Postback security — the anti-spoof hardening checklist
An unsecured postback URL is a public endpoint anyone can hit to inject fake conversions. Harden it in this order.
— Add a secret key parameter to the postback URL that only you and the network know. Reject any postback missing or with the wrong key. This alone blocks casual spoofing.
— Allowlist the network's postback IP ranges if your tracker supports it. A conversion from outside the network's IP space is a forgery.
— Enforce that the click-id must match a real logged click. Reject any postback whose click-id was never issued by your tracker.
— Enforce a sane time window. Reject postbacks for click-ids older than the offer's realistic conversion window. A conversion on a 6-month-old click is noise or fraud.
— Rate-limit per source. A flood of postbacks in seconds is an injection attempt, not organic conversions.
— Log every rejected postback with reason. A rising reject count is your early warning that someone found and is probing your endpoint.
Validation:
— Fire a postback with the wrong secret key. Confirm it is rejected, not recorded.
— Fire one with a fabricated click-id. Confirm it logs as orphan or reject, never as a sale.
Save this SOP. Harden every postback before it goes live.
Tracker Playbook
@TrackerPlaybook
Postback security — the anti-spoof hardening checklist
Этот пост опубликован в Telegram-канале Tracker Playbook. Подписаться можно по ссылке: @TrackerPlaybook.