Seatext library / BotRefund evidence

How to Block Specific IP Addresses in Google Ads to Stop Fake Leads

Yes, you can block specific IP addresses in Google Ads using the IP exclusions setting. This lets you prevent known bot networks, competitor offices, or suspicious IP ranges from seeing or clicking your ads....

Built for advertisers who need clear, refund-ready traffic evidence.

Google Ads provides a built-in IP exclusions feature that lets you block individual IP addresses or CIDR ranges from seeing your ads. You'll find it under Campaign Settings → Additional settings → IP exclusions. Enter each IP or range (for example, 192.0.2.0/24) and save. The change takes effect within a few hours. This is the direct, manual way to stop known bad actors from clicking your ads.

Why IP Blocking Exists in Google Ads

Advertisers noticed patterns: certain office parks, data centers, or VPN exit nodes generated clicks that never turned into leads. Google added IP exclusions so you could cut off those sources without waiting for automated filters. The feature is free, immediate, and under your control.

Step-by-Step: Add IP Exclusions in Google Ads

  1. Sign in to Google Ads and select the campaign you want to protect.
  2. Click Settings in the left menu, then scroll to Additional settings.
  3. Expand IP exclusions.
  4. Enter one IP address per line (IPv4 or IPv6) or use CIDR notation for ranges (e.g., 203.0.113.0/24).
  5. Click Save.

You can add up to 500 IP entries per campaign. For larger lists, apply the same exclusions at the account level via the shared library.

How CIDR Notation Works for IP Ranges

CIDR (Classless Inter-Domain Routing) lets you block a whole block of addresses with one entry. The notation 192.0.2.0/24 means the first 24 bits are fixed, covering 256 addresses from 192.0.2.0 to 192.0.2.255. A /16 covers 65,536 addresses. Use CIDR when you see many bad IPs from the same subnet, such as a hosting provider or a corporate network. Be careful: a broad range can also block legitimate users.

How to Find IPs Worth Blocking

Start with your website analytics. Look for sessions with:

  • High bounce rates and zero scroll depth
  • Multiple clicks from the same IP within minutes
  • Clicks from known data-center ASNs (Amazon AWS, Google Cloud, DigitalOcean, etc.)
  • Form submissions with fake or disposable email domains

Export the offending IPs, deduplicate, and paste them into the exclusions box. Many advertisers also subscribe to third-party blocklists that update daily.

Example of a Fake Google Ads Lead Pattern

A typical fake lead arrives from a data-center IP like 35.180.45.12 (AWS). The session lasts 8 seconds. The user lands on the contact page, fills the form in 1.2 seconds, uses a disposable email like user@tempmail.com, and submits. No mouse movement is recorded before the click. The GCLID shows a click from a campaign targeting "enterprise software". This pattern — fast form fill, disposable email, data-center IP, no engagement — signals a bot or a low-quality click farm.

Verification: Confirm the Block Is Working

After saving, wait 2–4 hours. Then check your Google Ads Click Performance report segmented by IP address (available via scripts or the API). The excluded IPs should show zero impressions and clicks. If you still see traffic from those addresses, double-check CIDR formatting and ensure the exclusion is applied to the correct campaign or account level.

For a programmatic check, use a Google Ads script. Example:

function checkIPExclusions() {
  var campaignIterator = AdsApp.campaigns().withCondition('Status = ENABLED').get();
  while (campaignIterator.hasNext()) {
    var campaign = campaignIterator.next();
    var excludedIps = campaign.settings().getExcludedIps();
    Logger.log('Campaign: ' + campaign.getName() + ' excluded IPs: ' + excludedIps.join(', '));
  }
}

Run this script in the Google Ads Scripts editor. It logs all active exclusions per campaign. For API users, call CampaignCriterionService with criterion type IP_BLOCK to retrieve the list. Compare the returned IPs with your blocklist to confirm they match.

Limitations of Manual IP Blocking

IP exclusions stop only the addresses you know about. Modern click fraud uses residential proxy networks — real home connections that rotate IPs every few minutes. BotRefund audit data shows 11% to 14% average invalid click rate across all Google Ads campaigns, and Google's own automated filters catch less than 50% of invalid traffic, leaving the rest classified as sophisticated invalid traffic (SIVT) that requires manual evidence submission. Blocking a few hundred IPs barely dents that volume.

