"The cloaker is blocking real people" and "the cloaker is letting bots through" are the two most common complaints from media buyers. Both can almost always be sorted out in five minutes if you know where to look. In ArtisanClo every visit has a decision reason: a short label explaining why the visitor saw the offer or the White Page. It is not a black box with a final yes/no but a log that shows which check fired — which is exactly how you find out why a click went to the White Page. The path of a visit itself is covered in how a cloaker works.
Where to find the block reason
The click log (in the "Analytics" section) is your main tool. By default it opens for today; filters let you pick the status (passed or blocked), a specific reason, the flow, geo and whether there was a lead.
Clicking a row opens the click card:
- visit — where it was sent and how it was shown;
- visitor — device, browser, OS;
- network — VPN, proxy, data center, ISP;
- ad — platform, click ID, campaign, cost;
- checks — what exactly was checked and with what result;
- parameters and conversions.
For the deepest analysis there is the Visit report — a link in the flow's connection window. Instead of the page it shows every signal, conclusion and the final decision for one visit. It is also what to attach if you write to support about a wrong decision.
Check order: why the sequence matters
The cloaker checks conditions top to bottom, and the first match wins — the visit is not checked any further. That is why a click always has one reason, not a list. Simplified, the order is:
| # | Condition | What the visitor sees | Reason in the log |
|---|---|---|---|
| 1 | No active plan, or trial clicks used up | White Page | "No active plan", "Click limit reached" |
| 2 | Flow paused or in draft | White Page | "Flow is not running" |
| 3 | Address already confidently identified as a bot — at your account or another client's | White Page without checks | "Known bot address" |
| 4 | A mode is on in which the flow shows everyone the White Page | White Page without checks | "Flow under review" |
| 5 | Cloaking switched off | White Page | "Cloaking off" |
| 6 | Address is in your IP blacklist | White Page without checks | "In your blacklist" |
| 7 | Warm-up in progress | White Page without checks | "Before filtering" |
| 8 | Address is in the IP whitelist | Offer | "Allowed by whitelist" |
| 9 | Daily click limit per IP exceeded | White Page | "Too many clicks from one IP" |
| 10 | Address already caught before, or an obvious robot browser | White Page | "Previously flagged address", "Headless browser detected" |
| 11 | Spy service, a program instead of a browser, a preview bot | White Page always | "Ad verification or spy service", "A program, not a browser", "Search or platform crawler" |
| 12 | Audiences: geo, device, language, schedule and so on | White Page if not matching | "Country not allowed", "Outside campaign hours" |
| 13 | Shield is up and the link has no ad click parameter | White Page | "Shield: not a paid click" |
| 14 | A minimum time on page is set | Waiting page, then a re-check | — |
| 15 | Trust scoring | White Page if too much suspicious stuff adds up | "Trust score too low", "High-risk network" |
| 16 | Extra guard finds the visit similar to your bots | White Page | "Second opinion: looks like your bots" |
| 17 | All checks passed | Offer | "Allowed" |
The table shows something important: the IP whitelist sits below the flow status, review mode, cloaking being off, the blacklist and warm-up. So your test click from a whitelisted address will still see the White Page if the flow is warming up.
Reason groups: what each one means
There are dozens of reasons, but they all fall into a few groups. The group tells you right away what to do.
Bot / automation
Platform robots, ad verification services, spy services, robot browsers, programs instead of browsers. This is exactly what a cloaker is installed for. If this group has a lot of visits, the filter is working. More about who comes to look at your landing pages in protection from spy services and headless browsers and browser fingerprinting.
Infrastructure traffic
Data centers, hosting, proxy networks. Real buyers rarely sit on cloud provider servers, so such visits are almost always scanners and bots. How services detect these networks is covered in VPN, proxy and data center IP detection.
Campaign rule
Your setting fired: geo, device, schedule, click limit per address, VPN, script check, trust score, your blacklist, or an address already caught automating. This is the group where a setup mistake most often hides: geo too narrow, a limit too strict, an unnecessary ban.
Flow or plan state
"Flow under review", "Cloaking off", "Flow is not running", "No active plan", "Click limit reached". If all visits in a flow have such a reason, the problem is not the traffic but the status.
Waiting page
The browser was given time to prove it is alive: run a script, stay on the page for a minimum time.
