Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Fraud & invalid traffic · also called Referer spoofing, Fake referrer

Referrer spoofing

Referrer spoofing is faking the information that says which page a visitor came from, to make low-quality traffic appear to come from a trusted source.

The short answer, from the The Arbitrage Desk glossary

When a browser moves from one page to another, it normally passes along a "referrer": the address of the page the visitor just left. Trackers, feed providers and fraud filters use it to understand where traffic originates.

Referrer spoofing replaces the true origin with a false one. Visits that really came from a pop-under network or a bot script arrive labelled as if from a search engine, a social app or a quality publisher. In search arbitrage this is used to slip unapproved traffic past traffic source approval, or to strip the referrer altogether so nobody can tell.

Signs include referrers that do not match the Click ID or UTM parameters on the same visit, a "social" visitor whose browser is not the app's in-app browser, large volumes with a blank referrer, and upstream pages that do not actually link to the lander.

Google's RSOC rules require parameters to be accurate and complete, and declaring a false upstream source or creative is itself a violation. Defence is cross-checking: compare the referrer with the paid click records from the traffic source and with on-page signals.

Think of it like this

It is a forged postmark on an envelope, so a letter posted from a back alley looks as if it came from head office.

Related terms

Sources: Google AdSense Help: Related search for your content pages, MRC Invalid Traffic Detection and Filtration Standards Addendum (June 2020 update)