Seatext library / BotRefund evidence

How to Assign a Questionable Session to a Campaign When It Didn't Come from an Ad

Use indirect attribution methods such as analyzing referral sources, session patterns, and device fingerprinting to match the session to a campaign. If no clear match exists, consider whether the session is from bot traffic...

Built for advertisers who need clear, refund-ready traffic evidence.

When a session doesn't come from an ad click, you can still assign it to a campaign by looking at indirect clues. Check the referral source, session behavior, and device fingerprints. If those don't point to a campaign, the session may be from bots or low-quality traffic that should be filtered out instead of attributed.

What Makes a Session “Questionable”?

A questionable session is one that has no clear campaign source and behaves in ways that don't match a real human visitor. According to BotRefund's analysis of Meta ad traffic, bot traffic and form spam leave repeatable technical and behavioral patterns: unusually fast form completion, identical field structures, sudden placement-level spikes, or conversion events with no meaningful page engagement.

Common signs include:

  • No scrolling or field corrections
  • Uniform click paths
  • No meaningful time on the offer page
  • Leads arriving in short bursts
  • Forms submitted immediately after landing

Prerequisites Before You Start

Before you try to assign a questionable session to a campaign, make sure you have:

  • Access to your analytics platform (Google Analytics 4, Matomo, or similar)
  • A list of all active campaigns with their expected sources and audiences
  • Session-level data: referral path, device, location, behavior events
  • A bot detection tool or at least a manual review process to check for invalid traffic

Step-by-Step Attribution Process

  1. Check for missing campaign parameters. Look for UTM tags, GCLIDs, FBCLIDs, or other identifiers that may have been dropped. If the session has no parameters, move to indirect clues.
  2. Analyze the referral source. Is it direct, organic, referral, social, or email? Compare that to your campaign channels. For example, a spike in direct traffic may match a TV or billboard campaign.
  3. Examine session behavior patterns. Compare time on site, pages per session, device type, and location against known campaign audience profiles. If the session matches a campaign's typical user behavior, it's a candidate for attribution.
  4. Use device fingerprinting or probabilistic matching. Services like BotRefund capture behavioral signals (mouse movements, scroll patterns, input speed) that can link a session to a previous campaign exposure even without a click ID.
  5. Check for bot signals. If the session has superhuman speed, no scrolling, or grid-aligned movement, it is likely invalid. In that case, do not assign it to any campaign – filter it out instead.

Diagnostic Sequence: How to Identify Campaign Patterns

Use this diagnostic sequence to systematically evaluate questionable sessions:

  1. Contactability check: For lead forms, verify if the phone number is disconnected, email domain is invalid, or addresses repeat. These point to bot traffic rather than a real campaign.
  2. Timing analysis: Look at the timing of sessions. Several leads arriving in short bursts or forms submitted immediately after landing are common bot patterns.
  3. Session behavior review: Check for no scrolling, uniform click paths, and absence of humanlike mouse tremor. Real users have tiny imperfections in movement; bots move in straight lines.
  4. Campaign pattern comparison: Compare lead quality by placement, creative, audience expansion, device, or landing page. A sharp difference in quality by placement often reveals which traffic source is generating questionable sessions.
  5. CRM outcome check: If you have a high lead count but no calls connected, demos booked, or qualified opportunities, the sessions likely came from bots, not a campaign.

This sequence helps you separate real campaign traffic from automated activity.

How Analytics Platforms Classify Sessions Without Campaign Parameters

Analytics platforms like Google Analytics 4 and Matomo use a hierarchy to assign session campaigns when UTM parameters are missing. First, they check for click identifiers such as GCLID (Google Ads) or FBCLID (Meta Ads). If those are absent, they examine the HTTP referrer header. A referrer from google.com with a search query may be classified as organic search. A referrer from facebook.com may be classified as social. If the referrer is missing or stripped by privacy settings, the session often falls into "direct" or "(not set)" buckets.

