Cloaking and sneaky redirects are SEO techniques that show search engines something different from what your visitors actually see with the intent to mislead users. Google treats this as a deliberate attempt to manipulate rankings, and it’s one of the few SEO issues that can get a site removed from search results entirely – even when the mismatch wasn’t intentional.
Both of these techniques come under the umbrella of ‘Black hat SEO’ and are heavily penalised by search engines. Google considers these techniques an attempt to manipulate search rankings rather than provide the best possible result for users. Both cloaking and sneaky redirects violate Google’s Search Essentials (previously known as the Webmaster Guidelines). On 15th May 2026, Google explicitly updated its spam policies to apply to both traditional SERPs and generative AI features, such as AI Overviews.
Importantly, cloaking and sneaky redirects can sometimes occur unintentionally, particularly as a result of hacked websites or incorrect website configurations.
In the rest of this blog, we will cover:
- Quick Answer: What Is Cloaking in SEO?
- Quick Answer: What Are Sneaky Redirects in SEO?
- Real-world Cloaking Examples
- Types of Cloaking
- Cloaking vs. Legitimate Personalisation: What’s Not Cloaking?
- What are Sneaky Redirects?
- What Are the Consequences of Using Cloaking and Sneaky Redirects?
- Common Misconceptions About Cloaking and Sneaky Redirects
- How Do I Know the Agency I Choose is Using the Right SEO Practices?
- Build Your Website Presence Ethically With Wildcat Digital
- Cloaking and Sneaky Redirect FAQs
Quick Answer: What Is Cloaking in SEO?
Cloaking is a deceptive black-hat technique where the content displayed on a website to human visitors is different to what is displayed to search engines. There are different types of cloaking in SEO, including user-agent, IP, hidden text and HTTP language, but all forms risk severe penalties from search engines or even removal from the search engine results pages (SERPs) altogether.
Quick Answer: What are Sneaky Redirects in SEO?
Sneaky redirects are deceptive redirects that send users or search engines to unexpected or substantially different content from the URL they originally requested. Legitimate redirects, such as redirects used during website migrations, are not considered sneaky redirects.
Learn more about sneaky redirects.
Real-world Cloaking Examples:
- A page that shows keyword-stuffed text to Googlebot (Google’s Crawler) while showing a stripped-down sales page to human visitors.
- Google sees -> a page containing hundreds of keywords (e.g. “cheap flights”, “best flights”, “cheap flights UK”)
- Humans see -> a normal sales page with minimal text, focused on booking a flight.
- A website that shows Googlebot an informative article about “How to choose the best business insurance”, while redirecting human visitors to a completely different sales or affiliate page.
- Google sees → a detailed, helpful article targeting relevant insurance keywords.
- Humans see → a sales page promoting an insurance product or sending them to an affiliate website.
- A hacked website that shows search engines spam content and links, while showing the normal website to human visitors.
- Google sees → pages containing spam keywords and links to unrelated websites (e.g. “buy cheap watches”, “online casino”, “cheap medication”).
- Humans see → a legitimate business’ website with no visible spam content.
Types of Cloaking
Cloaking can be implemented in several ways, depending on how a website identifies the visitor and decides what content to serve. Common examples include:
- IP Cloaking
- HTTP Accept-Language Cloaking
- User-agent Cloaking
- Hidden Text Cloaking (defined as hidden text and link abuse in Google spam policies)
IP Cloaking
IP cloaking is used when a website will serve different content to different users, depending on their IP address. For example, a server that identifies the IP address of a search engine bot will provide content that is stuffed with more keywords. When the IP is not associated with a search engine, it will provide a different version – typically a more minimalist page that’s easier for human users to read and understand.
This can also work in reverse – if a bot is identified based on its IP address, the server will display well-optimised informational content. However, if a human user is identified, it serves a different page, e.g. ads or malicious content.
HTTP Accept-Language Cloaking
This is simply where the server will display different content to users based on the language preference set in their browser. Normal browsers send an Accept-Language request header telling the server which languages the user prefers, but crawlers often omit this header. This allows sites to distinguish between real human visitors and crawlers and therefore serve them different content.
