Cloaking vs Smart Landing Pages

Sep 18, 20269 min read1,685 words

On a whiteboard they are the same diagram: inspect the request, pick a destination. In a policy review they are nothing alike, because one serves everyone a variant of the same offer and the other serves two different pages. Here is where the line sits, what each costs, and how to decide.

1. Identical diagrams, different things

Draw both on a whiteboard and you get the same picture. A request arrives, something inspects it, and the visitor is sent to one of several experiences. Vendors in both categories use the same words — segmentation, routing, personalisation, dynamic destinations — which is why buyers end up believing they are variations on one technique.

They are not, and the distinction is simple once stated:

  • A smart landing page shows every visitor the same offer, adapted. The headline changes, the hero image changes, the currency and testimonials change. The product, the price, the claims and the terms are constant. Anyone auditing it sees a variant of what everyone else sees.
  • Cloaking shows different visitors materially different content. The filtered segment sees a compliant page; the audience sees the offer. They are not variants of each other. They are two pages with two purposes.

That is the whole difference, and every practical consequence — which policy applies, what it costs to run, what happens when you are caught, what you can say about it publicly — follows from it.

2. How each one actually decides

The mechanisms diverge in what they look at, and the gap tells you how much engineering each requires.

Smart landing pages

Personalisation engines read signals the visitor volunteers: UTM parameters, referrer, coarse geo from IP, device class, language headers, and whatever your CDP already knows about a returning session. Those signals are cheap, stable and uncontested — nobody is trying to spoof them, because there is nothing to gain. The decision usually resolves in a few milliseconds against a rules table or a feature flag, and the output is content substitution inside one document.

The engineering problem is measurement, not detection. You need statistically sound experiments, variant tracking that survives a session, and enough traffic to reach significance before the campaign ends.

Cloaking

A filter has to decide something the visitor is actively trying to hide, so it cannot rely on volunteered signals. It reads ASN ownership and datacenter classification, TLS cipher and extension ordering, HTTP/2 settings, header sequence, canvas and WebGL entropy, automation traces, and behavioural timing. It needs classifications for thousands of network ranges — we maintain 14,208 — and a model retrained weekly as the other side changes. The full path is in how ad cloaking works.

The engineering problem is adversarial. Your counterparty updates, so a filter that is not maintained decays — and unlike an A/B test, the cost of being wrong is not a lost experiment, it is a lost account.

3. Where platform policy draws its line

This is the part worth being precise about, because it is where most of the money is won or lost.

Every major platform prohibits cloaking by name. The Meta, Google and TikTok policies use close to the same formulation: concealing or misrepresenting the destination, or showing reviewers content that differs from what users see. The operative test is not "did content vary by visitor" — it is did the content shown to the platform's review process differ materially from the content shown to users.

Read that test against the two mechanisms and the result is unambiguous. A smart landing page that swaps a headline for German visitors passes it: a reviewer sees the same product, the same price and the same claims as everyone else, in a variant. A filter that serves reviewers a wellness blog and buyers a supplement offer fails it, because the difference is the entire point.

The grey band, and how to think about it

Between those poles sits real ambiguity, and pretending otherwise does not help anyone:

  • Geo-gating where the offer is unavailable in a region, so visitors there get an informational page. Defensible — it is a different offer, not a hidden one.
  • Blocking known scrapers and competitive-intelligence bots while serving everyone else normally. Common, widely tolerated, and not about reviewers.
  • Age or eligibility gating ahead of a regulated offer. Usually required of you, not prohibited.

A practical test that holds up better than any vendor's framing: could you explain this configuration to the platform's policy team without embarrassment? "We route EU visitors to an informational page because we are not licensed there" survives that question. "We route anyone who looks like a reviewer to a page about something else" does not. The cloaking safety guide turns that test into a pre-launch checklist.

4. What each one costs to run

Licence price is the smallest line item in both cases, which is not how either is usually sold.

