Seatext library / BotRefund evidence

How to Separate a Single Unusual IP from a Country-Wide Invalid Traffic Pattern

A single suspicious IP usually shows isolated anomalies — one burst of fast form fills, a lone data-center address, or a single impossible-travel event. A country-wide pattern repeats those signals across many IPs, placements,...

Built for advertisers who need clear, refund-ready traffic evidence.

When one IP looks odd — maybe it submitted three leads in ten seconds from a cloud provider — you need a quick way to decide whether it's a lone scraper or the tip of a coordinated botnet hitting your campaigns across an entire region. The difference changes your response: block one address versus pause a placement, request a refund, or rewrite your audience expansion settings.

The practical test is evidence breadth. A single bad actor leaves a narrow trail: one device fingerprint, one user-agent, one session pattern. A systematic invalid-traffic wave leaves the same behavioral fingerprints — superhuman input speed, zero scroll, grid-aligned mouse paths — across dozens of IPs that share only geography or ASN. If the same anomalies appear on multiple placements, creatives, and audience segments at once, you're looking at a pattern, not an outlier.

Why the Distinction Matters

Treating every unresponsive lead as fraud makes you exclude valuable audiences. Treating a coordinated botnet as a few bad apples lets it keep poisoning your pixel and inflating your cost per real lead. The source pack notes that "not every bad lead is a bot, and that matters" — a weak campaign can attract real people who aren't ready to buy, while bot traffic leaves "repeatable technical and behavioral patterns" (S1). Misclassification wastes budget twice: once on the invalid clicks, again on the wrong fix.

Meta campaigns reach people across Facebook, Instagram, and Audience Network at high volume. That reach brings accidental interactions, low-intent traffic, automated browsing, and deliberate fraud. A fake lead might aim to earn an affiliate payout, inflate a publisher's metrics, scrape an offer, or just waste a sales team's time. The investigation must start with a structured audit that compares ad-platform data, website sessions, and CRM outcomes before changing targeting or filing a refund request (S1).

Core Signals: Single IP vs. Systematic Pattern

Single-IP Anomalies

  • One address, one device fingerprint, one user-agent string
  • Burst of conversions in minutes, then silence
  • Data-center or VPN IP with no prior history
  • Superhuman form completion (<1 ms keystrokes) on a single session
  • No scroll, no field corrections, uniform click path

Country-Wide Pattern Indicators

  • Same behavioral signatures across 20+ IPs in the same region
  • Identical timing curves: conversions cluster at same hours daily
  • Placement-level spike: Audience Network or specific third-party apps
  • Creative-agnostic: every ad variant shows the same lead-quality drop
  • CRM outcome collapse: high reported leads, zero calls connected, zero demos booked

BotRefund's client-side detection watches for "ghost click detection," "trap behavior," "pointer behavior," "motion behavior," "speed behavior," "path behavior," "engagement behavior," and "session behavior" — each capturing a different non-human signature (S2). When those signatures appear across many IPs simultaneously, the pattern is systematic.

Diagnostic Sequence: Step-by-Step Investigation

  1. Preserve attribution before changing anything. Keep campaign, ad set, creative, placement, click IDs, and landing-page URLs intact. Any edit breaks the chain you need for evidence.
  2. Pull the raw click and conversion logs. Export from Ads Manager: click ID (fbclid/gclid), timestamp, placement, creative, audience, device, country, IP (if available), and conversion event name.
  3. Join with on-site session data. Match each click ID to your analytics or BotRefund session replay. Look for: time on page, scroll depth, mouse movement, keystroke timing, honeypot triggers, and whether the conversion event fired before any meaningful engagement.
  4. Join with CRM outcomes. Tag each lead: contacted, qualified, demo booked, closed, or dead. Calculate contact rate and qualification rate per placement, creative, audience, and country.
  5. Segment by IP frequency. Count conversions per IP. Flag IPs with >3 conversions in 1 hour or >5 in 24 hours. Note whether flagged IPs share ASN, subnet, or device fingerprint.
  6. Check fingerprint diversity. For each flagged IP, list user-agent, screen resolution, timezone, language, canvas hash, and behavioral vectors (mouse tremor, scroll velocity, click intervals). A single bad actor reuses the same fingerprint; a botnet rotates fingerprints but keeps behavioral constants (zero tremor, grid-aligned paths, <1 ms inputs).
  7. Map placement correlation. Plot lead quality (CRM qualification rate) by placement. If Audience Network shows 2% qualification while Feed shows 35%, the problem is placement-specific, not IP-specific.
  8. Map creative and audience correlation. Same test: does every creative suffer equally? Does the drop persist across lookalike, interest, and broad audiences? Systematic patterns survive creative and audience changes; single IPs don't.
  9. Score the pattern. Assign points: +2 for multi-IP behavioral match, +2 for placement correlation, +1 for creative-agnostic, +1 for audience-agnostic, +2 for CRM outcome collapse. Score ≥6 = country-wide pattern. Score ≤2 = isolated IP. Score 3–5 = investigate further with a 7-day lookback.
  10. Decide action. Isolated IP: add to exclusion list, monitor 48 hours. Pattern: pause worst placement, request invalid-traffic refund with session-level evidence, tighten audience expansion, enable client-side verification on all landing pages.