User-agent Cloaking
User-agent cloaking can identify the user-agent visiting the website using the User-Agent string (which states whether it’s, for example, Googlebot or an iPhone Safari browser). Depending on whether the visitor is identified as a crawler/scanner or a real human user, the site will display a different version of the content.
Hidden Text Cloaking
This is where a website will have more links and keywords written directly into the code of the website. This means they are visible to web crawlers but not human website visitors. These are usually hidden from users by:
- Matching the font colour to the background, for example, black text on a black background
- Tiny fonts
- Placing text or links behind images
- Using CSS to push text outside the visible browser window
- Placing links on a small section of text, for example, on a full stop.
Google treats this technique as a direct violation of its Spam Policies for Google Web Search.
SEO Cloaking Types: Key Differences
| Type of cloaking | How it works | What is used to identify the visitor? | Example | Main purpose |
| IP Cloaking | Different content is served depending on the visitor’s IP address. | IP address | Googlebot’s IP receives keyword-rich content, while other IPs receive a simplified sales page. | To show search engines a more SEO-focused version of a page. |
| HTTP Accept-Language Cloaking | Different content is served depending on the language preference sent by the browser. | Accept-Language HTTP header | A crawler that doesn’t send a language preference receives an SEO-optimised page, while users receive a different version. | To distinguish between crawlers and human visitors and serve different content. |
| User-agent Cloaking | Different content is served depending on the visitor’s User-Agent string. | User-Agent string | Googlebot receives an informational article, while users are shown a sales or affiliate page. | To specifically target search engine crawlers with different content. |
| Hidden Text Cloaking | Additional keywords or links are included in the page but hidden from human visitors. | CSS/HTML visibility rather than visitor identification | Google can crawl keyword-rich text that is hidden using matching font/background colours, tiny text or CSS positioning. | To add additional ranking signals without displaying the content to users. |
Cloaking vs. Legitimate Personalisation: What’s Not Cloaking?
Not every version of your site that changes based on the visitor is cloaking. Localisation, responsive design, and A/B testing all show different content to different people – the difference is intent and whether search engines see a fair, accessible version of the page too.
Legitimate personalisation is generally safe when search engines can access and understand the same underlying content and functionality as users, and there is no attempt to hide content or serve search engines a deliberately different version of the page.
The following are typically not considered cloaking by search engines, but rather legitimate personalisation techniques:
- Geolocation/ localisation – Shows location-specific content to improve the user experience, such as local prices or services.
- Responsive/adaptive design – Adjusts the layout or functionality based on the user’s device or screen size.
- A/B testing – Shows different versions of a page to users to test which performs better, without deliberately deceiving search engines.
| Legitimate technique | How it works | What makes it legitimate? | How it can tip into cloaking |
| Geolocation/Localisation | Content can change based on a user’s location, such as showing prices in their local currency or providing location-specific information. | The variations are designed to provide a better experience for users in different locations, rather than to manipulate rankings. Search engines can access the relevant content. | Serving Googlebot a keyword-rich location page while showing users a substantially different page, or deliberately hiding content from search engines. |
| Responsive/Adaptive Design | The layout or functionality changes depending on the user’s device or screen size. | The same core content is available to users and search engines, with the page adapting to the device being used. | Detecting Googlebot and deliberately serving it a different or more SEO-focused version of the page than the version shown to real users. |
| A/B Testing | Different users are randomly shown different versions of a page to determine which performs better. | The test is designed to improve the user experience or conversion rate, and Googlebot is not deliberately given a preferential version. | Serving Googlebot a static, keyword-optimised version while real visitors are shown a substantially different test version specifically to influence rankings. |
Wildcat Digital Insight: When a Legitimate Technical Set-Up Accidentally Looks Like Cloaking
Cloaking doesn’t always need to be malicious or intentionally deceptive; even legitimate technical set-ups can lead to potential cloaking risks.
How Would We Handle This?
