---
title: "When Good Publishers Go Bad: How ‘Premium’ Publishers Get Caught Up In Ad Fraud & How it Can Be Prevented"
description: Sometimes good publishers get flagged for bad traffic. Here's a look at how premium publishers can get caught up in ad fraud and what can be done to prevent it.
image: https://blog.fraudlogix.com/hubfs/PublisherPostingOnline.jpg
---

[![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg)](http://www.fraudlogix.com/)

- [See More >>](https://www.fraudlogix.com/research-studies/)
- [Subscribe Now >>](https://www.fraudlogix.com/our-blog/)

# Articles and Research

# When Good Publishers Go Bad: How ‘Premium’ Publishers Get Caught Up In Ad Fraud & How it Can Be Prevented

Posted by [Fraudlogix](https://blog.fraudlogix.com/author/fraudlogix) on Jan 23, 2018 11:50:00 AM

![](https://blog.fraudlogix.com/hubfs/Fraudlogix_Favicon.png)

- [Tweet](https://twitter.com/share)

Every corner of the [programmatic ecosystem can be affected by ad fraud](https://blog.fraudlogix.com/how-programmatic-platforms-prevent-ad-fraud-qa-with-acuityads) – even premium publishers and quality ad tech vendors can get inadvertently pulled into programmatic’s fraudulent underbelly. Some publishers are unaware of a problem until they’re blocked from a platform. On the flip side, an ad tech platform on the [supply side](https://blog.fraudlogix.com/rtb-corner-jan-3-2019) might approach a normally quality publisher with evidence of ad fraud and the publisher legitimately doesn’t know where the problem is originating or how to fix it. So how does this happen, and what can publishers do to prevent ending up on someone’s [blacklist](http://wiki.fraudlogix.com/glossary/blacklisting/)?

## **Use Caution Around Purchased (Sourced) Traffic**

There’s an increased risk of fraud in traffic that is purchased or sourced. Period. Here, purchased and sourced traffic can be defined as any non-organic traffic to a site. [Purchased traffic](http://wiki.fraudlogix.com/glossary/traffic-sourcing/) can include buying clicks, impressions, or actions across display, video, or mobile channels and encompasses many different sources, including:

- Blind networks, where someone is paid for clicks or impressions and in return they’ll “drive traffic to a site from millions of global websites”, but it's not clear where the traffic is coming from;
- Direct from other publishers;
- Second and third-tier search networks (i.e., search traffic from extended search networks);
- Traffic exchange partnerships;
- Pop-under traffic, toolbar traffic, and parking page traffic.

If purchasing traffic, a publisher needs to understand the sources and be cautious. They should know who and where the traffic is coming from and track metrics closely.

## **Have a Quality Solution in Place**

It’s best for publishers to have automated, [real-time quality measures](https://blog.fraudlogix.com/seven-forces-that-will-affect-the-rtb-programmatic-space-in-2018) in place to block [invalid traffic](http://wiki.fraudlogix.com/glossary/invalid-traffic/) coming to sites. This is especially true if they’re sourcing traffic. Publishers should make use of both publicly and privately available publisher, domain, or IP-level block lists. Additionally, they should analyze traffic logs on a regular basis to help identify anomalies and signal [bot-driven traffic](http://wiki.fraudlogix.com/glossary/bot-traffic/). Publishers can audit logs for things like:

- Old, outdated browsers;
- Large unexplained spikes in traffic;
- Abnormally high CTRs;
- Heavy traffic to sites at odd times;
- Traffic coming from referring sites with unrecognizable domains.

## **Be Careful Where They Advertise: Ads for a Website Could Drive Fraudulent Traffic to the Site**

Publishers should be sure ads are really running where they think they are – where they’re being told. If ads for a site are showing up on low-quality domains, they may be unknowingly generating fraudulent traffic to a site through their advertising and marketing efforts.

