---
title: What are industry standards for Server-Side Ad Insertion (SSAI) in OTT/CTV?
description: How are the ad industry’s governing bodies — namely the MRC and the IAB — approaching server-side ad insertion (“SSAI”) measurement?
image: https://www.pixalate.com/hubfs/Blog_Media/Blog%20photos/industry-standards-for-ssai.png
---

[![pixalate-full-logo](https://www.pixalate.com/hs-fs/hubfs/Pixalate_Logos/pixalate-full-logo.jpg?width=150&height=60&name=pixalate-full-logo.jpg "pixalate-full-logo")](https://www.pixalate.com)

Search

**Menu**

** **

![](https://www.pixalate.com/hubfs/Blog_Media/Blog%20photos/industry-standards-for-ssai.png)

[Thought Leadership](https://www.pixalate.com/blog/topic/thought-leadership) | [CTV](https://www.pixalate.com/blog/topic/ctv) |

 6 min read

# What are industry standards for Server-Side Ad Insertion (SSAI) in OTT/CTV?

 Written by [Pixalate](https://www.pixalate.com/blog/author/pixalate)

 Jun 25, 2019 2:59:12 PM

How are the industry’s governing bodies — namely the Media Rating Council (“MRC”) and the Interactive Advertising Bureau (“IAB”) — approaching server-side ad insertion (“SSAI”) measurement?![iab-mrc-ssai-industry-standards](https://www.pixalate.com/hs-fs/hubfs/Blog_Media/Blog%20photos/iab-mrc-ssai-industry-standards.png?width=300&name=iab-mrc-ssai-industry-standards.png)

Per Pixalate, SSAI is used in 38% of programmatic OTT/CTV transactions. However, it’s prone to fraud: When SSAI is used in programmatic OTT/CTV, it’s invalid 26% of the time, as measured by Pixalate.

The IAB and MRC have collaborated with partners across the industry to establish best practices as they relate to SSAI. This blog, the latest in our SSAI series, explains the latest guidelines.

*Want more SSAI content? Follow along with our series:*

- Background

- Current solutions for SSAI

- Looking ahead *(coming July 2019)*

### **What the IAB’s VAST 4.0 spec says about SSAI**

The IAB’s[ VAST 4.0](https://www.iab.com/wp-content/uploads/2016/04/VAST4.0_Updated_April_2016.pdf) specification — released in January 2016 — offered the industry its first guidelines for dealing with SSAI, or ad stitching.

The guidelines note: "When an ad-stitching service is involved, the ad-stitching server may send tracking on the player’s behalf. This server-to-server tracking process is problematic because all the tracking is coming from one IP address. To an ad server that is receiving tracking information, the reports look similar to faked traffic fraud.”

The 4.0 guidelines note that SSAI providers can avoid being mistaken for fraud by including two headers as part of the ad request: X-Forwarded-For (a header that identifier the client IP address) and X-Device-User-Agent (a head that identifies the client’s device user agent string).

The VAST 4.0 guidelines note that the Forwarded HTTP Extension may also be used — which allows all proxy information to be disclosed in one field — but notes that most systems look for X-Forwarded-For and X-Device-User-Agent.

### **VAST 4.1 adds more guidelines for SSAI**

**![vast-41-ssai-standards-iab](https://www.pixalate.com/hs-fs/hubfs/Blog_Media/Blog%20photos/vast-41-ssai-standards-iab.png?width=600&name=vast-41-ssai-standards-iab.png)**

The IAB’s[ VAST 4.1](https://iabtechlab.com/wp-content/uploads/2018/11/VAST4.1-final-Nov-8-2018.pdf) (November 2018) specification added additional guidelines for how to best deal with SSAI, this time with more conviction and hierarchy. The guidelines say what must be included, what should be included, and what can be included.

- **What “must” be included when SSAI is used:**

VAST 4.1 guidelines say ad stitching providers *must* include the following HTTP headers to avoid being mistaken as ad fraud:

- **What “should” be included when SSAI is used:**

VAST 4.1 guidelines say ad stitching providers *should* include the following HTTP headers:

- **What “can” be included when SSAI is used:**

VAST 4.1 guidelines say ad stitching providers *may also* include the following HTTP headers:

Importantly, the VAST 4.1 guidelines note: “The information included in these headers must match the information in the original ad request payload."