Let’s look at an example scenario: a new client is running an A/B test on a key landing page. The test is designed to show approximately 50% of visitors a new version of the page while the remaining visitors see the original.
During our initial technical SEO audit, we would investigate whether search engines are being exposed to the same experience as users, particularly where a page is being dynamically served or altered based on the visitor.
What Would We Look For?
Our technical SEO team would compare how the page is served to a normal user with how it is accessed by Googlebot.
If we found that the A/B testing configuration was identifying search engine crawlers and deliberately excluding them from the experiment, this would raise a potential cloaking concern.
For example:
- Real users could be split between the original and test versions.
- Googlebot could consistently be shown the original version.
- Google could therefore be seeing a different version of the page from a significant proportion of users.
What Could Be Causing It?
The issue could stem from the way the A/B testing platform has been configured. For example, a setting intended to prevent search engines from seeing experimental content could result in Googlebot being treated differently from normal users.
Although the purpose may be to protect organic visibility during testing, deliberately serving different content based on whether a visitor is identified as a search engine crawler can create a potential cloaking risk.
How Would We Resolve It?
We would work with the development team to review how the experiment is being served and identify whether Googlebot is being treated differently from other visitors.
Our approach would be to:
- Identify the difference – compare the page served to users with the version accessed by Googlebot.
- Investigate the configuration – establish why search engine crawlers are being excluded or treated differently.
- Review the SEO implications – assess whether the implementation could result in materially different content being served to search engines.
- Work with developers – adjust the testing configuration so that Googlebot isn’t deliberately served a different version simply because it has been identified as a crawler.
- Re-test – verify that the page is being served consistently and that the A/B test continues to function as intended
The key lesson is that A/B testing itself isn’t cloaking. Risks arise when the implementation specifically treats search engine crawlers differently from normal users.
SEO takeaway: When investigating potential cloaking, don’t just compare the page source or visible content. Check how the site behaves for different user types, including Googlebot. Legitimate personalisation, testing or technical functionality can create unexpected differences if crawlers are handled separately.
What are Sneaky Redirects?
Sneaky redirects are deceptive redirects that send users or search engines to a different URL than the one displayed or expected. They violate official Google Search Central Spam Policies because they intentionally mislead visitors.
With a sneaky redirect, a user clicks on a link in the search results, but the site sends them to a different page. Whilst sneaky redirects can be deliberately used by some sites to manipulate search results, they are also commonly caused by security breaches or malicious third-party code.
Legitimate vs. Sneaky Redirects
Not all redirects are bad. Sneaky redirects should not be confused with standard redirects (3xx status codes), which are used to send users and search engines to a new URL either temporarily or permanently, for example, when a page has been removed or a URL has been changed.
The Simple Rule
Different content does not automatically mean cloaking. The key question is why the difference exists and whether search engines are deliberately being treated differently to manipulate rankings or mislead users.
| Legitimate Redirects | Sneaky Redirects | |
| Purpose | Move users to a new, relevant URL for a genuine reason. | Deceive users or search engines or manipulate search rankings. |
| Typical use | Deleted pages, changed URLs, site migrations or consolidating content. | Sending users to unrelated, misleading or different content from what search engines see. |
| Destination | Relevant and expected based on the original URL. | Unexpected, irrelevant or different depending on the visitor. |
| Example | /old-page/ → /new-page/ after a site restructure. | Googlebot sees an informational page, but users are redirected to a commercial or unrelated page. |
| SEO impact | Generally safe when implemented correctly using the appropriate redirect. | Can violate Google’s spam policies and lead to ranking demotions or removal from search results. |
“Remember: a redirect that sends a user from an old URL to its updated version, visibly and consistently, is not a sneaky redirect. A legitimate redirect helps users reach the right page; a sneaky redirect deliberately sends them somewhere different to deceive or manipulate”
Dariusz Baczyk
Team Lead & Technical SEO Account Manager
Learn more about redirects in our informative guides:
- Is a 301 or 302 Redirect Better for SEO?
- Everything You Need to Know About Website Redirects
- When Should You Use a 302 Redirect?
