---
title: "Domain Spoofing: Publishers Losing Ad Revenue and Reputation Without Realizing"
description: The effects of domain masking go beyond lost revenue on a few impressions - publisher's reputations are in jeopardy.
image: https://blog.fraudlogix.com/hubfs/SheepWolf.jpg
---

[![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg)](http://www.fraudlogix.com/)

- [See More >>](https://www.fraudlogix.com/research-studies/)
- [Subscribe Now >>](https://www.fraudlogix.com/our-blog/)

# Articles and Research

# Domain Spoofing: Publishers Losing Ad Revenue and Reputation Without Realizing

Posted by [Fraudlogix](https://blog.fraudlogix.com/author/fraudlogix) on Jun 21, 2017 2:53:41 PM

![](https://blog.fraudlogix.com/hubfs/Fraudlogix_Favicon.png)

- [Tweet](https://twitter.com/share)

[Domain ( or URL) spoofing](http://wiki.fraudlogix.com/glossary/domain-spoofing/) has been a thorn in the side of the programmatic advertising industry for years now and the common narrative usually describes it as fraudsters trying to capitalize on the domains of big-name premium publishers. However, it should be noted that domain masking reaches beyond the top echelon of high-traffic sites and the damage it causes doesn’t stop at a few lost impressions.

## What is domain spoofing?

In the context presented here, domain spoofing is when a publisher declares in the [real-time bidding (RTB)](http://wiki.fraudlogix.com/glossary/rtb/) ad request that an ad will run on a specific domain, but the ad actually appears on a different, less-desirable one. It’s a separate issue from typical [ad fraud,](http://wiki.fraudlogix.com/glossary/ad-fraud/) which deals with [fake traffic](http://wiki.fraudlogix.com/glossary/fraudulent-traffic/), because the end user that sees the ad may be real, but he or she is seeing the ad on a different site than the one the advertiser intended.

Often, domain spoofing is used by sites that have been, or would quickly be, blacklisted by buyers because of their content (e.g., sites with [malware](http://wiki.fraudlogix.com/glossary/malware/), spyware, viruses, phishing schemes and pirated materials). So the creators of offending websites try to capitalize on the integrity of reputable domains by forging their name in the RTB bid.

At Fraudlogix we routinely see sites that rotate through domain names trying to monetize. One site, which specialized in pirated cartoons, used 38 different domain names in RTB auctions over a period of a few days, including “accuweather.com” and the domain of a small local newspaper from Central Pennsylvania. Another site hawking pirated movies used more than 80 different domain names in a few days. From “allmovies.com” to “zillow.com”, they targeted an entire spectrum of publishers.

## Who is affected by domain spoofing?

No legitimate publisher is safe from domain masking. This type of fraud affects everyone in the digital ad tech chain. The most obvious - and often talked about - is the advertisers, who are wasting ad spend on less desirable sites as well as the brand safety issues involved - they could be unintentionally funding websites with illegal and unscrupulous content.

But the publishers whose domain names are being used are also losing out here. Not just from the revenue lost from impressions going to another publisher, but their reputations may be damaged moving forward. Think of it like identity fraud - the publisher whose domain name is being spoofed is essentially taking the rap for the brand safety issues and abysmal conversion rates of the fraudulent sites using its name.

Buyers not diving deep enough into RTB data may inadvertently block high-quality publishers because their domains have been flagged for brand safety or illegal content. The publisher’s reputation, or “credit-score” has now been damaged because of domain masking and its revenue will also suffer. As buyers ramp up brand safety monitoring, especially in the wake of the [Google/YouTube controversy](https://www.thetimes.co.uk/edition/news/taxpayers-fund-extremism-csdn0npsf), they should keep domain masking in mind. Monitoring the two simultaneously will guard against blocking the wrong sources of sketchy ad placements.

