"Cloaked images" manual action: when Google Images shows something else

Some of your site's images "may display differently in Google's search results than when viewed on your site." Google gives two examples: serving Google an image that is covered by something else, such as a block of text over it, and serving Google a different image from the one visitors get. Both leave searchers clicking a thumbnail that is not what they expected.

On WordPress this is usually the side effect of trying to stop image theft, not of trying to game rankings. Hotlink protection and watermark tricks that treat Google differently from everyone else are the usual cause. Google also offers a sanctioned way to limit full-size images in its results, which does not count as cloaking.

The report entry lists the affected pages or patterns. Often it is the whole uploads path, because a single server rule applies to every image file. Google does not spell out the ranking effect of this particular action beyond saying cloaked images give image search users a bad experience, so treat every listed image as at risk until the review succeeds.

How image protection turns into cloaking

Look for anything on the site that changes an image response depending on who asks:

  • Hotlink protection in .htaccess, your CDN or a security plugin that checks the referrer and returns a "stolen image" graphic when it is not your domain. When someone opens a result in Google Images, the browser requests your file with a Google referrer, gets the replacement, and sees something different from the thumbnail Google indexed.
  • Overlay or watermark tricks that serve a clean image to crawlers and a covered or cropped one to people, or the other way around.
  • Different files by user agent, such as a high-quality image for Googlebot and a low-quality or blurred preview for visitors.
  • CDN image rewriting that returns unrelated placeholder images to some requests.

A typical hotlink rule that causes trouble:

apache
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^https://(www\.)?example\.com/ [NC]
RewriteRule \.(jpe?g|png|webp|gif)$ /hotlink-warning.png [L]

Testing what each side receives

Request an affected image as a plain visitor, as Googlebot-Image, and with a Google referrer, then compare the size and checksum:

bash
IMG=https://example.com/wp-content/uploads/2024/05/kitchen.jpg
curl -s "$IMG" | md5sum
curl -s -A 'Googlebot-Image/1.0' "$IMG" | md5sum
curl -s -e 'https://www.google.com/' "$IMG" | md5sum

All three should match. If the referrer version differs, your hotlink rule is the cause. Also look at the page itself in URL Inspection's screenshot and compare it with a normal browser: an overlay that only one side sees shows up there.

Fixing it, or opting out properly

Pick one approach and apply it to every image:

  1. Serve the same image to everyone. Remove the hotlink rule, or exempt Google's referrers from it, and remove any overlay or watermark that only one audience gets. Watermark the real file if you need one; the same watermarked image for crawlers and people is fine.
  2. Opt out of inline linking. If you do not want full-size images shown in Google's results, Google describes a method: when an image is requested, check the HTTP referrer, and if it comes from a Google domain, reply with HTTP 200 or 204 and no content. Google still crawls the page and the image, and shows a thumbnail generated at crawl time. Google states this "is not considered image cloaking and will not result in a manual action."
  3. Keep images out of results entirely with Google's documented image blocking methods if you want no image presence at all.

After changes, purge the CDN and any image optimization cache, since many WordPress image plugins keep their own copies. Hydrogen SEO's image features (filling missing alt text, AI alt text on upload, images in the XML sitemap) do not change image responses, so they are not a cause here.

Filing once every image matches

Google's condition is that images are exactly the same whether viewed on your site or from Google search results. Once that is true, select Request Review and say what changed:

text
Our security plugin's hotlink protection returned a warning image to
requests with non-site referrers, including Google Images. We removed
the rule. The same file is now served to all referrers and user agents
(checked with curl on 30 sample images).

You will see status messages in Search Console and get an email when the review is done. Allow several days to a few weeks. Rebuilding image thumbnails in Google's index happens on Google's recrawl schedule, so the first results may still show old previews for a while.

Common questions

Is hotlink protection against Google's rules?

Blocking other sites from embedding your images is fine. It becomes cloaking when Google indexes one image and searchers get a different one, which happens when the rule treats Google's referrer like any other site.

How do I stop Google showing my full-size images?

Google's documented method is to check the referrer on image requests and return HTTP 200 or 204 with no content when the request comes from a Google domain. Google says this is not image cloaking.

Can I watermark images and still show them in Google?

Yes, as long as the same watermarked image is served to Google and to visitors. The problem is serving one version to crawlers and another to people.