What is cloaking in SEO? Google’s answer is precise: “Cloaking refers to the practice of presenting different content to users and search engines with the intent to manipulate search rankings and mislead users.” The definition has two conditions, and both matter. The content must differ between the two audiences, and the point of the difference must be to manipulate rankings and mislead.
That second condition is why so many legitimate setups are not cloaking, even though they do vary what a visitor sees. This piece explains how to recognise cloaking, what Google treats as acceptable, and how to check that your own site is not doing it without your knowledge. It does not explain how to cloak.
Cloaking in SEO examples from Google
Google’s spam policies give two examples of cloaking:
- “Showing a page about travel destinations to search engines while showing a page about discount drugs to users”
- “Inserting text or keywords into a page only when the user agent that is requesting the page is a search engine, not a human visitor”

The first example is a full bait and switch: the page that ranks is not the page people receive. The second is quieter. The page is broadly the same for everyone, but extra keyword text appears only when the request identifies itself as a crawler. Both share the same structure: the server decides what to send based on who is asking, and the crawler is shown something designed to rank that people never see.
The user agent is the identifying string a browser or crawler sends with each request. Varying content on that basis is not wrong in itself; varying it so the crawler gets a different, ranking-oriented page is the problem.

What is cloaking in SEO, and what is not
The received wisdom is that any difference between what Googlebot sees and what a user sees is cloaking. That is too broad, and it leads people to worry about setups that are entirely normal. The table sets out the common cases.
| Situation | Cloaking? | Why |
|---|---|---|
| A different page topic served to search engines than to users | Yes | Google’s first cloaking example |
| Keywords inserted only when the user agent is a search engine | Yes | Google’s second cloaking example |
| Paywalled content that Google can see in full, following Flexible Sampling guidance | No | Google’s stated paywall exception |
| The same content laid out differently for mobile and desktop | No | Same content, adapted to the device |
| Dynamic rendering that gives users and Googlebot equivalent content | No | The content is equivalent, only the delivery differs |
| Spam injected by an attacker and shown only to Googlebot | Yes, though not by the owner | Different content, aimed at search engines |
The first three verdicts come from Google’s spam policies; the others are our summary of how the definition applies, based on whether the content is equivalent.

Paywalls
Paywalls look like cloaking at first glance, because Google can read text that a visitor without a subscription cannot. Google addresses this directly: “we don’t consider this to be cloaking if Google can see the full content of what’s behind the paywall just like any person who has access to the gated material and if you follow our Flexible Sampling general guidance.” The content is the same; access is what differs.
Device layouts and rendering
Serving the same content in a layout adapted to the device is not cloaking. Neither is dynamic rendering, provided users and Googlebot receive equivalent content. If your site relies on JavaScript, our guide to JavaScript SEO covers how to make sure Google sees what your visitors see.
Hacked sites: cloaking you did not choose
Most cloaking found on real sites today is not the owner’s work. When a site is compromised, attackers often inject spam pages or links and serve them only to search engine crawlers. Visitors see the normal site, so the owner sees nothing wrong, while Google indexes pages full of spam under the site’s name.

The first signs are usually indirect: unfamiliar URLs or foreign-language titles in search results for your domain, or queries in Search Console that have nothing to do with your business. Because the spam is hidden from ordinary visitors, browsing the site will not reveal it.
The reliable check is Search Console’s URL Inspection tool. Its rendered view shows the page as Googlebot received it. Compare that with what you see in a browser. If the rendered page contains text, links or content you did not publish, treat it as a security incident first and an SEO problem second.
Cleaning up means removing the injected content, closing the hole the attacker used, and only then asking Google to look again. Fixing the visible symptoms while leaving an outdated plugin or a compromised account in place usually means the spam returns within weeks.

What happens if Google finds cloaking
Cloaking is one of the named practices in Google’s spam policies, and it is among the most clear-cut. There is no legitimate reason to show search engines a different page in order to rank it, so there is little room for a site to argue intent. A page or site can be demoted algorithmically or receive a manual action reported in Search Console. Our guide to the Google manual action process covers reconsideration once the problem is fixed.
Cloaking also sits alongside the other techniques covered in our overview of black hat SEO. A related pattern is the sneaky redirect, where users are sent somewhere different from what the crawler saw. If you are auditing redirects anyway, our guide to redirect chains is a useful companion.

How to check your own site
A simple routine catches most problems. Inspect your key templates in URL Inspection every few months and compare the rendered view with the live page. Search Google for your domain and scan the results for pages you do not recognise. Watch Search Console for sudden spikes in indexed pages or for queries unrelated to your topic.
If you run a paywall, an A/B testing tool or dynamic rendering, check that each one gives Googlebot content equivalent to what a user receives. Plugins and third-party scripts deserve the same scrutiny, because they can change output in ways the site owner never sees.
One limitation is worth stating. URL Inspection shows you one fetch of one URL. A compromised site can serve spam selectively, by URL or by time, so a single clean inspection is not proof the site is clean. Repeat the check across templates, and treat any unexplained discrepancy as worth investigating.
Frequently asked questions
What is cloaking in SEO in simple terms?
Showing search engines different content from what users see, with the intent to manipulate rankings and mislead users.
Is a paywall cloaking?
Not if Google can see the full content behind the paywall, just like a person with access, and you follow Google’s Flexible Sampling guidance.
Is a mobile-specific layout cloaking?
No. Adapting the layout of the same content to the device is not cloaking. The content has to be equivalent, not the design.
How can I tell if my hacked site is cloaking?
Use URL Inspection in Search Console and compare the rendered view with what you see in a browser. Spam visible only in the rendered view is a strong sign.
The takeaway Cloaking is defined by intent and by different content, not by any variation at all. Most site owners will only meet it on a compromised site, so check what Googlebot sees, not just what you see.

