Seatext library / BotRefund evidence

How BotRefund Uses Browser, Network, Device, and Behavior Evidence to Detect Bots

BotRefund runs 106 independent checks across browser, network, device, and behavior signals, then feeds every signal into an AI model that weighs the full pattern instead of relying on any single rule. This cross-checked,...

Built for advertisers who need clear, refund-ready traffic evidence.

How the Evidence Layers Work Together

BotRefund does not decide "bot" or "human" from one tell. Each visit produces dozens of measurable signals — how the browser renders, where the IP originates, what the device hardware reports, and how the pointer moves. The platform treats every signal as a piece of evidence, not a verdict. An AI prediction model then evaluates the complete pattern across all four evidence categories and assigns a probability. Only when multiple independent signals tell the same story does the system flag the visit as invalid. This design keeps false positives low even when privacy tools, corporate networks, or unusual devices create anomalies for real people.

Browser Evidence: Fingerprinting and Automation Artifacts

The browser layer captures attributes that scripts struggle to forge consistently. BotRefund checks for mismatches between the declared user-agent and actual rendering behavior, canvas and WebGL fingerprints, font enumeration, and the presence of automation markers such as navigator.webdriver. One documented check, "Impossible Tab Speed," measures whether tab-switching and focus events occur faster than a human can physically perform them. The source notes that "scripts can send clicks and scrolls, but they struggle to reproduce the varied timing, movement, and hesitation of real people" (S1). Because privacy extensions and hardened browsers can alter these same attributes, the browser signal is kept as evidence and cross-referenced rather than acted on alone.

Network Evidence: IP Reputation, VPN, and Proxy Detection

Network signals start with IP reputation: data-center ranges, known VPN exit nodes, and previously flagged proxy pools. BotRefund also runs a dedicated "VPN Detection" check (S2) that looks for protocol-level inconsistencies and latency patterns typical of tunnelled traffic. Residential proxy botnets — malware on consumer devices that routes clicks through legitimate home IPs — are a known blind spot for pure IP-blocking tools (S5). By combining IP reputation with behavioral timing and device signals, the platform can still flag sessions that originate from clean residential addresses but behave like automation.

Device Evidence: Hardware Signals and Biometric Interactions

Device evidence covers hardware concurrency, battery status, touch support, screen resolution versus reported viewport, and sensor availability. Biometric and behavioral interaction checks (S1) capture the micro-variations that come from a physical input device: pointer tremor, click pressure curves on capable hardware, and the natural hesitation before a deliberate action. The source describes this as "imperfect, varied behavior: pauses, hesitation, natural movement, and interactions shaped by reading and decision-making" (S1). Automated browsers often produce either perfectly smooth paths or no movement at all, both of which deviate from the human baseline.

Behavior Evidence: Timing, Movement, and Engagement Patterns

Behavioral checks are the largest group. They include:

  • Pointer behavior: robotic linear movements, grid-aligned snapping, and absence of humanlike tremor (S2).
  • Speed behavior: superhuman input speed under 1 ms, impossible tab transitions, and form completions faster than reading allows (S1, S2).
  • Path behavior: movement that snaps to precise lines or blocks instead of natural curves (S2).
  • Engagement behavior: sessions with no scrolling, no field corrections, and no meaningful time on the offer page (S2, S3).
  • Session behavior: visit lengths that are too short, too long, or too uniform to be human (S2).
  • Trap and honeypot interactions: clicks on hidden or deceptive page elements that real users never see (S2).

Meta-focused guides add campaign-level patterns: bursts of leads in short windows, immediate form submissions after landing, and sharp quality differences by placement, creative, or device (S3).