Each campaign supports up to 500 IPv4 or IPv6 entries. Account-level shared lists also have a 500-entry limit per list, but you can create multiple lists. IPv6 ranges are supported, but many advertisers only block IPv4 because IPv6 adoption in fraud is lower. Residential proxy rotation means a single bot can appear as thousands of different IPs over a day. Behavioral detection — analyzing mouse movement, scroll depth, timing, and interaction patterns — is required to catch SIVT that IP lists miss.

When IP Blocking Works — and When It Doesn't

ScenarioIP Blocking EffectivenessBetter Approach
Known competitor office IPHighBlock the IP; monitor for new ranges
Data-center botnet (fixed IPs)MediumBlock ASN ranges; add behavioral detection
Residential proxy rotationLowClient-side behavioral verification (mouse movement, scroll, timing)
Click farms on real devicesVery lowForensic evidence collection for refund disputes

Beyond Blocking: Detecting Bots You Can't See

Since most invalid traffic bypasses IP filters, the practical next step is behavioral detection. BotRefund runs client-side checks — pointer behavior, motion behavior, speed behavior, engagement behavior, and session behavior — to flag non-human patterns like robotic linear mouse movements, absence of humanlike mouse tremor, superhuman input speed (<1ms), and grid-aligned movement patterns. These signals build the evidence Google requires for refund disputes.

Recovering Spend from Already-Clicked Fraud

Blocking future clicks doesn't refund past waste. Google's refund process requires structured evidence: GCLIDs, timestamps, behavioral logs, and a formal dispute. BotRefund automates this — it captures GCLIDs with behavioral evidence and generates audit-ready refund dispute reports, achieving an 83% refund success rate for high-volume advertisers. The platform can recover bot-click refunds from Google Ads spend dating back to 2017.

Common Mistakes to Avoid

Each mistake below includes the consequence and the correct fix.

  • Blocking your own office or VPN — Consequence: your team cannot see or test ads. Fix: test exclusions in a draft campaign first.
  • Using /32 for every IP when a /24 covers the whole hostile subnet — Consequence: you hit the 500-entry limit quickly. Fix: aggregate IPs into CIDR blocks where possible.
  • Assuming IP blocking solves the problem — Consequence: sophisticated bots continue to click and waste budget. Fix: treat IP blocking as a first layer; add behavioral detection and refund claims.
  • Forgetting to apply exclusions to new campaigns — Consequence: new campaigns bleed money from known bad IPs. Fix: use account-level shared lists so every campaign inherits the blocklist.

FAQ

How many IPs can I block in one campaign?

Up to 500 entries per campaign. For larger lists, use account-level IP exclusions in the shared library. You can create multiple shared lists, each with 500 entries, and apply them to campaigns as needed.

Does blocking an IP stop it from seeing my ads immediately?

Changes propagate within a few hours. Check the Click Performance report the next day to confirm. If you need faster verification, use the Google Ads API to pull real-time impression data for the excluded IP.

Can I block entire countries instead of individual IPs?

Yes — use location targeting (exclude countries) rather than IP exclusions. It's cleaner and doesn't count toward the 500-entry limit. Go to Campaign Settings → Locations → Exclude and select the countries you want to block.

Will IP blocking hurt my Quality Score?

No. Excluding invalid traffic can improve CTR and conversion rates, which may help Quality Score. Removing bot clicks reduces wasted spend and improves the relevance signals Google uses.

What's the difference between IP exclusions and invalid click filters?

IP exclusions are manual rules you set. Invalid click filters are Google's automated systems — they catch basic bots but miss sophisticated invalid traffic (SIVT). Google's filters run continuously and you cannot see or adjust them. IP exclusions give you control over known bad addresses, but they don't replace automated filters.

How do I get refunds for clicks that already happened?

Collect GCLIDs, timestamps, and behavioral evidence (mouse paths, scroll depth, session duration). In Google Ads, go to Billing → Disputes → Request a refund. Attach your evidence. Tools like BotRefund automate evidence collection and dispute filing, increasing approval rates. Start by exporting the Click Performance report for the suspicious period, filter for high-click, zero-conversion IPs, and match them to your behavioral logs.

Should I use a third-party blocklist?

Reputable blocklists (e.g., known proxy/VPN exit nodes) save time. Update them weekly; stale lists block legitimate users. Combine a blocklist with your own analytics data for best coverage. Always test a new list in a draft campaign before applying to live traffic.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more