Seatext library / BotRefund evidence

How BotRefund Detects Bots: The 106-Check Framework Explained

BotRefund detects bots by running 106 independent checks across browser, network, device, and behavior signals. Each check contributes one piece of evidence — such as impossible tab speeds, robotic mouse movements, or superhuman input...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund does not rely on a single tell. Instead, it runs 106 independent checks that each produce one objective fact about a visit. These checks span biometric behavior, pointer motion, input speed, engagement patterns, session structure, and trap interactions. No single anomaly triggers a bot verdict. The system cross-references every signal against browser, network, device, and behavior context, then feeds the complete pattern into a prediction model that identifies bots with 99% accuracy.

The 106-Check Framework: How BotRefund Builds a Complete Picture

BotRefund organizes detection into four evidence layers: browser, network, device, and behavior. Each layer contributes multiple independent checks. A check might measure how fast a tab activates, whether mouse movement shows human tremor, or whether a session duration fits a realistic reading pattern. The key principle is corroboration — a single odd signal is kept as evidence, not a verdict. Privacy tools, corporate networks, and unusual devices can all create outliers for real people. By requiring multiple signals to align, the system avoids false positives while catching sophisticated bots that pass basic filters.

The 106 checks are not a flat list. They group into functional families: pointer behavior checks examine cursor paths; motion behavior checks look for micro-jitter; speed behavior checks flag sub-millisecond inputs; path behavior checks detect grid-aligned movement; engagement behavior checks watch for static sessions; session behavior checks measure visit length anomalies; trap behavior checks monitor honeypot and ghost-click interactions. Each family covers a different attack surface. A bot that mimics human mouse curves may still fail speed checks. A bot that nails timing may still trigger a honeypot. The breadth forces automation to be perfect across every dimension simultaneously.

Behavioral & Biometric Signals: What the Browser Reveals

The Impossible Tab Speed check illustrates how behavioral detection works. A real visitor produces imperfect, varied behavior: pauses, hesitation, natural movement shaped by reading and decision-making. Scripts can send clicks and scrolls, but they struggle to reproduce the varied timing and hesitation of real people. This check looks for a mismatch that a real browsing session does not normally create. It is one of 106 such checks. Others examine whether form completion happens faster than humanly possible, whether scrolling follows a natural rhythm, or whether focus events match a person tabbing through fields.

Biometric signals go beyond simple timing. The browser exposes subtle cues: how a user hesitates before a click, how scroll velocity changes when reading versus skimming, whether keystroke intervals show natural variation. Automation frameworks often produce uniform intervals or burst patterns that do not match human motor variability. BotRefund captures these micro-patterns as independent facts. A single micro-pattern proves nothing. But when hesitation patterns, scroll rhythms, and focus sequences all deviate together, the combined weight becomes significant.

Pointer & Motion Analysis: Catching Robotic Movement

Human mouse movement contains tiny imperfections — micro-jitter, slight curves, hesitation before clicks. BotRefund tracks several pointer signals. Robotic linear mouse movements flag unnaturally straight paths that rarely appear in real sessions. Grid-aligned movement patterns detect movement that snaps to precise lines or blocks instead of natural curves. Absence of humanlike mouse tremor looks for the missing micro-jitter typical of human motor control. Together, these signals distinguish a person guiding a cursor from a script injecting coordinate events.

Motion behavior checks add a temporal dimension. Human cursor paths show acceleration and deceleration curves that follow biomechanical constraints. Automated movement often moves at constant velocity or jumps between coordinates without intermediate frames. The system also watches for "teleportation" — cursor position changes that skip the intermediate pixels a physical mouse must traverse. These motion anomalies are recorded as independent checks. They do not block the visitor. They enter the evidence pool for cross-checking.

Speed & Timing Anomalies: Superhuman Input Detection

Speed behavior checks identify interactions that happen faster than a person could realistically perform. Superhuman input speed under 1 millisecond is a clear indicator of automation. VPN detection adds network context — residential proxy botnets often route traffic through consumer IPs to hide. The system also watches for unnatural session durations: visits that are too short, too long, or too uniform to be human. These timing signals work together; a fast click might be a power user, but a fast click combined with zero scroll, linear mouse path, and a proxy IP tells a different story.

