Seatext library / BotRefund evidence
How to Set Up IP Exclusions to Block Bot Clicks in Google Ads and Meta
IP exclusions let you block specific addresses in Google Ads (Settings > IP exclusions, up to 500 entries) and Meta (Business Manager > Block lists). They stop known bad IPs but miss bots on...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
To block bot clicks with IP exclusions, go to Google Ads Settings → IP exclusions and paste the addresses you want to block, then save. In Meta, open Business Manager → Brand Safety → Block Lists → IP Addresses and add the same list. Both platforms cap you at 500 entries per account, so you cannot scale this manually for large botnets.
What IP Exclusions Actually Do
An IP exclusion tells the ad platform not to show your ads to requests coming from listed addresses. It is a static allow/deny list applied at the network edge before the auction. Google Ads applies exclusions at the campaign or account level. Meta applies them at the ad account level through block lists. Neither platform inspects the visitor’s behavior; they only check the source IP against your list.
This works when bots operate from a stable set of data-center IPs. It fails when attackers rotate through residential proxies, mobile gateways, or compromised home routers—all of which appear as legitimate consumer IPs. The 500-entry limit also means you cannot keep up with a botnet that cycles thousands of addresses daily.
Step-by-Step: Google Ads IP Exclusions
- Sign in to Google Ads and click the tools icon (wrench) in the top navigation.
- Under “Setup,” select “IP exclusions.”
- Click the blue plus button to add addresses.
- Enter one IP per line (IPv4 or IPv6). You can paste up to 500 lines.
- Choose “Account level” to apply everywhere or “Campaign level” for a single campaign.
- Click “Save.”
Changes take effect within a few hours. You can verify by checking the “Invalid clicks” report in the next day’s data. Note that Google does not refund spend already charged for excluded IPs; it only prevents future impressions.
Step-by-Step: Meta (Facebook/Instagram) IP Block Lists
- Open Meta Business Manager and select the ad account.
- Go to “Brand Safety” in the left menu, then “Block Lists.”
- Choose “IP Addresses” and click “Add IP Addresses.”
- Paste or type addresses (one per line, up to 500).
- Save the list. It applies to all campaigns in that ad account.
Meta also lets you upload a CSV for bulk updates. Like Google, the block is forward-looking only. Past spend on those IPs is not automatically refunded; you must open a billing dispute with evidence.
The 500-IP Limit and Why It Matters
Both platforms enforce a hard cap of 500 excluded IPs per account. A single click farm can rotate through tens of thousands of residential proxies in a day. Once you hit the limit, you must delete old entries to add new ones, creating a gap that bots exploit immediately. Automation tools from third parties (e.g., Lunio, TrafficGuard, ClickPatrol) sync larger blocklists via API, but they still rely on the same static IP signal.
If you manage multiple client accounts, the limit applies per account, not per manager account. Agencies often hit the ceiling faster because they consolidate bad-IP intelligence across clients.
Why IP Blocking Alone Fails Against Modern Bots
Sophisticated bot traffic no longer comes from identifiable data-center ranges. The source pack identifies three common sources that bypass IP lists:
- Click farms using real smartphones on consumer mobile networks, so each click originates from a legitimate carrier IP.
- Residential proxy botnets that route traffic through malware-infected home devices, blending bot clicks with genuine household traffic.
- Meta Audience Network placements where third-party apps run headless browsers (Puppeteer, Playwright, stealth Chromium) to generate publisher revenue.
Behavioral Detection: A More Complete Approach
BotRefund replaces static IP lists with client-side behavioral telemetry. The script collects 106 signals—mouse tremor, pointer path geometry, input speed, scroll depth, focus events, hardware rendering fingerprints—to distinguish human from automated sessions in real time. When a session fails the behavioral check, BotRefund suppresses the conversion pixel (Google Ads conversion tag, Meta Pixel, CAPI) so the platform’s optimization engine never sees the bot as a converter.
The same behavioral logs become forensic evidence for refund claims. BotRefund packages FBCLIDs (Meta) and GCLIDs (Google) with timestamped signal data into compliance-ready reports that ad-platform reps accept. The homepage states an 83% refund success rate for high-volume advertisers and the ability to recover bot-click refunds from Google Ads spend dating back to 2017.
In the Digitopia case study, behavioral auditing identified a 19% fake lead rate and recovered $18,200 in wasted spend while increasing conversion rate by 22% because the platform’s AI stopped optimizing for bot conversions.
Key Facts
| Metric | Value | Source |
|---|---|---|
| Average bot click rate detected | 19% | S1 |
| Ad spend recovered in case study | $18,200 | S1 |
| Conversion rate increase after suppression | +22% | S1 |
| Refund success rate (high-volume advertisers) | 83% | S2 |
| Behavioral signals analyzed | 106 | S7 |
| Historical refund window (Google Ads) | Back to 2017 | S2 |
| IP exclusion limit (Google Ads & Meta) | 500 per account | SERP |
Limitations of IP Exclusions
- No retroactive refunds. Platforms only stop future impressions; past spend requires a separate dispute with evidence.
- No behavioral insight. You cannot tell if a blocked IP was a bot or a VPN user who might convert.
- Maintenance burden. Lists rot quickly; automated sync helps but still caps at 500 entries.
- False positives. Blocking a corporate NAT or university gateway can cut off legitimate buyers.
- Platform gaps. Google and Meta do not share blocklists; you must maintain both separately.
When to Use IP Exclusions vs. Behavioral Detection
Use IP exclusions for:
- Known internal traffic (office, QA, staging servers).
- One-off abuse from a specific hosting provider you confirmed via server logs.
- Quick mitigation while you deploy a behavioral layer.
Switch to behavioral detection when:
- Invalid clicks persist after exhausting the 500-IP list.
- You see high bounce, zero scroll, sub-second sessions from diverse IPs.
- Conversion quality drops (fake leads, spam forms) despite stable click volume.
- You need evidence for platform refund disputes.
FAQ
Does Google Ads refund money for clicks from excluded IPs?
No. Exclusions prevent future impressions only. You must file an invalid-click refund request with supporting logs (GCLIDs, timestamps, behavioral evidence) to recover past spend.
Can I import a third-party blocklist into Google Ads automatically?
Google Ads API allows programmatic updates, but the 500-entry limit still applies. Tools like Lunio or TrafficGuard manage the rotation for you, swapping oldest entries for newest threats.
How does Meta’s block list differ from Google’s IP exclusions?
Functionally similar: both cap at 500 IPs per ad account and apply forward-only. Meta’s list lives in Brand Safety → Block Lists; Google’s lives in Tools → Setup → IP exclusions. Neither shares data with the other.
What behavioral signals does BotRefund capture that IPs miss?
Mouse tremor (micro-jitter), pointer path curvature, input speed (<1 ms keystrokes), scroll depth, focus/blur events, hardware rendering fingerprints, and session duration patterns—106 signals total.
How long does a BotRefund refund claim take?
Varies by platform and claim size. BotRefund prepares the evidence packet; Google and Meta review on their own timelines. The 83% success rate reflects approved claims across high-volume clients.
Can I run IP exclusions and BotRefund together?
Yes. IP exclusions handle known bad infrastructure; BotRefund catches everything else behaviorally. The two layers are complementary.
What happens if I exceed 500 IPs in Google Ads?
The interface rejects the save. You must delete entries before adding new ones. API-based tools automate this rotation but cannot exceed the platform limit.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.