Seatext library / BotRefund evidence
How to Differentiate Bot Traffic from Real Users: A Step-by-Step Diagnostic Guide
Bot traffic leaves repeatable technical and behavioral patterns that real users do not. Look for superhuman input speeds, missing mouse tremor, grid-aligned movements, ghost clicks without intent sequences, honeypot interactions, and sessions with no...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Start with the outcome: what separates bots from humans
Real visitors produce imperfect, varied behavior: pauses, hesitation, natural movement, and interactions shaped by reading and decision-making. Automated scripts can send clicks and scrolls, but they struggle to reproduce the varied timing, movement, and hesitation of real people. The practical difference shows up in measurable signals: input speed faster than 1 millisecond, pointer paths that are unnaturally straight or snap to a grid, complete absence of the micro-tremor present in human mouse movement, clicks that fire without the preceding hover or focus sequence, interactions with hidden page elements designed to trap bots, and sessions that show no scrolling, no field corrections, and dwell times that are too short, too long, or suspiciously uniform.
No single signal is a verdict. Privacy tools, corporate networks, unusual devices, and travel can create anomalies for genuine users. Reliable differentiation comes from corroboration: each signal adds one objective fact, the system tests whether other signals support the same story, and a prediction model weighs the complete pattern instead of trusting a raw rule. BotRefund uses 106 independent checks and reaches up to 99% confidence when the session evidence supports it.
How bot detection works: the evidence layers
Detection happens in four parallel layers. The browser layer checks for automation fingerprints: mismatched APIs, patched properties, and rendering contexts that break when viewed from another angle (for example, the Clean Context Iframe check). The device layer looks at hardware signals such as scrollbar width leaks that differ between real browsers and headless automation. The network layer evaluates IP reputation, proxy use, and connection consistency. The behavior layer records pointer dynamics, click timing, scroll depth, form interaction patterns, and session flow. Each layer produces independent evidence; the AI prediction step combines them.
Step-by-step differentiation process
- Preserve attribution before changing anything. Keep campaign, ad set, creative, placement, and click identifiers intact so any refund claim stays tied to the original paid click.
- Collect onsite behavioral evidence. Deploy a script that records pointer movement, click timing, scroll behavior, form field interactions, and navigation flow for every session that follows a paid click.
- Run the 106 independent checks. The system evaluates browser consistency, device signals, network context, and behavioral patterns. Each check returns a binary or scored signal.
- Cross-check signals for corroboration. A single anomaly (e.g., superhuman click speed) is held as evidence, not a verdict. The model asks whether browser, device, network, and behavior signals tell the same story.
- Classify the session. The AI prediction outputs a bot/human probability. Sessions with high bot probability are flagged; borderline sessions stay in review.
- Export a refund-ready report. The report ties each flagged session to its click ID, timestamp, placement, and campaign, and includes video replay of the session for platform review.
- Submit to Google or Meta. Use the platform's invalid traffic or refund workflow with the exported evidence. BotRefund customers report an average approved refund rate across submitted claims.
Key detection signals and what they reveal
- Ghost click detection: Catches click activity that happens without the natural sequence of human intent (hover, focus, then click).
- Honeypot trap interactions: Watches for bots that respond to hidden or intentionally deceptive page elements.
- Robotic linear mouse movements: Flags unnaturally straight pointer paths that rarely appear in real user sessions.
- Absence of humanlike mouse tremor: Looks for the tiny imperfections and jitter typical of human movement.
- Superhuman input speed (<1ms): Identifies interactions that happen faster than a person could realistically perform.
- Grid-aligned movement patterns: Detects movement that snaps to precise lines or blocks instead of natural curves.
- Absence of clicks or scrolling: Highlights sessions that stay too static to match a real browsing journey.
- Unnatural session durations: Catches visit lengths that are too short, too long, or too uniform to be human.
- Scrollbar Width Leak: Detects a mismatch in scrollbar rendering that a real browsing session does not normally create.
- Clean Context Iframe: Finds automation tools that patch or hide browser APIs, which break when checked from another angle.
Common mistakes that lead to false positives or missed bots
- Relying on a single rule. Blocking every session with a fast click catches users on low-latency connections or accessibility tools.
- Ignoring context. Corporate VPNs, privacy browsers, and assistive technologies create legitimate anomalies. Cross-checking prevents misclassification.
- Changing campaign settings before preserving evidence. Pausing ads or altering targeting destroys the click-to-session link needed for a refund claim.
