Seatext library / BotRefund evidence
How to Set Up Bot Detection Across Multiple Domains and Subdomains
You set up multi-domain bot detection by deploying a single fingerprinting script across all properties and routing detection results to a central decision endpoint, so that a bot identified on one domain is blocked...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
You set up multi-domain bot detection by deploying a single fingerprinting script across all properties and routing detection results to a central decision endpoint, so that a bot identified on one domain is blocked across all subdomains without re-evaluation. BotRefund supports this approach with 106 independent detection checks that cross-reference browser, network, device, and behavior signals.
Before you begin, confirm that you have administrative access to every domain and subdomain you want to protect, and that you can place a script tag in the header or footer of each property. The process below assumes you are protecting a corporate network where different teams own different subdomains but share one security goal: stopping automated traffic from wasting ad spend and distorting analytics.
Prerequisites before you begin
Gather three things before you start the setup. First, a list of every domain and subdomain that needs protection, including any that are behind a CDN or load balancer. Second, access to the DNS or tag-management system where you will deploy the detection script. Third, a central server or endpoint where all domains can send their detection results for unified decision-making.
One common mistake is to skip the inventory step. If you miss a subdomain, bots can enter through that gap and spread their activity across your network. BotRefund keeps each signal as evidence—not a verdict—and cross-checks it against independent browser, network, device, and behavior data, so a complete inventory helps the AI build a fuller picture.
Step 1: Deploy the fingerprinting script on every domain and subdomain
Add the BotRefund detection script to the header of every domain and subdomain you listed in your inventory. The script runs 106 independent checks, including hardware and GPU fingerprinting, empty font canvas analysis, and suspicious port detection. Each check produces one objective fact about the visit.
Use a tag manager or a shared configuration file to push the same script version to all properties. This ensures that every domain sends data in the same format to your central endpoint. If you use a CDN, place the script in the global header template so new subdomains inherit it automatically.
Step 2: Route all detection results to a central decision endpoint
Configure each domain's script to POST detection results to a single API endpoint that you control. This endpoint collects the signals from every property and builds a unified view of each visitor. When a bot is flagged on one subdomain, the endpoint can apply that verdict to all other domains in your fleet.
The central endpoint also lets you adjust rules in one place instead of updating each domain separately. BotRefund sends each signal into its prediction AI, which weighs the complete pattern across browser, network, device, and behavior evidence to identify a visit as bot or human with 99% accuracy.
Step 3: Share bot verdicts across your domain fleet
Set up a shared verdict cache or database that all domains can query. When the central endpoint flags a visitor as a bot, it writes the verdict and the supporting evidence to this cache. Each domain's script checks the cache before serving content, so a bot caught on one subdomain is blocked on all of them.
This step is what makes the multi-domain setup work. Without shared verdicts, each domain would evaluate visitors independently, and a bot that rotates between subdomains could slip through. The Suspicious Ports check, for example, looks for mismatches that a real browsing session does not normally create, and proxy rotation can make separate network facts disagree. Cross-domain sharing catches these patterns faster.
Step 4: Configure challenge and blocking rules per domain
Not every domain needs the same response to a bot. Define rules that specify whether a flagged visitor gets a challenge (such as a CAPTCHA), a silent block, or a redirect to a honeypot page. You can set different rules for different subdomains based on their sensitivity and traffic volume.
For example, a public-facing marketing subdomain might use a challenge-first approach to avoid blocking legitimate visitors, while a login or checkout subdomain might block immediately. BotRefund's detection covers ghost click detection, honeypot trap interactions, robotic linear mouse movements, superhuman input speed, and grid-aligned movement patterns, giving you fine-grained signals to base these rules on.
Step 5: Verify the setup works across all properties
Run a test from each domain using a known bot simulator or a headless browser. Confirm that the detection script fires, the results reach the central endpoint, and the verdict propagates to all other domains. Check that legitimate traffic from your corporate network is not falsely flagged, since privacy tools, travel, and unusual devices can produce unexpected behavior for genuine people.
