Cloaking Safety Guide

Sep 27, 202611 min read2,122 words

Almost nobody loses an account because the filter failed. They lose it to a thin safe page, a reused creative, a threshold nobody tuned, or a burning variant left up overnight. This is the operational discipline that prevents each one — including the eleven checks we ask buyers to run before launch.

1. What actually kills accounts

Almost nobody loses an account because a filter failed. The filter is the part people obsess over and the part that least often breaks. Accounts die for duller reasons, and knowing the real distribution changes where you spend effort.

From what we see across the platform, in rough order of frequency:

  1. A thin safe page. The filter worked, the reviewer was correctly identified, and the page they landed on was a template with placeholder text and a dead contact form. Correctly routing someone to an obviously fake page is worse than not routing them at all.
  2. Creative reuse across accounts. The same asset, previously actioned, uploaded to a fresh account. The account is new; the fingerprint is not. This is the problem creative masking exists for and the one most setups ignore entirely.
  3. Complaint and refund rate. Nothing in a cloaking stack touches this. If buyers feel misled after purchase, the enforcement comes from the payment and complaint side and no amount of routing helps.
  4. Mismatch between ad and destination. Not a policy subtlety — a reviewer clicks an ad about one thing and lands on something unrelated. Easy to catch and easy to fix.
  5. Leaving a burning creative up. Signals accumulate for hours while nobody is watching, and a recoverable situation becomes a permanent one.
  6. Running something prohibited. Covered at the end, and it is not a tooling question.

Four of those six are operational discipline rather than technology. That is the argument of this guide.

2. Start with what you will not run

The first safety decision is a scope decision, and it happens before you touch any configuration.

We refuse malware and unwanted-software distribution, phishing and credential harvesting, payment fraud and unauthorised charging, counterfeit goods, and anything targeting minors. That is checked at signup and enforced on detection — eleven accounts closed under it in the last twelve months. It is written into the acceptable use policy because it is enforced, not because it reads well on a marketing page.

Beyond our list, you need your own. Write down the categories you will not take, including the ones that are technically permissible but would not survive a journalist reading your funnel. The useful property of a written list is that it decides for you at the moment you are most tempted to make an exception — when a client with budget asks.

Then apply the test from cloaking versus smart landing pages: could you explain this configuration to the platform's policy team without embarrassment? If the answer is no and the reason is the offer rather than a blunt classifier, the tooling is not your problem.

3. Safe-page quality is the whole game

Since the most common failure is a thin safe page, this deserves more attention than the filter settings and almost never gets it.

A safe page that survives a human reading it has:

  • Depth. An About page, a working contact route, a privacy policy, terms, and a populated archive or catalogue. Five or six real pages, not one.
  • Topical fit with the ad. If the creative is about joint supplements, the safe page is a health publication — not a generic SaaS template. Reviewers read the ad first.
  • History. A domain registered last Tuesday with no crawl record is a signal by itself. Let pages be indexed and age before you point spend at them.
  • Function. Forms submit. Links resolve. Images load at their declared dimensions. Nothing throws a console error.
  • No tell-tales. No lorem ipsum, no unreplaced {{placeholder}} tokens, no stock photo that reverse-searches to a template gallery, no copyright year three years stale.

The generator produces these from a niche prompt across 50+ templates, and you edit before publishing. Budget an hour per page on the edit rather than ten minutes. The strongest position is a safe page that is a genuinely useful page for the audience it claims to serve — at which point much of the risk in the model simply goes away, because there is nothing to catch.

4. Setting the threshold, and both ways to get it wrong

The filter emits a score and you choose where to cut. Both directions have a cost, and the instinct to maximise one side is how people lose money.

Too permissive and reviewers reach your offer. This is the failure everyone fears and it ends accounts.

Too aggressive and real customers get the safe page. This is the failure nobody notices, because it looks like weak campaign performance rather than a misconfiguration. A threshold that routes 8% of genuine mobile traffic to an article about wellness is quietly destroying your return, and you will blame the creative.

Practical approach:

  1. Start conservative — filter only high-confidence datacenter and known-crawler traffic.
  2. Watch the bypass rate in analytics for a few days. If it sits far from the share of traffic you would expect to be automated, your threshold is wrong in whichever direction the gap points.
  3. Tighten in small steps, one signal family at a time, and give each change 48 hours of data.
  4. Watch conversion rate on the audience side as you tighten. A fall there with stable click-through means you are filtering customers.

Threshold stays your parameter rather than ours precisely because the right trade-off depends on the vertical and on what the account is worth to you.

5. Geo, ASN and device rules that do not backfire

The rule builder goes down to city, ASN, carrier, OS build and screen class. That is enough rope to hang a campaign with, so a few patterns worth avoiding.

Do not filter by country when you mean by availability

Blocking a whole country because reviewers are headquartered there also blocks that country's customers. If the offer genuinely is not available somewhere, gate availability and say so on the page — that configuration is explainable, and it is the one in the grey band that holds up.

