Seatext library / BotRefund evidence
How to Tell If Bots Are Clicking Your Ads and Wasting Your Budget
Bot clicks often show up as unusually high click-through rates with zero conversions, traffic spikes at odd hours, identical user-agent strings, and clicks from known data-center IP ranges. A structured audit of your ad...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
If your campaigns show high click-through rates but conversions stay flat, or you see traffic surges at 3 AM from the same IP blocks, bots are likely clicking your ads. The fastest way to confirm is to cross-reference Google Ads or Meta Ads Manager data with your website analytics and server logs. Look for sessions with zero scroll depth, sub-second page times, identical user-agent strings, and clicks originating from hosting-provider IP ranges. If those patterns line up, you have bot traffic eating your budget.
Common signs your ads are getting bot clicks
Bot traffic leaves repeatable fingerprints. The most reliable indicators appear when you compare platform-reported clicks with what actually happens on your site.
- High CTR, no conversions: Click-through rates far above your historical baseline while conversion rates drop to near zero.
- Odd-hour spikes: Clicks concentrated between midnight and 5 AM in your target time zone, especially on weekends.
- Identical user agents: Dozens of clicks sharing the exact same browser version, OS, and screen resolution.
- Data-center IPs: Clicks resolving to AWS, Google Cloud, DigitalOcean, or other hosting ranges instead of residential ISPs.
- Zero engagement: Sessions with no scroll, no mouse movement, and time-on-page under one second.
- Repeated click IDs: The same GCLID or FBCLID appearing multiple times in your logs.
Any single signal can have a benign explanation. The diagnosis gets stronger when three or more appear together in the same campaign or ad set.
How to audit your ad accounts for bot traffic
Run this checklist in your own Google Ads and Meta accounts. Each step uses data you already have access to.
- Pull the click-performance report. In Google Ads, download the "Click performance" report with GCLID, timestamp, campaign, ad group, and device. In Meta, export the "Ad clicks" breakdown with FBCLID, placement, and time.
- Match clicks to sessions. Join the click IDs to your analytics (GA4, Matomo, or server logs) on the landing-page query parameter. Flag clicks with no matching session or a session duration of 0 seconds.
- Segment by IP and user agent. Group the matched sessions by IP address and user-agent string. Count occurrences. Anything above 20 clicks from the same IP/UA combo in one hour warrants review.
- Check IP reputation. Run the flagged IPs through a free ASN lookup (e.g., ipinfo.io, db-ip.com). Hosting, proxy, or VPN ASNs are a strong bot indicator.
- Review engagement metrics. For the flagged sessions, check scroll depth, mouse-move events, and form interactions. Bots typically show none of these.
- Compare placement performance. In Meta, break down by placement (Facebook Feed, Instagram Stories, Audience Network). A single placement driving 80% of clicks but 0% of qualified leads is a red flag.
- Document the pattern. Screenshot the reports, note the date ranges, campaign names, and the specific signals you found. You'll need this evidence for a refund request.
Technical signals that indicate automated traffic
Beyond the account-level audit, client-side behavioral checks catch bots that slip past IP filters. BotRefund runs 106 independent checks; the most telling ones for ad-click bots are:
- Ghost click detection: Clicks that fire without the natural sequence of human intent — no hover, no focus change, no preceding scroll.
- Honeypot trap interactions: Bots that click hidden or deceptive page elements real users never see.
- Robotic linear mouse movements: Pointer paths that are unnaturally straight or grid-aligned, lacking the micro-tremor of a human hand.
- Superhuman input speed: Form fills or clicks occurring in under 1 millisecond, faster than any person can react.
- Absence of scroll or dwell: Sessions that stay completely static or exit before the page finishes rendering.
- Unnatural session durations: Visits that are too short (<1s), too long (>30min with no activity), or identical across hundreds of sessions.
These signals are collected via a lightweight script on your landing pages. No single check is a verdict; BotRefund cross-checks each signal against browser, network, device, and behavior data before scoring a visit as bot or human.
What to do when you confirm bot activity
Once your audit shows a clear pattern, take these steps in order:
- Pause the affected campaigns or ad sets. Stop the bleed while you prepare evidence.
- Compile the refund packet. Include: click-performance reports, matched analytics sessions, IP/ASN lookups, behavioral screenshots, and a summary table linking each click ID to the bot signals you found.
- Submit an invalid-click dispute. In Google Ads, use the "Invalid clicks contact form" with your packet attached. In Meta, open a "Billing & Payments" support case and select "Invalid traffic / click fraud."
