How to Test Your Cloaking Setup
Knowing how to test your cloaking setup is something to nail down before launch, not after your first domain ban. Below: checking White and Offer by geo, bot, and reviewer traffic, plus the ?nc=1 bypass so you don't lock yourself out of your own offer.
Why test cloaking before launch
Cloaking decides who sees White — the safe page — and who lands on Offer, the live PWA with the actual offer. Get the rule wrong and either a reviewer sees the live offer and gets the ad account banned, or a real user lands on White and simply never converts. Catching that before launch is always cheaper than untangling an already-banned account afterward.
Checking White/Offer by geo
Access the funnel through a VPN or proxy with a clean IP for the target geo, not your everyday working IP — that IP might already be on the cloaking allowlist, or already flagged. It's worth separately confirming that every non-target geo consistently sees White. Check edge cases too, like carrier mobile data versus home WiFi — their IP ranges often get classified differently by the cloak.
Checking bot and antidetect filters
Open the offer from a datacenter IP — a server or hosting provider — it should show White by default, not Offer. Next, test the usual bot signals a platform looks for: a headless browser, no browsing history, an unusual user agent. It's also worth confirming that an antidetect browser with a clean profile doesn't accidentally trigger the cloak for genuine users, or you'll lose live traffic for no reason.
Checking the ?nc=1 bypass
The bypass parameter configured in the cloak should always show Offer to you and your team — QA, designers — regardless of geo or any other filter, so nobody has to spin up a VPN just to review a page. Never post that parameter in the ad itself, in promo material, or in open chats — anyone who gets hold of it can bypass the cloak, including a platform reviewer.
Common mistakes when testing cloaking
A common mistake is testing from a single device and IP and calling it done, without separately checking the target geo against your own. Another is skipping a re-check after a domain change or rotation, since some settings may not carry over automatically. A third is mistaking browser cache for actual cloak behavior — clear cookies and cache between tests, or the results won't be reliable. APEX's built-in cloaking, with geo, bot, and datacenter filters plus IP intelligence, is configured right in the dashboard, so testing comes down to verifying rules that are already in place rather than building a cloak from scratch.
FAQ
- How do I see the White page if I forgot the bypass parameter?
- Access it from an IP that clearly fails the geo check or reads as datacenter or bot traffic — the cloak defaults to White; or recover the bypass parameter from the cloaking settings in your dashboard.
- Do I need to test cloaking before every campaign launch?
- Yes, at minimum a quick White/Offer and bypass check for the target geo — cloaking rules may have changed or the domain may have rotated, and it's better to catch a mismatch before launch than after a ban.
- How do I confirm the cloak isn't letting platform bots through?
- Open the offer from a datacenter IP or a headless browser with no history — if Offer shows up instead of White under those conditions, the filter is misconfigured.
- What do I do if a reviewer saw Offer instead of White?
- Check the geo and datacenter filter first, since reviewers usually come from datacenter IPs, update the cloaking rules, and rotate the domain if the ad account already picked up a restriction.
Cloaking, anti-bot, push, split tests and your own domains — in one service.
Get started free