Is Cloaking Illegal? Ad Network Rules, FTC Risk & the Honest Answer
Cloaking sits in a legal grey zone — but the deception it conceals usually doesn't. What the law actually says, why every ad network bans it, how it gets detected, and what the ban-cycle economics really look like.

Cloaking — showing an ad network's reviewers a compliant page while sending real users somewhere else — is not, in most jurisdictions, a crime by itself. But that answer is misleading comfort. Cloaking violates every major ad platform's policies without exception, voids your contracts with networks and affiliate programs, and when it hides deceptive claims, fake endorsements or billing traps, it becomes evidence of intent in consumer-protection enforcement. The honest answer: the technique lives in a legal grey zone; what it is used to hide usually does not.
What cloaking actually is#
Ad cloaking is deliberate split delivery: one version of a page for the people who police ads, another for the people who see them. The mechanics are mundane — the cloaker fingerprints incoming traffic by IP range, user agent, referrer, headless-browser signals and behavioral tells, then routes suspected reviewers to a clean "white" page and everyone else through a redirect chain to the real "black" offer.
Equally important is what cloaking is not. Geo-targeting that shows Germans a German page, honest A/B tests, mobile-specific layouts, and logged-in personalization all show different content to different people — legitimately. The line is intent: if the network's reviewer, seeing exactly what they are meant to police, would approve what your users see, you are targeting. If the setup exists so the reviewer never sees what users see, you are cloaking.
The legal answer#
There is no statute titled "cloaking" in the US, EU, UK or Australia. Legal exposure arrives through what the cloak conceals and enables:
- Consumer protection law. The FTC Act prohibits deceptive acts and practices in commerce — the FTC's enforcement authority covers the misleading claims, fake endorsements and billing tricks that cloaked funnels typically hide. In enforcement actions, the cloak itself reads as consciousness of guilt: you built machinery specifically to avoid scrutiny.
- Fraud statutes. Where a cloaked funnel is part of a scheme to obtain money by deception — fake billing, impersonation, counterfeit goods — prosecutors have ordinary fraud tools available. The cloak is how the scheme stayed live long enough to matter.
- Trademark and publicity claims. Cloaked funnels that impersonate brands or fabricate celebrity endorsements invite civil suits that do not care whether cloaking is "illegal" — the impersonation is the offense.
- Contract law. Every network's terms prohibit deceptive delivery. Cloaking voids the agreement, which is the legal basis for confiscated ad balances and withheld affiliate commissions. Nobody sues to recover money forfeited under terms they deliberately breached.
The picture is similar outside the US. The EU's unfair commercial practices rules and the UK's consumer protection regime both prohibit misleading commercial practices in terms broad enough to cover what cloaked funnels deliver, and platform-accountability rules keep pushing networks toward more aggressive policing of deceptive advertisers on their inventory. Nowhere does the technique enjoy a safe harbor.
None of this is legal advice — if you are assessing real exposure, pay a lawyer, not a forum. But the pattern in public enforcement is consistent: regulators charge the deception, and the cloaking features as evidence of how deliberate it was.
The platform answer: banned everywhere#
On the platform side there is no grey zone at all. Google Ads bans cloaking explicitly under its misrepresentation policies; native networks prohibit deceptive redirection and misrepresenting destinations in their advertiser terms (check each network's current documentation for exact language). Affiliate networks and payment processors carry parallel prohibitions.
The consequences ladder is also consistent across the industry:
- Campaign rejection, then account suspension — usually permanent, with balances forfeited.
- Entity-level bans: payment instruments, domains, business identities and lookalike accounts flagged together.
- Offer-side fallout: affiliate networks void unpaid commissions and terminate on evidence of cloaked traffic.
- Reputational flow-through: publishers and networks share fraud signals, so one detection propagates.
The pattern worth internalizing: platforms don't have to prove anything to anyone. A network can terminate on suspicion under its own terms, keep the balance, and move on — no discovery, no regulator to appeal to, no precedent to argue. Contract enforcement is the fastest and most certain of every exposure on this page.
Why people cloak anyway — and why the economics fail#
Cloaking persists because restricted verticals dangle payouts that compliant review would never approve. The pitch is always the same: one profitable window before detection. The reality is an arms race with recurring costs — cloaking tools, disposable accounts, aged domains, fresh payment instruments — stacked against detection that has compounding advantages. Networks re-check live campaigns from clean residential IPs and real devices on schedules you cannot predict; complaint volume scales with your spend; and the more a campaign profits, the more scrutiny it attracts. The steady state is not "cloak and collect" — it is a treadmill of burned infrastructure where the setup tax eats the margin the cloak was supposed to protect.
There is also a quieter cost: everything a cloaked operation builds is disposable by design. No pixel seasoning, no retargeting audiences, no account history earning better treatment from the network, no brand a customer could return to. The compliant buyer's assets compound while the cloaker's reset to zero on every detection — which means the two are not running the same business at different risk levels; they are running different businesses entirely.
How cloaking gets caught#
Detection is multi-layered, which is why confident cloakers still get swept:
- Clean re-review. Post-approval checks from residential IPs, mobile devices and varied geos that look nothing like a data-center reviewer.
- Complaint signals. Users who got the "black" page file reports the reviewer's "white" page cannot explain.
- Rhythm analysis. Funnels that die and reappear under fresh domains at the same publishers leave a cadence that detection systems learn to recognize — the resurrection pattern is itself a signal.
- Brand-protection monitoring. Brands hunt copycat landing pages and fake endorsements, and their takedown teams report the whole chain — anyone can report a scam ad with evidence attached.
- Independent capture. Transparency indexes photograph the ecosystem continuously. OpenAdLibrary captures native ad creatives together with their click chains and landing pages — over 1.3 million landing captures across 49 networks (June 2026) — creating auditable, timestamped evidence of what actually served. Cross-geo, cross-device capture is exactly the comparison that exposes cloaked funnels, and it is public record via ad intelligence tools rather than a network's private logs.
Flagged but not cloaking? Fix the signals#
Legitimate advertisers occasionally trip cloaking detection without deceptive intent, because some setups look like split delivery from the outside. The usual culprits: geo-redirects that send the reviewer's location somewhere unrepresentative, tracker redirect chains through low-reputation domains, landing pages that vary aggressively by device, and destination URLs that change after approval. The fixes are unglamorous but effective — keep the reviewed URL and the served URL identical, shorten and stabilize your redirect chain on a clean tracking domain, make geo and device variants honest renditions of the same page rather than different funnels, and resubmit for review after any destination change instead of swapping silently. If your funnel would survive the reviewer seeing any variant of it, you have a false-positive problem, not a cloaking problem — and false positives are fixable with hygiene.
What to run instead#
The compliant version of almost every cloaked play exists. Aggressive-but-honest advertorials pass review when claims are substantiated and FTC disclosure rules are followed. A well-built pre-lander manufactures the intent that cloakers try to shortcut. And the research edge cloaking chased — knowing which angles actually sustain spend — is available by studying long-running compliant funnels in the open index instead of gambling an entity on a ban cycle.
Cloaking is not "illegal" the way theft is illegal. It is worse positioned than that: a guaranteed contract breach and platform ban, wrapped around activity that frequently is illegal, documented by an ecosystem that now keeps receipts.






