Seatext library / BotRefund evidence

BotRefund and Cloudflare: How to Integrate Origin-Side Bot Protection

Yes, BotRefund works with Cloudflare by operating as an origin-side check that analyzes traffic after Cloudflare's edge protections. This allows both systems to complement each other, with Cloudflare handling DDoS and CDN features while...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund integrates with Cloudflare by running on your origin server, where it examines requests that have already passed through Cloudflare's security layers. This architecture means BotRefund adds depth without conflicting with Cloudflare's existing protections, such as Bot Fight Mode or rate limiting. You can deploy both tools to create a layered defense: Cloudflare blocks malicious bots at the edge, and BotRefund catches any automated traffic that slips through by analyzing behavior after the request reaches your server.

BotRefund focuses on detecting bot activity through independent checks, like monitoring mouse movements or session patterns. Since it operates origin-side, it doesn't interfere with Cloudflare's CDN caching or DDoS mitigation. This setup is particularly useful if you run ad campaigns on Google or Meta, as BotRefund can identify bot clicks that waste budget, even if they bypass Cloudflare's initial filters.

Why This Integration Matters

Ignoring bot traffic can drain your ad spend by up to 20%, according to BotRefund's data. Cloudflare provides strong edge protection, but sophisticated bots may still reach your origin server. By adding BotRefund origin-side, you ensure that every visit is evaluated for behavioral anomalies, reducing false negatives. This matters most for advertisers with high click-through rates or those noticing discrepancies between ad platform data and real conversions.

If you skip this layer, you might miss bot-generated clicks that Cloudflare doesn't catch, leading to wasted budget and distorted analytics. The integration helps maintain data accuracy for ad optimization, ensuring your campaigns target genuine human users.

How BotRefund's Origin-Side Check Works

BotRefund uses a JavaScript snippet or server-side integration to collect data on each visitor. It runs 106 independent checks, such as:

  • CPU Concurrency Lie: Detects mismatches in hardware reporting that automated browsers often reveal.
  • window.open Tamper: Looks for unnatural script interactions that real users don't produce.
  • Impossible Tab Speed: Identifies interactions happening faster than humanly possible.

These signals are cross-checked by BotRefund's AI model to avoid false positives from privacy tools or unusual devices. Since it runs after Cloudflare, it doesn't rely on edge-level data but analyzes the full session behavior at your server.

Prerequisites for a Smooth Setup

Before integrating, gather these items:

  1. Active Cloudflare Account: Ensure your domain is on a Free, Pro, Business, or Enterprise plan with basic bot protection enabled.
  2. Origin Server Access: You need to modify your website's HTML or server configuration to add BotRefund's code.
  3. BotRefund Account: Sign up to get your unique script snippet; setup typically takes about one minute.
  4. Ad Campaign Data: If recovering ad spend, have your Google Ads or Meta Ads account details ready.

Verify that your Cloudflare settings don't block BotRefund's scripts. For example, check that the Web Application Firewall (WAF) rules allow the BotRefund domain.

Step-by-Step Configuration Guide

  1. Enable Cloudflare's Basic Protection: In your Cloudflare dashboard, go to Security > Bots and turn on Bot Fight Mode. This blocks common malicious bots at the edge.
  2. Add BotRefund to Your Website: Log into BotRefund, copy the JavaScript snippet, and paste it into your site's HTML or before the closing tag. If using a CMS like WordPress, use a plugin or theme option to insert the code safely.
  3. Configure Cloudflare Origin Rules: In Cloudflare, set up a Page Rule or Origin Rule to ensure traffic passes through to your server without interference. For instance, create a rule for your ad landing pages that excludes them from aggressive rate limiting.
  4. Test in a Staging Environment: Deploy changes on a staging site first. Monitor server logs to confirm BotRefund is receiving requests and that Cloudflare isn't blocking the script.
  5. Go Live and Monitor: Push the changes to production. Use the BotRefund dashboard to watch for traffic analysis and check Cloudflare analytics to ensure edge protection remains active.