- How to Set Up 301 Redirects and When You Should Do it
What Are the Consequences of Using Cloaking and Sneaky Redirects?
Cloaking and sneaky redirects can have serious SEO and business consequences when they cause search engines to see or experience pages significantly different from users. Whether the behaviour is deliberate, caused by a technical implementation or the result of a security breach, it can affect how search engines crawl, index and rank your pages.
Potential consequences include:
- Manual actions: Google may issue a manual action if it determines that a site is violating its spam policies. This can result in affected pages being demoted or removed from search results. Learn more about Google penalties and how they can impact your website in our blog, ‘What is a Google Penalty? 5 Things You Should Know’.
- Ranking and traffic losses: If Google is unable to see or evaluate the same content that users experience, important pages may lose visibility and organic traffic.
- Pages being removed from the index: In more serious cases, affected URLs may be excluded from Google’s search results altogether.
- Loss of leads and revenue: Reduced organic visibility can result in fewer visitors, enquiries, conversions and sales.
- Damage to user trust: Unexpected redirects or content that doesn’t match what users expected can damage a brand’s credibility and reputation.
- Additional recovery work: Resolving the issue may require technical investigation, removing the offending behaviour, securing a compromised site and monitoring the site to ensure the problem does not return.
Recovering from this kind of penalisation can take a very long time – cleaning up your site, submitting reconsideration requests via Google Search Console and trying to rebuild trust with both search engines and users. It’s essential to be aware of cloaking, sneaky redirects and other Black Hat SEO practices, so you can avoid accidentally getting penalised by search engines and causing long-lasting damage to your site.
Common Misconceptions About Cloaking and Sneaky Redirects
There are several common misconceptions about cloaking and sneaky redirects. Understanding the difference between legitimate SEO practices and deceptive techniques can help businesses avoid unnecessary SEO risks.
Myth 1: Every redirect is a sneaky redirect – FALSE
Redirects are a normal part of SEO and website management. They are commonly used when pages are moved/deleted, URLs change, websites migrate or multiple pages are consolidated. A redirect only becomes sneaky when it is used to deceive users or search engines, such as sending them to unexpected or substantially different content.
Myth 2: Personalisation Is Cloaking – FALSE
Personalisation, localisation, responsive design and correctly implemented A/B testing can show different experiences to users without being deceptive or being classed as cloaking. The key difference is whether search engines are deliberately treated differently from users in a way that manipulates rankings or misleads them.
Myth 3: Only Large Websites Get Caught – FALSE
Google uses both automated systems and manual human checks to detect spam policy violations. Sites can also be reported by users. Cloaking and sneaky redirects can negatively impact websites of all sizes.
Myth 4: Cloaking Penalties Only Affect Search Results – FALSE
Google’s spam policies apply across Google Search, including generative AI features such as AI Overviews. In May 2026, Google clarified that its spam policies also apply to generative AI responses in Google Search, including features such as AI Overviews and AI Mode.
How Can Cloaking and Sneaky Redirects Be Identified?
Google can identify potential cloaking and sneaky redirects by comparing what search engine crawlers see with what real users see.
Google may look for:
- Different content: Googlebot receives substantially different HTML or rendered content from normal users.
- Different redirects: Search engines and users are sent to different URLs or destinations.
- Different server responses: The server, CDN or other technology responds differently depending on the visitor.
- User reports and other signals: Reports or technical signals may indicate that search engines and users are being treated differently.
How Can You Check for Cloaking Yourself?
Businesses and SEOs can carry out several checks:
- Compare what Googlebot receives with what users receive – Check whether Googlebot receives substantially different content from a normal browser. Screaming Frog SEO Spider can help with this by allowing you to change the crawler’s user-agent, including to Googlebot, and compare responses.
- Check for unexpected redirects – Crawl the website with Screaming Frog to identify 3xx redirects, redirect chains and unexpected destinations. You can then investigate whether redirects behave differently depending on the user-agent, device or other conditions.
