Detection
Referrer Spoofing
Referrer spoofing is sending a fabricated or stripped Referrer/Referer header to make traffic look like it originated from a different source than it actually did — used both defensively (a legitimate delivery technique to avoid leaking the money page's origin to any site it links out to) and as a fraud/evasion technique (disguising bot or click-farm traffic as coming from a real ad platform). Cloaking X's own money-redirect responses set Referrer-Policy: no-referrer so the money page never even receives a referrer header that could leak the operator's tracking domain.