### **Update to MRC and IAB ‘Digital Video Ad Impression Measurement Guidelines’ addresses SSAI**

Published in June 2018, the IAB/MRC’s updated *Digital Video Ad Impression Measurement Guidelines* ([MMTF Final Draft v1](http://mediaratingcouncil.org/Digital%20Video%20Served%20Impression%20Measurement%20Guidelines%20(MMTF%20June%202018).pdf)) defined specific measurement criteria for Server-Side Ad Stitching and Server-to-Server measurement.

The document notes: “This server-to-server tracking process may ... be problematic because all the tracking is coming from one IP address and therefore may be susceptible to IVT filtration techniques.”

The guidelines note that a client-initiated counting methodology is still required across these integrations in a manner consistent with previous IAB/MRC guidance. The IAB’s VAST (video ad serving template) framework complements this guidance in that[ VAST 4.0](https://www.iab.com/wp-content/uploads/2016/04/VAST4.0_Updated_April_2016.pdf) and[ VAST 4.1](https://iabtechlab.com/wp-content/uploads/2018/11/VAST4.1-final-Nov-8-2018.pdf) have established specific protocols for self-declaring SSAI integrations.

The MRC’s and IAB’s [Digital Video Impression Measurement Guidelines](http://mediaratingcouncil.org/Digital%20Video%20Served%20Impression%20Measurement%20Guidelines%20(MMTF%20June%202018).pdf) were updated in June 2018, and as part of that [update](http://mediaratingcouncil.org/MRC%20Announces%20Release%20of%20Updated%20Digital%20Video%20Ad%20Measurement%20Guidelines.pdf), “new guidance for measuring ad serving that utilized SSAI” was introduced.

### **The IAB Tech Lab’s ‘Guidelines for Identifier for Advertising (IFA) on OTT platforms’ **

In 2018, the IAB Tech Lab released its “[Guidelines for Identifier for Advertising on OTT Platforms](https://iabtechlab.com/standards/guidelines-identifier-advertising-over-the-top-platforms/),” which are “recommendations on how to maintain a high-quality advertising experience within over-the-top television (OTT) environments.”

These guidelines aim to align the OTT advertising industry with best practices from the mobile ecosystem.

“Due to the wide variety of different Smart TV, Connected Device and other over the top television (OTT) platforms, it cannot be guaranteed that devices support the traditional cookie-based semi-persistent device or audience management for ad-related activities,” wrote the IAB Tech Lab. “In order to maintain a high-quality audience experience within OTT environments, it is recommended that parties manage advertising-related activities through an identifier for advertising (IFA), while respecting the user’s privacy settings.”

The IAB Tech Lab recommends passing three data fields through each step of the video delivery chain:

- IFA - in UUID (Universally Unique Identifier) format
- IFA Type (ifa_type)
- Limit Ad Tracking (lmt)

The IFA aims to serve as a Universal Unique Identifier (UUID) of a specific OTT device, such as Smart TVs, gaming consoles, streaming devices, etc. If that UUID is passed through each part of the chain, then the buyer would be better able to validate that the ad was served to a real OTT device.

While the guidelines for Identifier for Advertising do not directly address invalid SSAI, it does call for more transparency throughout the OTT video supply chain, which will help in the overall battle against ad fraud.

### **The Media Rating Council (MRC) has begun accrediting third-party verification companies in OTT/CTV**

The MRC has begun accrediting companies for services in OTT/CTV environments, including for video served ad impressions and sophisticated invalid traffic (SIVT) detection and filtration.

As OTT/CTV becomes a bigger part of advertisers’ plans, the MRC’s guidance helps buyers, sellers, and everyone in between know who they can trust to help with measurement, verification, and ad fraud detection.

The list of[ companies accredited by the MRC](http://mediaratingcouncil.org/Digital%20Landscape.pdf) has become the ad industry’s *de facto* standard of trustworthy third-party measurement companies. 

### **The battle against ad fraud is ongoing**

Scammers are highly incentivized to profit from rising OTT/CTV ad budgets, and it’s important to remember that the fraudsters are equally capable of evolving.

The industry’s growing standards around SSAI — coupled with other standards aimed at improving transparency and quality in OTT/CTV, (such as app-ads.txt) — are all steps in the right direction, and Pixalate strongly encourages their widespread adoption.