Passed
"Allowed", "Allowed by whitelist", "Watched, not cut" (shadow mode — the filter only marks whom it would have cut), "Tracked, not filtered" ("Tracker" mode).
Other
Warm-up, "Offer did not load" (the offer page failed to open, so the White Page was shown to avoid losing the click), "The flow has no offer to send to", shield, extra guard.
Where visits are filtered out: the three filter steps
Every rejection belongs to one of three steps — the same logic by which ad measurement vendors split invalid traffic into general (GIVT) and sophisticated (SIVT):
- Network and request — the visit was filtered before the browser check: by address, network, ISP, headers, click parameter, flow rules. This step touches real people the least.
- Browser check — the script ran and its answer revealed automation or did not earn enough trust. This is where bots pretending to be human get caught, and also where the filter makes mistakes most often. If this share grows, check how strict your settings are.
- Check never came back — the check page was served, but no answer came. That is how programs without JavaScript behave.
The shares of the three steps are shown above the list of reasons in the Statistics section, and the step for an individual click is in its card in the log.
The most common reasons and what to do about them
"Before filtering"
Warm-up is on: the first N clicks of a flow see the White Page without checks. This is deliberate — spy services and automated visits are usually the first to arrive at a new link. If your test clicks have this reason, just wait for warm-up to end or test on another flow.
"Country not allowed"
The visitor is from a country that is not in the allowed list. Sometimes it really is the wrong geo; sometimes it is a person roaming or on a mobile carrier whose address resolves to a neighboring country. If you see many such visits from your ads, check the targeting in the ad platform.
"High-risk network" and "Trust score too low"
The visit collected too many penalties: VPN, data center, IPv6, no ISP, no referrer, no JavaScript. Look in the card to see which signs fired. If your audience needs a VPN, turn off "Block VPN/Proxy" — but first estimate the losses in Diagnostics.
"Too many clicks from one IP"
More clicks per day came from one address than allowed. Keep in mind that mobile carriers often route many subscribers through one address. For native and push the limit is usually higher — those platforms have a lot of repeat impressions.
"Shield: not a paid click"
The shield is up, and the link has no platform click parameter (fbclid, gclid, ttclid and so on). That is by design: the shield lets only ad clicks through to the offer, while bots, scrapers and spy services most often open the link without a parameter. But forwarded links and bookmark visits also fall under the shield. About click parameters: fbclid, gclid, ttclid.
"Offer did not load"
The filter let the visitor through, but the offer page in "Loading" mode did not open. Check the offer: ArtisanClo checks every minute whether the offer of an active flow responds and sends a notification if it does not.
Bot or lost buyer: how to tell
One reason proves nothing — look at the whole picture.
- Compare with conversions. If the flow lets few people through but the passed visits produce leads normally, the filter is most likely cutting junk.
- Look at the pass rate. On its own it is not a verdict: with paid traffic that carries a click ID, most visitors can reach the offer, and that is normal. The warning sign is when very few get through: then the rules are probably hitting real people. The dashboard and notifications warn you about this themselves.
- Open Diagnostics. The "What to fix" tab replays past visits through the current settings and shows "The X filter is cutting traffic" with an estimate of lost leads and money. You can turn the filter off there with one button.
- Turn on shadow mode for a while if you connect via the PHP file: the filter cuts no one, but the log shows whom it would have cut ("Watched, not cut").
More about the signs of bots in bot traffic: how to detect it.
When every click goes to the White Page
If every visit goes to the white page, look for a status, not a bot:
- Is the plan active, have the trial clicks run out?
- Is the flow status "Active", not "Draft" or "Paused"?
- Is the main "Cloaking" switch on?
- Is review mode on (there will be a banner on every page of the dashboard)?
- Is warm-up in progress?
- Is the shield up for a platform that does not pass a click parameter?
If everything is fine and the problem persists, go to cloaker not working: how to check and fix it. For an overview of the filter's capabilities, see the ArtisanClo features page.
Summary
A decision reason is the answer to "why", recorded for every visit. Checks run in order, and the first one that fires decides the outcome. The reason group points you in the right direction: bots and infrastructure traffic — the filter is working; campaign rule — check your settings; flow state — check the status. And to stop guessing whether the filter is cutting real people, use Diagnostics and shadow mode rather than intuition.