## How to stop domain spoofing

Here are three low-tech ways to spot domain spoofing:

- **Domain traffic quality across sellers doesn’t measure up**. If a domain’s traffic bought through one exchange is consistently flagged for quality issues (e.g., low [view-ability](http://wiki.fraudlogix.com/glossary/view-ability/), [brand safety](http://wiki.fraudlogix.com/glossary/brand-safety/), etc.) while the traffic for the same domain bought through a different [exchange](http://wiki.fraudlogix.com/glossary/exchange/) doesn't get flagged, there’s a chance domain spoofing is occurring.
- **The CPM is too good to be true**. If the going rate for a site is normally $5 [CPM](http://wiki.fraudlogix.com/glossary/cpm/) but suddenly impressions are available for $1 CPM, be very wary.
- **Domains with no ads or whose publishers don’t sell ad space in RTB auctions**. Look at who the publisher is. Fraudsters aren’t always so sophisticated, and will try to spoof any domain, especially well-known ones, regardless of that publisher’s advertising strategies (of lack thereof).

Domain spoofing harms the programmatic ecosystem in lost revenue and damaged reputations as legitimate domains, large and small are being used to front the sale of ads to fund illicit websites. The industry should take a closer look at their analytics and be sure they’re [blacklisting](http://wiki.fraudlogix.com/glossary/blacklisting/) the correct sources of low-quality placements and poorly performing traffic.

[![Learn more about Fraudlogix's RTB solutions.](https://no-cache.hubspot.com/cta/default/2077077/240eb5ed-a075-4273-a7e1-c2b66a788f77.png)](https://cta-redirect.hubspot.com/cta/redirect/2077077/240eb5ed-a075-4273-a7e1-c2b66a788f77)

 Topics: [Programmatic RTB](https://blog.fraudlogix.com/topic/programmatic-rtb)

#### Contact Us

**Address:** Fraudlogix, 221 W. Hallandale Beach Blvd., Suite 107  
Hallandale Beach, FL 33009

**Phone:** +1-954-889-7805

**E-mail:** sales\_req@fraudlogix.com

![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/footer_logo.png)

© 2023 Fraudlogix. All rights reserved. [Privacy Policy](http://fraudlogix.com/privacy-policy/)

**Follow us on**

**[![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/linkedin_icon.png)](https://www.linkedin.com/company/fraudlogix) [![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/fb_icon.png)](https://www.facebook.com/fraudlogix) [![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/twitter_icon.png)](https://twitter.com/fraudlogix)**

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"ad-fraud",						
"@type":"Thing",						
"description":"Any time engagement with an online ad has been forged to generate revenue.",						
"name":"ad fraud",						
"alternatename": ["ad fraud","invalid traffic"],						
"sameAs":"https://en.wikipedia.org/wiki/Ad_fraud"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Blacklisting",						
"@type":"Thing",						
"description":"In terms of ad fraud, it’s a way to block ad traffic from high-risk sources (i.e., high-risk IP addresses). They may be used to prevent a company from bidding on ad impressions that have a high probability of being fraudulent in the RTB environment. They may also be used to prevent fraudulent actions such as views, installs, clicks, and sales.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/blacklisting/",						
"name":"blacklisting",						
"alternatename": ["blacklist","blocklist"]					
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Brand-safety",						
"@type":"Thing",						
"description":"In online marketing, advertisers must be cognizant of ad placements and a brand safety strategy is used to avoid having their ads appear on websites or pages that may be harmful to a brand’s image.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/brand-safety/",						
"name":"brand safety"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"CPM",						
"@type":"Thing",						
"description":"An online advertising pricing model used in the programmatic RTB space where advertisers are charged a set price for every 1,000 impressions of their ad (e.g., with a $1 CPM an advertiser is paying $1 for their ad to be shown 1,000 times).",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/cpm/",						
"name":"CPM",
"alternatename": ["Cost per mille","cost per thousand impressions"],						
"sameAs":"https://en.wikipedia.org/wiki/Cost_per_mille"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Domain-Spoofing",						
"@type":"Thing",						
"description":"A form of ad fraud that occurs when a publisher fraudulently declares a domain name in a bid request that’s different from where the ad will actually be run (e.g., the publisher declares “cnn.com” in the bid request but the ad will actually be served on “fakewebsite.com”). This is done to trick advertisers into running their ads on sites where they normally wouldn’t and/or to increase the amount the advertiser will pay for the ad placements. It opens advertisers up to brand safety issues, wastes ad dollars by placing ads on low-quality domains, and can be harmful to legitimate publishers whose domain names are being spoofed.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/domain-spoofing/",						
"name":"Domain Spoofing",
"alternatename": ["domain masking"]					
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"fraudulent-traffic",						
"@type":"Thing",						
"description":"Ad traffic that’s been generated by bots, malware, compromised devices, or other fraudulent means and is falsely masquerading as human traffic by visiting, viewing, and interacting with online ads.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/fraudulent-traffic/",						
"name":"fraudulent traffic",
"alternatename": ["fake traffic","invalid traffic","non-human traffic"]						