Timing anomalies extend beyond raw speed. The system measures intervals between events: time to first scroll, time between field focuses, pause duration before form submission. Humans show log-normal distributions with heavy tails. Bots often show tight clusters or deterministic sequences. The checks capture these statistical deviations. Each deviation is one fact. The cross-checking layer then asks whether the same visit also shows pointer anomalies, engagement gaps, or network red flags.

Engagement & Session Patterns: Identifying Non-Human Journeys

Engagement behavior checks highlight sessions that stay too static to match a real browsing journey. Absence of clicks or scrolling, no field corrections, uniform click paths, and no meaningful time on the offer page all suggest automation. Session behavior checks catch visit lengths that don't fit human patterns — instant bounces, marathon sessions with no idle time, or identical durations across many visits. These patterns matter because they poison conversion pixels: when bots trigger conversion events, ad platforms optimize toward more bot traffic.

Pixel poisoning is a compounding problem. A single bot conversion skews the platform's model. The model then bids more aggressively for similar traffic, attracting more bots. BotRefund's real-time filtering prevents invalid sessions from firing conversion pixels in the first place. This protects the bidding algorithm's training data. The engagement checks also feed refund evidence: a session with zero scroll, zero hover, and a conversion event is a documented anomaly that platforms accept as invalid activity.

Trap & Honeypot Techniques: Catching Automated Scripts

Honeypot trap interactions watch for bots that respond to hidden or intentionally deceptive page elements. Real users never see these elements, so any interaction is a strong automation signal. Ghost click detection catches click activity that happens without the natural sequence of human intent — clicks that appear without preceding hover, focus, or scroll context. These traps are passive; they do not affect the user experience but provide high-confidence evidence when triggered.

Trap behavior checks are designed to be invisible to humans. Elements may be positioned off-screen, hidden via CSS, or rendered transparent. Automation scripts that scrape the DOM or simulate clicks often interact with these elements because they do not render the page visually. The system also deploys behavioral traps: forms with fields that humans skip but bots fill, links that humans never click but crawlers follow. Each trap interaction is recorded as an independent check. Because traps produce near-zero false positives, they carry high weight in the AI model.

Cross-Checking & AI Prediction: From Signals to Verdict

Each of the 106 checks adds one independent fact. The system then tests whether other signals support the same story — this is the cross-checked context layer. Browser fingerprint, network reputation, device characteristics, and behavior patterns must align. Finally, the AI prediction model weighs the complete pattern instead of trusting any raw rule. This three-step process — independent evidence, cross-checked context, AI prediction — is how BotRefund reaches 99% accuracy. The model evaluates how all signals fit together, identifying a visit as bot or human based on the full picture.

The cross-checking layer resolves conflicts. A visitor using a privacy browser may show fingerprint anomalies but normal behavior. A corporate proxy may show network anomalies but human motion. The model learns which combinations indicate automation versus legitimate edge cases. This is why single-rule blockers fail: they treat every anomaly as a verdict. BotRefund treats every anomaly as a data point. The AI model is trained on labeled outcomes from refund disputes — cases where Google and Meta confirmed invalid clicks. This ground truth lets the model calibrate weights against real platform decisions.

Why Detection Methodology Matters for Ad Budgets

Bot clicks steal up to 20% of Google and Meta ad budgets. When bots click ads, advertisers pay for traffic that cannot convert. Worse, when bots trigger conversion pixels, they poison the platform's optimization algorithms. Smart Bidding and Meta's delivery system then learn to target more bot-like users. This creates a feedback loop: more bot traffic, higher costs, lower return on ad spend. BotRefund stops the loop at the source by preventing invalid sessions from firing conversion pixels in real time.

The financial impact compounds. A campaign with 20% bot traffic does not just waste 20% of spend. The poisoned pixel data degrades targeting for the remaining 80%. Recovery is possible but requires evidence. BotRefund captures the Google Click ID (GCLID) or Facebook Click ID (FBCLID) linked to behavioral proof, generates audit-ready refund reports, and helps negotiate disputes with Google and Meta. High-volume advertisers see an 83% refund success rate. Refunds can reach back to Google Ads spend from 2017.

