Seatext library / BotRefund evidence
How to Prevent Geo-Blocking from Killing Your Legitimate Audience
Start with IP-level exclusions based on behavioral evidence, then expand to geographic blocks only after a full day of confirmed invalid patterns. This stepwise approach preserves reach while stopping the traffic that wastes budget...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Geo-blocking is a blunt instrument. When you exclude an entire country or region because a fraction of its traffic is invalid, you also cut off real buyers who happen to live there. The practical alternative is a layered filter: identify and block individual offending IPs first, verify the pattern persists for at least 24 hours, and only then consider a geographic exclusion if the bad traffic is genuinely concentrated and persistent.
Why blanket geo-blocks backfire
Ad platforms bill every click the moment it happens. They do not distinguish between a human buyer and a bot that loads your landing page, triggers a conversion pixel, and leaves. When you respond by blocking an entire country, you remove both the bots and the legitimate prospects in that geography. Your cost per lead may look better on paper, but your total addressable market shrinks — and the bots often reappear from a different IP range the next day.
Meta campaigns in particular can reach people across Facebook, Instagram, and the Audience Network at high volume. That reach is valuable, but it also means a lead campaign can receive accidental interactions, low-intent traffic, automated browsing, and deliberately fraudulent submissions. Treating every unresponsive contact as fraud can make a team exclude a valuable audience.
How invalid traffic actually behaves
Bot traffic and form spam tend to leave repeatable technical and behavioral patterns: unusually fast form completion, identical field structures, sudden placement-level spikes, or conversion events with no meaningful page engagement. These signals appear at the session level — not the country level. A single IP address may generate dozens of clicks in minutes with no scrolling, no mouse tremor, and superhuman input speed (<1ms). Another IP from the same country may show perfectly human behavior.
Client-side detection captures these signals in the browser: ghost clicks that happen without the natural sequence of human intent, honeypot trap interactions, robotic linear mouse movements, absence of humanlike mouse tremor, grid-aligned movement patterns, and unnatural session durations. Server-side logs alone miss most of this because advanced botnets rotate residential proxies and mimic valid headers.
Stepwise filter: IP first, geography last
- Audit before you block. Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, and click identifiers intact so you can trace any refund claim back to the exact charge.
- Flag individual IPs with behavioral evidence. Use client-side tracking to record the full interaction sequence — mouse path, scroll depth, timing, form interactions. Flag IPs that show multiple bot signatures (speed, pointer, trap, session) within a single session.
- Exclude flagged IPs in the ad platform. Add the offending IPs to your Google Ads or Meta exclusion lists. This stops the known bad actors without touching any other traffic from their geography.
- Monitor for 24 hours. Watch whether the invalid pattern re-emerges from new IPs in the same region. A coordinated botnet often rotates addresses within the same ASN or country.
- Escalate to geo-exclusion only if the pattern is dense and persistent. If >80% of clicks from a specific country show bot signatures across multiple days, and IP-level exclusions are playing whack-a-mole, a temporary geographic block may be justified. Document the evidence so you can lift the block when the wave passes.
Tradeoff table: reach vs. blocking protection
| Approach | Legitimate reach retained | Invalid traffic stopped | Operational effort | Risk of over-blocking | Best fit |
|---|---|---|---|---|---|
| No filtering | 100% | 0% | None | None | Brand-new campaigns with no history |
| Platform automatic filters only | ~95% | ~30-50% | None | Low | Baseline for every account |
| IP-level exclusions (evidence-based) | ~98% | ~70-85% | Low (daily review) | Very low | Most advertisers; first line of active defense |
| ASN / subnet exclusions | ~90-95% | ~80-90% | Medium (weekly review) | Low | When botnets cluster in hosting ranges |
| Country-level geo-block | ~60-90% (varies by market) | ~90-95% | Low (set and forget) | High | Last resort; only after 24h+ of dense invalid pattern |
| Combined: IP + ASN + temporary geo | ~85-95% | ~95%+ | Medium (ongoing) | Low | High-spend accounts with persistent fraud waves |
Takeaway: Each layer adds protection but costs reach. Start at the top of the table and move down only when the data forces you to. The combined row is the practical steady state for accounts spending >$50K/month on Meta and Google.
