Spy Tool Protection: How Not to Hand Your Funnel to Competitors

Ad spy tools collect other people's creatives and landing pages and sell access to them. Spy tool protection is how you keep your winning funnel out of their database on day one.

Bots and Fraud10 min read
Spy Tool Protection: How Not to Hand Your Funnel to Competitors
Contents
  1. What spy tools are and why they are dangerous
  2. How spy tools collect landing pages
  3. Signs of a spy tool in your traffic
  4. How to hide your landing page from spy tools
  5. Protecting ad creatives: what you can realistically do
  6. How ArtisanClo protects against spy tools
  7. What spy tool protection cannot do
  8. If your funnel has already been copied: what to do
  9. Bottom line

You found a funnel that pays off, and a week later you see your pre-lander at three competitors, with the same headlines and the same image. Almost everyone who has run traffic for more than a couple of months knows the feeling. Most likely the landing page was picked up by a spy tool: a robot that crawls ads and saves everything it finds behind them.

What spy tools are and why they are dangerous

An ad spy tool is a database of ads collected from ad platforms, searchable by geo, niche, text and run date. In good databases each ad comes with its landing page: the pre-lander, the landing page, sometimes the final offer and the link parameters.

For media buyers it is a handy reconnaissance tool. For the person who built the funnel, it is a threat:

  • The funnel gets copied. The creative, the angle, the pre-lander, the offer: everything you found through tests and budget goes to others for free.
  • The auction gets more expensive. The more people run the same funnel, the higher the cost per click and the faster the audience burns out.
  • The offer gets exposed. If the offer lands in the database along with the ad, competitors pick it up, and the advertiser and the affiliate network see that your stream has become common property.

How spy tools collect landing pages

To defend yourself, you need to understand the mechanics. Collection usually works like this:

  1. Collecting ads. The service runs many accounts on the platform or uses its public ad libraries and saves the ads it is shown.
  2. Following the link. It then automatically follows the ad link, often from servers or through proxies in the right geo.
  3. Rendering the page. To save the full page it needs a browser, usually an automated one, often in headless mode.
  4. Walking the chain. Advanced services click the button on the pre-lander to reach the offer and record the redirects.
  5. Repeat visits. The service comes back to see whether the page has changed.

At every step the robot leaves traces, and protection is built on them. The same principle underlies any anti-bot protection for a website.

Signs of a spy tool in your traffic

Sign Why it gives the spy tool away
Hosting or cloud network a server has no need for home internet; network ownership shows in the ASN
Proxy or VPN in the target geo the service has to «look like» a user from the country where the ad runs
Automated browser traces of headless mode and browser control
No ad click ID the visit came from a saved link, not an ad impression
Repeat visits to one link monitoring for changes
Instant actions on the page the button is clicked without reading or scrolling

Network signals are covered in detail in VPN, proxy and data center IP detection, browser signals in headless browsers and fingerprinting.

An important point: some spy tools can come in through residential proxies, the addresses of ordinary home users. Then network signals do not help, and browser and behavior checks decide.

How to hide your landing page from spy tools

1. Filter every visit before the page is shown

The main defense is not to show the offer or pre-lander to anyone who has not been checked. That is exactly a cloaker's job: a real person sees the offer, a robot sees a neutral White Page. The decision must be made before the page becomes visible: a script that fires a second after loading will not stop a spy tool.

2. Serve a plausible White Page, not an error

A blank page, a 403 or «site under construction» is a signal to a spy tool: something is being hidden here, worth coming back from another address. A good neutral page looks like an ordinary site on the ad's topic, and to a crawler there is simply nothing interesting on it. How spy tools give themselves away at the browser level is covered in headless browsers and browser fingerprinting.

3. Do not expose the offer in the address bar

If the person is redirected to the offer's domain, that domain is easy to see and record. Loading the offer under your site's address hides it from surface-level analysis. It is not a cure-all, but it stops lazy collection.

4. Limit repeat visits

A spy tool comes back to the link. A visitor uniqueness window and a cap on clicks per IP per day keep a robot from monitoring the page endlessly.

5. Do not leave traces on your server

Trivial but common leaks:

  • open directory listings on your hosting;
  • predictable unprotected paths like /offer.php or /land2/;
  • landing page archives and backups in a public folder;
  • the affiliate link in plain sight in the pre-lander's code.

Tip. Look at your landing page through a robot's eyes: open it without an ad click ID, from a hosting network or through a VPN. If you can see the offer, so can the spy tool.

6. Use a shield during mass collection

A mode in which only visits with an ad click ID (fbclid, gclid, ttclid and so on) reach the offer cuts off everyone who came via a saved link. It has a price: forwarded links and direct visits will also see the safe page. So turn it on temporarily, not permanently. More on these parameters in fbclid, gclid, ttclid, yclid.

Protecting ad creatives: what you can realistically do

The ads themselves cannot be hidden: any platform user can see them. But you can make a copy less useful:

  • Make the funnel multi-step. A creative without the pre-lander and offer is half the picture.
  • Do not put anything in the creative that reveals the offer. The less the ad gives the offer away, the less it is worth to a spy tool.
  • Refresh creatives more often. A copied ad burns out faster for the copycat if you have already moved to a new angle.
  • Spread campaigns across flows. One campaign, one flow: then you can see exactly where you got exposed.

