Seatext library / BotRefund evidence
How to Tell If Your Website Is Under a Bot Attack
Bot attacks show up as sudden traffic spikes, failed login attempts, and increased server load. You can confirm an attack by checking for mismatched browser signals, unnatural mouse movements, and sessions that lack human...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
If your analytics show a sharp traffic jump but conversions stay flat, or your server logs reveal thousands of requests from a single IP range in minutes, you are likely seeing automated traffic. The clearest proof comes from combining traffic patterns with browser‑level behavior: real users move mice in jittery curves, take seconds to fill forms, and trigger conversion pixels after scrolling. Bots often move in straight lines, submit forms in milliseconds, and never scroll.
| Detection Method | Catches Residential Proxies | Behavioral Signals | Real‑Time Evidence | Refund‑Ready | Cost |
|---|---|---|---|---|---|
| Server Logs | No | No | Yes (requests) | No | Free (existing) |
| Google Analytics | No | Limited | Delayed | No | Free |
| Client‑Side Behavioral Scripts | Yes | Yes | Yes | Yes | SaaS fee |
Takeaway: Server logs and analytics catch basic spikes but miss advanced botnets. Client‑side scripts capture the behavioral evidence needed for refunds. Check with the vendor for exact pricing.
Why bot attacks matter
Bots waste your ad budget. Industry estimates show over $100 billion lost to invalid traffic in 2026. Every fake click costs you money. Bots also poison your conversion data. When bots trigger conversion pixels, your ad platform's algorithm learns from bad data. It then optimizes for more bots, not real customers. This cycle increases your cost per acquisition and reduces campaign performance.
BotRefund clients recover an average of 20% of claimed ad spend. The refund success rate for high‑volume advertisers is 83% (source). This shows that detecting and proving bot attacks is worth the effort. Without detection, you pay for traffic that will never convert.
Traffic patterns that signal a bot attack
Start with the metrics you already have. A sudden spike in sessions from a single country, a bounce rate near 100%, and average session durations under five seconds are classic red flags. Look for:
- Traffic spikes that coincide with ad campaign launches or budget increases.
- High click‑through rates paired with near‑zero conversion rates.
- Repeated failed login or checkout attempts from the same IP block.
- Server load spikes that don't match your normal user‑activity calendar.
These patterns appear in server logs, Google Analytics, and your ad platform dashboards. They tell you that something is wrong, but not what is causing it. For example, a sudden jump in sessions from a single country might be a botnet using residential proxies. A high bounce rate with low session duration often means automated scripts are loading pages and leaving immediately.
Check placement‑level data. Meta Audience Network and Google Display placements often show higher invalid‑traffic rates (source). If one placement drives 80% of clicks but zero conversions, that placement is likely targetted by bots.
Behavioral signals that separate humans from automation
Human browsing leaves a trail of micro‑behaviors: tiny mouse tremors, variable scroll speeds, pauses before clicks, and natural form‑completion rhythms. Bots often miss these. BotRefund's detection watches for "robotic linear mouse movements" and the "absence of humanlike mouse tremor" that real users produce (source). It also flags "superhuman input speed (<1ms)" and "grid‑aligned movement patterns" that snap to precise lines instead of natural curves (source).
Engagement gaps are another giveaway. Sessions with "absence of clicks or scrolling" and "unnatural session durations" — too short, too long, or too uniform — rarely belong to real visitors (source).
Key behavioral signals include:
- Pointer behavior: Bots move in straight lines or snap to grid points. Humans move in jittery curves.
- Speed behavior: Bots interact in under 1 millisecond. Humans take at least 100–200 ms.
- Session behavior: Bots often have uniform session lengths (e.g., exactly 30 seconds). Humans vary.
- Form interaction: Bots fill forms instantly without pausing, correcting, or scrolling.
Technical signals from browser and network
Beyond behavior, the browser itself leaks evidence. BotRefund evaluates 106 browser, network, hardware, and behavior signals together before classifying a visit (source). Key technical vectors include:
- Network & geolocation evasion: WebRTC leaks, DNS tunnel leaks, timezone mismatches, latency mismatches, suspicious ports, IP address inconsistencies, and OS/TCP TTL mismatches.
- Browser fingerprint evasion: HTTP User‑Agent mismatches, Accept‑Language mismatches, HTTP protocol mismatches, and DNS routing mismatches.
- Automation & anti‑stealth traps: CDP debugger leaks, native patching, engine mismatches, rebrowser leaks, JS engine mismatches, and automation properties.
