Articles on: CAMPAIGN CREATION

How to Set Up a Shadow Campaign in The White Rabbit

The White Rabbit (TWR) Shadow campaign installs protection directly on your hosting through a script, without generating an external redirect link. It is designed for traffic sources that do not allow redirects and ensures that bots and competitor spy tools receive the safe page, while qualified traffic reaches your offer page.



Before you begin



Step by step


1. Create a new campaign


In the campaigns dashboard, click New campaign.



2. Name the campaign and select the domain


Enter a name of your choice to identify the campaign and select the domain registered in the tool. The script is generated from that domain.



3. Select the traffic source


Under Traffic Source, choose the platform where you will run your ads. The available sources vary by subscription plan, and not all of them offer the Shadow method.



4. Configure countries and devices


Select the countries and devices that match your ad targeting. Only the accesses matching your selection are allowed to pass through the TWR filter and reach the offer page.



Accesses outside this selection go straight to the safe page. If you leave desktop unchecked, for example, every desktop click is sent to the safe page. Keep this configuration identical to your ad targeting.


5. Enter the safe page URL


Under Safe Page, paste the URL of the page shown to unwanted access (bots, spy tools, competitors). It must be consistent with your ad's topic and comply 100% with the platforms' policies, without any elements that could trigger a rejection.



Recommended: use the same domain for both. Point a subdomain to TWR (via CNAME) and keep the root domain connected to your safe page hosting. The hosting setup varies by provider.


6. Enter the offer page URL


Under Offer Page, paste the URL of the page shown to qualified traffic, that is, your potential customers. It can be on hosting completely separate from the safe page.



As the delivery method, we recommend prioritizing TWR Mirror. It mirrors the page content on the ad URL without revealing the real URL, which offers more protection. Some pages may be incompatible with mirroring, so test that they load correctly before launching the ad (see step 10).


7. Save and copy the script and parameters


Click Save. TWR generates the Shadow script and the URL parameters. Copy the parameters, you will use them in your ad.



Do not transfer the script or the parameters via WhatsApp, Notion, or any service that may alter characters. Even a small change will break the script. Use only a plain-text notepad to store these values.


8. Install the script on your safe page hosting


The script must stand alone on a dedicated blank page. The recommended setup is to install it on your safe page hosting, keeping the offer page isolated:


  1. Open your hosting file manager and go to your site's public folder.
  2. Create a new subfolder with a name of your choice (e.g., vsl).
  3. Inside it, create a file named index.php.
  4. Paste the Shadow script into index.php and save.



The ad URL becomes the address of that folder (e.g., yourdomain.com/vsl). That is where all filtering happens: suspicious access sees the safe page, and qualified access sees the offer page.


9. Build the ad URL with the parameters


Use the URL of the folder where the script was installed together with the parameters generated by TWR. How you insert them depends on the traffic source:


Scenario

How to insert

Source with a separate field for parameters

Clean URL in the URL field + parameters in the tool's own field (tracking template)

Source without a separate field

URL?parameters — add the parameters right after the URL


To add tracking parameters from your own tool, append & after TWR's parameters and paste yours right after.


The domain registered in TWR must always point to the service. Any change to the pointing will make the script stop working.


10. Test the offer page


Inside the campaign, use the Test Offer button to generate a test parameter. Add that parameter to the URL where the script was installed and open the link: you will be redirected to the offer page, confirming that the delivery method loads correctly. This parameter is for testing only, disable it afterward.



To check the safe page, just open the script URL directly, without the test parameter. A regular access is identified as suspicious and lands on the safe page.


11. Track the campaign through the chart


Once the ad is running, the campaign chart shows in real time the total number of requests and where each one went (offer page or safe page). Bots are counted separately and are not charged, but they are also routed to the safe page.




Updated on: 21/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!