The creative must still be honest: promises, before-and-after images and disclaimers are governed by platform rules; see compliant ad creatives.

How ArtisanClo protects against spy tools

In ArtisanClo, spy tools belong to the visits that go to the White Page always, whatever the flow settings. In the click log their reason is «Ad verification or spy service». Programs instead of a browser and link preview robots are cut off just as unconditionally.

What else works:

  • A shared bot list. If a spy tool or bot is confidently identified for any customer, its address is remembered across the whole service. Its next visit to any of your flows gets the White Page right away, with no checks; the reason is «Known bot address».
  • Network checks. Blocking data center ASNs, VPNs and proxies cuts off server-side collection.
  • Browser checks. Headless blocking catches automation; the live interaction check looks at how the mouse or finger moves.
  • Limits and uniqueness. A cap on clicks per IP per day and a unique visitor window get in the way of repeat monitoring.
  • Shield. Temporarily lets through to the offer only visitors with an ad click ID. Auto-shield raises it on its own when it spots a spike in suspicious visits.
  • Offer in «Loading» mode. The address bar keeps the URL from the ad, and the offer page is loaded under it.

You connect it with a JS tag in <head> or a PHP file on your server; the site stays yours. The tag hides the page until the decision arrives, so a spy tool will not see the offer even for a split second, provided the code is the first line and is not loaded through a tag manager. Details in how to connect a cloaker to your site. The full list is on the features page.

What spy tool protection cannot do

To be honest about the limits:

  • Ads remain visible. Spy tools will collect creatives through ordinary user accounts.
  • A real person can copy everything by hand. A competitor who clicked your ad from their own phone is an ordinary visitor to any protection.
  • Residential proxies make network checks harder. Here browser and behavior signals decide.
  • Services evolve. Spy tools keep improving their disguise, and protection set up once weakens over time. That is why shared lists of already-caught robots and a regular look at the log matter: new collection tricks show up there first.

But the difference between «the funnel was copied in a day» and «the funnel was found a month later by manual search» is the difference in a whole campaign's profit.

So think of spy tool protection as a way to buy time. Every week your funnel runs only for you is a week without competition in the auction and without audience burnout. And when a copy does appear, you will already have the next version of the pre-lander and new creatives.

If your funnel has already been copied: what to do

Sometimes protection arrives later than the funnel hit the database. Then you need a different approach.

  1. Do not panic or change everything at once. A copy rarely performs like the original: the competitor has different accounts, different domains, a different campaign history. A sudden change of White Page or landing page in a live campaign also gives the platform a reason to review the ad again.
  2. See what exactly leaked. If the database has only the ad and the White Page, there is essentially no leak. If it has the pre-lander or the offer, there was a period when the filter showed them.
  3. Find the moment of the leak. In the visit log, look for visits from hosting networks, through proxies or from automated browsers that reached the offer. That will tell you which check was missing.
  4. Close the hole and update the pre-lander. A new pre-lander version with a different angle wipes out the value of the old copy, and you are one step ahead again.
  5. Put new campaigns into new flows. That way you will see whether the new funnel gets exposed and can compare.

How to check that spy tools cannot see your landing page

A simple test: find your ad in any spy tool you have access to and see which page is attached to it. If it is the White Page, the protection works. If it is the offer or the pre-lander, find the matching visit in the log by time and work out why it got through. Run this check for every new funnel in the first days after launch: that is when spy tools collect fresh campaigns most actively.

Bottom line

Spy tools collect landing pages automatically: from servers, through proxies, in automated browsers, via saved links. Each of these steps leaves traces that let you cut the visit off before the page is shown. Filter every visit, serve robots a plausible White Page, keep the offer out of the address bar and close technical leaks on your server. You cannot hide the creative, but you can protect the most expensive part of the funnel.

Frequently asked questions

01

What is a spy tool in affiliate marketing?

It is a service that collects ads from ad platforms together with their landing pages and makes them searchable. Media buyers use it to find working funnels, offers and creative angles. For the person who built the funnel, it means competitors will quickly repeat the find.

02

Can I completely hide my ad creatives from spy tools?

Not the ads themselves: any platform user can see them, and a spy tool can collect them through ordinary accounts. What you can protect is what lies behind them: the landing page, pre-lander, offer and link parameters. That is the most valuable part of the funnel.

03

How does a spy tool get to my landing page?

It follows the ad link just like a user, only automatically: usually from servers or through proxies, often in an automated browser. Sometimes it comes back to track changes. If it is shown the offer at that moment, the funnel ends up in the database.

04

Does password protection or noindex protect a page from spy tools?

Noindex protects against search engine crawlers, not spy tools: they follow the ad link, not search results. A password does not work because it locks out buyers too. What works is filtering every visit for signs of automation.

05

What does a spy tool see if the landing page is protected by a cloaker?

It sees a White Page, a plausible neutral page. The database gets an ad with a harmless site, and the competitor learns neither your offer, nor your pre-lander, nor your affiliate network.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.