## **Implement ads.txt**

[Domain spoofing can affect a publisher without them ever knowing](https://blog.fraudlogix.com/blog/domain-masking-publishers-losing-ad-revenue-and-reputation-without-realizing). A fraudster forging a  publisher's domain on a bid request could not only steal ad revenue that was intended for that publisher's domain, but could also cause the domain to be flagged as fraudulent. Using [ads.txt](https://blog.fraudlogix.com/blog/fraudlogix-adds-adstxt-reporting-to-verification-suite) can protect a domain from being used on fraudulent bid requests and its reputation in the eyes of advertisers. Major players in the ad tech stack are increasingly looking at ads.txt files. It’s possible that within the coming months publishers that do not have ads.txt implemented, or an accurate ads.txt file, could lose out on lucrative ad placements because their authorized sellers were not declared, or there was no ads.txt file at all.

Additionally, no matter how much traffic or how popular a site is, publishers should implement ads.txt and be wary of [domain spoofing](http://wiki.fraudlogix.com/glossary/domain-spoofing/). There are many shady publishers that have been blacklisted from the RTB space because of fraudulent content or [brand safety](http://wiki.fraudlogix.com/glossary/brand-safety/) issues (e.g., sites with pirated content) that use domain spoofing to get back into the market to monetize their sites, and they'll target any legitimate domain name.

## **Consider Domain Spoofing, Brand Safety, And Viewability Affecting Quality Scores**

Domain spoofing, brand safety, and poor [viewability](http://wiki.fraudlogix.com/glossary/view-ability/) may get a domain flagged for poor quality by some verification vendors. Publishers should consider all aspects of their sites, not just traffic, when thinking of quality (e.g., if they have high traffic volume but their viewability is hovering around 0%, their site’s overall quality score may suffer).

Publishers can use these suggestions to help pinpoint where low-quality traffic may be coming from and what they can do to avoid fraud. Ad tech vendors are encouraged to use them as a check list for publishers and as a way to facilitate conversations with publishing partners about quality.

[![Learn More About Fraudlogix](https://no-cache.hubspot.com/cta/default/2077077/ff4dae8b-ad27-4dec-aa34-1052443f09f2.png)](https://cta-redirect.hubspot.com/cta/redirect/2077077/ff4dae8b-ad27-4dec-aa34-1052443f09f2)

 Topics: [Programmatic RTB](https://blog.fraudlogix.com/topic/programmatic-rtb)

#### Contact Us

**Address:** Fraudlogix, 221 W. Hallandale Beach Blvd., Suite 107  
Hallandale Beach, FL 33009

**Phone:** +1-954-889-7805

**E-mail:** sales\_req@fraudlogix.com

![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/footer_logo.png)

© 2023 Fraudlogix. All rights reserved. [Privacy Policy](http://fraudlogix.com/privacy-policy/)

**Follow us on**

**[![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/linkedin_icon.png)](https://www.linkedin.com/company/fraudlogix) [![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/fb_icon.png)](https://www.facebook.com/fraudlogix) [![Fraudlogix](https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/twitter_icon.png)](https://twitter.com/fraudlogix)**

