How to Test Your Cloaking Setup

Knowing how to test your cloaking setup is something to nail down before launch, not after your first domain ban. Below: checking White and Offer by geo, bot, and reviewer traffic, plus the ?nc=1 bypass so you don't lock yourself out of your own offer.

Why test cloaking before launch

Cloaking decides who sees White — the safe page — and who lands on Offer, the live PWA with the actual offer. Get the rule wrong and either a reviewer sees the live offer and gets the ad account banned, or a real user lands on White and simply never converts. Catching that before launch is always cheaper than untangling an already-banned account afterward.

Checking White/Offer by geo

Access the funnel through a VPN or proxy with a clean IP for the target geo, not your everyday working IP — that IP might already be on the cloaking allowlist, or already flagged. It's worth separately confirming that every non-target geo consistently sees White. Check edge cases too, like carrier mobile data versus home WiFi — their IP ranges often get classified differently by the cloak.

Checking bot and antidetect filters

Open the offer from a datacenter IP — a server or hosting provider — it should show White by default, not Offer. Next, test the usual bot signals a platform looks for: a headless browser, no browsing history, an unusual user agent. It's also worth confirming that an antidetect browser with a clean profile doesn't accidentally trigger the cloak for genuine users, or you'll lose live traffic for no reason.

Checking the ?nc=1 bypass

The bypass parameter configured in the cloak should always show Offer to you and your team — QA, designers — regardless of geo or any other filter, so nobody has to spin up a VPN just to review a page. Never post that parameter in the ad itself, in promo material, or in open chats — anyone who gets hold of it can bypass the cloak, including a platform reviewer.

Common mistakes when testing cloaking

A common mistake is testing from a single device and IP and calling it done, without separately checking the target geo against your own. Another is skipping a re-check after a domain change or rotation, since some settings may not carry over automatically. A third is mistaking browser cache for actual cloak behavior — clear cookies and cache between tests, or the results won't be reliable. APEX's built-in cloaking, with geo, bot, and datacenter filters plus IP intelligence, is configured right in the dashboard, so testing comes down to verifying rules that are already in place rather than building a cloak from scratch.

FAQ

How do I see the White page if I forgot the bypass parameter?
Access it from an IP that clearly fails the geo check or reads as datacenter or bot traffic — the cloak defaults to White; or recover the bypass parameter from the cloaking settings in your dashboard.
Do I need to test cloaking before every campaign launch?
Yes, at minimum a quick White/Offer and bypass check for the target geo — cloaking rules may have changed or the domain may have rotated, and it's better to catch a mismatch before launch than after a ban.
How do I confirm the cloak isn't letting platform bots through?
Open the offer from a datacenter IP or a headless browser with no history — if Offer shows up instead of White under those conditions, the filter is misconfigured.
What do I do if a reviewer saw Offer instead of White?
Check the geo and datacenter filter first, since reviewers usually come from datacenter IPs, update the cloaking rules, and rotate the domain if the ad account already picked up a restriction.
Build your PWA in APEX in minutes

Cloaking, anti-bot, push, split tests and your own domains — in one service.

Get started free

Read also