- Treating all bad leads as bots. Low-intent real users, accidental clicks, and form confusion produce poor leads without automation. Compare CRM outcomes (no calls connected, no demos booked) against session behavior before concluding fraud.
- Using only server-side logs. Server logs miss client-side behavior: pointer dynamics, scroll depth, and browser API consistency. Onsite behavioral investigation is required for refund-ready evidence.
Verification step: confirm the classification before acting
After the system flags a session cluster, open the session replay. Verify that the flagged behavior matches the signal description: straight-line pointer paths, zero scroll events, form submission in under a second, interaction with a hidden honeypot field. Check that the click ID, timestamp, and campaign metadata are intact. If the replay shows a real person struggling with a form or using a screen reader, reclassify as human and adjust the suppression rule. This manual spot-check on a sample of flagged sessions is the practical verification step before submitting a refund request.
Limitations and when this advice does not apply
- Low-traffic sites. Statistical confidence improves with volume. Sites with fewer than a few thousand paid clicks per month may not generate enough evidence for high-confidence classification.
- Non-ad traffic. This process is built for paid click investigation (Google Ads, Meta Ads). Organic, direct, or referral traffic does not carry the click identifiers needed for platform refund workflows.
- Sophisticated human fraud farms. Low-cost click farms use real humans on real devices. Behavioral signals may look human; detection then relies on pattern anomalies (burst timing, identical field structures, geographic concentration) rather than automation fingerprints.
- Platform policy changes. Google and Meta update invalid traffic definitions and refund processes. The evidence format must match current platform requirements.
- Implementation gaps. If the tracking script is blocked by ad blockers, consent banners, or CSP policies, evidence collection is incomplete.
Key facts
| Metric | Value | Source |
|---|---|---|
| Independent detection checks | 106 | S3, S5 |
| Reported AI prediction accuracy | Up to 99% when session evidence supports it | S3, S5 |
| Superhuman input speed threshold | <1ms | S2 |
| Typical setup time | About 1 minute | S2 |
| Ad spend recovery lookback | Dating back to 2017 | S2 |
| Platforms supported for refunds | Google Ads, Meta Ads | S2, S4, S7, S8 |
| Case study refund amounts (examples) | $1.2M, $140K, $92K, $112K, $84K, $71K, $58K, $47K, $45K, $38K, $36.5K, $32.4K, $28K, $24.5K, $22K, $19.5K, $18.2K, $15.4K | S1 |
| Average bot click rate reported in case studies | 14%–35% lift after suppression | S1, S7 |
Frequently asked questions
How many signals do I need before I can call a session a bot?
There is no fixed count. BotRefund's model weighs the complete pattern across browser, network, device, and behavior layers. A cluster of 3–5 corroborating signals (e.g., superhuman speed + grid-aligned movement + honeypot interaction + no scroll) typically reaches high confidence. A single signal is held as evidence only.
Can I use Google Analytics or Meta's built-in invalid traffic filters instead?
Platform filters catch known bad IPs and simple patterns. They do not record client-side behavioral evidence (pointer tremor, scrollbar width, iframe context) and they do not produce the session-level video replay and click-ID mapping that refund teams require. Onsite behavioral investigation adds the evidence layer platforms accept for manual review.
What if my site uses a strict Content Security Policy or ad blockers?
The tracking script must be allowed to load and execute. Work with your dev team to whitelist the script domain in CSP and ensure consent banners do not block it before the paid click lands. Incomplete coverage creates blind spots in the evidence chain.
How far back can I claim refunds?
BotRefund can recover Google and Meta ad spend dating back to 2017, provided the click identifiers and session evidence are preserved or reconstructible. Platform time limits vary; submit claims as soon as a pattern is confirmed.
Does this replace Cloudflare or a WAF?
No. Edge protection (DDoS mitigation, CDN, WAF rules) and onsite behavioral investigation solve different problems. If your goal is proving invalid paid traffic and recovering ad spend, you need the marketing-layer evidence: click-ID mapping, session replay, and refund-ready reports. Many advertisers keep their edge provider and add BotRefund for the evidence layer.
What does the free bot audit include?
The audit runs the 106 checks on your live traffic, produces a report showing bot percentage by campaign and placement, and identifies the top signal clusters. It requires adding the script (about one minute) and does not need a credit card.
How do I know the refund will be approved?
Approval is at the platform's discretion. BotRefund customers report an average approved refund rate across submitted claims. The evidence format (click ID, timestamp, video replay, signal breakdown) is designed to meet Google and Meta review standards.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.