Seatext library / BotRefund evidence

How to Configure Custom Rules for Automated Fraud Prevention

To configure custom rules, use your platform’s rule builder to define specific conditions based on IP reputation, device fingerprint, click velocity, and geographic anomalies. By mapping these signals to your unique traffic patterns, you...

Built for advertisers who need clear, refund-ready traffic evidence.

Defining Your Detection Logic

To configure custom rules, use your platform's rule builder to define conditions on IP reputation, device fingerprint, click velocity, and geo anomalies. Map these signals to your unique traffic patterns to automatically flag or block sessions that deviate from human behavior.

Configuring custom rules is about translating your specific business risks into machine-readable logic. Most automated platforms provide a rule builder interface where you combine signals (the data points) with actions (what the system does when a signal is triggered).

Start by identifying your most common pain points. If you see high bounce rates from specific regions or suspicious click speeds, these are your primary candidates for custom rules.

Why Custom Rules Matter

Default fraud filters are generic. They catch obvious bots but miss sophisticated attacks that mimic human behavior. Custom rules let you tailor detection to your specific traffic patterns, business model, and risk tolerance.

For example, a B2B SaaS company might see legitimate users from enterprise IP ranges. A gaming site might expect rapid clicks. A lead gen form might want to block all traffic from certain countries. Default rules cannot know these nuances.

Custom rules also help you respond faster to new fraud tactics. When you notice a spike in invalid traffic from a particular source, you can create a rule to block it immediately. This reduces wasted ad spend and protects your conversion data.

Without custom rules, you rely on the platform's one-size-fits-all logic. That often means either too many false positives or too many false negatives. Custom rules give you control.

Choosing the Right Signals

Not all signals are equally useful for every business. You need to select the ones that best separate your real users from bots. Here are four core signals to consider:

  • IP reputation: Checks if the IP address is known for fraud, part of a proxy, or from a data center. Low-reputation IPs are often used by bots.
  • Device fingerprint: Identifies the browser, operating system, screen size, and other attributes. Bots often use headless browsers or inconsistent fingerprints.
  • Click velocity: Measures how fast a user clicks or interacts. Humans cannot click faster than a few times per second. Superhuman speed is a red flag.
  • Geo anomalies: Flags traffic from locations that do not match your target audience or that show impossible travel patterns.

You can also use behavioral signals like mouse movement, scroll depth, and session duration. The key is to combine multiple signals. A single signal is rarely enough to confirm fraud.

Start with the signals that directly relate to your known fraud cases. Review your audit logs to see what patterns appear in invalid sessions. Then build rules around those patterns.

Step-by-Step Rule Configuration

  1. Analyze Baseline Traffic: Before creating rules, review your audit logs to understand what "normal" looks like for your site. Identify the average session duration, typical click intervals, and common device types. Also note the IP ranges and geographic regions of your legitimate users.
  2. Select Your Signals: Choose the parameters you want to monitor. Common signals include:
    • IP reputation: Flag sessions from known proxy, VPN, or data center IPs.
    • Device fingerprint: Detect mismatched browser and OS combinations or headless browser indicators.
    • Click velocity: Flag interactions faster than humanly possible (e.g., <1ms).
    • Geo anomalies: Block traffic from countries you do not serve or that show impossible location jumps.
    • Pointer behavior: Detecting unnaturally straight mouse paths or a lack of human-like jitter.
    • Session behavior: Catching visit lengths that are too uniform or static to be human.
  3. Define the Condition: Use the rule builder to set thresholds. For example: If [IP Reputation] is [Low] AND [Click Velocity] is [Greater than 5 clicks per second], then [Flag as Invalid]. Combine signals to reduce false positives.
  4. Test in "Monitor Only" Mode: Always run new rules in a passive state first. This allows you to see how many legitimate users might be caught by the rule before you start blocking traffic or suppressing conversion events.
  5. Deploy and Monitor: Once you are confident the rule targets only fraudulent traffic, move it to active status. Monitor its impact on conversion rates and user complaints.

Limitations of Rule-Based Detection

Rule-based detection is not perfect. Bots evolve quickly. They can change IPs, spoof fingerprints, and slow down to mimic human speed. A rule that works today may fail tomorrow.

Rules also create false positives. A legitimate user on a shared IP or using a VPN might get blocked. This can hurt your conversion rate and brand reputation.

To mitigate these issues, use rules as one layer of a broader fraud prevention strategy. Combine them with machine learning models that adapt to new patterns. Also review and update your rules regularly.

Another limitation is that rules only catch what you explicitly define. They cannot detect novel fraud techniques. For that, you need behavioral analytics and anomaly detection.

Finally, rules require ongoing maintenance. As your traffic mix changes, you may need to adjust thresholds. Set a monthly review schedule to keep your rules effective.

Verification and Maintenance

To verify your rules are working, export your behavioral logs and compare them against your ad platform's billing data. If you see a decrease in invalid traffic reports or a stabilization in your conversion data, your rules are effectively filtering out noise.

Review your rules monthly. Bot networks frequently update their tactics to mimic human behavior. What worked last month may not work now. Look for new patterns in your audit logs and adjust your rules accordingly.

Also track false positive rates. If legitimate users are being blocked, you will see a drop in conversions or an increase in support tickets. Tune your thresholds to reduce these incidents.

Common Pitfalls to Avoid

The most common mistake is setting thresholds that are too aggressive. If you block traffic based on a single signal—like a slightly fast click—you risk losing legitimate customers. Always use a combination of signals to create a "high-confidence" flag.

Avoid "set and forget" strategies. Fraud tactics evolve, so your rules must be updated to remain effective. Schedule regular reviews.

Another pitfall is ignoring the business context. A rule that works for an e-commerce site may not work for a lead gen form. Tailor your rules to your specific funnel and audience.

Finally, do not rely solely on rules. Use them alongside other detection methods like machine learning and manual review. Rules are a starting point, not a complete solution.

Frequently Asked Questions

How do I know if my rules are too strict?

Check your conversion rate and bounce rate after enabling a rule. If you see a sudden, unexplained drop in conversions or an increase in legitimate user complaints, your rule is likely too broad.

Can I use rules to recover money?

Rules help you identify and log invalid traffic. You can then use these logs as evidence to dispute charges with ad platforms like Google or Meta.

How often should I update my custom rules?

Review your traffic patterns at least once a month. If you notice new spikes in bounce rates or unusual traffic sources, it is time to refine your detection logic.

Do I need technical expertise to build rules?

Most modern platforms use a visual rule builder that does not require coding. If you can define a logical "if-this-then-that" statement, you can build effective rules.

What is the difference between a rule and a machine learning model?

A rule is a static condition you define. A machine learning model learns from data and adapts automatically. Rules are transparent and easy to explain, but they require manual updates. Models are more flexible but harder to interpret.

Can custom rules block legitimate users?

Yes, if the thresholds are too aggressive or the signals are not well chosen. Always test in monitor mode first and use multiple signals to reduce false positives.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more