Client-Side vs Server-Side Detection: Trade-offs

Server-side audits look at server log files. They monitor IP addresses, request headers, and user-agent data. While this catches basic scraper bots, it struggles to detect advanced botnets that use residential proxies and real browser engines. Client-side audits analyze the visitor's browser environment directly. They see mouse movement, scroll behavior, focus events, and timing that server logs never capture. BotRefund runs client-side in the browser. This gives it visibility into behavioral signals that server-side tools miss.

The trade-off is coverage. Client-side detection requires JavaScript execution. Traffic that never runs JavaScript — API calls, server-to-server integrations, non-browser clients — is invisible to BotRefund. Advertisers with significant non-browser traffic need complementary server-side analysis. BotRefund's detection also cannot analyze CDN edge data or historical server logs. The 99% accuracy figure applies to the combined model across all signals for browser-executed traffic. Individual checks have higher false-positive rates by design; the cross-checking layer resolves them.

Key Facts

FactDetail
Total independent checks106
Detection layersBrowser, network, device, behavior
Accuracy claim99% via AI prediction model
Core principleCorroboration, not single rules
Refund success rate (high-volume advertisers)83%
Ad budget waste from botsUp to 20%
Refund lookback windowGoogle Ads spend back to 2017
Installation timeAbout one minute, no credit card
Conversion pixel protectionReal-time filtering prevents pixel poisoning
Evidence captureGCLID and FBCLID linked to behavioral proof

Limitations & When This Advice Doesn't Apply

BotRefund's detection runs client-side in the browser. It cannot analyze server logs, CDN edge data, or traffic that never executes JavaScript. Advertisers whose traffic comes primarily from API calls, server-to-server integrations, or non-browser clients will need complementary server-side analysis. The 99% accuracy figure applies to the combined model across all signals; individual checks have higher false-positive rates by design. Privacy tools, unusual hardware, and corporate proxies can create outliers that require the cross-checking layer to resolve. This article covers detection methodology only — refund negotiation, pixel protection, and platform-specific dispute processes are separate capabilities.

Detection effectiveness also depends on traffic volume. The AI model benefits from large sample sizes to calibrate patterns. Very low-traffic sites may see less stable predictions. The system is designed for paid traffic campaigns where click volume justifies the analysis. Organic traffic, direct navigation, and email clicks are not the primary focus. Advertisers should also understand that refund recovery depends on platform policies. Google and Meta have final authority on credit approvals. BotRefund provides the evidence; the platforms decide.

FAQ

How many checks does BotRefund run per visit?

106 independent checks across browser, network, device, and behavior layers.

Does a single failed check mean the visitor is a bot?

No. Each check contributes one piece of evidence. The system cross-references signals and uses an AI model to weigh the complete pattern before reaching a verdict.

What makes the Impossible Tab Speed check different from basic bot filters?

It measures a specific behavioral mismatch — tab activation timing that scripts struggle to replicate — rather than relying on IP reputation or user-agent strings.

Can sophisticated bots that mimic human mouse movement evade detection?

They must simultaneously fool pointer motion, speed timing, engagement patterns, trap interactions, and network/device checks. The cross-checking layer makes this extremely difficult.

How does BotRefund handle false positives from privacy tools or corporate networks?

Outliers from legitimate sources are kept as evidence, not verdicts. The cross-checking layer tests whether other signals support the same conclusion before the AI model decides.

What happens after a bot is detected?

BotRefund captures the Google Click ID (GCLID) or Facebook Click ID (FBCLID) linked to behavioral proof, generates audit-ready refund reports, and helps negotiate disputes with Google and Meta.

Is the detection real-time or post-session?

Detection happens during the session. Real-time filtering prevents invalid sessions from triggering conversion pixels and poisoning bidding algorithms.

Does BotRefund work on Meta Audience Network traffic?

Yes. The detection runs on the landing page regardless of traffic source. Audience Network placements often show high bot rates; the same behavioral checks apply.

Can I use BotRefund alongside other click fraud tools?

Yes. BotRefund focuses on behavioral evidence and refund recovery. It complements IP-based blockers and server-side filters. Multiple layers reduce overall risk.

What ad platforms does the refund evidence support?

Google Ads and Meta Ads (Facebook and Instagram). The system captures GCLIDs for Google and FBCLIDs for Meta, formatted for each platform's dispute process.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more