Seatext library / BotRefund evidence
How to Prove Click Fraud to Google Support: Evidence, Process, and Refund Requirements
To prove click fraud to Google, submit a detailed Invalid Click Refund Request with IP addresses, timestamps, user agent strings, GCLIDs, and behavioral evidence showing patterns that deviate from human traffic. Google's automated filters...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Google's automated systems filter out basic invalid traffic, but they miss sophisticated bot networks that mimic human behavior. When that happens, the burden shifts to you: you must document the fraud with specific technical evidence and submit it through the Google Ads Invalid Click Refund Request form. The form asks for campaign IDs, date ranges, and a narrative explanation, but the deciding factor is the quality of your supporting data — IP logs, click timestamps, Google Click IDs (GCLIDs), user agent strings, and behavioral signals that prove the clicks could not have come from real people.
What Google Considers Invalid Traffic
Google divides invalid traffic into two categories. General Invalid Traffic (GIVT) includes known bots, spiders, and crawlers that identify themselves honestly — think search engine indexers or monitoring tools. These are caught by Google's automated filters. Sophisticated Invalid Traffic (SIVT) covers traffic that deliberately disguises itself: rotating residential proxies, headless browsers with forged fingerprints, click farms, and competitor click networks. SIVT is what slips through the automated net and requires manual evidence submission.
According to aggregated audit data, the average Google Ads campaign sees an 11% to 14% invalid click rate, and Google's own filters catch less than half of that. The remainder — SIVT — is what you have to prove yourself.
Evidence Google Requires for Refund Requests
The refund form does not accept vague complaints. You need concrete, time-stamped records tied to specific clicks. The most useful evidence includes:
- Google Click IDs (GCLIDs) — the unique parameter Google appends to each ad click. Without GCLIDs, Google cannot trace the click back to your billing.
- IP addresses — ideally with geographic and ISP context. Clusters of clicks from the same IP block, data center ranges, or known proxy networks are strong signals.
- Timestamps — down to the second. Patterns like clicks at exact intervals, bursts in short windows, or activity outside normal business hours for your targeting region help demonstrate automation.
- User agent strings — mismatches between the claimed browser/OS and actual behavior (e.g., a Chrome user agent with no mouse movement) indicate spoofing.
- Behavioral telemetry — mouse movement paths, scroll depth, dwell time, click sequences, and form interactions. Real humans exhibit micro-tremors, curved paths, variable timing; bots often show linear movements, superhuman speed (<1ms inputs), grid-aligned paths, or complete absence of scrolling.
Server logs alone rarely suffice. They capture the request but not the browser-side behavior that distinguishes a human from a headless browser. Client-side behavioral data — collected via JavaScript on your landing page — is what turns a list of IPs into a refundable case.
Step-by-Step: Building Your Invalid Click Report
- Enable GCLID capture on your landing pages. Ensure your tracking preserves the
gclidquery parameter from the ad click through to your analytics and form submissions. If you use a tag manager, verify the parameter isn't stripped. - Deploy client-side behavioral tracking. You need a script that records mouse movements, scroll events, click coordinates, timing between actions, and session duration. This data must be linked to each GCLID.
- Identify suspicious patterns. Look for: multiple clicks from the same IP/GCLID cluster; sessions with zero scroll or zero mouse movement; clicks faster than human reaction time; identical paths across sessions; sessions that hit conversion pixels without prior engagement.
- Export a clean evidence package. Compile a CSV or JSON file with one row per suspicious click: GCLID, timestamp, IP, user agent, behavioral flags (e.g., "no mouse movement," "linear path," "<1ms click speed"), and your campaign/ad group/keyword context.
- Write a concise narrative. Summarize the pattern, the date range, the estimated wasted spend, and why you believe this is SIVT rather than low-quality but human traffic. Reference the specific behavioral anomalies.
- Submit via the Invalid Click Refund Request form. Attach your evidence file. Google's traffic quality team reviews manually; response times vary from a few days to several weeks.
- Follow up if needed. If the initial response is a generic denial, reply with a focused addendum highlighting the behavioral evidence that automated filters would miss. Persistence with better-organized data often changes the outcome.
Common Mistakes That Get Claims Rejected
| Mistake | Why It Fails | Fix |
|---|---|---|
| Submitting only IP lists | IPs alone don't prove the click was non-human; shared networks, VPNs, and corporate proxies create false positives. | Pair every IP with behavioral proof tied to the GCLID. |
| Using server logs without client-side data | Server logs show the request, not the browser behavior. Headless browsers look identical to real browsers in server logs. | Add JavaScript-based behavioral capture on the landing page. |
| Including low-quality traffic (e.g., accidental clicks) | Google already filters accidental and duplicate clicks. Mixing them dilutes the SIVT signal. | Filter your evidence to only show patterns automation cannot explain. |
| Vague date ranges or campaign selection | The review team needs to match clicks to billing records precisely. | Provide exact start/end dates, campaign IDs, and GCLID lists. |
| No narrative connecting evidence to fraud | Raw data without interpretation forces the reviewer to guess your argument. | Write a 150-word summary explaining the pattern and why it's SIVT. |
How Behavioral Detection Strengthens Your Case
Behavioral evidence is the difference between a denied claim and an approved refund. Automated filters rely on reputation lists and simple heuristics — IP reputation, click frequency, known bot signatures. They miss bots that use clean residential IPs, realistic user agents, and randomized timing. Behavioral signals catch what reputation lists miss:
- Ghost clicks — click events that fire without the preceding mouse movement, hover, or focus sequence a human requires.
