You’ve directed traffic, opened the offer from your IP — everything looks clean. But a week later, your account gets banned for “prohibited content” that you’ve never even seen. This is a classic scheme where the affiliate program or the advertiser shows you one page while a real user from another geo sees a completely different one. Let’s figure out how to detect such substitution in 15 minutes using proxies and an anti-detect browser.
What is Cloaking and Why Do Affiliates Hide It From You
Cloaking is a technique where the server shows different content to different visitors based on their IP, User-Agent, referrer, or other parameters. It was originally devised to bypass moderation in Facebook Ads, Google Ads, and TikTok Ads: a safe “white” page is shown to the moderator, while a real user sees an aggressive offer (gambling, nutra, dating with deceptive promises).
The problem is that cloaking can sometimes work against you, the arbitrageur. The affiliate program may show you (from your usual working IP) one landing page for quality checks, while the traffic from your purchased ads sees something completely different: with another offer, different payouts, or even a dead page without a lead capture form. You’re pouring budget, seeing conversions in the affiliate interface, but can’t understand why the ROI doesn’t match what the ad platform shows.
The second scenario is that the affiliate program cloaks geo-targeting: it promises an offer for the USA, but in reality, part of the traffic from Tier-1 countries is redirected to a cheap default landing page because there are no real offers for a specific state or city. You pay for traffic as if it’s premium geo, but receive a regular placeholder.
The third scenario involves substitution by device. The affiliate program shows you, the checker on desktop, a clean desktop version, while mobile users (the main source of traffic in Facebook Ads and TikTok Ads) are redirected to a suspicious push dump or APK installation. If this comes up during the moderation of the ad account — it’s you who gets banned, not the affiliate program.
Why It’s Beneficial for Arbitrageurs to Check Offers Themselves
Many direct traffic “on trust” — they open the offer in a regular browser, see an adequate landing page, and launch the campaign. But moderators from Facebook, Google, and TikTok check ads specifically from the IPs, UA, and geos indicated in the campaign targeting. If the affiliate program cloaks specifically for these parameters, showing a “clean” version, while actually running something different for users — the advertiser's account gets banned, not the domain owner’s.
Self-checking through proxies from different geos solves three tasks simultaneously: you see the real landing page of the end user, you can catch the offer substitution for the required geo, and you document evidence (screenshots, network request logs) in case of a dispute with the affiliate program over unpaid commissions.
For such checks, you need not just any proxies, but specifically those that correspond to the real traffic of the target audience. Data center IPs are often detected by anti-fraud systems and cloakers as “non-target” traffic, so for an honest check, it’s better to use residential proxies — they look like regular home connections and provide a real picture of what a live user will see.
Check 1: Comparing Landing Pages by IP from Different Countries
The most basic check is to open the same offer link with IPs from three to five different countries included in your targeting. Don’t just take the “main” geo of the campaign, but also neighboring ones: if the campaign is set for the USA, check Canada and the UK as well — often the cloaker distinguishes them differently.
Practical scheme: open an anti-detect browser (Dolphin Anty, AdsPower, or Octo Browser will do), create a profile with a residential IP from the desired country, clear the cache, open the offer, and take a full screenshot of the page plus a record of the source code via “View Page Source.” Repeat for each geo in a separate profile — this is important because if you use the same browser without changing the fingerprint, the cloaker may recognize the repeat visit and show a cached “safe” version.
If the landing pages visually and in code match — everything is clean. If at least in one country a different offer appears, a form with different fields, or a redirect to a third-party domain — this is a signal of geo cloaking, and it’s better not to launch the campaign in that geo until clarifying the reasons with the affiliate manager.
Check 2: Substitution by User-Agent and Device Type
The cloaker often looks not only at the IP but also at the combination of IP + User-Agent + request headers. Checking the IP without changing the User-Agent won’t reveal anything if the cloaking script is set up specifically for that combination of parameters. Therefore, as a second step, change the User-Agent within the same anti-detect profile, keeping the IP the same: try different versions of Chrome, Safari on iOS, Samsung Internet on Android.