However, as programmatic OTT/CTV ad budgets rise, instances of invalid traffic and ad fraud will continue to crop up, and companies that are serious about protecting their OTT/CTV investments are encouraged to utilize advanced IVT solutions for ongoing measurement and detection.

### **SSAI webinar: Learn from industry experts**

[![ssai-webinar-pixalate-header](https://www.pixalate.com/hs-fs/hubfs/Blog_Media/ssai-webinar-pixalate-header.png?width=600&name=ssai-webinar-pixalate-header.png)](https://pixal.at/2NgDS6g)

Pixalate, the first and currently only company [accredited](https://blog.pixalate.com/mrc-accreditation-ott-invalid-traffic-detection-filtration) by the MRC for sophisticated invalid traffic (SIVT) detection and filtration in OTT/CTV, has gathered industry experts for a [webinar](https://pixal.at/2NgDS6g) on the use of Server-Side Ad Insertion (SSAI) in OTT/CTV advertising. 

On **Thursday, July 11, 2019 at 1:00pm ET**, Pixalate Product Manager Chris Schwarz will host:

- Amit Shetty, Sr. Director of Video & Audio Products, IAB Tech Lab
- Ian Trider, Director of RTB Platform Operations, Centro
- Jeremy Smith, VP of Sales Engineering, Telaria

Register today!

[![Register for the Webinar](https://no-cache.hubspot.com/cta/default/2364596/69ca8622-8e4c-4737-9fb8-c427b31a9512.png)](https://cta-redirect.hubspot.com/cta/redirect/2364596/69ca8622-8e4c-4737-9fb8-c427b31a9512)

***Disclaimer***

*Although grounded in Pixalate’s proprietary technology and analytics (which Pixalate evaluates and updates continuously), invalid traffic (IVT) designations in this blog post represent Pixalate’s opinions (i.e., they are neither facts nor guarantees). Per the*[*MRC*](http://www.mediaratingcouncil.org/063014%20Viewable%20Ad%20Impression%20Guideline_Final.pdf)*, the term “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes;” and also per the*[*MRC*](http://mediaratingcouncil.org/101515_IVT%20Addendum%20FINAL%20(Version%201.0).pdf)*, “'Invalid Traffic' is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”*

### Search Blog

Search

### Follow Pixalate

<https://twitter.com/pixalateinc> <https://www.linkedin.com/company/pixalate> <https://www.facebook.com/pixalate>

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

Previous Story

[← Pixalate Week in Review: June 17 - 21, 2019](https://www.pixalate.com/blog/programmatic-ad-fraud-news-week-in-review-june-21-2019)

[** ](https://www.pixalate.com/blog)

Next Story

[Anarchy in OTT/CTV: How Fraudsters Exploit Security Gaps in SSAI →](https://www.pixalate.com/blog/webinar-ad-fraud-server-side-ad-insertion-ssai-ott-ctv)

## You May Also Like

These Stories on Thought Leadership

[![](https://www.pixalate.com/hubfs/Q%26A%20with%20Krush%20Media%20-%20cover.png) ](https://www.pixalate.com/blog/krush-media-qa)

[Case Studies](https://www.pixalate.com/blog/topic/case-studies)

### [Q&A with Steven Slaughter, Head of Ad Ops & Yield at Krush Media, on managing a clean CTV and Mobile Ad Supply Chain](https://www.pixalate.com/blog/krush-media-qa)

 Jun 27, 2023 12:00:00 PM |

 4 min read

[![](https://www.pixalate.com/hubfs/Q%26A%20with%20Screencore%20-%20cover.png) ](https://www.pixalate.com/blog/screencore-qa)

[Case Studies](https://www.pixalate.com/blog/topic/case-studies)

### [Q&A with Jess Okan, Co-founder and CEO of Screencore, on strategies for minimizing ad fraud in the connected TV ecosystem](https://www.pixalate.com/blog/screencore-qa)

 May 30, 2023 7:00:00 AM |

 6 min read

[![](https://www.pixalate.com/hubfs/Oleksandra%20Kazantseva.png) ](https://www.pixalate.com/blog/bizzclick-qa)

[Case Studies](https://www.pixalate.com/blog/topic/case-studies)

