It has probably happened to you. You open a site to read one specific thing, and before the page loads, a popup tells you your phone is infected, or the browser drags you off to the App Store, or a download starts that you didn’t ask for. You close the tab. You don’t come back. You don’t think about which ad served it. You think the site is sketchy.
Your readers do the same thing. A lot of publishers underestimate this part when picking a monetization partner, and it’s the part Google’s Chrome team, the EU’s Digital Services Act, and your returning users are all paying attention to.
The numbers are still significant. Confiant’s Mid-Year 2025 Malvertising & Ad Quality Index found that roughly 1 in 78 ads delivered to real users posed real risks, including scams, malware, and AI-generated deception.
The worst-performing major platform let bad ads through nearly 300 times more often than the best – roughly 1 in 70 impressions versus 1 in 20,000.
Both had access to the same kinds of advertisers. The variable was feed control: scans before any ad loads on the page, watching the landing page across the campaign’s full run, and a policy team that permanently bans advertisers who break the rules.
Platforms that build this stack – Monetag documents its own version openly – sit at the clean end of the spectrum. Platforms with less of this infrastructure sit further out.
Each of these looks the same to a user: the site did something they didn’t ask for.
On the defense side, every category needs its own layer. Pattern-matching scans cover known malware creatives. Watching the landing page across the campaign covers cloaking. Behavior-based checks cover scripts that only fire on mobile or in a specific GEO. A network’s safety story is the sum of the layers it stacks.
Together, these are what publisher-facing copy usually shortens to “bad ads”. The detail matters because different defenses catch different things.
Imagine a publisher on a network with looser filtering. A bad ad lands on the page, gets reported, gets pulled. Weeks later the damage shows up in three places, and each one feeds the next. Strict filtering is what keeps that loop from starting.
Monetag
Daily readers become one-time visitors. The bounce shows up weeks later in your direct-traffic numbers.
Search Console flags your domain. 30 days to fix, then Chrome blocks all ads on the affected pages.
Lose ad coverage. Drop from lists of advertisers who pay top rates. Harder to monetize after the warning lifts.
Even the biggest sites get hit.
In November 2023, the malvertising group known as ScamClub pushed fake McAfee virus alerts onto readers of Associated Press, ESPN, and CBS, with 96% of victims on iPhones: the attackers were deliberately targeting iOS to bypass desktop ad blockers, and they routed through 16 different ad exchanges to do it.
At Insider Inc. (Business Insider), Confiant’s case study reports more than 43.8 million ads with security or quality issues blocked over time across 9.66 billion monitored impressions. That’s the scale of attempts even at top-tier publishers: what slips past is what costs the publisher money.
What does that cost look like?
Rarely a single visible event. HUMAN Security documented a publisher network called PubPlus that, during peak malvertising attacks on its sites, lost more than 50% of page views per session and conservatively estimated 3% of monthly revenue gone. Sessions shortened, returning users came back less often, and CPMs drifted down.
For publishers in those cases, the math is brutal because none of it lands as a clear notification. The signal shows up weeks later in lower daily revenue, a flatter direct-traffic curve, and one of the formats suddenly performing worse than the others. By the time the cause is obvious, the loss is already baked in.
Strict filtering is what keeps that scenario from starting. With those layers in place, sessions stay full, returning users come back, and CPMs hold where the network’s optimization can keep them.
Much of strict filtering’s job is what happens after a campaign goes live: a creative swapping its landing page an hour after approval, an advertiser registering a new account after a ban, a campaign that scanned clean in the morning behaving differently by the afternoon.
The list below covers what that work has to handle.
Monetag
Every ad shown to a reader is picked from a large pool of advertisers in the moment. Each one is evaluated before it loads.
A creative can pass review and quietly swap its landing page an hour later. Monitoring catches the swap — the cloaking play — and stops the campaign.
Banned advertisers try to come back under a new entity. Detection picks them up and re-bans them.
ads.txt and sellers.json verify which networks are authorized to sell your inventory. A working abuse-report channel closes the loop.
Every protection traces back to one choice: whose tag goes on your site. After it’s installed, your job shifts to watching for the things you want a second pair of eyes on. The list below covers both moments.
Before placing a tag
After the tag is live
If you’re sizing up a network, here’s what to expect from a serious one.
Creative scanning catches known malware signatures before any ad loads. Watching the landing page across the campaign is what stops cloaking – the move where a creative passes review and then swaps its landing page hours later.
A manual policy review team handles the edge cases, particularly new advertisers and campaigns that change behavior after going live. Permanent bans paired with multi-account detection close the loop on advertisers who break the rules and try to come back under a new entity.
Beyond those four, signals like TAG Certified Against Malware seals, third-party audit reports, or a published transparency dashboard are useful additions when a network has them. Confiant’s 300x gap between platforms is an outside number you can actually point to when comparing networks on safety the same way you’d compare them on CPM.
Monetag’s ad safety stack is documented openly across the company blog and Help Center. The most detailed source is the Premium Ad Feed post, which describes a policy team that reviews each campaign before it goes live and keeps reviewing it through its run.
Alongside that human layer, ads are scanned around the clock by automated anti-ad-fraud and malware-prevention tools. Campaigns that violate the rules are rejected outright, and advertisers caught violating them are banned with no readmission.
The reject categories are spelled out: malware, scareware, fake tech support, misleading claims, sexual content, and unauthorized brand logos do not enter the feed.
Cloaking – where a creative passes review and then quietly swaps its landing page after approval is caught by an in-house tool that monitors every campaign’s destination URL across its full lifetime and stops the campaign the moment the URL changes.
Advertisers who get banned and try to re-register under a new entity are picked up by multi-account detection and re-banned; the Premium Ad Feed post publishes how often that happens.
Two more checks operate on the publisher side of the relationship. Monetag works only with mainstream sites: news, entertainment, movie fan sites, blogs, social media. Torrent sites, adult content, and sites that violate IP, hate-content, illegal-activity, or hacking rules are not accepted; the Website Content rules Help Center entry has the full list. Publishers are also verified through KYC checks via Sumsub, an identity-verification platform that handles compliance and ID checks at publisher onboarding.
Two regulations now sit between a publisher and their ad revenue: Chrome’s enforcement of Google’s Abusive Experiences policy and the EU’s Digital Services Act. Both have already produced concrete consequences for sites and for ad networks. A publisher who understands both has more warning when something goes wrong, and more leverage in choosing who to work with.
For you, the practical effect is that the networks you work with are now legally obligated to do more of the work you would otherwise have to chase. That’s a positive shift. It also means if your network gets fined or sanctioned, the risk can flow through to your domain — so pick partners who already operate at the standard.
Before adding any ad tag to a domain you care about:
None of this is hyper-complicated. All of it is cheaper than recovering from a Chrome block.
Monetization and user safety work in the same loop. A clean feed protects returning traffic. Returning traffic is what keeps CPMs and CTRs where the network’s optimization can find good offers.
The networks that built filtering as a core capability are the same ones that pay better – the advertisers willing to spend on quality inventory show up where the supply chain is trusted.
The publishers who win the next two years are the ones who treat ad safety as a revenue feature.