Smart landing pages

A personalisation tool runs $0 to a few hundred a month at the volumes most advertisers work at. The real cost is content: every segment you add is another headline, another hero, another set of testimonials to write and keep current. Teams routinely build twelve variants, maintain three, and quietly serve the default to everyone else. Ongoing engineering is close to zero — the signals do not move.

Cloaking

Tooling runs $100 to $600 a month. On top of that:

  • Safe-page production. A page thin enough to be obvious is worse than no filter at all. Credible ones take real work, which is why generators exist — 50+ niche templates against a hand-built site each time.
  • Domain and hosting overhead. Separate domains with their own history, kept warm.
  • Monitoring. Someone has to watch approval rates, bypass rates and reviewer-block counts, and act on them. This is where rotation automation earns its keep — a variant pulled at 02:00 on a Sunday rather than at 09:00 on Monday is the difference between two minutes of exposure and a day of it.
  • Tail risk. The honest line item. Accounts do get lost, and a warmed account with history is worth considerably more than the spend sitting in it.

A fair comparison is not $200 a month against $50 a month. It is the full operating cost plus the expected value of losing an account, against a cheaper tool that cannot do the job at all if the job genuinely requires two pages.

5. Choosing, honestly

Work through it in this order. It takes about five minutes and saves a lot of argument.

  1. Would a reviewer approve your actual offer page? If yes — and for most legitimate businesses in unremarkable verticals, yes — you do not need a filter. Use personalisation, spend the budget on the offer, and stop reading.
  2. If no, why not? This is the question that matters. "Our vertical is restricted and compliant advertisers are caught by a blunt classifier" is a different answer from "our claims would not survive review". The second is not a cloaking problem; it is a product problem, and a filter postpones the reckoning while raising the cost of it.
  3. Is the asymmetry geographic or regulatory? If the offer is genuinely unavailable to a segment, you are gating availability rather than hiding content. That is defensible, cheaper, and explainable.
  4. Can you fund the whole operation? Filter plus credible safe pages plus domains plus monitoring plus the account you may lose. Half-funded is the worst outcome: you carry the full risk and get a fraction of the protection.

Most buyers who arrive asking for cloaking need creative-layer masking and a better safe page, not an adversarial traffic filter. Those are separable: masking your creative so a previously-flagged asset is not matched on a new account is a different intervention from serving reviewers a different page, and it carries different risk.

6. Using both at once

They are not alternatives, and the strongest setups we see run both for different reasons.

Personalisation does the commercial work on the offer page: currency, language, social proof matched to the segment, headline matched to the ad that was clicked. Every visitor who reaches it is a real visitor, and every one of them sees a variant of the same honest page. That is where conversion rate comes from.

The filter does one narrow job in front of it: keep scrapers, competitive-intelligence bots and automated harvesters out of a page you are spending money to drive traffic to. Between those sits the creative layer, which is about neither — it stops an asset flagged on one account from being matched on the next, regardless of what either page contains.

Run that way, each layer is doing something you could describe out loud. That is the test worth keeping.

7. Side by side

Everything above, compressed:

  • Content shown — personalisation: one offer, adapted. Cloaking: two materially different pages.
  • Signals read — personalisation: volunteered (UTM, referrer, geo, device). Cloaking: contested (ASN, TLS ordering, rendering entropy, automation traces, timing).
  • Adversarial? — personalisation: no, signals are stable. Cloaking: yes, requires continuous retraining.
  • Platform policy — personalisation: permitted and encouraged. Cloaking: prohibited by name on every major platform.
  • Primary cost — personalisation: content production. Cloaking: safe-page quality, monitoring, and account tail risk.
  • Failure mode — personalisation: a variant underperforms. Cloaking: the account is gone.
  • Can you explain it publicly? — personalisation: yes. Cloaking: only for the narrow, defensible configurations.

If your honest answer to the last line is no, that is the finding. It does not automatically mean stop — it means the operational discipline has to be real, which is what the safety guide covers.

Signal report

Get the reviewer-signal teardown

A short, specific email twice a month: what changed in platform review, which creative signatures started getting matched, and the thresholds we moved in response. No drip sequence, one click to leave.

Stored in the EU, never sold or shared. Unsubscribe link in every email.