Key Facts

MetricValueSource
Industry automated traffic share of paid clicks9%–20%S6
BotRefund detection confidence99%S6
Refund claim approval rate83%S2, S6
Typical setup time for BotRefund script~1 minuteS2, S6
Google Ads invalid activity detection signalsRapid clicking, duplicate clicks, known bad IPs, abnormal patternsS5
Meta Audience Network riskHigh CTR, near-instant bounce, publisher bot clicksS3
Client-side vs server-side auditClient-side catches advanced botnets; server-side misses themS4
Click fraud impact on effective CPC~16% higher if 14% clicks invalidS7

Common Mistakes and How to Avoid Them

  • Blocking one IP and declaring victory. Botnets rotate IPs hourly. Use the diagnostic sequence to confirm whether the behavior persists across new addresses.
  • Relying only on server logs. Server-side sees IP, headers, user-agent. It misses mouse tremor, scroll behavior, and keystroke timing — the signals that separate sophisticated bots from humans (S4).
  • Confusing low intent with fraud. A real person who isn't ready to buy still scrolls, hesitates, corrects typos. Bots don't. Check session behavior before labeling a lead invalid.
  • Filing refund claims without session-level evidence. Platforms approve claims when you "contest specific charges with specific evidence" (S6). A spreadsheet of IPs isn't enough; you need click IDs paired with behavioral proof.
  • Ignoring placement-level data. Audience Network has historically shown "high click-through rates and near-instant bounce rates" from publisher bots (S3). If you don't segment by placement, you'll blame the wrong variable.

Limitations: When This Approach Doesn't Apply

  • Low-volume campaigns (<50 conversions/week). Statistical patterns need volume. With few conversions, you can't distinguish noise from signal; treat each anomaly individually and rely on platform auto-credits.
  • No client-side tracking installed. Without browser-level behavioral data, you only have IP and headers — insufficient for the fingerprint-diversity step.
  • Single-placement campaigns. If you run only Feed or only Search, you lose the placement-correlation signal that helps separate systematic from isolated.
  • CRM not connected to click IDs. If you can't tie a lead back to its fbclid/gclid, you can't measure qualification rate per placement or creative.
  • Brand-search or remarketing campaigns. These attract high-intent humans; bot patterns differ. The diagnostic sequence assumes top-of-funnel prospecting where bot incentives are highest.

Terminology

Invalid traffic
Clicks or impressions not from genuine user interest — automated tools, bots, accidental taps, competitor click fraud, impression fraud (S5).
Pixel poisoning
Bots triggering conversion events, teaching Meta's or Google's optimization algorithms to target more bots (S3).
Client-side audit
JavaScript running in the visitor's browser that captures mouse movement, scroll, keystroke timing, canvas fingerprint, and honeypot interactions (S4).
Server-side audit
Analysis of server logs: IP, headers, user-agent, request timing. Misses advanced bots that rotate fingerprints and mimic headers.
Click ID (fbclid, gclid)
Unique parameter appended to landing-page URL by ad platform; ties a click to its campaign, ad set, creative, placement, and audience.
ASN (Autonomous System Number)
Identifies the network operator (ISP, cloud provider, hosting company). Botnets often cluster in hosting ASNs.
Honeypot
Hidden form field or link invisible to humans; any interaction signals a bot.

FAQ

How many IPs make a "country-wide" pattern?

There's no fixed count. Look for behavioral consistency across IPs that share only geography or ASN. Ten IPs showing identical superhuman input speed, zero scroll, and grid-aligned paths at the same hours daily is a pattern. Fifty IPs with random behavior is noise.

Can I use Google's or Meta's automatic invalid-activity credits instead of investigating?

Platform auto-detection catches basic patterns — rapid clicks from one IP, known data-center ranges — but misses advanced botnets that rotate IPs and mimic human timing (S5). The source pack notes Google's detection is "sophisticated but far from perfect." Manual investigation with client-side evidence catches what auto-systems miss and supports refund claims they deny.

What if I don't have a CRM or can't tie leads to click IDs?

You lose the CRM-outcome correlation step. Compensate by weighting on-site behavioral signals more heavily: scroll depth, time on page, honeypot triggers, and mouse tremor. BotRefund's free audit captures these without CRM integration (S2).

Does audience expansion (lookalike, broad) increase invalid traffic risk?

Yes. Expansion broadens reach into inventory with less quality control. The diagnostic sequence tests this: if lead quality drops equally across all audiences, the problem is inventory-wide. If only expanded audiences suffer, tighten expansion settings.

How long should I monitor before deciding it's a pattern?

Run the diagnostic sequence over a 7-day window. Single-day spikes can be a lone scraper or a temporary publisher issue. A pattern persists across days, placements, and creatives.

What evidence do ad platforms require for a refund claim?

Click IDs (fbclid/gclid), timestamps, placement, and behavioral proof per session: mouse paths, keystroke timing, scroll data, honeypot hits. BotRefund packages this into "compliance-grade evidence" and "audit-ready refund dispute reports" (S2, S6).

Can I run this diagnostic without BotRefund?

You can build parts of it: export Ads Manager logs, join with GA4 or server logs, add honeypots to forms. But capturing mouse tremor, sub-millisecond keystrokes, and grid-aligned paths reliably requires a dedicated client-side script. BotRefund's script installs in ~1 minute and provides the behavioral vectors used in steps 3 and 6 (S2, S6).

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more