Seatext library / BotRefund evidence
How to Spot Bot Traffic Before Deciding a Lead Is Bad
Spot bot traffic by checking behavioral signals (click speed, mouse paths, session length, hidden-field traps) and contact signals (invalid emails, disconnected numbers, duplicate details) before you label a lead as bad. Use a structured...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Before you mark a lead as bad, run a short bot-detection sequence. Look at how the form was filled (speed, mouse path, hidden-field traps), check whether the contact details actually work, and compare the session against your normal baseline. A single red flag is not enough; a pattern of signals is what separates a bot from a real person who simply is not ready to buy.
This guide walks through that sequence step by step, then covers the limits of each signal, common mistakes, and what to do when the evidence is mixed.
Why bot detection matters before lead scoring
Marking a real person as a bot wastes a sales conversation. Marking a bot as a real person poisons your CRM, inflates your cost per lead, and trains your ad-platform algorithm to optimize for non-human traffic. The cost of guessing wrong goes both ways, which is why a structured check beats gut instinct.
Industry audits place automated traffic somewhere between 9% and 20% of paid clicks, but that range is context, not a rule for your account. Your own baseline matters more than any benchmark.
The diagnostic sequence: 5 checks before you label a lead bad
Run these checks in order. Stop and flag the lead as a likely bot when two or more signals line up.
1. Preserve the evidence first
Before you change anything in your CRM or ad account, capture the click identifier (GCLID, Meta click ID), campaign context, timestamp, landing-page URL, and the form fields submitted. Once you pause a campaign or delete a record, that evidence is gone, and you cannot file a refund or prove a pattern later.
2. Audit the session behavior
Look at how the visitor interacted with the page, not just that they arrived. Bot sessions tend to share a recognizable shape:
- Form submitted within seconds of the page loading, with no scrolling or field corrections.
- Mouse or pointer movement that is unnaturally straight, snaps to grid lines, or shows no humanlike tremor.
- Click speed faster than a person could realistically perform (under 1 ms between events).
- Session duration that is too short, too long, or too uniform across many visits.
- No meaningful engagement with the offer page before the form fires.
One short session is normal. A cluster of sessions with the same shape is a signal.
3. Check the contact details
Bots often submit contact data that looks real but fails basic checks:
- Email on a disposable or role-based domain, or a typo of a major provider.
- Phone number that is disconnected, wrong length, or concentrated in one unusual country code.
- Name and address combinations that repeat across many submissions.
- Form fields filled with copied strings, gibberish, or identical structures across leads.
Run an email deliverability check and a phone-connect test before you score the lead.
4. Look at timing and clustering
Bots tend to arrive in bursts. Watch for several leads landing in the same minute, forms submitted immediately after the click with no reading time, or conversions concentrated at unusual hours for your audience. A sudden spike from one placement, creative, or geography is more useful than a site-wide average.
5. Compare against your own baseline
Before you call traffic fraudulent, know what normal looks like for your account: landing-page sessions per click, contactable leads, qualified opportunities, and revenue by campaign. A lead that falls outside that baseline by a wide margin deserves a closer look. A lead that sits inside it, even if it does not convert, is probably a real person.
Key signals at a glance
| Signal category | What to check | Bot pattern | Human pattern |
|---|---|---|---|
| Form speed | Time from page load to submit | Under 3 seconds, no corrections | Reads, scrolls, corrects typos |
| Mouse path | Pointer movement shape | Straight lines, grid snaps, no tremor | Curves, jitter, pauses |
| Click speed | Time between events | Under 1 ms between actions | Natural reaction time |
| Session length | Total time on page | Too short, too long, or uniform | Varies by intent |
| Hidden fields | Honeypot or trap inputs | Bot fills the hidden field | Human leaves it blank |
| Deliverability and domain | Disposable, role-based, typo | Real domain, valid format | |
| Phone | Connect test | Disconnected, wrong length | Connects, reaches a person |
| Timing | Arrival clustering | Bursts, off-hours spikes | Spread across business hours |
| Placement | Quality by ad placement | One placement far worse | Consistent across placements |
Common mistakes when judging a lead
Three errors come up again and again:
- Treating every unresponsive lead as a bot. Real people get busy, change jobs, and ignore emails. Use contactability and behavior, not silence alone.
