Google 'detecting' Circumventing System/Cloaking - how?

jiayu2301

Newbie
Jun 24, 2015
43
8
Hello fellow BH PPC advertisers,

I'm sharing my experience with the hope of getting input on demystifying how Google detects cloaking.
Needless to say, I'd never underestimate big G and give them credit for detecting policy violations. The same way I give credit to Advertisers who were and are able to be a step a head of Google, i.e. successfully cloak their campaigns and trick Google. (A small tap on my shoulder, eeh?!)

But being brutally honest as it alway has been part of the game, most of us have experienced and seen it:

Your account is suspended

Your Google Ads account XXX-XXX-XXXX has been suspended for Circumventing systems.
If you believe this is an error, submit an appeal and we’ll review your account.
If you have a prepaid balance remaining in your account, you can request a refund at any time.

The Google Ads Team

In one of my latest campaigns the following happened and I'm still in the dark as to how Google detected my cloaking attempt.

I had set up a fresh SAFE site with unqiue content that Google wouldn't see as restricted and which had enough relevancy to the niche that is restricted by their policies.
  • A fresh gmail email addy was used to set up the Google Ad account
  • Domain, domain registrar used and hosting have been 100% fresh
  • A fresh residential IP and new machine was used for the entire operation and set up of the Google Ad account and campaign
  • Pretty much all was kept natural and SAFE (there was no link in settings used in a previously banned account/campaign, at least that's what we truly aimed for)
The campaign approach:
  1. Creation of SAFE campaign, i.e. submitting of SAFE ad copies for review along with SAFE keywords
  2. Wait for approval and run campaign on SAFE mode to warm up the account
  3. Add cloaker tracking code on SAFE site to log visits and set up redirect configs to MONEY page (cloaking 'disabled' at any time)
  4. Let Google come and take an automatic payment for the ad spend
  5. Keep preparing for transition, i.e. submission and wait for approval of MONEY ad copy (= the copy that is perfectly ambiguous to cover relevancy for the SAFE funnel but also the MONEY one, yet keep running the campaign on SAFE mode)
  6. Add MONEY keywords and keep running on SAFE mode
  7. Keep monitoring on visit log all visits especially Google Ad bot ones and all regular real visits that you wish you had already successfully sent to your MONEY site/content
So far so good, your campaign nicely runs, Google makes their AdRevenues, your campaign stats look as expected good and nothing suspicious nor policy violating has been happening at all - well done, well done! Now you feel you're ready to flip the switch and enable cloaking to start sending the quality traffic to your MONEY content that you well know would and will convert for you.

Here is what happened:
  • Cloaking got eventually turned on (prior to successful confirmation of it to be fully fuctional and correctly set up)
  • 3-4 hours later the account was flagged for Circumventing systems (So yeah Google detected the cloaking, but I really wonder how?)
The visit log revaled no successful redirect at all, absolutely noone/zero visits were sent to the actual MONEY content, not even any single visits in that time span of a few hours after the cloaking was enabled. Fair enough Google detected "SOMETHING" and me believing in cause and effect, I track this back to the actual action of me enabling of the cloaking, but in this case I would expect Google to leave footprint as the question remains, how can you find out that I cloak if you possibly visit my SAFE site but are not able to trigger the redirect i.e. qualify to be sent to the MONEY page. In this particular case we would must have logged that successful redirect on our end.

In other words how can Google find out my cloaking without leaving footprint themselves. The redirect happens on the server side, you must have visited my site in order to be able to identify the cloaking part, yet the log didn't reveal anyone to be redirect, that means everyone stayed on the SAFE funnel which is all in line with how the campaign had been running without any issues before the enabling of cloaking.

To me this remains to be a mystery, and again kudos to Google to catch me on this one. But I do wonder how this was done as I've been able to successfully run campaigns with the exact same approach and method.

Did anyone have similar experiences?
Can someone shed some light on this?
Anyone, any clue?

Any constructive input is greatly appreciated.

