Free to explore: filter winning sites by DR, traffic and niche  ·  Try the live explorer →

Cloaking in SEO, with examples

A mask with two faces

What is cloaking in SEO? Google’s answer is precise: “Cloaking refers to the practice of presenting different content to users and search engines with the intent to manipulate search rankings and mislead users.” The definition has two conditions, and both matter. The content must differ between the two audiences, and the point of the difference must be to manipulate rankings and mislead.

That second condition is why so many legitimate setups are not cloaking, even though they do vary what a visitor sees. This piece explains how to recognise cloaking, what Google treats as acceptable, and how to check that your own site is not doing it without your knowledge. It does not explain how to cloak.

Cloaking in SEO examples from Google

Google’s spam policies give two examples of cloaking:

  • “Showing a page about travel destinations to search engines while showing a page about discount drugs to users”
  • “Inserting text or keywords into a page only when the user agent that is requesting the page is a search engine, not a human visitor”
A user agent string in code

The first example is a full bait and switch: the page that ranks is not the page people receive. The second is quieter. The page is broadly the same for everyone, but extra keyword text appears only when the request identifies itself as a crawler. Both share the same structure: the server decides what to send based on who is asking, and the crawler is shown something designed to rank that people never see.

The user agent is the identifying string a browser or crawler sends with each request. Varying content on that basis is not wrong in itself; varying it so the crawler gets a different, ranking-oriented page is the problem.

Two versions of a page side by side

What is cloaking in SEO, and what is not

The received wisdom is that any difference between what Googlebot sees and what a user sees is cloaking. That is too broad, and it leads people to worry about setups that are entirely normal. The table sets out the common cases.

SituationCloaking?Why
A different page topic served to search engines than to usersYesGoogle’s first cloaking example
Keywords inserted only when the user agent is a search engineYesGoogle’s second cloaking example
Paywalled content that Google can see in full, following Flexible Sampling guidanceNoGoogle’s stated paywall exception
The same content laid out differently for mobile and desktopNoSame content, adapted to the device
Dynamic rendering that gives users and Googlebot equivalent contentNoThe content is equivalent, only the delivery differs
Spam injected by an attacker and shown only to GooglebotYes, though not by the ownerDifferent content, aimed at search engines

The first three verdicts come from Google’s spam policies; the others are our summary of how the definition applies, based on whether the content is equivalent.

A subscription paywall

Paywalls

Paywalls look like cloaking at first glance, because Google can read text that a visitor without a subscription cannot. Google addresses this directly: “we don’t consider this to be cloaking if Google can see the full content of what’s behind the paywall just like any person who has access to the gated material and if you follow our Flexible Sampling general guidance.” The content is the same; access is what differs.

Device layouts and rendering

Serving the same content in a layout adapted to the device is not cloaking. Neither is dynamic rendering, provided users and Googlebot receive equivalent content. If your site relies on JavaScript, our guide to JavaScript SEO covers how to make sure Google sees what your visitors see.

Hacked sites: cloaking you did not choose

Most cloaking found on real sites today is not the owner’s work. When a site is compromised, attackers often inject spam pages or links and serve them only to search engine crawlers. Visitors see the normal site, so the owner sees nothing wrong, while Google indexes pages full of spam under the site’s name.

A rendered page view in an inspection tool

The first signs are usually indirect: unfamiliar URLs or foreign-language titles in search results for your domain, or queries in Search Console that have nothing to do with your business. Because the spam is hidden from ordinary visitors, browsing the site will not reveal it.

The reliable check is Search Console’s URL Inspection tool. Its rendered view shows the page as Googlebot received it. Compare that with what you see in a browser. If the rendered page contains text, links or content you did not publish, treat it as a security incident first and an SEO problem second.

Cleaning up means removing the injected content, closing the hole the attacker used, and only then asking Google to look again. Fixing the visible symptoms while leaving an outdated plugin or a compromised account in place usually means the spam returns within weeks.

A hacked site warning

What happens if Google finds cloaking

Cloaking is one of the named practices in Google’s spam policies, and it is among the most clear-cut. There is no legitimate reason to show search engines a different page in order to rank it, so there is little room for a site to argue intent. A page or site can be demoted algorithmically or receive a manual action reported in Search Console. Our guide to the Google manual action process covers reconsideration once the problem is fixed.

Cloaking also sits alongside the other techniques covered in our overview of black hat SEO. A related pattern is the sneaky redirect, where users are sent somewhere different from what the crawler saw. If you are auditing redirects anyway, our guide to redirect chains is a useful companion.

A website security audit

How to check your own site

A simple routine catches most problems. Inspect your key templates in URL Inspection every few months and compare the rendered view with the live page. Search Google for your domain and scan the results for pages you do not recognise. Watch Search Console for sudden spikes in indexed pages or for queries unrelated to your topic.

If you run a paywall, an A/B testing tool or dynamic rendering, check that each one gives Googlebot content equivalent to what a user receives. Plugins and third-party scripts deserve the same scrutiny, because they can change output in ways the site owner never sees.

One limitation is worth stating. URL Inspection shows you one fetch of one URL. A compromised site can serve spam selectively, by URL or by time, so a single clean inspection is not proof the site is clean. Repeat the check across templates, and treat any unexplained discrepancy as worth investigating.

Frequently asked questions

What is cloaking in SEO in simple terms?

Showing search engines different content from what users see, with the intent to manipulate rankings and mislead users.

Is a paywall cloaking?

Not if Google can see the full content behind the paywall, just like a person with access, and you follow Google’s Flexible Sampling guidance.

Is a mobile-specific layout cloaking?

No. Adapting the layout of the same content to the device is not cloaking. The content has to be equivalent, not the design.

How can I tell if my hacked site is cloaking?

Use URL Inspection in Search Console and compare the rendered view with what you see in a browser. Spam visible only in the rendered view is a strong sign.

The takeaway Cloaking is defined by intent and by different content, not by any variation at all. Most site owners will only meet it on a compromised site, so check what Googlebot sees, not just what you see.