Common Mistake: Skipping the staging test can lead to conflicts where Cloudflare blocks BotRefund, causing gaps in detection. Always validate in a non-production setting.

Verifying Your Integration

After setup, confirm everything works with these checks:

  • BotRefund Dashboard: Look for incoming traffic data and analysis reports. If visits are being logged, the integration is active.
  • Cloudflare Analytics: Ensure that bot requests are still being filtered at the edge, as shown in security events.
  • Manual Test: Use a bot simulation tool or trigger a test click from an automated browser. Verify that BotRefund detects it as bot traffic while Cloudflare doesn't block it entirely.

If issues arise, check for JavaScript errors in your browser console or review Cloudflare's firewall events for blocked requests.

Key Facts and Limitations

FactValueSource
Independent Detection Checks106 per visitBotRefund S1
Reported Accuracy99% for bot identificationBotRefund S1
Typical Setup TimeUnder one minuteBotRefund S2
Core FocusBehavioral and ad fraud detectionBotRefund S6

Limitations: BotRefund is designed for origin-side behavioral analysis and may not replace Cloudflare's edge security for DDoS protection or rate limiting. It primarily targets bot traffic affecting ad campaigns, so it might not cover all bot types, like basic scrapers. Additionally, privacy-focused browsers or corporate networks can sometimes trigger false positives, though BotRefund's cross-checking minimizes this.

Practical Scenarios

Consider these situations where the integration shines:

  • High Ad Spend on Google Ads: If you notice invalid clicks in your campaigns, BotRefund can catch bots that Cloudflare lets through, helping you recover spend.
  • Meta Lead Generation: When form submissions look suspicious, BotRefund's behavioral checks can filter out automated entries, improving lead quality.
  • E-commerce Sites: During sales, bots might bypass Cloudflare to scrape prices or stock; BotRefund adds an extra layer to detect such activity.

In each case, the origin-side check ensures no conflict with Cloudflare's CDN, so your site speed and uptime remain unaffected.

Common Questions and Answers

Why should I use BotRefund alongside Cloudflare?

Cloudflare provides broad edge protection, but sophisticated bots can evolve to slip past it. BotRefund adds targeted behavioral analysis at the origin, catching nuanced threats that affect ad performance. This layered approach improves overall accuracy.

How do I prevent conflicts between BotRefund and Cloudflare rules?

Ensure Cloudflare's WAF or rate limiting rules allow BotRefund's script domain. Test in staging and monitor logs for any blocked requests. Avoid setting overly strict rules that might interfere with BotRefund's data collection.

When is the best time to enable this integration?

Enable it immediately if you run paid ad campaigns and suspect bot traffic. It's especially useful during peak advertising periods or when you see discrepancies between ad platform data and real conversions.

What does BotRefund cost to integrate?

Pricing depends on your ad spend and volume; BotRefund offers a free bot audit to start. Check their website for details, as plans scale with usage.

How does BotRefund's detection differ from Cloudflare's?

Cloudflare uses network-level and machine learning tools at the edge to block known threats. BotRefund focuses on origin-side behavioral signals, like mouse movement and session timing, providing complementary data for ad fraud detection.

Terminology Clarified

Origin-Side Check: Analysis performed on your web server after requests have passed through a CDN or proxy like Cloudflare. This allows deeper inspection of traffic without affecting edge performance.

Behavioral Analysis: Monitoring user interactions such as clicks, scrolls, and timing to identify patterns that distinguish humans from bots, used by BotRefund to improve detection accuracy.

Integrating BotRefund with Cloudflare is a straightforward process that enhances your bot protection. By following these steps, you can ensure both systems work together to safeguard your ad budget and data integrity.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

How BotRefund can help

BotRefund runs as an origin-side check, using 106 independent behavioral signals to detect bots with 99% accuracy. It complements Cloudflare's edge protection by analyzing traffic after it reaches your server, ensuring no interference with CDN or DDoS features. However, it focuses primarily on ad fraud and may not replace edge security for all bot types, so configure Cloudflare rules to allow BotRefund's scripts.
Start Your Free Bot Audit