Referrer Checking in Cloaking
Referrer checking in cloaking filters out visitors who open the offer page directly — via a raw link, a bookmark, or a moderation panel — instead of clicking through from a live ad. Ad-platform moderators and anti-fraud bots often land on the page exactly that way, with no real referrer from a traffic source. Here's how the check works and why referrer is one filter layer, not the whole defense.
What a referrer is and why it matters
The referrer is a header the browser sends when a link is followed, showing which page the visitor came from. Real ad traffic almost always carries the referrer of the matching platform — Facebook, TikTok, a search engine — while a direct visit, a saved link, or a click from an internal review panel usually doesn't. Cloaking checks the referrer against an expected source list and decides whether to let the visitor through or show the safe page.
How moderators give themselves away through a missing referrer
Some reviewers open the final ad URL directly — pasting it into the address bar or clicking through an internal moderation panel instead of the live ad. Either way, the referrer is empty or doesn't match the expected ad-platform domain. It's one of the more reliable indirect signs of 'not a real ad click,' though not a guaranteed one.
The limits of referrer checking
Referrer can be spoofed manually, and some modern browsers and private-browsing modes strip or hide it even for genuine users, which creates false positives. That's why referrer checking never runs as the only filter — it's paired with UA, IP-intel, and behavioral signals. Referrer is a cheap, fast first pass, not the final verdict on a visitor.
Setting up referrer checking in APEX
In APEX's cloaking, the referrer check is configured as a list of expected source domains — specific Facebook or Google subdomains, for instance — and anything that doesn't match gets routed to the safe page automatically. The rule runs in the same check chain as the anti-bot filters and IP-intel, with no separate script needed on the landing page. The source list can be updated whenever a new ad channel gets added.
Where this check matters most
The referrer filter earns its keep where moderators actively review final pages by hand — gambling and other strict verticals on Facebook, for example. When scaling to new traffic sources, the expected referrer list needs updating per platform, or legitimate traffic from the new channel gets caught by the filter too.
FAQ
- Can a bot be identified from referrer alone?
- No, referrer alone isn't enough, since some genuine users also arrive without one because of private browsing modes. It works as one layer alongside UA and IP-intel.
- What does a moderator see if they lack the right referrer?
- The safe white page instead of the offer — usually neutral content that gives no grounds for an ad or account ban.
- Does the referrer list need updating when adding a new traffic source?
- Yes, each platform has its own source domain, and if it's missing from the expected list, legitimate traffic from the new channel gets routed to the white page too.
- Does referrer checking also catch regular users visiting directly?
- Yes, incidentally — a user who opens a saved link directly also lacks the expected referrer. That's usually a small, predictable loss compared to the benefit of filtering out reviewers.
Cloaking, anti-bot, push, split tests and your own domains — in one service.
Get started free