top of page

Mastering Affiliate Decloaking

A Comprehensive Guide to Link Cloaking

by Andy Cooney

October 28, 2024

Link cloaking in affiliate marketing means disguising or masking URLs to make them appear to have a different destination URL. While cloaking can be used for legitimate purposes, it has the most impact on brands when it is used maliciously to defraud businesses or scam their customers. We'll explore both in this article.

Image by Bastian Riccardi

Identifying signs that you are cannibalizing

Affiliate links are a primary way that some publishers monetise their users. These links contain IDs identifying who the affiliate is who referred the sale to the brands they work with. When a user clicks on these links, they are redirected through an affiliate network to the brand website, when the user makes a purchase the affiliate will qualify for a commission on the sale. â€‹

​

How Link Cloaking Works in Affiliate Marketing​

 

A cloaked link takes a link that might look long and contain identifying parameters such as the below:

​

https://examplewebsite.com/product/affiliateid=12345&source=affiliatemarketing&campaign=brandcampaign

​

And turns it into something visually attractive and simple to understand:

​

https://yourwebsite.com/productname

​

This is typically done using a link-cloaking service or plugin. Some legitimate link cloakers are well-known brands, such as Bitly or TinyUrl. 

​

Legitimate cloaking tools vary in the depth of features; some allow for A/B testing, analytics, or auto-routing based on geolocation. All work on the same principle: the link is changed to the desired format, and then when users click on it, they are automatically redirected to the correct place. 

Legitimate use cases of link cloaking in affiliate marketing

Affiliate marketers use link cloaking for several reasons:

​

  • Simplification: Long URLs full of tracking parameters may look suspicious or take up too much space on a page.  Cloaking the links makes them more user-friendly and potentially trustworthy.

  • Memorability: Shortening a URL to something easy to remember makes it more likely to be shared. This is particularly useful when an affiliate is promoting a link using social channels, where it might be expected that the user will manually type it into their browser. 

  • Personal Branding: Affiliates can add their name or brand to the domain using cloaking so the audience knows it came from them. 

  • Click-through Rate: Affiliates might want to cloak their links to make users more likely to click through as it is more descriptive. 

  • A/B Testing: Affiliate marketers can use link cloaking to change the final URLs behind their cloaked URL. For instance, they could test two different product links, using the same promotion or campaign to their audience to see which performed better. 

  • Tracking performance: If an affiliate promotes many links, using cloaking management software can allow them to monitor the performance of their efforts at a link-level. Many of the services mentioned provide an affiliate dashboard to show how different links perform. 

  • Updating redirects: If an affiliate has many links across their site, updating them individually when affiliate parameters change can be time-consuming. If they use a link cloaking provider this can make updates much quicker, as they update the final link destinations on the backend.

​

Malicious use cases of affiliate link cloaking

In addition to the legitimate link cloaking services that affiliates often use, there is a large industry of sophisticated cloaking systems that exist to enable fraud. These services inspect traffic as it passes through the cloaking server, and allows affiliates to send real users to the affiliate network (the “Money Page”). However, these services will identify anyone who may be an ad verification bot, associated with the brand, or otherwise investigating the affiliate and redirect them to the brand’s main website without any identifying information (the “Safe Page).

 

The cloaking services that enable illegitimate link cloaking offer affiliates a wide array of targeting options - affiliates can redirect users to the safe page if they are outside of geographical boundaries, use a non-allowed internet service provider, have a known browser fingerprint, are located too close to the brand’s (or Google’s) office, and many other configurations.

 

Some of the most popular link cloaking systems for illegitimate link cloaking can be found on public forums - Adspect, JustCloakIt, and MagicChecker are some of the most discussed platforms on BlackHatWorld. All of these platforms are well-tuned to try to identify ad verification / anti-fraud bots, for instance, Adspect platform has pre-configured settings for identifying AdPolice, BrandVerity, and The Search Monitor:

cloaking-targeting.gif

PPC Brand Hijacking and Link Cloaking

When running ads on services such as Google Search, Instagram, and TikTok, malicious affiliates have further ways to hide their activity. Brand Hijacking occurs when the affiliate runs an ad which displays the brand’s real domain and mimics a real brand ad, so is indistinguishable from an ad from the official brand. When paired with one of the cloaking systems above, it makes affiliates very difficult to decloak without specialized systems to find the affiliate’s identity. 

 

The majority of link cloaking that Marcode deals with is malicious. We see affiliate fraudsters using link cloaking to hide their affiliate details when hijacking paid search ads. Affiliates will commonly run hijacked ads on core brand keywords (i.e. the brand’s name without any modifiers) because these tend to have very low CPCs when using the brand’s main domain, have high user intent, and typically very high conversion rates. 

​

Our experience has shown us these sophisticated cloaking services can allow the cloaked affiliate links to remain live in search engines undetected at a great financial cost to brands. Without a way of de-cloaking links, brands run the risk of having their entire affiliate marketing strategy compromised.

​

How to Decloak Affiliate Links Effectively?

Using a Decloaking Tool for Free

 

For unsophisticated and legitimate link cloaking, you can use a free tool to check the redirects that happen after clicking on a link. The redirect path Chrome extension by Ayima shows all the redirects in a chain after clicking on a link and can alert to cloaking. Tools such as Link Expander or Unshorten.it will take a shortened or cloaked URL and reveal the final destination.

​

These measures are fine for checking the final destination of a legitimately cloaked URL, but they will not uncover the sophisticated paid search cloaking affiliate hijackers use. 

​

How Marcode excels at decloaking sophisticated paid search hijacking

 

Marcode’s ad analysis platform is able to decloak the links of 100% of known hijacking advertisers and sophisticated link-cloaking platforms. While we can’t share our secret sauce, our system is able to perfectly imitate a real user who has clicked on an ad - this tricks the cloaking system into sending our analysis platform to the affiliate network. With this information, we are able to identify the affiliate and automatically dispatch warnings and/or remove the offending accounts from your affiliate network.

Conclusion

While link cloaking serves legitimate purposes in affiliate marketing - from URL simplification to performance tracking - its potential for misuse poses significant challenges for brands. The rise of sophisticated cloaking systems designed to evade detection has made it increasingly difficult for companies to identify fraudulent affiliate activity, particularly in paid search hijacking. While basic decloaking tools can help identify simple cloaked links, addressing sophisticated fraud requires advanced solutions like Marcode's ad analysis platform, which can effectively identify masked affiliate IDs and protect brands from unauthorized affiliate activity. As affiliate marketing continues to evolve, maintaining vigilance against fraudulent cloaking practices while supporting legitimate affiliate tracking remains crucial for brand protection and program integrity.

Use Marcode's industry leading link decloaker

bottom of page