Seatext library / BotRefund evidence
How to Report Ad Click Fraud to Google Ads and Meta: A Step-by-Step Guide
To report click fraud, log into your Google Ads or Meta Ads Manager, navigate to the invalid traffic or billing dispute section, and submit a detailed report with click IDs, timestamps, and behavioral evidence...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
If you suspect bots are clicking your ads, the fastest path to a refund is filing a formal invalid-traffic report with the platform that billed you. Google Ads and Meta each have a dedicated dispute flow, but both require the same core evidence: click identifiers (GCLIDs for Google, FBCLIDs for Meta), precise timestamps, and behavioral data proving the visitor never acted like a human. Server-side logs — IP addresses, user-agent strings, referrer headers — are a starting point, but platforms routinely reject claims that lack client-side verification.
Below is the complete process for both major platforms, the evidence each one accepts, the common mistakes that get claims denied, and when it makes sense to bring in a specialist service that automates evidence collection and negotiation.
Understanding What Counts as Click Fraud
Click fraud is any paid click that originates from an automated script, a botnet, a click farm, or a competitor deliberately draining your budget. It also includes accidental clicks forced by deceptive UI ("ghost clicks") and traffic from Meta's Audience Network where publishers run bots to inflate their own revenue. The platforms define invalid traffic broadly: any interaction that does not come from a genuine human with purchase intent.
BotRefund's detection engine evaluates 106 browser, network, hardware, and behavior signals together — not in isolation — to classify traffic as human or bot with 99% accuracy. A single signal like a VPN or a mismatched timezone can be misleading; the pattern across all signals is what matters.
Prerequisites Before You File a Report
- Install client-side tracking. You need a script on your landing pages that captures click IDs (GCLID for Google, FBCLID for Meta) and records behavioral fingerprints: mouse tremor, scroll depth, interaction speed, session duration, and whether the visitor triggered hidden honeypot elements.
- Collect at least 7–14 days of data. Platforms look for patterns, not one-off anomalies. A single suspicious session is noise; a cluster of sessions with identical superhuman input speeds (<1 ms), grid-aligned mouse paths, or zero scroll depth is a pattern.
- Segment by campaign and placement. If you run Search, Display, Shopping, and Meta Audience Network campaigns, isolate the suspicious traffic to the specific placement. Meta's Audience Network historically shows high CTR and near-instant bounce rates — a red flag you can cite.
- Calculate the financial impact. Sum the spend on the flagged clicks. BotRefund's aggregated client data shows 14% of clicks are invalid on average, and advertisers who clean their traffic see a 40–60% improvement in true ROAS within 6–8 weeks.
Step-by-Step: Reporting to Google Ads
- Sign in to Google Ads and open the Tools & Settings menu (wrench icon).
- Under Billing, select Invalid clicks & traffic or go directly to the Invalid Clicks Contact Form.
- Choose Request a refund for invalid clicks.
- Enter the Customer ID, Campaign IDs, and the date range of the suspicious activity.
- Paste the GCLIDs (Google Click Identifiers) you captured. If you have hundreds, upload a CSV with columns: GCLID, Campaign ID, Ad Group ID, Timestamp, Click Cost.
- In the Explanation field, describe the behavioral evidence: e.g., "1,240 clicks from Campaign X between Aug 1–14 showed zero scroll depth, session duration <2 seconds, and mouse movement speed <1 ms — consistent with automated scripts."
- Attach any supporting screenshots from your analytics (behavior flow, event timelines) and a summary table of the flagged GCLIDs.
- Submit. Google typically responds within 5–10 business days. If approved, the credit appears in your Billing summary.
Tip: Google allows refund requests for clicks going back several years. BotRefund has recovered Google Ads spend dating back to 2017 for clients who retained the necessary click IDs.
Step-by-Step: Reporting to Meta (Facebook/Instagram)
- Open Meta Ads Manager and select the ad account.
- Go to Billing → Payment History → Dispute a charge (or use the Meta Ad Refund Request Form).
- Select Invalid traffic / click fraud as the reason.
- Provide the FBCLIDs (Facebook Click Identifiers) for the suspicious clicks. Export them from your pixel events or your tracking script.
