Seatext library / BotRefund evidence
How to Set Up IP Exclusions in Google Ads to Block Bot Traffic
To block known bot sources, go to Settings > IP exclusions in your Google Ads account, add the suspicious IP addresses or CIDR ranges, and save. This works at both account and campaign levels,...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Quick answer: set up IP exclusions in two minutes
Open your Google Ads account, click the tools icon, choose Settings then IP exclusions. Paste the IP addresses or CIDR ranges you want to block, one per line, and click Save. You can do this at the account level (applies to every campaign) or inside a single campaign for tighter control. The hard limit is 500 entries per account, so prioritize the worst offenders first.
Why IP exclusions matter for bot traffic
Google's automated filters catch less than 50% of invalid traffic, leaving the rest classified as sophisticated invalid traffic that requires manual evidence submission. Industry data shows an 11% to 14% average invalid click rate across all Google Ads campaigns, with high-CPC verticals seeing even higher rates. If you spend $50,000 a month, that translates to $5,000–$15,000 lost to bots every month. IP exclusions are a first line of defense — they stop known bad actors from seeing your ads again.
Prerequisites before you start
- Admin or Standard access on the Google Ads account.
- A list of suspicious IPs or CIDR ranges (see how to identify them below).
- Understanding that IP exclusions block ad serving, not clicks that already happened.
Step-by-step: account-level IP exclusions
- Sign in to Google Ads.
- Click the Tools icon (wrench) in the top navigation.
- Under Setup, select IP exclusions.
- Click the blue + button.
- Enter each IP address (e.g., 192.0.2.1) or CIDR range (e.g., 192.0.2.0/24) on its own line.
- Click Save.
Account-level exclusions apply to every campaign automatically. Use this for confirmed botnets, data-center ranges, or VPN exit nodes you see across multiple campaigns.
Step-by-step: campaign-level IP exclusions
- Select the campaign in the left navigation.
- Click Settings > Additional settings > IP exclusions.
- Click the pencil icon, add your IPs or ranges, then Save.
Campaign-level entries count toward the same 500-entry account cap. Use campaign-level exclusions when a specific campaign attracts unique bot traffic — for example, a display campaign hitting a fraudulent publisher network.
When to use account-level vs campaign-level exclusions
Account-level exclusions are best for broad threats like data-center IP ranges or known botnet exit nodes. They apply to all campaigns without extra work. Campaign-level exclusions are better for localized fraud — for instance, one campaign that targets a specific country where a click farm operates. Use campaign-level sparingly because each entry still counts toward the 500 limit. If you have 10 campaigns and block the same IP in each, that uses 10 entries. Instead, use account-level for common threats.
Common mistakes when setting up IP exclusions
- Blocking the wrong IPs: Double-check that the IP is not a shared proxy used by legitimate users. Use server logs to confirm bot behavior first.
- Forgetting to remove old entries: Botnets change IPs. An IP that was bad six months ago may now be a real user. Review your list quarterly.
- Ignoring CIDR consolidation: A single /24 range blocks 256 IPs in one entry. This saves space and is more effective than blocking individual IPs.
- Not combining with other methods: IP exclusions alone cannot stop residential proxy botnets. Pair them with client-side detection tools like BotRefund that capture behavioral evidence.
Understanding the 500-entry limit
Google Ads enforces a hard cap of 500 IP exclusions per account (combined account- and campaign-level). You cannot request an increase. When you hit the limit, you must audit existing entries and remove stale ones before adding new ranges. Consolidate single IPs into CIDR blocks where possible — a /24 block covers 256 addresses in one entry. Prioritize entries that have blocked recent impressions. Use the Google Ads API to automate audits and removals if you have many entries.
How to identify suspicious IPs to exclude
- Google Ads click performance report: segment by IP address (if available via API) or use the Invalid clicks column in campaign reports.
- Google Analytics 4: create an exploration with Session source/medium = google / cpc and Engagement rate < 10% or Average engagement time < 5s. Export the Stream ID or User ID and cross-reference with server logs for IPs.
- Server access logs: look for repeated hits from the same IP with gclid parameters but no subsequent pageviews, form submits, or scroll events.
- Third-party fraud detection tools (e.g., BotRefund, TrafficGuard, Lunio) surface IPs with ghost clicks, trap interactions, or superhuman input speed.
Focus on IPs showing: high click volume, near-zero dwell time, no conversions, and repetitive click patterns. BotRefund's behavioral detection flags robotic linear mouse movements, absence of humanlike mouse tremor, and interactions faster than 1 ms — signals you can correlate with IP addresses in your logs.
