Technical Monetization • Published September 12, 2026 • Updated October 2, 2026 • 12 min read

How to Create, Format, and Validate an ads.txt File for AdSense

Every publisher monetizing a website with Google AdSense will eventually encounter the dreaded dashboard warning: "Earnings at risk – You need to fix some ads.txt file issues to avoid severe impact to your revenue." While simple in concept, improper configuration of this single plain text file is one of the most common causes of silent revenue drops, suppressed advertising bids, and publisher disqualifications.

The ads.txt (Authorized Digital Sellers) standard is an open-source technical specification developed by the IAB Technology Laboratory. Its primary purpose is to eliminate domain spoofing, arbitrary ad injection, and unauthorized reseller arbitrage in programmatic ad exchanges.

In this technical manual, we explain the mechanics of ads.txt, dissect the 4-part Google AdSense entry format, examine HTTP routing and subdomain rules, walk through root server deployment, and provide a troubleshooting framework to resolve crawl delays.

Advertisement
Responsive In-Article Ad Unit
ANATOMY OF AN ADS.TXT RECORD Breakdown of the 4 Comma-Separated Fields in Google AdSense Field #1: Domain google.com Canonical ad system exchange domain (Mandatory) Field #2: Publisher ID pub-000000000000 Your 16-digit AdSense account identifier (Mandatory) Field #3: Account Type DIRECT DIRECT (own account) vs RESELLER (Mandatory) Field #4: Cert ID f08c47fec0942fa0 Google Trustworthy Accountability Group Hash (Optional / Rec)
Figure 1: Anatomy of the 4 comma-separated parameters in a standardized ads.txt entry.

1. What is ads.txt and Why Does It Exist?

Prior to the introduction of the ads.txt standard, the digital advertising ecosystem suffered billions of dollars in programmatic fraud through domain spoofing and counterfeit ad inventory. Malicious actors would manipulate RTB (Real-Time Bidding) bid requests to claim that their impressions originated from high-authority media domains (e.g., premium news publishers or reputable utility portals) when the actual clicks occurred on bot-driven spam hubs.

Advertisers were tricked into paying top-tier CPM prices for illegitimate impressions, while legitimate publishers were robbed of revenue. In response, the IAB Tech Lab created Authorized Digital Sellers (ads.txt).

By hosting a publicly crawlable plain text file at your root domain, you provide programmatic buyers (Demand Side Platforms, or DSPs like Google Display & Video 360, The Trade Desk, Amazon DSP) with an immutable cryptographic ledger verifying whether the ad exchange attempting to sell an impression on your domain actually holds legitimate authorization.

Audit Your ads.txt & Policy Health in Real Time

Use our automated pre-application diagnostic scanner to test root accessibility, MIME type headers, publisher ID match, and full AdSense compliance.

Launch AdSense Approval Checker →

2. The Anatomy of an AdSense ads.txt Record

An ads.txt file consists of plain text lines formatted with comma-separated values (CSV). For Google AdSense, the standard entry contains four distinct components:

google.com, pub-0000000000000000, DIRECT, f08c47fec0942fa0

Let us examine each field in technical detail:

Field 1: Domain Name of the Advertising System

google.com – This specifies the canonical domain of the ad exchange or supply-side platform (SSP). For Google AdSense and Google Ad Manager, this value must always be written in lowercase as google.com.

Field 2: Publisher's Account Identifier

pub-XXXXXXXXXXXXXXXX – This is your unique 16-digit publisher ID assigned inside your Google AdSense account console (found under Account > Settings > Account Information). You must include the full pub- prefix followed by the 16 numeric digits. Omitting the prefix or making a single digit typo prevents verification.

Field 3: Supply Chain Relationship Type

DIRECT or RESELLER – This defines your commercial relationship with the ad network:

  • DIRECT: You personally own and manage the AdSense account associated with Field 2. For individual website owners and direct publishers, this should always be set to DIRECT.
  • RESELLER: An intermediary or third-party ad monetization agency manages your ad inventory on their own master account.

Field 4: Certification Authority ID

f08c47fec0942fa0 – This is the unique Trustworthy Accountability Group (TAG) ID assigned to Google LLC. While Field 4 is technically optional under IAB syntax, Google strongly recommends including it to maximize DSP buyer trust and bid rates.

FRAUD PREVENTION & VERIFICATION FLOW How DSP Advertisers Validate Authorized Inventory 1. RTB Bid Request Supply Partner sends impression opportunity Claim: yoursite.com 2. Crawl ads.txt DSP queries yoursite.com/ads.txt Fetch Plain Text 3. Record Match Does pub-ID match seller in bid stream? Cryptographic Check 4. Result High CPM (Verified) Bid Dropped (Unverified)
Figure 2: Real-time RTB buyer verification flow against the publisher's hosted ads.txt record.