It’s also worth checking the Accept-Language header — sometimes the script relies on the browser language rather than the geo IP, showing different content to a user with an English interface and one with the local language of the country. This is especially critical for dating and nutra offers, where the landing page text is tightly tied to localization.
For checking via API or developer extensions in the browser, you can look at the raw request and response headers — if the server delivers different HTML for identical requests except for the User-Agent, this is direct evidence of device cloaking.
Check 3: Checking Referrer and Source of Traffic
Many cloaking scripts look at the Referrer header — where the user came from. If the transition is made directly via the link in the address bar (without a referrer), the script may show a “white” page specifically for cases of direct access by moderators. But if the referrer points to facebook.com or tiktok.com — it delivers the real offer.
To check this, you need to simulate a transition from the ad platform. The easiest way is to create a test ad with a minimal budget, open it in the feed through the same anti-detect profile, and click on it instead of pasting the link directly. This way, the referrer will be realistic, and you will see exactly what real viewers of the ad will see.
Compare the result of this click with the result of directly opening the same link without a referrer in a neighboring tab of the same profile. A difference in content is a clear sign that the affiliate or advertiser is hiding the real offer from direct accesses, that is, specifically from your check.
Check 4: Mobile Traffic vs Desktop
Facebook Ads and TikTok Ads are primarily mobile traffic, but arbitrageurs often check offers from a working desktop. The cloaker can easily distinguish the type of device and may show a clean page to the desktop, knowing that moderation and quality control usually occur from the computers of ad managers.
For an honest check, you need mobile IPs and a mobile device emulator. For this, mobile proxies are suitable — they provide real IPs from mobile operators, which the cloaker perceives as genuine mobile traffic, unlike desktop residential or data center IPs with a mobile User-Agent without a real mobile route.
In the anti-detect browser, set up a profile emulating an iPhone or Android device, connect a mobile proxy from the desired country and operator, and open the offer as a real user from the TikTok feed would. If the content differs from the desktop version — take a screenshot and proceed to the next check to understand the scale of the substitution.
Check 5: Time of Day and Frequency of Visits
Some cloaking systems limit the number of displays of the “real” offer per IP per day or activate cloaking only during certain hours — when moderators are less active. Therefore, one check in the morning is not enough: repeat the offer opening from the same IP in the evening and at night according to the local time of the target country.
It’s also worth checking the behavior during repeat visits from the same IP within a short time — five, ten, fifteen minutes. If on the third visit within an hour the content suddenly changes to a “safe” placeholder — this is protection against repeated checks by bots and automatic quality control scripts, and you need to make pauses between checks to avoid revealing yourself as a checker.
Document the time of each check in a separate table — this will be useful if you need to prove to the affiliate program that there is systematic content substitution, not a random server error.
Check 6: Clean Profiles Without History and Cookies
If you check the offer in a browser where cookies from previous visits to this domain are already set, the cloaker may identify you as a “known” visitor and show the same content as the first time — even if you’ve changed the IP. This creates a false sense that everything is clean, while the real reason is that the system simply remembered your fingerprint.
The correct scheme is to create a separate clean profile in the anti-detect browser for each new check with a unique canvas, WebGL, font, and timezone fingerprint corresponding to the geo of the proxy. This is exactly what Dolphin Anty, AdsPower, GoLogin, Multilogin, and Incogniton are designed for — they automatically generate dissimilar digital fingerprints so that the cloaker sees a “new” unique user each time, not the same browser with a different IP.
After checking, don’t forget to delete test profiles or at least clear their local storage — some scripts save tags in LocalStorage and IndexedDB, which survive a simple cookie clear through browser settings.
