Cloaking is the practice of showing search engines different content from what human visitors see, with the aim of ranking for something the page does not really offer. Google treats it as a breach of its spam policies, and a site caught doing it can lose rankings or be removed from results.
How cloaking works
A cloaked site checks who is asking for the page before deciding what to send. It might look at the user agent (the name a browser or crawler gives itself, such as Googlebot), at the IP address the request comes from, or at the referring page. If the request looks like a search engine, the server returns one version, often stuffed with keywords or written on a different subject. If it looks like a person, it returns something else.
Typical examples include a page that shows Google a long article about holiday lettings while visitors see a casino sign-up form, text that is only included when the request comes from a crawler, and a JavaScript redirect that sends people to a different site while crawlers stay on the original page.
Much of the cloaking found on small business sites today was not put there by the owner. Hacked WordPress sites are commonly injected with code that shows Google pages of spam about pharmaceuticals, replica goods or gambling, often in Japanese, while the owner browsing normally sees nothing wrong. The hack is designed to stay hidden from the one person most likely to fix it.
Why it matters
Google’s view is simple: the searcher should get what the result promised. When its systems or reviewers find cloaking, the usual outcome is a manual action in Search Console, which can affect individual pages or the whole site, followed by a reconsideration request once it is cleaned up. Algorithmic spam systems can demote a site without any notice at all.
For a business that did not know it was happening, the damage arrives twice: traffic falls, and the brand name appears next to spam in search results, which puts off customers. The cloaked pages can also be used to attack visitors.
Not every difference between users counts as cloaking. Adapting layout to mobile, showing prices in pounds to UK visitors or personalising a greeting is fine, provided Googlebot is treated like a normal visitor in the same situation. Paywalled content that is marked up correctly with structured data is also accepted. One UK-specific trap: Googlebot mostly crawls from US addresses, so a site that redirects or blocks visitors from outside the UK can accidentally hide itself from Google.
Common mistakes
- Only checking the site in your own browser. Hacks often hide from logged-in admins and visitors who do not arrive from Google.
- Serving bots a different “SEO version”. Old advice about giving crawlers keyword-rich text and humans a slick design is exactly what the policy forbids.
- Hiding text instead. White-on-white text or content placed off-screen to influence rankings is a close relative of cloaking, and Google’s spam policies forbid it too.
- Cleaning up without finding the cause. Removing spam pages but leaving the vulnerable plugin in place usually means the hack returns.
How to act on it
Search Google for site:yourdomain.co.uk and scroll through the results looking for pages or titles you did not create. Use the URL Inspection tool in Search Console to see the HTML Google received for your main pages, and compare it with what you see in the browser. Check the Security issues and Manual actions sections of Search Console, which is where Google reports hacked content and cloaking.
If something is wrong, take a backup, update WordPress, themes and plugins, remove unknown admin users, scan the files for injected code and rotate every password. Then request a review in Search Console. Cloaking is one of the black hat SEO tactics I check for in every SEO audit, because a hack that only shows to Google can go unnoticed for months.