### [Q&A with Oleksandra Kazantseva, Head of Programmatic at BizzClick, on transparency, trust, and security](https://www.pixalate.com/blog/bizzclick-qa)

 Apr 17, 2023 2:00:00 PM |

 4 min read

**

### Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use ](https://www.pixalate.com/terms)and [Privacy Policy.](https://www.pixalate.com/privacypolicy)

![pixalate-logo-red-small](https://www.pixalate.com/hs-fs/hubfs/2018NewTemplate/pixalate-logo-red-small.png?width=208&name=pixalate-logo-red-small.png "pixalate-logo-red-small")

**

 By entering your email address and clicking Subscribe, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy)

Products

[Analytics](https://www.pixalate.com/products/analytics) [Blocking](https://www.pixalate.com/products/blocking) [Media Rating Terminal](https://www.pixalate.com/products/mrt) [Publisher Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [Seller Trust Indexes](https://www.pixalate.com/rankings/?group=app&reportId=publisherTrustIndex) [IoT Device Rankings](https://www.pixalate.com/rankings/?group=app&reportId=iotDeviceReach)

Resources

[Blog](https://blog.pixalate.com/) [Press](https://www.pixalate.com/press) [Careers](https://www.pixalate.com/jobs) [Team](https://info.pixalate.com/pixalate-leadership-team)

Contact

Email

[** sales@pixalate.com ](mailto:sales@pixalate.com)

[** privacy@pixalate.com ](mailto:privacy@pixalate.com)

US:

[** +1 888 749 2528 ](tel:+1%20888%20749%202528)

EU:

[** +44 (0)800 011 2050 ](tel:+44%20(0)800%20011%202050)

Slack:

[Join ATSAPI Slack Channel ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

Offices

Global Offices

US

1775 Greensboro Station Place, Suite 425, McLean, VA 22102

UK

20 North Audley Street   
London, W1K 6WE, United Kingdom

EU

10 Earlsfort Terrace   
Dublin 2, D02 T380, Ireland

Singapore

10 Anson Road, #22-02 International Plaza, Singapore 079903

[![facebook](https://www.pixalate.com/hubfs/footer/icons/facebook.png) ](https://www.facebook.com/pixalate) [![x](https://www.pixalate.com/hubfs/footer/icons/twitter-x.png) ](https://twitter.com/pixalateinc) [![linkedin](https://www.pixalate.com/hubfs/footer/icons/linkedin.png) ](https://www.linkedin.com/company/pixalate) ![wechat](https://www.pixalate.com/hubfs/footer/icons/wechat.png) [![slack](https://www.pixalate.com/hubfs/footer/icons/slack.png) ](https://atsapi-pixalate.slack.com/join/shared_invite/zt-10dtow5cj-OEtlNr5yzJkrZMQUqcEEow#/shared-invite/email)

[Terms of Use](https://www.pixalate.com/terms) [Privacy Policy](https://www.pixalate.com/privacypolicy) [GDPR Compliance](https://www.pixalate.com/gdpr) Disclaimer

Copyright © 2025 Pixalate

[Back to top **](https://www.pixalate.com/blog/industry-standards-for-server-side-ad-insertion-ssai#)

# Disclaimer

 Disclaimer: The content of this page reflects Pixalate’s opinions with respect to the factors that Pixalate believes can be useful to the digital media industry. Any proprietary data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that - opinion, not facts or guarantees.

 Per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

**

**

*By clicking Download and entering your email address, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and have read and acknowledge our [Privacy Policy](https://www.pixalate.com/hubfs/2024-08-20_Pixalate_Privacy_Policy.pdf).

*Copyright © 2025 Pixalate** *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

* *

*

×

## Subscribe to the Pixalate Blog

The first step in ad fraud prevention.

Loading...

 By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Contact Us12

Loading...

![pixalate-logo-white](https://www.pixalate.com/hubfs/Blog_V2_08_26_2016/logo/Pixalate_Logo_WHITE.png)

##### Download GSTI

Loading...

Schedule your demo today

Please complete all fields

Loading...

By entering your email address and clicking Submit, you are agreeing to our [Terms of Use](https://www.pixalate.com/terms) and [Privacy Policy](https://www.pixalate.com/privacypolicy).

*

* *

*

*