- Write a concise evidence narrative. Example: "Between Sep 1–15, 3,400 clicks on Campaign Y (Audience Network placements) produced zero AddToCart events, 98% bounce rate, and median session duration of 1.3 seconds. Client-side telemetry shows absent mouse tremor and grid-aligned pointer paths across 87% of sessions."
- Attach a CSV of FBCLIDs with timestamps and costs, plus any behavioral heatmaps or session recordings that show non-human patterns.
- Submit. Meta's manual review team typically replies within 7–14 business days. Approved refunds are credited to your ad account balance.
Note: Meta's Audience Network is a frequent source of invalid traffic. If you have not explicitly opted out, your campaigns may be running on thousands of third-party apps where publishers use bots to generate artificial clicks.
What Evidence Platforms Actually Accept
| Evidence Type | Google Ads | Meta Ads | Weight in Review |
|---|---|---|---|
| Click IDs (GCLID / FBCLID) | Required | Required | High — without these, the claim cannot be matched to billed clicks |
| Client-side behavioral logs (mouse, scroll, timing, honeypot) | Strongly preferred | Strongly preferred | High — proves non-human interaction |
| Server logs (IP, user-agent, referrer) | Accepted as supplement | Accepted as supplement | Low — easily spoofed; insufficient alone |
| Analytics screenshots (GA4, Mixpanel, custom dashboards) | Helpful | Helpful | Medium — shows pattern but not tied to specific click IDs |
| Session recordings / heatmaps | Helpful | Helpful | Medium — visual proof of bot-like behavior |
| Third-party audit report (e.g., BotRefund compliance-ready report) | Accepted | Accepted | High — structured, platform-formatted evidence |
Server-side audits look at IP addresses, request headers, and user-agent data. While this catches basic scraper bots, it struggles to detect advanced botnets that use residential proxies and real device fingerprints. Client-side audits analyze the visitor's browser environment and behavior in real time — this is the evidence platforms trust.
Common Mistakes That Get Claims Rejected
- Submitting only IP blocks. Platforms know fraudsters rotate residential proxies. An IP list without behavioral correlation is routinely denied.
- Missing click IDs. If you didn't capture GCLIDs/FBCLIDs at the moment of the click, you cannot map the fraud to a specific billed event.
- Vague descriptions. "Lots of bad clicks" fails. "2,100 clicks on Campaign Z (Shopping) between Oct 1–10 with zero scroll, <1 ms input speed, and no honeypot interaction" succeeds.
- Including legitimate low-quality traffic. High bounce rate from a poorly targeted audience is not fraud. Mixing the two weakens the claim.
- Waiting too long. Both platforms have lookback windows. File as soon as you have a coherent pattern (7–14 days of data).
- Not opting out of Audience Network (Meta). If you keep running on Audience Network without exclusion, reviewers may view the risk as accepted.
How Long Refunds Take and What to Expect
Google: 5–10 business days for initial response. Complex cases (thousands of clicks, multiple campaigns) can take 3–4 weeks. Approved credits appear in your Billing → Transactions view.
Meta: 7–14 business days for initial response. Manual review by the Traffic Quality team can extend to 30 days for high-volume accounts. Refunds are credited to your ad account balance, not returned to your payment method.
Success rates vary. BotRefund reports an 83% refund approval rate for high-volume advertisers who submit client-side behavioral evidence packaged in compliance-ready reports. Claims backed only by server logs see significantly lower approval.
When to Escalate or Use a Specialist Service
- You manage multiple accounts or clients and need to file at scale.
- Your internal team lacks the engineering resources to deploy and maintain client-side tracking across all landing pages.
- Previous claims were rejected for "insufficient evidence" despite clear patterns.
- You want to recover historical spend (Google allows claims back to 2017 if you have the click IDs).
- You need ongoing protection: real-time blocking of bot traffic, pixel poisoning prevention, and automated evidence collection for future disputes.
A specialist service installs a lightweight script (about one minute, no credit card required) that captures every click ID, runs 106-signal behavioral verification, and auto-generates the formatted reports both platforms expect. This turns a manual, sporadic process into a continuous recovery loop.
