingThe app bundle ID and publisher IDs, so traffic from one app is sold as anotherKonfety (2024) "evil twin" apps posed as decoy apps on Google Play
Device spoofingThe device type, model or operating system, so a phone or server poses as a smart TVPARETO (2021) made Android phones pose as CTV devices

Domain spoofing and domain laundering

In its crudest form, a fraudster simply writes a famous domain into the bid request. A subtler variant, sometimes called domain laundering, sends traffic from a low-quality or fraudulent site but declares a cleaner, higher-value site it controls or pretends to represent. The MRC lists domain laundering and falsified site location as SIVT. Because many buyers built their allow-lists around big publisher names, spoofing let fraud walk straight through the front door.

The economics are brutal. If a spoofed request claiming to be a national news site in the UK or Japan wins at a $10 CPM while the real source would fetch 50 cents, the fraudster keeps the difference on every impression, and the real publisher loses a buyer who believes they already bought that site.

App spoofing: the evil twin trick

In July 2024, HUMAN's Satori threat intelligence team disclosed Konfety. Its operators published about 250 harmless-looking decoy apps on Google Play. Separately, they spread "evil twin" apps through malicious ads outside the store. The twins claimed the decoys' app IDs and publisher IDs when requesting ads, so ad platforms believed the traffic came from legitimate, store-listed apps. HUMAN said Konfety-linked bid requests peaked at 10 billion a day. In 2025, researchers at Zimperium reported a new Konfety variant using deliberately malformed app packages to resist analysis, a reminder that disrupted schemes often return in new forms.

Device spoofing: why everyone wants to be a TV

Connected TV ads often sell at several times the CPM of mobile display, so pretending to be a TV is lucrative. In April 2021, HUMAN, with Google, Roku, The Trade Desk, Magnite, Omnicom and others, disclosed PARETO: a botnet of nearly one million infected Android phones that impersonated streaming devices running Fire OS, tvOS, Roku OS and other TV platforms. HUMAN observed an average of 650 million PARETO bid requests a day, generated by 29 Android apps spoofing more than 6,000 CTV apps.

The industry's answer: a chain of receipts

Because the problem is unverified labels, the fix is verifiable ones. The IAB Tech Lab created three standards that work together, often summarised as "who is allowed to sell, who is selling, and through whom".

  1. ads.txt and app-ads.txt: who is allowed to sell meThe publisher posts a public file (ads.txt on its website, app-ads.txt on the developer site listed in the app store) naming every ad system and account ID authorised to sell its inventory, and whether each is a direct seller or a reseller. A buyer can check that the seller in the bid request is on the list.
  2. sellers.json: who that seller actually isEach SSP or exchange publishes a sellers.json file identifying the businesses behind its seller account IDs, so buyers can see which company they are paying.
  3. SupplyChain object: every hop in betweenThe supplyChain object (schain), carried inside the OpenRTB bid request, lists every intermediary that touched the impression. A buyer can check that each hop matches the ads.txt and sellers.json records.
  4. ads.cert: signing the labelads.cert adds cryptographic signatures so key fields cannot be altered in transit. Adoption has been slow, but it targets exactly the tampering that spoofing relies on.

ads.txt, sellers.json & schain

1/6
▤news.examplepublisher✓ads.txtwho may sell me⇄SSPseller ID 1234▦sellers.jsonwho 1234 is◎DSPthe buyer!Spooferclaims to be news.example★Verified pathbuy with confidence
1
The publisher declares its sellers

news.example posts a public file, ads.txt, listing every company allowed to sell its ads and the account ID it uses, marked DIRECT or RESELLER.

  1. The publisher declares its sellers: news.example posts a public file, ads.txt, listing every company allowed to sell its ads and the account ID it uses, marked DIRECT or RESELLER.
  2. A bid request arrives: The DSP receives a request “for news.example”, sent by SSP account 1234, with a SupplyChain object listing every hop it passed through.
  3. Check 1: is this seller authorised?: The buyer checks news.example/ads.txt: is SSP account 1234 listed? If not, the request is unauthorised and is not bought.
  4. Check 2: who is account 1234?: The SSP’s sellers.json names the business behind 1234 and whether it is the publisher itself or an intermediary. Hidden sellers are a warning sign.
  5. A spoofer tries the same trick: A fraudster sends requests claiming to be news.example from its own junk site. This is domain spoofing. Its seller ID is not in news.example’s ads.txt.
  6. Only verified paths get bought: Requests whose seller, ads.txt entry and schain all line up get bought; the spoofed ones fail. Simple public files closed one of the biggest fraud loopholes of the 2010s.

What detectors check beyond the files

  • Declared vs observed: does the page URL or app bundle seen when the ad renders match what the bid request claimed?
  • Volume sanity: is a small publisher suddenly selling more impressions than its known audience could produce, or through dozens of resellers?
  • Device consistency: does a "smart TV" behave like a TV, with TV-like screen size, network, session length and household patterns, or like a phone?
  • Reseller depth: long chains of resellers are a classic hiding place for laundered inventory, which is why supply path optimization favours short, direct paths.

Key takeaways

  • Spoofing lies about where an ad will run or on what device, so cheap or fake inventory can be sold at premium prices.
  • Domain spoofing (Methbot), app spoofing (Konfety) and device spoofing (PARETO) all exploit unverified bid-request labels.
  • ads.txt/app-ads.txt, sellers.json and schain let buyers verify who may sell, who is selling and every hop in between.
  • Authorisation files cannot prove a human saw the ad, so they must be combined with SIVT detection.

Questions people ask

What is domain spoofing in advertising?

Domain spoofing is when a seller misrepresents the website an ad will appear on, typically claiming a premium publisher's domain for traffic that actually comes from a low-quality or fake site. Buyers pay premium prices for worthless inventory. The MRC classes it as sophisticated invalid traffic. ads.txt, sellers.json and the SupplyChain object help buyers verify that a seller is authorised to sell a domain.

Does ads.txt stop ad fraud?

ads.txt stops some fraud, mainly unauthorised resale and crude domain spoofing, by letting publishers publicly list who may sell their inventory. It does not detect bots, hidden ads or spoofed devices, and it cannot prove a real person saw an ad. It is essential hygiene that works best alongside sellers.json, schain checks and independent SIVT measurement.

What is app spoofing?

App spoofing is when traffic from one app, often malicious or low quality, is declared in bid requests as coming from a different, legitimate app by copying its bundle ID and publisher IDs. HUMAN's 2024 Konfety investigation found evil twin apps impersonating about 250 decoy apps on Google Play. app-ads.txt and in-app measurement through the OM SDK help buyers detect it.

Previous: How bots fake humansNext: Mobile app and CTV fraud