Google’s published checklist
Google asks advertisers requesting an investigation to provide a customer ID, exact date range, campaign and ad group names, suspicious keywords, web-server logs, IP addresses, user agents, GCLIDs, and a short explanation of the trend. The same guidance says investigations are limited to the previous 60 days.
Where VPN evidence fits
Add the observed VPN or proxy classification to the row for the affected session. Include the apparent country, ASN or provider when available, the timestamp of the lookup, and a plain description of what the signal means. Do not state that the IP proves the visitor’s physical location or fraud.
Write the trend, not the accusation
A strong summary might say: “From June 3–7, campaign X received a cluster of clicks through networks classified as commercial VPN or hosting exits. These sessions shared repeated click timing, produced no qualified lead, and were concentrated in a segment with a 300% click increase and no corresponding conversion lift.” That is more useful than “VPN users clicked our ads.”
- Export the same time zone and format for every row.
- Keep click IDs intact and do not over-aggregate away the session evidence.
- Separate automatically filtered clicks from clicks you are asking Google to investigate.
- Submit promptly because Google’s public process is time-limited.
See BotRefund VPN Detection for the report fields, and compare the Meta evidence workflow.