- Honeypot interactions — clicks on hidden page elements (invisible links, off-screen buttons) that only a script would find.
- Pointer behavior — linear movements, grid-aligned paths, absence of micro-tremor, superhuman speed (<1ms between events).
- Session behavior — durations that are too short (instant bounce), too long (idle holding), or too uniform across sessions.
- Engagement gaps — conversion pixel fires with no prior scroll, no form focus, no time on page.
When you present GCLIDs linked to these behavioral flags, you give the review team a reproducible reason to classify the traffic as SIVT. Tools that automate this evidence collection — capturing GCLIDs, recording behavioral telemetry, and generating audit-ready reports — dramatically reduce the manual work per claim.
What Happens After You Submit the Form
Google's Traffic Quality team reviews the submission. They cross-reference your GCLIDs against their internal click logs, check their own detection signals, and evaluate your behavioral evidence. Outcomes fall into three buckets:
- Full or partial refund approved — credited to your Google Ads account as an invalid click adjustment. You'll see it in the Billing > Transactions view.
- Denied with generic explanation — often "our systems did not detect invalid activity." This usually means your evidence didn't clearly demonstrate SIVT patterns.
- Request for more information — the reviewer needs clarification on specific clicks or a narrower date range.
High-volume advertisers who submit well-structured, behaviorally-backed claims see refund approval rates around 83% based on aggregated client data. The key differentiator is client-side behavioral proof tied to GCLIDs — not just server logs.
Limitations and When This Process Doesn't Apply
- Time window: Google typically only considers refund requests for clicks within the last 60 days, though some evidence suggests disputes can reach back further with strong documentation.
- Minimum spend thresholds: Very low-spend accounts may not receive manual review; the form may return an automated response.
- Non-Google platforms: This process only covers Google Ads (Search, Display, YouTube, Shopping). Meta, Microsoft Ads, and other platforms have separate forms and evidence standards.
- Traffic you invited: If you bought traffic from a third-party network that resold bot clicks, Google may classify that as a policy violation on your end rather than invalid traffic they refund.
- Conversion fraud without click fraud: If bots click legitimately but then fake conversions (form fills, purchases), that's a pixel poisoning issue — Google's click refund process doesn't cover downstream conversion fraud.
Key Terms to Know
- GCLID (Google Click Identifier)
- A unique parameter appended to your landing page URL when someone clicks your ad. Essential for tying a specific click to your billing record.
- SIVT (Sophisticated Invalid Traffic)
- Invalid traffic that actively evades detection — rotating proxies, browser automation, human-like behavior simulation. Requires manual evidence to prove.
- GIVT (General Invalid Traffic)
- Known, identifiable non-human traffic (crawlers, monitoring bots) caught by automated filters.
- Pixel poisoning
- When bot traffic triggers your conversion pixels, corrupting the data Smart Bidding uses to optimize. This amplifies waste over time.
- Honeypot
- A hidden page element (link, button, form field) that real users never see but bots interact with, revealing their automated nature.
- Residential proxy
- An IP address assigned to a real household device, rented out to route bot traffic through "clean" IPs that bypass reputation blocks.
Key Facts from Industry Data
| Metric | Value | Source |
|---|---|---|
| Average invalid click rate across Google Ads campaigns | 11%–14% | S1 |
| Google automated filters catch rate | Less than 50% of invalid traffic | S1 |
| Global digital ad fraud projected cost (2026) | Over $100 billion | S1 |
| Invalid traffic share of programmatic spend | 10%–30% | S1 |
| Refund success rate for high-volume advertisers with behavioral evidence | 83% | S2 |
| Average ROAS improvement after cleaning traffic | 40%–60% within 6–8 weeks | S4 |
| Non-human share of total internet traffic | 43% | S5 |
| Google Search invalid click rate range | 4% (well-protected) to 35%+ (high-CPC competitive) | S5 |
FAQ
How long does Google take to review an invalid click refund request?
Typically 5–20 business days. Complex cases with large evidence packages can take longer. There's no guaranteed SLA.
Can I get refunds for clicks older than 60 days?
The official form focuses on recent traffic, but advertisers with detailed behavioral logs tied to GCLIDs have successfully disputed charges going back months. Evidence quality matters more than the exact window.
Do I need a third-party tool to collect this evidence?
You can build client-side tracking yourself, but it requires capturing mouse movements, scroll events, timing, and linking every event to the GCLID — then exporting a clean report. Most teams use a dedicated tool that automates GCLID capture, behavioral detection, and refund-ready report generation.
What if Google denies my claim?
Reply with a focused addendum. Highlight the specific behavioral anomalies (e.g., "12 clicks from 3 IPs, all with zero mouse movement, linear paths, and <1ms click speed"). Narrow the date range. Resubmit. Second reviews with sharper evidence often succeed.
Does this process work for YouTube and Display campaigns?
Yes. The same Invalid Click Refund Request form covers all Google Ads inventory. However, Display and YouTube see different bot patterns (e.g., background video plays, impression bots), so your behavioral evidence should reflect the channel.
Will filing a refund request hurt my account standing?
No. Google encourages advertisers to report invalid traffic. Legitimate claims improve their detection models. Only fraudulent or abusive submissions (e.g., claiming refunds for legitimate low-converting traffic) risk account flags.
How much budget should I expect to recover?
If your campaigns match the average 11–14% invalid click rate and you submit behavioral evidence for the SIVT portion, a typical recovery is 5–10% of total spend. High-CPC verticals (legal, insurance, B2B SaaS) often see higher rates.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.