The Cross-Checking Process: From Signal to Verdict

  1. Collect independent signals. Each of the 106 checks runs in the browser during the session and reports a single objective fact (S1: "This signal adds one objective fact about the visit").
  2. Cross-check context. The platform tests whether other signals support the same story (S1: "BotRefund tests whether other signals support the same story"). A fast form fill alone is weak; fast fill + linear mouse + data-center IP + no scroll is strong.
  3. AI prediction. The model weighs the complete pattern across browser, network, device, and behavior evidence (S1: "Our model weighs the complete pattern instead of trusting a raw rule").
  4. Produce a verdict with evidence. The output is a bot/human classification plus the linked signals — GCLIDs for Google, FBCLIDs for Meta — formatted into audit-ready refund reports (S2, S4).
  5. Real-time pixel protection. Invalid sessions are blocked from firing conversion pixels so Smart Bidding does not optimize toward bot traffic (S4).

Key Facts

CategoryDetailSource
Independent checks106 signals across browser, network, device, behaviorS1
Accuracy claim99% bot vs. human classification via AI pattern weighingS1
Refund success rate83% for high-volume advertisersS2
Evidence capturedGCLIDs (Google), FBCLIDs (Meta) linked to behavioral proofS2, S4
Real-time filteringBlocks invalid sessions from triggering conversion pixelsS4
Supported platformsGoogle Ads, Meta Ads (Facebook, Instagram, Audience Network)S2, S5, S6
Historical reachGoogle Ads refunds back to 2017S2
Detection scopeClick farms, residential proxy botnets, automation frameworks, scraper botsS5, S6

Limitations and When This Approach Doesn't Apply

  • Low-volume campaigns. The 83% refund success rate is reported for high-volume advertisers; smaller spenders may not meet platform thresholds for manual review.
  • Sophisticated human fraud. Click farms using real people on real devices can mimic human behavior closely enough to pass behavioral checks; the system targets automation, not low-intent human labor.
  • Privacy-hardened browsers. Extensions that randomize fingerprints or block sensors can increase noise; cross-checking mitigates but does not eliminate this.
  • First-party fraud. Invalid activity generated by the advertiser's own scripts or partners is outside the refund scope of Google and Meta policies.
  • Attribution windows. Google refunds typically cover the last 60 days; Meta's manual dispute process has its own look-back limits.

Terminology Quick Reference

  • GCLID / FBCLID: Click identifiers Google and Meta attach to ad clicks; required to tie a specific click to a refund claim.
  • Pixel poisoning: Bots triggering conversion events, causing bidding algorithms to optimize for non-human traffic.
  • Residential proxy botnet: Malware on consumer devices that routes automated clicks through legitimate home IP addresses.
  • Audience Network: Meta's third-party app and site placement network, historically high in bot click rates.
  • Honeypot trap: Hidden page element that only bots interact with, providing a clean automation signal.

FAQ

How many signals does BotRefund actually evaluate per visit?

106 independent checks across the four evidence categories (S1). Each check contributes one objective fact; the AI model weighs the full set.

Does a single anomaly like fast typing automatically flag a visit as a bot?

No. The source explicitly states "A single anomaly is not a bot verdict" and that privacy tools, travel, corporate networks, and unusual devices can create unexpected behavior for genuine people (S1). Signals are cross-checked before a verdict.

Can BotRefund detect bots that use residential proxies on real devices?

Yes. Because detection relies on behavioral and device evidence — not just IP reputation — sessions from clean residential IPs are still flagged when pointer movement, timing, and engagement patterns deviate from human baselines (S5, S2).

What evidence do I need to submit a refund claim to Google or Meta?

Google requires GCLIDs linked to behavioral proof of invalidity; Meta requires FBCLIDs and a compliant dispute package. BotRefund auto-captures these IDs and generates audit-ready reports formatted for each platform's review process (S2, S4).

How does real-time filtering protect my bidding strategy?

Invalid sessions are blocked from firing your conversion pixel during the visit. This prevents Smart Bidding from treating bot conversions as success signals and expanding targeting toward similar traffic (S4).

Is there a minimum ad spend to use BotRefund?

The pricing tiers shown start at under $10,000/mo and scale through enterprise bands over $5M/mo (S2). A free bot audit is available before committing.

How far back can I recover Google Ads spend?

BotRefund states it can recover refunds from Google Ads spend dating back to 2017 (S2), subject to Google's own data retention and policy limits.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more