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"ad-fraud",						
"@type":"Thing",						
"description":"Any time engagement with an online ad has been forged to generate revenue.",	
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/ad-fraud/",											
"name":"ad fraud",						
"alternatename": ["ad fraud","invalid traffic"],						
"sameAs":"https://en.wikipedia.org/wiki/Ad_fraud"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Ads.txt",						
"@type":"Thing",						
"description":"An initiative brought forth by the Interactive Advertising Bureau (IAB) that allows publishers to specify which ad tech companies are authorized to sell and resell ads on their pages. This was put in place to help stop domain spoofing.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/ads-txt/",						
"name":"Ads.txt",						
"alternatename": ["Authorized Digital Sellers"],						
"sameAs":"https://en.wikipedia.org/wiki/Ads.txt"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Bot-traffic",						
"@type":"Thing",						
"description":"The website/ad visits/views that are generated by a bot.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/bot-traffic/",						
"name":"bot traffic"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Brand-safety",						
"@type":"Thing",						
"description":"In online marketing, advertisers must be cognizant of ad placements and a brand safety strategy is used to avoid having their ads appear on websites or pages that may be harmful to a brand’s image.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/brand-safety/",						
"name":"brand safety"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Domain-Spoofing",						
"@type":"Thing",						
"description":"A form of ad fraud that occurs when a publisher fraudulently declares a domain name in a bid request that’s different from where the ad will actually be run (e.g., the publisher declares “cnn.com” in the bid request but the ad will actually be served on “fakewebsite.com”). This is done to trick advertisers into running their ads on sites where they normally wouldn’t and/or to increase the amount the advertiser will pay for the ad placements. It opens advertisers up to brand safety issues, wastes ad dollars by placing ads on low-quality domains, and can be harmful to legitimate publishers whose domain names are being spoofed.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/domain-spoofing/",						
"name":"Domain Spoofing",
"alternatename": ["domain masking"]					
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"invalid-traffic",						
"@type":"Thing",						
"description":"The MRC (Media Rating Council) considers Invalid traffic to be a collective term for both General and Sophisticated invalid traffic. It defines the two different types of invalid traffic as follows: General Invalid Traffic (GIVT) Traffic identified through routine means of filtrations executed through application of lists or with other standardized parameter checks”. Examples include: “known data-center traffic (determined to be a consistent source of non-human traffic; not including routing artifacts of legitimate users or virtual machine legitimate browsing),  bots and spiders or other crawlers (except those as noted below in the Sophisticated Invalid Traffic” category), activity-based filtration using campaign or application data and transaction parameters from campaign or application data, non-browser user-agent headers or other forms of unknown browsers and pre-fetch or browser pre-rendered traffic. Sophisticated Invalid Traffic (SIVT) Consists of more difficult to detect situations that require advanced analytics, multi-point corroboration/coordination, significant human intervention, etc., to analyze and identify.  Key examples are: bots and spiders or other crawlers masquerading as legitimate users; hijacked devices; hijacked sessions within hijacked devices; hijacked ad tags; hijacked creative; hidden/stacked/covered or otherwise intentionally obfuscated ad serving; invalid proxy traffic (originating from an intermediary proxy device that exists to manipulate traffic counts or create/pass-on non-human or invalid traffic or otherwise failing to meet protocol validation); adware; malware; incentivized manipulation of measurements (fraudulent incentivized promotion of an entity, without its knowledge or permission);  misappropriated content (where used to purposefully falsify traffic at a material level); falsified viewable impression decisions; falsely represented sites (sites masquerading as other entities for illegitimate purposes) or impressions; cookie stuffing, recycling or harvesting (inserting, deleting or misattributing cookies thereby manipulating or falsifying prior activity of users ); manipulation or falsification of location data or related attributes; and differentiating human and IVT traffic when originating from the same or similar source in certain closely intermingled circumstances. ",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/invalid-traffic/",						
"name":"invalid traffic",
"alternatename": ["IVT",  "SVIT","Non-human traffic"]						

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"programmatic",						
"@type":"Thing",						
"description":"Automated buying of online ad inventory where algorithms are used to identify website viewers and serve them relevant ads using the real-time-bidding (RTB) process.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/programmatic/",						
"name":"programmatic",
"alternatename": ["programmatic ad traffic","programmatic advertising"]						

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"RTB",						
"@type":"Thing",						
"description":"In the online advertising space, RTB is the way programmatic ads are bought and sold on a per-impression basis – it’s the instantaneous auction of ad space that happens every time a user views a webpage that monetizes programmatically. Very basically, a user visits a website, which generates a bid request for the ad space on that page. The bid request contains information on that user (e.g., IP address, user agent, location, cookie information, etc.). Advertisers bid on the impression based on the information from the bid request and the winner of the auction gets their ad served to that user. This all happens in a fraction of a second. ",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/rtb/",						
"name":"RTB",
"alternatename": ["real time bidding"],						
"sameAs":"https://en.wikipedia.org/wiki/Real-time_bidding"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"SSP",						
"@type":"Thing",						
"description":"The technology platform on the sell side of the programmatic RTB system that allows publishers to sell their ad inventory in real time.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/ssp/",						
"name":"SSB",
"alternatename": ["supply side platform","sell side platform"],						
"sameAs":"https://en.wikipedia.org/wiki/Supply-side_platform"						
					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"traffic",						
"@type":"Thing",						
"description":"The viewers, visits and interactions with online media (e.g., websites, ads, videos, etc.)",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/traffic/",						
"name":"traffic",
"alternatename": ["ad traffic"]						