Key Facts
| Metric | Value | Source |
|---|---|---|
| Average invalid click rate across advertisers | 14% | S6 |
| Typical ROAS improvement after cleaning traffic | 40–60% within 6–8 weeks | S6 |
| BotRefund refund success rate (high-volume advertisers) | 83% | S2 |
| Google Ads lookback for refund claims | Back to 2017 | S2 |
| Detection signals evaluated per visit | 106 browser, network, hardware, behavior signals | S1 |
| Classification accuracy | 99% | S1 |
| Install time for tracking script | ~1 minute | S2 |
| Primary Meta invalid traffic sources | Audience Network, click farms, residential proxy botnets, profile scrapers | S3, S5 |
Limitations of Platform Reporting
- No guarantee of approval. Each claim is reviewed manually. Even strong evidence can be denied if the reviewer disagrees with the interpretation.
- Refunds are account credits, not cash. Both Google and Meta return money as ad credit. You must spend it on future campaigns.
- Lookback windows are not infinite. Google's practical limit is several years (2017+ with click IDs). Meta's is shorter and less documented.
- Does not stop future fraud. A successful dispute recovers past spend. It does not prevent the same bots from clicking tomorrow.
- Requires ongoing evidence collection. Without client-side tracking on every landing page, you cannot file the next claim.
- Agency/client alignment needed. If an agency manages the account, the client must authorize the dispute or the agency must have billing permissions.
Terminology Quick Reference
- GCLID (Google Click Identifier)
- A unique parameter appended to landing-page URLs when a user clicks a Google ad. Required to map a specific click to a billed event.
- FBCLID (Facebook Click Identifier)
- The Meta equivalent of GCLID, appended when a user clicks a Facebook or Instagram ad.
- Client-side tracking
- JavaScript running in the visitor's browser that captures behavioral signals (mouse, scroll, timing, browser fingerprint) impossible to see from server logs alone.
- Server-side logs
- Web server records: IP, user-agent, referrer, request headers. Useful for correlation but easily spoofed by sophisticated bots.
- Pixel poisoning
- When bot traffic triggers conversion pixels (Purchase, Lead, AddToCart), corrupting the platform's optimization algorithms so they target more bots.
- Honeypot
- A hidden page element (link, button, form field) that real humans never interact with. Bots that click or fill it reveal themselves.
- Audience Network
- Meta's extended placement network of third-party mobile apps and websites. Historically higher invalid-click rates than Facebook/Instagram owned properties.
- Residential proxy botnet
- Malware on consumer devices that routes bot traffic through legitimate home IP addresses, bypassing IP-reputation filters.
- Click farm
- Operations (often rows of real smartphones) where low-cost labor or automated scripts click ads to drain budgets or inflate publisher revenue.
FAQ
Can I get a cash refund instead of ad credit?
No. Both Google Ads and Meta issue refunds as account credits applied to future ad spend. They do not return money to your credit card or bank account.
How far back can I claim refunds for Google Ads?
Google allows claims for clicks going back several years. BotRefund has successfully recovered spend dating back to 2017 when the advertiser retained the GCLIDs and behavioral evidence.
What if I don't have click IDs for past traffic?
You cannot file a claim for clicks you didn't capture. Going forward, install a client-side tracker that auto-captures GCLIDs and FBCLIDs on every landing page visit.
Does opting out of Meta Audience Network eliminate bot traffic?
It removes the largest single source, but click farms, residential proxy botnets, and profile scrapers can still reach your ads on Facebook and Instagram proper. You still need detection and evidence collection.
How much does a specialist service cost?
BotRefund offers a free bot audit and a free tier to start. Paid plans scale with ad spend; the service pays for itself through recovered credits. Exact pricing depends on monthly spend tier (under $10K, $10K–$50K, $50K–$250K, $250K–$1M, $1M–$5M, over $5M).
Will filing a dispute hurt my account standing or quality score?
No. Filing a legitimate invalid-traffic report is a standard advertiser right. It does not affect Quality Score, ad rank, or account health.
Can I automate the whole process?
Yes. A tracking script that captures click IDs, runs behavioral verification, and exports platform-formatted evidence CSVs removes the manual work. BotRefund's script installs in about one minute and generates compliance-ready reports for both Google and Meta.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.