Treat datacenter and residential proxies separately

They are not the same population. Datacenter ranges are mostly automation. Residential proxy exits include real people on privacy tooling and real customers in regions with aggressive carrier NAT. Score them separately — we classify 14,208 ASN ranges for exactly this reason — and do not apply one verdict to both.

Avoid rules that encode a single reviewer

A rule tuned to one observed reviewer fingerprint is overfitting. It survives until that environment is updated, which happens constantly, and meanwhile it adds false positives you cannot see. Prefer the model's score to a hand-written exception.

Keep the rule set small enough to explain

Forty overlapping rules nobody can reason about is a liability during an incident. If you cannot say what fires in what order, you cannot debug it at 02:00 — and you will need to.

6. Rotation thresholds and the overnight case

Every creative has a working life, and the end of it is visible before it is formal: delivery slows, review latency rises, cost per result drifts.

Run four variants per creative, weighted by click-through, with at least one genuine standby — a variant masked from a different source asset, not a re-export of the live one. A standby that shares a fingerprint family with the burning creative is not a standby.

Set the promotion threshold low enough to act on the second or third signal rather than the fifth. Promotion takes about 90 seconds, so the cost of being early is small and the cost of being late is the account. One operator attributes $38,740 of saved spend to a single promotion that fired at 02:00 on a Sunday and finished before anyone woke up.

Check the rotation log weekly even when nothing fired. A variant that never wins traffic is telling you something about the masking profile or the creative itself.

7. Keep records you can hand over

If a platform asks what a reviewer saw, "I think they got the safe page" is not an answer. A timestamped log is.

Every routing decision records the rule that fired, the score it produced and the page it served, and the log is exportable. Keep those exports somewhere outside the dashboard, with the campaign and creative IDs alongside, for at least as long as the campaign plus ninety days. Also keep the before and after hashes for every masked creative — they are in the job record — so you can show a specific asset was not a reupload of a previously actioned file.

Two reasons this matters beyond appeals. It makes your own debugging possible, which is most of its day-to-day value. And a stack that cannot produce a record of its own decisions is a stack you do not actually understand.

8. Eleven checks before a campaign goes live

This is the list we ask buyers to run. It takes under an hour and catches most of what the first section listed.

  1. Read your own safe page end to end as if you were the reviewer. Every link, every form.
  2. Search the safe page for template residue — lorem, placeholder tokens, unedited headings, a stale copyright year.
  3. Confirm topical fit between the ad creative and the safe page subject.
  4. Check the safe-page domain has crawl history and is not freshly registered.
  5. Compare source and masked creative side by side at full size. If you can see the difference, so can your audience.
  6. Verify the hash moved. The job record shows before and after; a small delta means the profile is too conservative for the asset.
  7. Confirm the creative is not a reupload of something actioned on another account without being re-masked.
  8. Test the masked link from a real phone on mobile data — not a desktop browser, not wifi. Confirm you reach the offer, not the safe page.
  9. Review the active rule set and delete anything you cannot explain.
  10. Confirm at least one standby variant exists and that it came from a different source asset.
  11. Set the rotation threshold and confirm notifications reach somewhere a human reads at 02:00.

Check 8 catches more live problems than the other ten combined. Test from the device your customers use.

9. When something goes wrong

Order matters here, and the instinct to delete everything is the wrong one.

  1. Pause spend on the affected creative. Not the account — the creative.
  2. Export the decision log for the relevant window before anything rotates out of it. This is the step people skip and regret.
  3. Look at what was actually served. The log says which page each request received. Often the answer is that a reviewer got the offer because of a rule change somebody made and did not record.
  4. Fix the cause, not the symptom. Promoting a standby around a misconfigured threshold buys you a few hours and the same outcome.
  5. If you appeal, appeal with the record. Specific, timestamped and checkable beats a narrative.
  6. Write down what happened. Most second incidents are the first one repeated by someone who was not there.

10. The limits worth saying out loud

Masking is a window, not immunity. Hash families and reviewer models are retrained on the other side too. Anyone selling permanence is selling something they cannot deliver.

Nothing here fixes complaint rate. If buyers feel misled after purchase, enforcement arrives from a direction no filter touches.

Responsibility does not transfer. We sell traffic-filtering and creative-management infrastructure. Which campaigns are permissible on Meta or Google is your judgement and your liability, and the terms say so in plain language rather than burying it.

We will close your account if you run what is on the refusal list. That is not a formality — it is the single clearest thing we can say about what this platform is for.

If the mechanics underneath all this are still fuzzy, how ad cloaking works is the one to read next.

Signal report

Get the reviewer-signal teardown

A short, specific email twice a month: what changed in platform review, which creative signatures started getting matched, and the thresholds we moved in response. No drip sequence, one click to leave.

Stored in the EU, never sold or shared. Unsubscribe link in every email.