PS: If you have been successfully cloaking and like to mastermind - please feel free to PM me.

Best,
J.
 
Your camp will not get affected if its Auto Review , but when you start spending high or your daily budget is high or AD copy / Keywords are too aggressive they do a Manual Review which is done from residential IP not from the datacenter IP , which causes your account go suspended .
 
Your camp will not get affected if its Auto Review , but when you start spending high or your daily budget is high or AD copy / Keywords are too aggressive they do a Manual Review which is done from residential IP not from the datacenter IP , which causes your account go suspended .

Spend has not been touch at all. It it was running on SAFE mode suppossedly long enough even with "aggressive" KWs, i.e. money keywords in place.
Also following your argument of a manual review, we would have captured that visit, that residential IP you are referring to. And I would have accepted them triggering the redirect and then taking appropriate action, i.e. banning the campaign and/or suspending the account.

BUT; there are no visits logged on our end that could hinted that it is Google, and even if they were - no successful redirect happened at all. And that's the big mysterious thing, I simply don't understand how Google possibly found out.
 
Is it possible that google were able to see the real IP behind your 2nd machine running on proxies, via the WEB RTC bug ?
 
Everyone has automatic redirection enabled by default, but in case of google they dont have to follow it, its enough to detect that redirection occured and link is not same as your campaign and boom, ure gone.
 
Hello , I have tested one site in one of the trendy markets, in last 3 months G baned my 3 site and account accordingly, however lately I have noticed very interesting thing. They checked my site 4 times, manual checkers were from India however they didnt find my money page . 4 days ago I get notification in my Ads account that I need a certificate for advertising in igaming niche. So I think they have updated their ML algo, now Algo predict in which niche we advertising .
Any Ideas how they predict?
 
The thing with BH gambling ads is that there are so many people doing them, in so many geos, it's easy for G to look at all the histrocial data on accounts they have banned (KWs, ad types etc) to learn what a BH campaign looks like. And then they just ban 90%+ of any new ads that crop up, whether they do it straight away, or whether they have extra teams doing "secret" checks days/weeks after.

I've had at least 100 campaigns go down in this niche in the last year, so I've left behind a load of evidence for Google to learn what was slipping through their net.

You have to keep getting inventive, otherwise G will catch on. If you keep repeating something that G have detected, you are in trouble.
 
Last edited by a moderator:
Do you think it is still worth trying to do BH gambling ads (which is my niche) given all the issues I'm reading about lately? I know I am certainly struggling over the last 6-9 months
 
After you are done running the ad with the safe keywords for a few days, is it safe to add your money keywords? Will that trigger a suspend the moment you add some keywords?
 
Seems that your cloaker is not too good. A good cloaker would be updated (in it's backend) on a non-stop basis with IPs, etc of review bots, typical manual review fingerprints, etc) and when this is not effectively done on a non-stop basis, then some review bots will end up seeing your money page instead of the safe page. That is why, one must try atleast 4 to 5 cloakers to have a better judgement.
 
I have lost 30+ google ads accounts in the last month and all of them get suspended after a visit/review from India. So it is clear that they are doing a lot of manual reviews from there and if they caught your money page in a review, the account would be gone. Also, the manual review could trigger at any time these days, may be after a budget raise and a new campaign/ads/keywords submission.
 

Sometimes the answers to the most complex questions are the most simple - What CMS are you using? and does it have a defult setting or plugin enabled that would automatically ping google every time there's a change of any sort on your site? (WP has that, several plugins acitvate it by default such as YOAST, RankMath, and others) Bludit does that and several others... if so, that info would have been transmitted to them the second you updated after "enabling cloaking" and they would have been delivered that info without ever having to visit/crawl your site again
 
Back
Top
AdBlock Detected

We get it, advertisements are annoying!

Sure, ad-blocking software does a great job at blocking ads, but it also blocks useful features and essential functions on BlackHatWorld and other forums. These functions are unrelated to ads, such as internal links and images. For the best site experience please disable your AdBlocker.

I've Disabled AdBlock