Seatext library / BotRefund evidence

How to Add BotRefund Protection to Your Website with a Custom Domain

You can add BotRefund protection to a custom domain by creating an account, adding a small JavaScript snippet to your site, and verifying it loads. The process takes about one minute, needs no credit...

Built for advertisers who need clear, refund-ready traffic evidence.

Adding BotRefund protection to a website with a custom domain is a quick, step-by-step process. You sign up, add a small snippet of JavaScript to your site, and verify it's working. The setup takes about one minute and requires no credit card. Custom domains work the same as any other domain because the protection runs in the visitor's browser via the snippet.

Before You Start: Prerequisites

Make sure you have these ready before you begin:

  • A custom domain pointing to your website (for example, yoursite.com).
  • Access to your website's HTML files or a tag manager like Google Tag Manager.
  • A BotRefund account – you can create one for free.
  • Optionally, an active Google Ads or Meta Ads account if you want to start recovering refunds later.

No DNS changes are required for the protection script itself. BotRefund works by adding a script that runs on your pages, regardless of how your domain is configured.

Step-by-Step: Add BotRefund to Your Custom Domain

Step 1: Create a BotRefund Account

Go to BotRefund's website and sign up. You'll need to provide basic details about your website and your ad spend. No credit card is required to start.

Step 2: Get Your Script Snippet

After signing up, you'll find a tracking or protection snippet in your dashboard. This is a small piece of JavaScript that BotRefund provides. Copy it exactly as shown.

Step 3: Add the Snippet to Your Website

Paste the snippet into your website's HTML. The best place is before the closing </head> tag or just before the </body> tag. If you use a CMS like WordPress, you can add it via a plugin, theme editor, or a tag manager. If you have multiple pages, add it to the global template or every page you want to protect.

Step 4: Publish and Clear Cache

Save the change and publish your site. If you use a caching plugin or CDN, clear the cache to ensure the snippet is served to visitors.

Step 5: Verify Installation

Run a quick test by opening your site in a private browser window and checking the BotRefund dashboard. You should see a “protection active” status. Alternatively, use the free bot audit to confirm the script is captured.

How BotRefund Protection Works on Your Site

BotRefund uses a combination of behavioral checks, browser fingerprinting, and AI to distinguish human visitors from automated bots. According to the source, it uses 106 independent checks to build a reliable picture of whether a visit is human or automated. These checks include factors like mouse movement patterns, tab speed, CPU concurrency, and more. The system cross-checks signals and uses AI prediction to avoid false positives, claiming 99% accuracy.

For a custom domain, the script runs exactly as it would on any other domain. It collects signals from each visitor's browser and sends them to BotRefund's servers for analysis. If a bot is detected, BotRefund can block it or collect evidence for refund claims.

Custom Domains vs. Subdomains and Hosted Pages

Custom domains are handled exactly like any other domain. There is no special configuration required. If you run multiple subdomains (for example, blog.yourdomain.com), you'll need to add the snippet to each subdomain separately because scripts don't automatically carry over. The same applies if you use a platform that serves pages from a different domain (like a landing page builder).

No DNS changes are needed for the protection script. BotRefund does not require you to point any records to their servers. The script simply talks to their API over HTTPS.

Common Mistakes to Avoid

  • Placing the snippet in the wrong file. Make sure it's on the live page that visitors actually load, not just in a template that isn't used.
  • Forgetting to clear cache. If your site uses aggressive caching, you might not see the script load until the cache is purged.
  • Blocking the script with a Content Security Policy (CSP). If your site has strict CSP rules, you may need to allow BotRefund's domain in the policy.
  • Using a tag manager incorrectly. If you use Google Tag Manager, ensure the snippet fires on all relevant pages and isn't delayed by triggers.

How to Verify the Protection Is Active

The easiest way is to visit your site in a private browser window and then check your BotRefund dashboard for real-time activity. You can also use the free bot audit BotRefund offers—it will show you if the script is detected and list suspicious sessions. The source pack mentions that a free bot audit is part of the setup process, so you can run it right after adding the snippet.

If you see no data after a few minutes, double-check the placement of the snippet and clear any caches.

Key Facts About BotRefund

FactDetail
Detection methodUses 106 independent checks, including CPU concurrency, tab speed, and behavioral signals.
AccuracyClaims 99% accuracy by cross-checking signals with AI prediction.
Setup timeAbout one minute per the source pack.
Credit card requiredNo credit card required to start.
Refund recoveryCan recover bot-click refunds from Google and Meta ads dating back to 2017.
Average ad budget lostBot clicks steal up to 20% of Google and Meta ad budgets.

Limitations and When BotRefund Might Not Cover You

BotRefund focuses on detecting invalid traffic on Google and Meta ad campaigns. If you run ads on other platforms, it may not provide the same refund recovery support. Additionally, the script cannot block bots that never execute JavaScript—for example, very primitive scrapers that don't render the page. However, those are unlikely to click ads.

If your website has an extremely strict Content Security Policy, you might need to whitelist BotRefund's script source. Also, if you use a service like Cloudflare that already provides bot management, you might have overlapping features—but BotRefund's value is the evidence and refund negotiation.

FAQ

Can I use BotRefund on a custom domain with a subdomain?

Yes. Add the snippet to each subdomain or page that you want to protect. The protection does not automatically extend to subdomains.

Do I need to change my DNS settings?

No. BotRefund does not require DNS changes. The script runs client-side and talks to their servers over HTTPS.

How long does setup actually take?

About one minute, according to the source pack. Adding the snippet to a static HTML file or via a tag manager is fast.

Do I need a credit card?

No. You can start without a credit card and even run a free bot audit.

Will BotRefund work if my site uses a CDN or proxy?

Yes. As long as the script is served to visitors, it will work. You may need to ensure the script is not blocked by your CDN's firewall rules.

What if I have multiple domains?

You can add the same snippet to each domain. BotRefund's dashboard likely lets you manage multiple sites under one account.

Final Check: Confirm Everything Is Set

Once you've added the snippet and verified it, you're done. Your custom domain now has BotRefund protection. Next, consider running the free bot audit to see how much invalid traffic you're already getting and what you might recover.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more