No single signal is decisive. The system only decides when the full pattern fits a bot profile, achieving a claimed 99% accuracy (source).
Diagnostic sequence: how to verify an attack
- Pull your ad‑platform click IDs (GCLIDs for Google, FBCLIDs for Meta) for the suspicious period.
- Cross‑reference with server logs — match click IDs to IP, user‑agent, and request timestamps.
- Check behavioral logs for the tell‑tale patterns: linear mouse paths, zero scroll, sub‑millisecond clicks, uniform session lengths.
- Run a client‑side audit script that captures the 106‑signal fingerprint on each visit. This is where server‑side logs fall short; they miss residential proxy botnets and click‑farm devices that use real hardware (source).
- Compare placement‑level performance. Meta Audience Network and Google Display placements often show higher invalid‑traffic rates (source).
- Correlate with CRM outcomes. If leads show "disconnected numbers, invalid email domains, repeated addresses" or "several leads arriving in short bursts" with "no scrolling, no field corrections", the traffic is likely invalid (source).
Common mistakes when diagnosing bot traffic
- Relying on IP blacklists alone. Modern botnets rotate residential proxies, so IP reputation changes daily.
- Trusting user‑agent strings. Bots spoof Chrome, Safari, and mobile browsers routinely.
- Ignoring placement data. A campaign can look healthy overall while one placement drives 80% of the fraud.
- Treating every low‑quality lead as a bot. Real users with low intent still behave like humans — they scroll, hesitate, and make typos.
- Waiting for the ad platform to flag it. Platform filters catch basic invalid traffic; sophisticated fraud often passes their checks and requires your own evidence for a refund.
Limitations of basic analytics
Google Analytics' built‑in bot filter only removes known crawlers from the IAB list. It does not catch click farms, residential proxy networks, or browser‑automation tools that mimic human sessions. Server‑side logs miss client‑side behavior entirely — they cannot see mouse movement, scroll depth, or form‑interaction timing. Without a client‑side script that captures behavioral and fingerprint signals, you are guessing.
Furthermore, basic analytics cannot provide the click ID evidence needed for refunds. Google and Meta require GCLID or FBCLID paired with proof of invalidity. Server logs alone do not link behavioral data to click IDs. Client‑side scripts do.
Key facts
| Fact | Detail | Source |
|---|---|---|
| Detection accuracy claim | 99% when 106 signals are evaluated together | S1 |
| Refund success rate (high‑volume advertisers) | 83% | S2 |
| Average ad spend recovered | 20% across client refund claims | S2 |
| Refund lookback window | Google and Meta spend dating back to 2017 | S2 |
| Behavioral signals monitored | Mouse tremor, linear vs. curved paths, click speed, scroll presence, session duration patterns | S2 |
| Technical signal categories | Network/geolocation evasion, browser fingerprint evasion, automation/anti‑stealth traps | S1 |
| Invalid traffic sources on Meta | Audience Network, profile scrapers, click farms, residential proxy botnets | S3, S4 |
| Investigation workflow steps | Preserve attribution, compare ad/platform/CRM data, check placement‑level spikes, capture client‑side evidence | S6 |
FAQ
How quickly can I confirm a bot attack?
If you have a client‑side detection script installed, you can see behavioral anomalies in real time. Without it, you need at least 24–48 hours of log data to spot patterns.
Do I need to block bots or just report them?
Both. Blocking stops future waste; reporting with behavioral evidence (GCLIDs/FBCLIDs linked to fingerprint data) is what ad platforms require for refunds.
Can Google Analytics alone catch sophisticated bots?
No. GA's bot filter only removes known crawlers. It misses click farms, residential proxies, and browser automation that mimic real users.
What evidence do Google and Meta accept for refunds?
They require click IDs (GCLID/FBCLID) paired with proof of invalidity — behavioral logs showing non‑human patterns, fingerprint mismatches, and placement‑level anomaly reports.
How much ad spend is typically lost to bots?
Industry estimates put invalid traffic at over $100 billion globally in 2026. BotRefund clients recover an average of 20% of claimed spend.
Does bot detection slow down my site?
A lightweight client‑side script adds negligible load. BotRefund's script installs in about one minute and runs asynchronously.
When should I involve an agency or enterprise support?
If you spend over $250,000/month on ads, manage multiple client accounts, or need custom integration with CRM and attribution systems, enterprise‑level support and dedicated audit calls are available.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.