- Compare raw and rendered HTML – Use Screaming Frog’s JavaScript rendering to compare the HTML received before and after JavaScript is executed. Significant differences can help identify content that is being added, removed or changed during rendering.
- Review server and CDN rules – Check whether IP, user-agent or other rules are serving different content or redirects.
- Use Google Search Console – Use the URL Inspection tool to compare Google’s view of a URL with the live page.
- Investigate unexpected differences – Differences do not automatically mean cloaking, but they should be investigated to determine why they occur.
Useful tools:
- Screaming Frog can be used to crawl with different user-agents, analyse redirects and compare rendered HTML.
- Google Search Console’s URL Inspection tool can show how Google accesses and renders a URL.
- Chrome DevTools can be used to inspect network requests and redirects, while curl can be used to compare server responses for different user-agents.
Key takeaway: Cloaking and sneaky redirects can result from technical misconfigurations, third-party tools, A/B testing or security breaches, not just deliberate SEO manipulation. Regular technical checks can help identify unexpected differences before they cause SEO problems.
How Can I Avoid Cloaking and Other Black Hat SEO Techniques?
Choose an SEO agency who is transparent with you about their practices, and doesn’t promise you results overnight. SEO is a long-term strategy and an agency promising instant or guaranteed results may be using black-hat techniques that might work temporarily, but could be disastrous for your business over the long term.
Your SEO agency should be transparent about the work they are going to complete for you and what impact they expect it to have. While a good agency should identify quick wins and prioritise work which will have the biggest impact, they should never resort to black-hat techniques to get results.
Build Your Website Presence Ethically With Wildcat Digital
Here at Wildcat Digital, our SEO experts follow only white-hat SEO practices, building your online presence with your users at the heart of your campaign. We follow Google’s search essentials guidelines to build trust and authority with both search engines and users, delivering helpful, high-quality content on solid technical SEO foundations.
If you want to boost your online presence we have experts on SEO and PPC who can help you achieve your goals.
Get in touch with us today!
Key Definitions
| Term | Simple definition |
| Cloaking | Showing search engines substantially different content from users to manipulate rankings or mislead visitors. |
| Sneaky redirect | Sending users or search engines to unexpected or substantially different content from the requested URL. |
| Legitimate redirect | Sending users and search engines to a relevant new URL for a genuine reason, such as a site migration. |
| Personalisation | Changing content or functionality based on legitimate factors such as location or device without deliberately deceiving search engines. |
Cloaking and Sneaky Redirect FAQs
Is a Redirect After a Website Migration a Sneaky Redirect?
No. Redirecting an old URL to a relevant new URL as part of a website migration is a legitimate SEO practice. A redirect becomes a sneaky redirect when it is used to deceive users or search engines by sending them to unexpected or substantially different content.
Are Redirects Bad for SEO?
No, redirects are not inherently bad for SEO. Properly implemented redirects can help preserve rankings and ensure both users and search engines reach the correct URL. The problem occurs when redirects are used deceptively or to manipulate search rankings, referred to as sneaky redirects.
Can Cloaking Happen by Accident?
Yes. Cloaking can occur unintentionally due to technical misconfigurations, A/B testing tools, third-party scripts, CDN or server rules, or a website security breach. If search engines are consistently shown substantially different content from human users, the implementation should be investigated.
Concerned that your website may be using cloaking? Contact the Wildcat Digital team for help investigating the issue.
Does Google’s Cloaking Policy Apply to AI Overviews?
Yes. Google’s Search spam policies also apply to generative AI features in Search, including AI Overviews (updated to explicitly state this on 15 May 2026). This means websites should not use cloaking or other spam techniques to manipulate how their content is represented in Google’s AI-generated search features.
How Do I Check if My Site Is Cloaking?
Compare what Googlebot receives with what a normal user sees. You can use tools such as Google Search Console’s URL Inspection tool and Screaming Frog to investigate differences in content, rendering, redirects and server responses. Unexpected differences do not automatically mean cloaking, so investigate the technical reason behind them with the help of an expert technical SEO agency like Wildcat Digital.