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"exchange",						
"@type":"Thing",						
"description":"The technology platforms that act as a marketplace between the buy and sell sides of the real-time-bidding (RTB) programmatic system. They normally have ad inventory from multiple supply sources and networks and have multiple DSPs integrated with them to bid on and purchase inventory.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/exchange/",						
"name":"exchange",
"alternatename": ["ad exchange"],						
"sameAs":"https://en.wikipedia.org/wiki/Ad_exchange"						
					
}
// ]]>
```

```json
// <![CDATA[
{  
      "@context":"http:\/\/schema.org",
      "@id":"malware",
      "@type":"Thing",
      "description":"Malware, short for malicious (or malevolent) software, is software used or programmed by attackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems. It can appear in the form of code, scripts, active content, and other software. 'Malware' is a general term used to refer to a variety of forms...",
      "mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/malware/",
      "name":"Malware",
      "sameAs":[  
         "http:\/\/rdf.freebase.com\/ns\/m.0582c",
         "http:\/\/dbpedia.org\/resource\/Malware","https://en.wikipedia.org/wiki/Malware"
      ]
   }
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"RTB",						
"@type":"Thing",						
"description":"In the online advertising space, RTB is the way programmatic ads are bought and sold on a per-impression basis – it’s the instantaneous auction of ad space that happens every time a user views a webpage that monetizes programmatically. Very basically, a user visits a website, which generates a bid request for the ad space on that page. The bid request contains information on that user (e.g., IP address, user agent, location, cookie information, etc.). Advertisers bid on the impression based on the information from the bid request and the winner of the auction gets their ad served to that user. This all happens in a fraction of a second. ",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/rtb/",						
"name":"RTB",
"alternatename": ["real time bidding"],						
"sameAs":"https://en.wikipedia.org/wiki/Real-time_bidding"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"view-ability",						
"@type":"Thing",						
"description":"Online advertising metric that measures how long an ad was in view (if at all) for the end user.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/view-ability/",						
"name":"view-ability"

					
}
// ]]>
```

```json
// <![CDATA[
[
	{
		"@context":"http://schema.org",
		"@id":"domain-masking-publishers-losing-ad-revenue-and-reputation-without-realizing",
		"@type":"Article",
		"description":"The effects of domain spoofing go beyond lost revenue on a few impressions - publisher's reputations are in jeopardy.",
		"mainEntityOfPage":"http://blog.fraudlogix.com/domain-masking-publishers-losing-ad-revenue-and-reputation-without-realizing",
		"Image"
			:[
				{
					"@type":"ImageObject",
					"url":"https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg",
					"Width":112,"height":43
				}
			],
		"headline":"Domain Spoofing: Publishers Losing Ad Revenue and Reputation Without Realizing",
		"datePublished":"2017-06-21",
		"datemodified":"2017-06-21",
		"wordCount":694,
		"Publisher":
			{
				"@type":"Organization",
				"@id":"www.fraudlogix.com",
				"name":"Fraud Logix",
				"Logo":
					{
						"@type":"ImageObject",
						"url":"https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg",
						"Width":112,"height":43
					}
			},
		"Mentions":
			[
				{"@id":"http://wiki.fraudlogix.com/glossary/domain-spoofing/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/rtb/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/ad-fraud/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/fraudulent-traffic/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/malware/"},
				{"@id":"https://www.thetimes.co.uk/edition/news/taxpayers-fund-extremism-csdn0npsf"},
				{"@id":"http://wiki.fraudlogix.com/glossary/view-ability/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/brand-safety/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/exchange/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/cpm/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/blacklisting/"}
				
		
			],
		"author":
			{
			"@type":"Organization",
			"@id":"www.fraudlogix.com",
			"Name":"Fraud Logix"}
			}
	]
// ]]>
```