Seatext library / BotRefund evidence
How to Apply an Exclusion List in Meta Ads Manager to Block Known Bots
Open Meta Ads Manager, go to Settings → Library → Exclusion Lists, create a new list with IP addresses, domains, or device identifiers you want to block, then assign that list to the ad...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
To block known bots in Meta Ads Manager, navigate to Settings → Library → Exclusion Lists. Click Create Exclusion List. Add the IP addresses, domains, or device identifiers you have identified as bot sources. Save the list. Then open the relevant ad set, scroll to the Exclusions section, and select your list. The exclusion takes effect immediately for new impressions.
Why exclusion lists matter for bot traffic
Meta campaigns can reach people across Facebook, Instagram, and the Audience Network. The Audience Network is a group of third-party apps and sites. It is often on by default when you run a campaign. Source S3 notes that many publishers on this network use automated bots to click on ads in their apps. The goal is to generate artificial publisher revenue.
Those clicks still bill your account. If they trigger your pixel, they also poison the conversion signals Meta uses to optimize delivery. Source S3 warns that this can make Meta's machine learning optimize for bots instead of real buyers.
Meta divides traffic into valid and invalid traffic, Source S4 explains. Valid traffic is human. Invalid traffic is automated. Exclusion lists let you stop impressions from specific IPs, domains, or device IDs before the auction serves your ad. They are a first-line defense that works alongside placement controls and frequency caps.
What an exclusion list can and cannot do
An exclusion list is a saved set of sources you do not want to reach. You apply it to an ad set or campaign. Meta then avoids showing that ad to those sources.
It can stop known IP addresses, domains, and device identifiers. It is useful when you have clear evidence that a specific source sends bot traffic.
It cannot catch every bot. Source S5 explains that click farms use real mobile hardware. They bypass standard IP-range filters. Residential proxy botnets route clicks through normal consumer IP addresses. They look like real regional traffic. Advanced bots need behavioral detection, not just list matching.
An exclusion list also does not refund past charges. It stops future impressions. To recover money already spent on invalid traffic, you need a separate billing dispute with evidence. Source S5 confirms that Meta offers a manual refund process for advertisers billed for invalid clicks.
Before you build the list: collect the right evidence
Start with a structured audit before you change targeting. Source S1 advises: "Preserve attribution before changing the campaign — keep campaign, ad set, creative, placement, click identifiers." This lets you compare performance after the exclusion.
Look for repeatable technical and behavioral patterns. Source S1 lists these signals:
- Contactability: disconnected numbers, invalid email domains, repeated addresses, or one unusual country code.
- Timing: several leads in short bursts, forms submitted immediately after landing, or conversions at unusual hours.
- Session behavior: no scrolling, no field corrections, uniform click paths, and no meaningful time on the page.
- Campaign patterns: a sharp lead-quality difference by placement, creative, device, or landing page.
- CRM outcome: a high reported lead count but no calls connected, demos booked, or qualified opportunities.
Server-side logs monitor IP addresses, request headers, and user-agent data. Source S4 says this catches basic scraper bots. But it struggles with advanced botnets. Client-side audits analyze the visitor's browser behavior. They can detect superhuman input speed under 1 ms, absence of humanlike mouse tremor, grid-aligned mouse movement, and unnatural session durations. Source S2 describes these as strong bot signals.
Use this evidence to choose which IPs, domains, or device IDs go into your exclusion list. A list built from observed behavior is more accurate than a random blocklist.
Step-by-step: create and assign an exclusion list
- In Meta Ads Manager, click the gear icon (Settings) in the left rail.
- Select Library → Exclusion Lists.
- Click Create Exclusion List.
- Name the list, for example "Known Bot IPs — Q3 2025".
- Choose the entry type: IP address, Domain, or Device ID.
- Paste or upload your entries. Use one entry per line. Keep them within Meta's current list limit.
- Save the list.
- Open the ad set you want to protect.
- In the editing panel, scroll to Exclusions under Targeting.
- Click Add Exclusion List and pick the list you just created.
- Publish the ad set changes.
The exclusion is live for new impressions immediately. Existing clicks already billed are not refunded automatically. If you need a refund, file a dispute with evidence.
