Traffic laundering
Referrer and domain spoofing
The traffic lies about where it came from, naming an approved site as its origin when it really started somewhere else.
How it works
When a visit arrives, it carries a note saying which page it came from (the referrer) and the feed request names the site showing the ads. Both notes can be falsified. Referrer spoofing rewrites the origin of the click; domain spoofing declares a respectable site as the place the ads are shown.
It is the digital version of relabelling goods: the crate says "Product of Italy" and the contents came from elsewhere. Search engines approve partners domain by domain and source by source, so a false label lets unapproved traffic be paid as though it were approved. Microsoft called the practice click laundering when it sued over it in 2010.
Who pays for it
Advertisers, who believe their ads ran on a reviewed site. The approved site or partner whose name was used may be blamed and penalised. The feed provider carries the clawback.
Who does it, and why
Sub-publishers and traffic sellers without approval of their own, and fraud operators who need a clean name to cash out.
Warning signs
- Traffic volume attributed to a site that is far larger than the site's real audience.
- Referrers that do not match the pages where the ad or link actually appears.
- Requests for one domain coming from pages or apps that are not that domain.
- Missing or blank referrers at unusually high rates.
Defences
- Verify the declared page against what the browser itself reports, on the page, at the moment of the request.
- Compare claimed volumes with independent audience estimates for the named site.
- Authorise sellers explicitly (the idea behind ads.txt) and reject unlisted ones.
- Pass honest source data to the feed; never rewrite referrers, even to "tidy" tracking.
An example
Real case (alleged): Microsoft's May 2010 lawsuit described invalid clicks, generated by malware and scripts, being made to appear to come from a legitimate publisher in its ad network. Microsoft spotted it through unusual click patterns on two sites and said the losses could have reached hundreds of thousands of dollars.
Documented cases
- Microsoft click-laundering lawsuit (2010): Click laundering: invalid clicks disguised as coming from a legitimate publisher
- Clickbot.A (2006): Botnet click fraud aimed at syndicated search engines