- Trusting a single signal. A fast form fill can be a returning visitor. A disconnected number can be a typo. Look for patterns, not one-offs.
- Deleting evidence too early. Once you remove the record, you lose the ability to file a refund or prove a campaign-level pattern.
What to do when the evidence is mixed
Not every lead will be clearly human or clearly bot. When signals conflict, hold the lead in a review queue rather than scoring it as bad. Add a qualification step (a confirmation email, a short call, a booking link) and let the response decide. A lead that confirms interest is human regardless of how the form looked. A lead that never responds after a real outreach attempt is probably low-intent, not necessarily a bot.
Limitations of bot detection
No single check catches every bot. Server-side filters (IP, user-agent, request headers) catch basic scrapers but miss advanced botnets that rotate identities. Client-side behavioral checks catch more, but they require a script on your site and can miss bots that mimic human movement well. Honeypot fields catch lazy bots but not sophisticated ones. Treat detection as a layered system, not a single tool.
Detection also cannot tell you intent. A real person who fills the form quickly because they already know your offer is not a bot. A bot that lingers on the page for 30 seconds is still a bot. Use behavior to flag, then use contact verification and sales outcome to confirm.
How this fits into a wider lead-quality audit
Bot detection is one layer of a four-layer audit: platform delivery (clicks vs. sessions vs. spend), landing-page evidence (engagement before the form), lead verification (contact works, details are real), and sales outcome (dispositions from your team). Bot signals usually show up in layers two and three. A lead that passes all four is almost certainly human, even if it never buys.
Key facts
| Fact | Detail |
|---|---|
| Industry context | Automated traffic is estimated at 9% to 20% of paid clicks across audits. |
| Bot session length | Bot sessions are typically under 3 seconds with no page interaction. |
| Click speed threshold | Interactions under 1 ms between events are faster than a person can perform. |
| Detection layers | Server-side (IP, headers) catches basic bots; client-side (mouse, scroll, timing) catches more. |
| Evidence to preserve | Click ID, campaign context, timestamp, URL parameters, CRM record, verification result. |
| Baseline first | Calculate your own normal rates before judging any lead as fraudulent. |
Frequently asked questions
What is the fastest single check for bot traffic?
Form completion time combined with a hidden honeypot field. A submission under 3 seconds that also fills the hidden field is almost certainly automated. Use it as a first filter, then verify with contact checks.
Can a real person look like a bot?
Yes. Returning visitors, mobile auto-fill, and people in a hurry can all submit forms quickly with little scrolling. That is why a single fast submission is not enough; look for clusters of similar sessions and confirm with contact verification.
How many signals do I need before marking a lead as a bot?
Two or more independent signals. A fast form fill alone is weak. A fast form fill plus an invalid email plus a burst of similar submissions is strong. The more signals line up, the safer the call.
Do honeypot fields still work?
Yes, against basic bots. Sophisticated bots can read CSS and skip hidden fields, so honeypots are a layer, not a complete solution. Pair them with behavioral checks and contact verification.
Should I block bots at the ad platform or on my site?
Both, if possible. Ad-platform filters miss advanced bots, which is why client-side detection matters. Blocking on your site protects your CRM and conversion data; blocking at the platform protects your budget and targeting signals.
What should I do with a lead I am unsure about?
Hold it in a review queue and add a confirmation step. A short confirmation email or booking link separates real people from bots without losing the lead entirely.
How does this connect to ad refunds?
Bot detection produces the evidence (click IDs, session recordings, behavioral logs) that ad platforms require for invalid-traffic claims. Without that evidence, refund requests are usually denied.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.