What you can exclude: IP, domain, and device ID
The table below shows the three entry types and when they help.
| Entry type | When it helps | Limitation |
|---|---|---|
| IP address | Data-center ranges, known VPN exit nodes, and office networks running scrapers. | Residential proxy botnets rotate through real consumer IPs. Static IP blocks miss them. Source S5 confirms this. |
| Domain | Specific Audience Network apps or sites that show high CTR and zero conversions. | Domain lists only work where Meta exposes the publisher domain. Many in-app placements are opaque. |
| Device ID | Click farms using the same physical phones repeatedly. | Device IDs reset on factory reset. Sophisticated farms rotate hardware. Source S5 says they bypass standard IP-range filters. |
Verify the exclusion is working
- Wait 24–48 hours for fresh delivery data.
- In Ads Manager, open the ad set and go to Breakdown → Placement.
- Check that the excluded domains or IPs no longer appear in the impression or click rows.
- Cross-reference with your analytics. The blocked sources should show zero new sessions.
- If you still see traffic from excluded entries, confirm the list is attached to the correct ad set.
- Check that the entry format matches exactly. Remove extra spaces. Use correct CIDR notation for IP ranges.
Verification is important. A list may look active but not be attached to the right ad set. Always check the targeting summary before you publish.
Common mistakes and limits
- Blocking too broadly. A /16 CIDR block can wipe out legitimate regional traffic. Start with single IPs or /24 ranges.
- Forgetting to re-assign after duplication. Duplicating an ad set does not always carry over exclusion-list assignments. Re-apply manually.
- Relying only on IP lists. Click farms and residential proxies bypass standard IP filters. Source S5 explains both methods.
- No retroactive refund. Exclusions stop future spend. They do not claw back money already spent on blocked sources.
- Ignoring the Audience Network. Source S3 says Meta defaults to opting you into the Audience Network. If you do not audit placements, bot traffic can keep coming from there.
When to combine exclusions with other controls
Exclusion lists work best as part of a layered approach. No single control catches every bot.
- Placement opt-out. Turn off Audience Network entirely if its traffic quality is consistently poor. Source S3 says it is often the source of fake publisher revenue.
- Frequency caps. Limit impressions per user. This reduces the impact of any single bot.
- Client-side behavioral detection. Tools that capture mouse tremor, scroll depth, and click-path entropy give you the evidence to build accurate lists. Source S4 describes client-side audits that detect superhuman input speed and missing humanlike mouse tremor.
- Refund requests. With forensic logs, click IDs, and behavioral traces, you can dispute invalid clicks directly with Meta. Source S5 calls this a real recovery mechanism for advertisers billed for invalid clicks.
- Account-level monitoring. Watch for placement-level spikes and conversion events with no page engagement. Source S1 says these are repeatable technical patterns.
Key facts
| Fact | Detail |
|---|---|
| Primary bot entry points | Audience Network publisher scripts, profile scrapers, click farms, residential proxy botnets |
| Exclusion list location | Settings → Library → Exclusion Lists |
| Supported entry types | IP address, Domain, Device ID |
| Assignment level | Ad set via Exclusions section, or account via Library |
| Effect timing | Immediate for new impressions |
| Retroactive billing impact | None — requires separate dispute with evidence |
FAQ
How many entries can one exclusion list hold?
Meta sets a limit for each list. If you have many entries, create multiple lists and assign them all to the same ad set. Check with Meta for the current limit.
Can I exclude by ASN or country instead of individual IPs?
Not directly in the Exclusion Lists UI. Use geographic targeting exclusions or firewall rules for ASN-level blocks.
Do exclusion lists apply to Instagram and Messenger placements?
Yes. When you assign a list to an ad set, Meta uses it across the surfaces that ad set targets. This includes Facebook, Instagram, and Audience Network.
Will adding an exclusion list reset my ad set's learning phase?
Meta treats many targeting edits as non-reset changes. Watch the learning status in Ads Manager after you publish. If it changes, the edit may have triggered a reset.
How do I get the IPs or domains to put in the list?
Collect them from server logs, analytics, or a client-side detection script. Source S1 recommends looking for fast form completion, zero scroll, and placement-level spikes. Source S4 adds superhuman input speed and missing mouse tremor.
Can I automate list updates via API?
Meta's Marketing API supports custom audiences and exclusions. You can push new bot signatures programmatically. Check the current API documentation for exact endpoints.
What if a legitimate user shares an IP with a bot?
That user will stop seeing your ads. Monitor conversion volume after applying a list. If it drops unexpectedly, narrow the block to a single IP instead of a range.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.