Cloaking and sneaky redirects
Showing one page to Google's robot and another to the visitor, or sending the human somewhere other than where they thought they were going: cloaking is the most outright cheat in the catalogue, and one of the most harshly punished. Punished practices series, part four.
The previous parts described exaggerations, real content pushed too far. Here the nature of the thing changes: cloaking consists of deliberately serving two different contents, one for Google’s robot, one for the human. It is the most outright cheat in the catalogue, and the spam policies treat it as such.
The mechanism
Technically, nothing mysterious: when a page is requested, the server knows who is asking, and can recognize Google’s robot by its signature. The cloaked site then serves it a respectable page, rich in all the right vocabulary, while the human visitor receives something else entirely, an aggressive sales page, unrelated content, sometimes worse. The engine ranks the page it was shown; the searcher clicks and discovers the one that was hidden from it.
The kinship with the hidden text of part two leaps out: it is the same move, showing two faces, carried from the scale of a paragraph to that of a whole page. And the unfairness is total, since the search result becomes a promise the page behind it no longer has anything to do with.
Sneaky redirects
A variant of the same principle, which Google treats separately: the deceptive redirect. The indexed page does exist, but anyone who reaches it is immediately sent elsewhere, to a destination that has nothing to do with what the result promised. Some setups redirect only visitors on phones, or only those coming from Google, precisely so that the site owner and the robot never see anything unusual.
To be distinguished absolutely from legitimate redirects, which are a normal tool of the web: a site moving to a new address, a page merged into another, a trial version brought back to the current page. The criterion is always the same: an honest redirect takes the visitor where they wanted to go, under another address; a sneaky redirect takes them where someone else wanted them to go.
Why this concerns you: the hacked site
Here is the point that justifies this part for an honest reader: cloaking and sneaky redirects are the classic payload of a hack. A compromised SME site keeps working normally for its owner, that is deliberate, while it serves pharmaceutical spam to the robot or redirects visitors coming from Google to fraudulent pages. Google penalizes hacked content by demoting or excluding it, and displays warnings that ruin hard-won trust.
The defences are the ones already covered elsewhere: a site kept up to date, and an open Search Console account, because that is where security alerts and manual actions arrive. A simple test from time to time: search for your own site on Google and click the result from a phone. If you don’t end up at your own place, you know you need to call for help today, not next month.
Next part: content manufactured at scale, expired domains recycled for their reputation, and other people’s reputations squatted.
Who writes these notes
This journal is kept by the workshop that designs and maintains the house’s websites. Everything described here, the Search Console, internal links, the business profile, is part of the work delivered with a site: if you would rather someone took care of it, that is precisely the trade.