Practical scenarios
Scenario A: Sudden spike from one country
Your Meta lead campaign shows 200 leads in 6 hours from Country X. CRM shows zero connected calls. Client-side logs reveal 180 of those sessions had <500ms dwell, no scroll, and superhuman form fills. Action: exclude the 45 offending IPs immediately. Monitor 24 hours. If new IPs from Country X repeat the pattern, add the top 3 ASNs. Only if the wave continues into day 3 do you consider a temporary country block.
Scenario B: Chronic low-level noise across many countries
Every week you see 5-10% invalid clicks spread across 30 countries. No single geography dominates. Action: keep platform automatic filters on. Add IP exclusions for the worst offenders each week. Do not geo-block — the legitimate reach loss would far exceed the fraud savings.
Scenario C: Competitor click fraud on brand terms
Google Ads Search brand campaign shows repeated clicks from a data-center IP range in your home country. Action: exclude the subnet. This is not a geo decision; it's an infrastructure decision. Geo-blocking your own country would be catastrophic.
Key facts
| Metric | Value | Source |
|---|---|---|
| Bot click share of paid clicks (industry audits) | 9% – 20% | S6 |
| BotRefund detection confidence | 99% | S6 |
| Refund claim approval rate | 83% | S2, S6 |
| Typical recoverable spend | Up to 20% of ad budget | S2, S3, S7 |
| Setup time for detection script | ~1 minute | S2 |
| Meta Audience Network opt-in default | On by default | S4 |
Limitations and when this advice does not apply
- Brand safety mandates: If your legal or compliance team requires hard geographic restrictions (e.g., sanctions, licensing), follow those rules regardless of traffic quality.
- Micro-geo campaigns: If you only target one city or DMA, IP-level exclusions are still preferable to radius blocks, but the reach tradeoff is smaller.
- No client-side tracking: Without browser-level behavioral data, you cannot reliably distinguish bots from humans at the IP level. Server-side logs alone will lead to over-blocking.
- Very low spend (<$5K/month): The operational overhead of daily IP review may not pay off. Rely on platform automatic filters and quarterly audits instead.
Terminology
- Invalid traffic (IVT): Clicks or impressions not resulting from genuine user interest — includes bots, scrapers, click farms, and accidental taps.
- Pixel poisoning: When bots trigger conversion pixels, teaching the ad platform's ML to optimize for bot-like behavior.
- Client-side detection: JavaScript running in the visitor's browser that records mouse, scroll, timing, and interaction signals.
- ASN (Autonomous System Number): A routing prefix owned by an ISP or hosting provider; useful for blocking entire botnet infrastructure.
- GCLID / FBCLID: Click identifiers Google and Meta append to landing-page URLs; required for refund disputes.
FAQ
How long should I wait before escalating from IP blocks to a geo-block?
At least 24 hours of continuous monitoring. A single day of bad traffic from a country is often a transient botnet rotation. If the pattern holds for 2-3 days with >80% invalid rate, a temporary geo-block is defensible.
Will excluding IPs in Google Ads and Meta also stop them from seeing my organic content?
No. Ad-platform IP exclusions apply only to paid delivery. Organic reach is unaffected.
Can I automate IP exclusions instead of reviewing daily?
Yes, if your detection system exports a clean list of IPs with behavioral evidence. BotRefund's script captures the evidence and can feed exclusion lists via API. Manual review is still recommended for the first 2-3 weeks to calibrate thresholds.
What if the bots use residential proxies that rotate every request?
Residential proxies still leave behavioral fingerprints: superhuman speed, linear pointer paths, missing tremor. Client-side detection catches these even when the IP changes every click. Block the behavior, not just the IP.
Does geo-blocking hurt my Quality Score or ad relevance?
Indirectly. If you block a geography that contains real converters, your conversion rate drops and the platform has fewer signals to optimize. Narrow exclusions preserve the learning loop.
How do I prove to Google or Meta that a geo-block was justified?
You don't need to justify the block to the platform. You need evidence to claim refunds for the invalid clicks that occurred before the block. Client-side session recordings with click IDs (GCLID, FBCLID) are the evidence both platforms accept.
What's the typical recovery timeline after filing a refund claim?
Google typically processes invalid activity credits within 2-4 weeks. Meta's timeline varies; having compliance-ready reports with behavioral evidence per click ID speeds up both.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.