Verification: confirm exclusions are working
- Wait 24 hours for propagation.
- Run a Search terms report filtered by the excluded IP ranges (if you have IP-level logging).
- Check the Invalid clicks metric in Google Ads — it should drop for the excluded ranges.
- In GA4, verify that sessions from those IPs no longer appear with google / cpc source.
If clicks persist, the traffic may be rotating through residential proxy botnets that change IPs per request. IP exclusions alone cannot stop that; you need client-side behavioral verification and refund claims.
Limitations of IP exclusions for bot blocking
- Residential proxy botnets rotate through millions of consumer IPs — blocking one IP does nothing.
- Click farms use real mobile devices on real carrier networks; their IPs look like legitimate users.
- No retroactive effect: exclusions prevent future impressions, they don't refund past spend.
- 500-entry cap forces constant curation.
- IPv6 ranges are harder to block precisely; a /64 is often a single household.
For sophisticated invalid traffic (SIVT), you need client-side behavioral evidence — mouse tremor, scroll depth, form interaction timing — to build refund disputes. BotRefund captures GCLIDs with that evidence and negotiates directly with Google for refunds, achieving an 83% success rate for high-volume advertisers.
Combining IP exclusions with other bot defenses
IP exclusions are just one layer. For complete protection, combine them with:
- Client-side behavioral detection: Tools like BotRefund analyze mouse movements, scroll patterns, and timing to catch bots that IP exclusions miss.
- Conversion pixel protection: Prevent bots from triggering conversion events, which poisons your bidding models.
- Automated refund claims: Use behavioral evidence to dispute invalid clicks and recover spend.
- Location targeting: Exclude entire countries or regions instead of thousands of IPs.
This multi-layered approach blocks more bot traffic and helps you recover money from undetectable fraud.
Key facts
| Metric | Value | Source |
|---|---|---|
| Average invalid click rate (all Google Ads campaigns) | 11%–14% | S1 |
| Google automated filters catch rate | <50% of invalid traffic | S1 |
| Invalid click rate range by vertical | 4% (well-protected) to >35% (high-CPC) | S7 |
| Monthly waste at $50k spend | $5,000–$15,000 | S7 |
| Global ad fraud projection 2026 | >$100 billion | S1 |
| BotRefund refund success rate (high-volume) | 83% | S3 |
| Estimated bot share of ad traffic | 20% | S3 |
Terminology
- CIDR notation: compact way to write IP ranges (e.g., 192.0.2.0/24 = 192.0.2.0–192.0.2.255).
- SIVT (Sophisticated Invalid Traffic): bot traffic that mimics human behavior well enough to bypass Google's automated filters.
- GCLID: Google Click Identifier — a unique parameter appended to landing-page URLs for attribution.
- Pixel poisoning: bots triggering conversion pixels, corrupting the machine-learning model that optimizes your bidding.
FAQ
How often should I review and update my IP exclusion list?
Weekly for active campaigns. Botnets rotate IPs daily; a monthly review leaves weeks of wasted spend.
Can I block entire countries with IP exclusions?
Not practically. Country-level CIDR lists run into thousands of entries — you'll hit the 500 limit instantly. Use campaign location targeting instead.
Do IP exclusions stop bots from clicking my ads on the Display Network?
Yes, if the bot's IP is in your exclusion list. But display fraud often comes from compromised apps on residential IPs you can't pre-identify.
What's the difference between IP exclusions and the "Invalid clicks" refund process?
IP exclusions are preventive (stop future impressions). The refund process is reactive — you submit evidence (GCLIDs, timestamps, behavioral logs) for clicks already billed. Google's automated system refunds some; the rest require manual disputes.
Can I automate IP exclusion updates?
Yes, via the Google Ads API or scripts. Tools like TrafficGuard and Lunio offer automated syncing of threat-intel feeds into your exclusion list.
Will IP exclusions hurt my Quality Score?
No. Excluding non-converting traffic can improve CTR and conversion rate, which may help Quality Score.
What should I do after I hit the 500-entry limit?
Audit the list: remove entries older than 90 days with zero recent impressions, consolidate single IPs into CIDR blocks, and shift to client-side detection + refund claims for the rotating traffic you can't block.
How do I know if my IP exclusions are actually saving money?
Compare your invalid click rate before and after adding exclusions. Also monitor your cost per conversion. If it drops, the exclusions are working. Use Google Ads reports to track metrics over time.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.