LinkScaleLinkScale

What cloaking means in SEO, and what it means for links

Cloaking means showing crawlers and people different content. One version gets you removed from Google, the other keeps bots out of your analytics. The difference.

Written byReviewed byRobin Bosca
Updated on 5 min readReviewed in-house
What cloaking means in SEO, and what it means for links

Cloaking means showing one version of a page to a crawler and a different version to a human visitor. That is the whole definition, and it covers two very different practices that get confused constantly: a deceptive technique that Google penalises, and a routine filtering step that most large sites perform without anyone calling it cloaking.

Knowing which one you are doing matters, because one of them can cost you your search visibility and the other is how you keep bot traffic out of your numbers.

What is cloaking in SEO?

The definition Google uses

In search, cloaking means serving content to Googlebot that differs from what a person sees, in order to change how the page ranks. Showing a crawler a page stuffed with keywords while showing visitors a photo gallery is the textbook case.

This is a violation of Google's spam policies, and the penalty is removal from the index. It is not a grey area and there is no clever version of it that works long term.

Why people still try it

Because it appears to work for a few weeks. A page ranks for terms it does not deserve, traffic arrives, and then the site disappears from search results with no warning and no easy way back. The upside is temporary and the downside is permanent.

If you are optimising a page for search, the honest answer is that the crawler and the visitor should see the same thing.

The word is also used for something unrelated to search rankings: deciding what an automated request receives when it hits a link, as opposed to what a real person receives.

Every link you publish on a social platform gets fetched by machines before, and often instead of, being fetched by people. Preview generators, security scanners, spam filters, monitoring services and scrapers all request the URL. Some identify themselves honestly. Many do not.

Why anyone filters at all

Three reasons, none of which have anything to do with search rankings.

Measurement. If a third of the requests hitting your link are automated, your click count is fiction and every decision you make from it is wrong. Separating machines from people is the difference between analytics and noise.

Preview control. When a link is shared, the preview is generated by a crawler that reads your page's metadata. Controlling what that crawler receives is how you control the preview card, which is a normal and expected part of publishing a link.

Protection against scraping. A link that resolves identically for everyone is trivially harvested at scale. Filtering automated requests is standard practice, and it is the same logic behind every rate limiter and bot-management product on the market.

Where the line is

Here is the distinction that matters, and it is worth being precise about it.

Filtering automated traffic to keep your analytics clean and your content from being scraped is ordinary infrastructure. Serving deceptive content to a platform's review systems in order to publish something that would otherwise be refused is a different thing, it breaks the platform's terms, and it puts the account at risk rather than protecting it.

We do not build for the second case and we would not recommend it. If a destination cannot pass a platform's review, the answer is to change the destination, not to hide it. That is a harder answer and it is the only one that survives contact with an enforcement team.

What LinkScale actually does

Our filtering layer is built for the first case: telling machines and people apart, and treating them differently.

What arrivesWhat it getsWhy
A real visitorYour page, and routing toward their own browser rather than an in-app webviewFewer steps between them and your destination
A preview crawlerClean metadata for the preview cardThe link looks right when shared
A datacenter request, proxy or known scraperA neutral responseIt is not a visitor, and it should not be counted as one

The routing part matters as much as the filtering. A visitor who lands in a social app's in-app browser is not signed in and does not have their saved payment details, which is why the same page converts differently depending on where it opens. We cover that mechanism in detail in what is a deep link.

Traffic quality is the useful output

The point of separating machines from people is not the separation itself, it is the number you get afterwards.

Once automated requests are excluded, your click count means something. You can compare platforms honestly, see which source sends people who actually arrive, and stop optimising campaigns against inflated figures. Our traffic quality page covers the signals we use, and analytics covers what you get to see.

What you should track

Clicks alone tell you almost nothing. The fields that change decisions:

  • how many requests were automated, and what share of the total that represents
  • the referring platform, so you can compare sources on equal terms
  • device, operating system and browser
  • whether the request came from an in-app webview
  • country
  • which route the visitor took, and whether a fallback fired

A click count that has not been filtered is not a metric, it is a maximum.

Frequently asked questions

Is cloaking illegal? No, it is not a legal question. Cloaking for search rankings violates Google's spam policies and can get a site removed from the index. Serving deceptive content to a social platform's review systems breaks that platform's terms of service and puts the account at risk. Neither is a criminal matter, both carry real consequences.

Is filtering bot traffic the same as cloaking? They overlap in mechanism and differ completely in purpose. Filtering automated requests to keep analytics accurate and prevent scraping is standard practice. Serving different content to a reviewer in order to publish something that would be refused is not, and it is the version that gets accounts banned.

Will Google penalise me for filtering bots on my links? Filtering automated requests on a redirect link is not the same as showing Googlebot a different version of an indexable page. The behaviour Google penalises is deception aimed at changing rankings. If you are unsure, the safe rule is that any page you want ranked should serve crawlers and people the same content.

Does cloaking prevent a shadowban? No, and treating it as protection is how people end up losing accounts. Platform restrictions follow from the content and the destination, not from whether a crawler was filtered. The durable fixes are a clean destination, a domain you control, and an account with real history behind it.

What is the difference between cloaking and a redirect? A redirect sends everyone to the same place. Filtering decides what a given request receives based on what it appears to be. A link can do both, and most do.


Last updated: 4 September 2026. Written by Thomas Melto, CEO of LinkScale.

Written by

, Founder & CEO, LinkScale

Builds LinkScale daily with the creators and agencies who run their business through their bio link.

Reviewed by Robin Bosca, Co-founder & CTO, LinkScale

Keep going with our content on branded links, landing pages and analytics.

+100% conversion