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"traffic-sourcing",						
"@type":"Thing",						
"description":"A practice sometimes used by online publishers where they purchase or source an audience from third parties and sell the ad space to advertisers. This practice increases if advertiser demand outpaces the publishers’ inventory. An increased risk of fraudulent, bot-generated traffic is associated with sourced traffic.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/traffic-sourcing/",						
"name":"traffic sourcing",
"alternatename": ["sourced traffic","purchased traffic"]						

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"view-ability",						
"@type":"Thing",						
"description":"Online advertising metric that measures how long an ad was in view (if at all) for the end user.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/view-ability/",						
"name":"view-ability"

					
}
// ]]>
```

```json
// <![CDATA[
{						
"@context":"http:\/\/schema.org",						
"@id":"Blacklisting",						
"@type":"Thing",						
"description":"In terms of ad fraud, it’s a way to block ad traffic from high-risk sources (i.e., high-risk IP addresses). They may be used to prevent a company from bidding on ad impressions that have a high probability of being fraudulent in the RTB environment. They may also be used to prevent fraudulent actions such as views, installs, clicks, and sales.",						
"mainEntityOfPage":"http://wiki.fraudlogix.com/glossary/blacklisting/",						
"name":"blacklisting",						
"alternatename": ["blacklist","blocklist"]					
					
}
// ]]>
```

```json
// <![CDATA[
[
	{
		"@context":"http://schema.org",
		"@id":"when-good-publishers-go-bad-how-premium-publishers-get-caught-up-in-ad-fraud-how-it-can-be-prevented",
		"@type":"Article",
		"description":"Sometimes good publishers get flagged for bad traffic. Here's a look at how premium publishers can get caught up in ad fraud and what can be done to prevent it.",
		"mainEntityOfPage":"http://blog.fraudlogix.com/when-good-publishers-go-bad-how-premium-publishers-get-caught-up-in-ad-fraud-how-it-can-be-prevented",
		"Image"
			:[
				{
					"@type":"ImageObject",
					"url":"https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg",
					"Width":112,"height":43
				}
			],
		"headline":"When Good Publishers Go Bad: How ‘Premium’ Publishers Get Caught Up In Ad Fraud & How it Can Be Prevented",
		"datePublished":"2018-01-23",
		"datemodified":"2018-01-23",
		"wordCount":708,
		"Publisher":
			{
				"@type":"Organization",
				"@id":"www.fraudlogix.com",
				"name":"Fraud Logix",
				"Logo":
					{
						"@type":"ImageObject",
						"url":"https://blog.fraudlogix.com/hubfs/Fraudlogix%20June%202017/logo.jpg",
						"Width":112,"height":43
					}
			},
		"Mentions":
			[
				{"@id":"http://blog.fraudlogix.com/how-programmatic-platforms-prevent-ad-fraud-qa-with-acuityads"},
				{"@id":"http://blog.fraudlogix.com/rtb-corner-jan-3-2019"},
				{"@id":"http://wiki.fraudlogix.com/glossary/blacklisting/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/traffic-sourcing/"},
				{"@id":"http://blog.fraudlogix.com/seven-forces-that-will-affect-the-rtb-programmatic-space-in-2018"},
				{"@id":"http://wiki.fraudlogix.com/glossary/invalid-traffic/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/bot-traffic/"},
				{"@id":"http://blog.fraudlogix.com/blog/domain-masking-publishers-losing-ad-revenue-and-reputation-without-realizing"},
				{"@id":"http://blog.fraudlogix.com/blog/fraudlogix-adds-adstxt-reporting-to-verification-suite"},
				{"@id":"http://wiki.fraudlogix.com/glossary/domain-spoofing/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/brand-safety/"},
				{"@id":"http://wiki.fraudlogix.com/glossary/view-ability/"}
				
			],
		"author":
			{
			"@type":"Organization",
			"@id":"www.fraudlogix.com",
			"Name":"Fraud Logix"}
			}
	]
// ]]>
```