- Add exclusion lists. Block the offending IP ranges, ASNs, and placements at the campaign level.
- Install continuous monitoring. A one-time audit catches today's bots. Ongoing client-side detection catches tomorrow's.
Google and Meta both honor refunds for proven invalid traffic, but they require granular, click-level evidence. Platform-level "invalid click" filters catch only the most obvious bots; the rest slip through unless you bring your own proof.
How BotRefund helps detect and recover from bot clicks
BotRefund automates the audit you just ran manually. The script adds to your landing pages in about one minute and starts a free bot audit immediately.
- Continuous 106-signal detection: Click, trap, pointer, motion, speed, path, engagement, and session behavior checks run on every visit.
- Video proof per bot click: Each flagged session gets a replay showing the exact behavior that triggered the bot score.
- Automatic GCLID/FBCLID logging: Every ad click ID is captured and tied to the behavioral evidence.
- Audit-ready dispute reports: One-click export formats the evidence into the structure Google and Meta support teams expect.
- Refund negotiation: BotRefund's team submits and follows up on disputes, with an 83% approval rate across client claims.
- Historical recovery: Can reclaim Google Ads spend dating back to 2017 if you have the click IDs.
The free audit shows you the bot percentage on your current traffic before you pay anything. If the audit finds bots, you decide whether to activate protection and pursue refunds.
Limitations and when this advice doesn't apply
- Low-volume campaigns: If you get fewer than 500 clicks/month, statistical patterns are noisy. Manual review of each conversion may be more practical.
- Brand-only search campaigns: Bots rarely target exact-brand terms. High CTR with low conversions there usually means landing-page or offer issues, not fraud.
- Aggressive platform filters already on: If you've enabled Google's "Invalid click protection" and Meta's "Traffic quality" controls, the remaining bot percentage is typically under 2%. The audit may not justify the effort.
- No access to landing-page code: You need to add a script tag to run client-side behavioral checks. If you can't modify the page, you're limited to server-log and platform-data analysis.
- Non-Google/Meta channels: The refund process described applies to Google Ads and Meta Ads. TikTok, LinkedIn, Twitter/X, and programmatic DSPs have different dispute workflows.
Key facts
| Metric | Value | Source |
|---|---|---|
| Bot click share of Google/Meta ad budget | Up to 20% | S2 |
| Independent behavioral checks per visit | 106 | S3, S5 |
| Bot detection accuracy (cross-checked) | 99% | S3, S5 |
| Refund approval rate across client claims | 83% | S2 |
| Typical setup time for free audit | About 1 minute | S2 |
| Historical Google Ads recovery window | Back to 2017 | S2 |
| FinTrust case study: ad spend refunded | $140,000 | S6 |
| FinTrust case study: average bot click rate | 14% | S6 |
| FinTrust case study: conversion rate increase | +18% | S6 |
FAQ
How quickly can I see results from the free bot audit?
The script starts collecting data on the first visit after install. Most accounts see a preliminary bot-percentage estimate within a few hours if they have steady traffic. The full audit report with click-level detail is ready after 24–48 hours.
Does BotRefund block bots in real time or just report them?
Detection and reporting come first. The platform suppresses conversion events for flagged bot sessions so Google and Meta AI don't train on them. Real-time blocking at the edge (WAF/CDN) is available on enterprise plans.
What if Google or Meta rejects my refund request?
BotRefund's team handles the appeal. They re-submit with additional behavioral evidence (video replays, signal breakdowns) and escalate to platform policy teams. The 83% approval rate includes successful appeals.
Can I use this on client accounts if I'm an agency?
Yes. The agency dashboard lets you manage multiple client sites, run audits, and generate white-labeled dispute reports. Pricing scales by total managed ad spend.
Will the detection script slow down my landing pages?
The script is ~12 KB gzipped, loads asynchronously, and has no measurable impact on Core Web Vitals. It runs after the page is interactive.
What's the difference between BotRefund and Google's built-in invalid-click filter?
Google's filter catches known data-center IPs and simple crawlers. It does not run client-side behavioral checks (mouse tremor, scrollbar width, iframe context, etc.), so sophisticated bots using residential proxies and headless browsers pass through. BotRefund catches those and provides the evidence Google requires for a refund.
How far back can I recover wasted spend?
For Google Ads, BotRefund can process refunds for clicks dating back to 2017 if you have the GCLID logs. Meta's window is typically 90 days, but exceptions are possible with strong evidence.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.