The problem
Ad fraud and malvertising often rely on cloaking: verification crawlers from known datacentre ranges receive a clean page, while real users in the targeted region are sent through redirects to something else.
Verifying a campaign therefore means loading placements from residential addresses in the targeted cities and following the full redirect chain from the same IP.
Configuration
- Product
- Rotating residential with city targeting
- Session
- Sticky, 5–10 minutes, one session per verification run
- Targeting
- -country-it-city-milan, matching the campaign's geo-targeting
- Redirects
- Follow and log every hop from the same session
- Device
- Mobile user agent for mobile inventory; mobile proxies for carrier-only campaigns
- Evidence
- Store screenshots, final URLs and timestamps per run
Example
import secrets
import requests
LOGIN, PASSWORD = "px7h2k9m4q", "Rq4Tn8Vw2Lx6Bz9C"
def session_proxy(country, city, ttl=10):
sid = secrets.token_hex(4)
user = f"{LOGIN}-country-{country}-city-{city}-session-{sid}-ttl-{ttl}"
return f"http://{user}:{PASSWORD}@resi.gw.proxuno.com:7000"
proxy = session_proxy("it", "milan")
s = requests.Session()
s.proxies = {"http": proxy, "https": proxy}
r = s.get("https://publisher.example/article-with-ad", timeout=30)
for hop in r.history:
print(hop.status_code, hop.headers.get("location"))
print("final:", r.url)
Example credentials. Replace them with yours from the dashboard.
Best practices
- Use one sticky session per verification run so the whole redirect chain is seen from one address.
- Vary cities within the campaign's target area; cloaking is often limited to a few metropolitan areas.
- Keep request rates low per placement — you are checking what users see, not load-testing the ad server.
- Keep evidence (HAR files, screenshots) with the exit city and time for disputes with the network.
Compliance
Do not click ads or generate impressions that are billed to advertisers. Verification traffic must not inflate campaign metrics.