BotRefund's setup typically takes about one minute per property. After verification, monitor the dashboard for false positives during the first two weeks and adjust your rules as needed.
Key facts about BotRefund's detection signals
The table below summarizes the detection signals BotRefund uses, drawn from its 106 independent checks.
| Signal category | What it detects | Why it matters for multi-domain setups |
|---|---|---|
| Click behavior | Ghost clicks without natural human intent sequence | Catches bots that click across multiple subdomains |
| Trap behavior | Interactions with hidden or deceptive page elements | Identifies bots that probe different domains for vulnerabilities |
| Pointer behavior | Unnaturally straight pointer paths | Flags automated navigation that spans subdomains |
| Motion behavior | Absence of humanlike mouse tremor | Detects scripted browsing across properties |
| Speed behavior | Superhuman input speed under 1ms | Catches bots that move faster than a person could across domains |
| Path behavior | Grid-aligned movement patterns | Identifies bots that follow precise paths across subdomains |
| Engagement behavior | Absence of clicks or scrolling | Highlights static sessions that waste ad budget |
| Session behavior | Unnatural session durations | Catches bots with uniform visit lengths across properties |
| Network checks | Suspicious ports, proxy rotation, location masking | Detects infrastructure-level evasion across domains |
| Hardware & GPU fingerprinting | Device mismatch between claimed and actual hardware | Spotted VMs and spoofed profiles that cross subdomains |
Common mistakes when scaling bot detection
The biggest mistake is treating each domain as a separate deployment. When you run independent setups, you lose the cross-domain signal that makes bot detection effective. A bot that visits five subdomains in one session looks like five separate visitors if you do not share verdicts.
Another mistake is relying on a single detection signal. A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund's approach cross-checks every signal against independent browser, network, device, and behavior data before reaching a conclusion.
A third mistake is ignoring the ad-spend impact. Bot clicks steal up to 20% of your Google and Meta ad budget. Without multi-domain detection, you may be losing budget on one subdomain while trying to recover it on another.
FAQ
How long does it take to set up bot detection across multiple domains?
BotRefund can be added to a website in about one minute. For a multi-domain deployment, the total setup time depends on how many domains and subdomains you have, but the script deployment itself is fast when you use a tag manager or shared configuration.
What happens if a legitimate visitor is flagged as a bot?
BotRefund keeps each signal as evidence rather than a verdict. The AI model weighs the complete pattern across all signals, and a single anomaly does not trigger a block. You can adjust challenge rules to give flagged visitors a chance to prove they are human before blocking them.
Does BotRefund work with CDNs and load balancers?
Yes. The detection script runs in the visitor's browser, so it works regardless of whether your domains are behind Cloudflare, NetScaler, AWS, or any other CDN or load balancer. The script collects signals client-side and sends them to the central endpoint.
What pricing tiers does BotRefund offer?
Pricing starts under $10,000 per month for smaller deployments and scales up through $10,000–$50,000, $50,000–$250,000, $250,000–$1M, $1M–$5M, and over $5M per month tiers. The right tier depends on your traffic volume and the number of domains you protect.
Can BotRefund recover ad spend lost to bot clicks?
Yes. BotRefund proves bot clicks, negotiates with Google and Meta, and gets your money back. The company recovers ad spend from Google Ads billing disputes dating back to 2017, and 83% of customers successfully get a refund.
How does BotRefund handle corporate networks with unusual traffic patterns?
BotRefund treats unusual network behavior as evidence to cross-check, not as a bot verdict. Corporate networks, VPNs, and privacy tools can produce signals that look suspicious in isolation, but the AI model evaluates the full pattern across all 106 checks before making a decision.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
How BotRefund can help
BotRefund deploys a single fingerprinting script across all your domains and subdomains, routing detection results to a central endpoint so that a bot identified on one property is blocked across the entire fleet. The platform runs 106 independent checks—including hardware fingerprinting, empty font canvas analysis, and suspicious port detection—and cross-references each signal against browser, network, device, and behavior data before reaching a verdict. Setup takes about one minute per property, and the free bot audit lets you validate the detection before committing to a paid tier.