Check 7: Anti-Detect Browser + Multiple Proxies Simultaneously
To avoid spending hours on sequential checks, it’s wise to open five to seven anti-detect browser profiles simultaneously, each with its own proxy: two to three geos on residential IPs, one on mobile, and one on data center for control. This will immediately show whether the cloaker distinguishes the type of proxy — some cloaking scripts specifically ban known ranges of data center IPs, suspecting them of being bots and parsers, and serve them a default safe page instead of the real offer.
If the landing page looks different on the data center IP than on the residential one from the same country — this is not always cloaking against you, often it’s just the advertiser's site protecting itself from clicks and automatic parsing. But for the purity of the experiment and to get a real picture, it’s better to focus on residential and mobile proxies, using data center ones only as a control group for comparison.
Such parallel launches take 20-30 minutes and provide a complete map: where the content matches, where it differs, and by which specific parameter (IP, UA, referrer, or proxy type) the display separation occurs.
Check 8: Automatic Monitoring of Landing Page Changes
A one-time check before launching a campaign does not protect against the affiliate program changing the cloaking logic a week after traffic starts, when you’ve already spent the budget. Therefore, if the offer works for a long time and brings a significant volume of conversions, it’s worth setting up periodic automatic checks — once a day or every other day, a script (or monitoring service) opens the landing page from several pre-configured geos and compares the HTML code with a saved reference version.
For such monitoring, a full-fledged anti-detect browser is not needed — a simple script with rotation through a pool of proxies that makes requests, saves responses, and sends notifications upon significant discrepancies is sufficient. It’s important to use proxies with real geography from the required countries; otherwise, the monitoring will check the wrong geo where the traffic is directed, and discrepancies will go unnoticed until the ad account is banned.
Such constant control is especially important for long-running campaigns in Google Ads and Yandex.Direct, where the moderation cycle is longer, and the affiliate program can technically “wait” until the advertiser relaxes, and activate cloaking later when the likelihood of a repeat check from your side is minimal.
Table: Which Proxies Are Needed for Which Check
| Type of Check | Recommended Proxy | Why |
|---|---|---|
| Geo Comparison | Residential Proxies | Look like real home IPs, not blocked as suspicious |
| Mobile Traffic | Mobile Proxies | Real IP from mobile operators, matches traffic from TikTok and Facebook |
| Control Check for Protection | Data Center Proxies | Fast and cheap, convenient for frequent automatic monitoring |
| Automatic Daily Monitoring | Residential + Data Center in Pair | Comparison shows whether the cloaker distinguishes the type of IP |
Checklist Before Launching a Campaign
Check the offer against these points before pouring traffic:
- The landing page has been opened from residential IPs of at least three targeting countries
- The check has been repeated from a mobile profile and mobile proxy
- The result has been compared with the referrer from the ad platform and without it
- The check has been done at different times of the day (morning, evening, night)
- Each check was done in a separate clean profile of the anti-detect browser
- Screenshots have been taken and the source code of the page saved for each case
- A control check has been launched via a data center IP for comparison
- Periodic monitoring has been set up if the campaign will run longer than a week
Conclusion
Cloaking from the affiliate side is not a conspiracy theory, but a real practice that arbitrageurs encounter in Facebook Ads, TikTok Ads, and Google Ads almost every month. The difference between what is shown to you and what the end user receives can cost you your account, budget, and reputation with the ad platform. The eight checks from this article — comparing by geo, device, referrer, time, and type of IP — cover most substitution scenarios and allow you to catch cloaking before it costs more than the price of the check itself.
For regular checks of offers, it’s wise to keep several types of IPs on hand: for simulating a regular user, residential proxies are suitable, for mobile traffic from ad campaigns — mobile IPs, and for quick automatic monitoring of landing page changes on an ongoing basis, data center proxies are convenient due to their speed and low cost for a large volume of requests. The combination of these three types along with an anti-detect browser provides a complete picture of what the user actually sees, regardless of what the affiliate decided to show you.