3. How to Create and Deploy Your ads.txt File

Deploying your ads.txt file takes only a few minutes across different web hosting environments. Follow these step-by-step instructions:

Method A: Static HTML / Custom Server (Apache, Nginx, Netlify, Vercel)

  1. Create a new plain text file named exactly ads.txt (all lowercase).
  2. Paste your formatted line: google.com, pub-XXXXXXXXXXXXXXXX, DIRECT, f08c47fec0942fa0.
  3. Upload ads.txt into your public web root directory (e.g., /public_html/, /var/www/html/, or /public/).
  4. Ensure the file permissions are set to 644 (readable by world/crawlers).

Method B: WordPress Sites

  1. Install a lightweight ads.txt manager plugin (such as Ads.txt Manager) or place the file directly inside your WordPress root directory via cPanel File Manager or SFTP.
  2. Paste your AdSense entry into the plugin editor and save changes.
  3. Purge any server-side caching plugins (WP Rocket, LiteSpeed Cache, Cloudflare) to ensure immediate public delivery.

4. Root Domain Accessibility & Subdomain Routing Rules

IAB Tech Lab specifications enforce rigid rules regarding URL endpoints, HTTP redirects, and subdomains:

  • Root Domain Requirement: The ads.txt crawler always looks for the file at the top-level domain: https://example.com/ads.txt.
  • Subdomain Delegation: If you run a multi-site network or serve ads on a subdomain (e.g., app.example.com or blog.example.com), the crawler will query the root domain first. If you need subdomain-specific sellers, you can declare delegation in the root file using:
    subdomain=blog.example.com
  • HTTP to HTTPS Redirects: Crawlers will follow standard 301 and 302 HTTP redirects, but you must not exceed 5 redirect hops. Ensure your redirect terminates on a valid HTTP 200 OK response.
  • MIME Type: The web server must serve the file with the header Content-Type: text/plain. Serving ads.txt with text/html or application/octet-stream triggers crawler parse failures.

5. Troubleshooting & Fixing "Earnings at Risk" Warnings

If your Google AdSense account displays an "Earnings at risk" warning or fails to find your ads.txt file, follow this diagnostic checklist:

Issue Symptoms Root Cause Step-by-Step Fix
HTTP 404 Not Found File placed in subfolder or mistyped filename Move file to root folder (e.g. /public_html/) and ensure name is lowercase ads.txt.
Robots.txt Blocking Disallow: / blocking crawler access Add User-agent: * Allow: /ads.txt explicitly to your robots.txt.
Publisher ID Typo Missing pub- prefix or copied incorrect number Copy exact ID from AdSense Settings > Account Information.
Cloudflare WAF / Bot Fight Mode Cloudflare challenge page blocking Googlebot Create Cloudflare WAF Bypass rule for URI path /ads.txt.
Crawl Delay After Deployment Normal AdSense crawler indexing latency Wait 24 to 72 hours. Google automatically scans and clears dashboard flags.

Frequently Asked Questions

An ads.txt (Authorized Digital Sellers) file is an IAB Tech Lab initiative that lets publishers publicly declare who is authorized to sell their digital ad inventory. While technically optional by internet protocols, Google AdSense heavily enforces it—failing to implement ads.txt triggers 'Earnings at risk' dashboard alerts, and programmatic DSP buyers will refuse to bid on your impressions.
'f08c47fec0942fa0' is the unique, static cryptographic Certification Authority identifier assigned to Google LLC by the Trustworthy Accountability Group (TAG). It proves that the seller is officially vetted under TAG fraud-prevention registries.
DIRECT indicates that you directly control and own the advertising account (such as your personal AdSense publisher account). RESELLER indicates that you have authorized an external agency, ad network, or mediation partner (such as Ezoic, Mediavine, or Raptive) to re-sell ad space on your behalf.
The ads.txt file must always be hosted at the root level of your top-level domain (TLD) as a plain text file accessible via HTTP/HTTPS at https://example.com/ads.txt. It cannot be nested inside subdirectories (e.g. /assets/ads.txt is invalid).
Google AdSense crawlers automatically scan ads.txt files every 24 to 72 hours. Once crawled, the 'Earnings at risk' dashboard warning clears automatically within 1 to 3 business days, provided the file returns an HTTP 200 status code and UTF-8 plain text MIME type.

Conclusion

Properly configuring and validating your ads.txt file is one of the quickest, highest-impact technical tasks you can complete to protect your website's advertising earnings. By ensuring your file is positioned at the root domain, correctly structured with your active 16-digit publisher ID, and accessible without WAF or robots.txt interference, you guarantee maximum programmatic bid competition and revenue safety.

Before launching or expanding your monetization strategy, make sure to audit your entire website using our free AdSense Approval Checker to catch policy or technical oversights before Google reviewers do.

CS

Collabsource Editorial Team

Programmatic advertising engineers and web infrastructure specialists analyzing real-time bidding protocols, IAB specifications, and publisher monetization health.