GA4 also uses modeled conversions and consent mode to estimate campaign attribution when data is incomplete. This modeling relies on aggregated patterns from users who consented to tracking. It does not assign a specific campaign ID to an individual session. For session-level attribution, you must rely on the referrer, click IDs, or your own fingerprinting logic.

Matomo offers a similar fallback chain: campaign parameters > click IDs > referrer > direct. You can configure custom channel groupings to map specific referrer domains to your internal campaign names. This mapping works best when you maintain a lookup table of known campaign landing pages and their expected referrer patterns.

Mapping Referral Paths to Campaign IDs

To map a referral path to a campaign ID, start by exporting your active campaign list with their target URLs and expected traffic sources. For each campaign, note the landing page URL patterns, UTM structures, and any partner domains that may send traffic (e.g., affiliate networks, email platforms).

In your analytics platform, create a segment for sessions with missing campaign parameters. Export the session-level data: landing page, referrer, device, geo, and behavior events. Use a spreadsheet or script to join this data against your campaign list. Match on landing page path first. If multiple campaigns share a landing page, use referrer domain as a tiebreaker. For example, traffic from mailchimp.com to a product page likely belongs to your email campaign, not your paid search campaign.

When referrer data is missing (common with direct traffic or privacy-preserving browsers), use behavioral clustering. Group sessions by device fingerprint, time of day, and navigation pattern. Compare these clusters to known campaign audience profiles. A cluster that matches the geo, device, and behavior of your Meta lookalike audience may be attributed to that campaign with a confidence score.

Document every mapping rule. When a session matches multiple campaigns, assign it to the one with the highest confidence score and flag it for review. This audit trail lets you adjust rules later without losing historical attribution.

Practical Walkthrough: Fingerprinting and Probabilistic Matching

Device fingerprinting collects a set of browser and hardware attributes to create a stable identifier. Common signals include screen resolution, timezone, language, installed fonts, canvas rendering, WebGL parameters, and battery status. BotRefund's client-side script captures additional behavioral signals: mouse movement trajectories, scroll depth and velocity, keystroke timing, and touch interactions on mobile.

To link a questionable session to a prior campaign exposure, you need a fingerprint store. When a user clicks an ad, record the click ID (GCLID or FBCLID) alongside the fingerprint at that moment. Store this pair in a database with a TTL of 30 to 90 days, matching your attribution window.

When a questionable session arrives without a click ID, compute its fingerprint. Query the store for recent fingerprints that match within a similarity threshold. A match suggests the same browser visited via an ad click earlier. Assign the session to the campaign associated with that click ID.

Probabilistic matching extends this by weighting signals. Exact matches on canvas fingerprint and IP subnet carry high weight. Matches on screen resolution alone carry low weight. Combine scores into a probability. Set a threshold (e.g., 80%) for automatic attribution. Below that, flag for manual review.

Example: A session lands on your pricing page with no referrer and no UTM. Its fingerprint matches a stored fingerprint from an FBCLID click three days ago. The match score is 92%. Attribute the session to the Meta campaign that generated that FBCLID. If the same fingerprint also matches a GCLID from yesterday, attribute to the more recent click or split credit based on your attribution model.

Limitations: Apple's App Tracking Transparency and browser privacy features (Firefox Enhanced Tracking Protection, Safari ITP) reduce fingerprint stability. Rotate fingerprint algorithms quarterly. Test match rates on known human traffic before relying on them for attribution.

Decision Checklist: Attributing vs Filtering Questionable Sessions

Use this checklist for each questionable session or cluster of sessions. Answer each question. If you reach a "Filter" decision, stop and exclude the session from campaign reporting.

  1. Does the session have a click ID (GCLID, FBCLID, MSCLKID)? Yes → Attribute to that campaign. No → Continue.
  2. Does the referrer domain match a known campaign channel (e.g., google.com for search, facebook.com for social)? Yes → Attribute to that channel's campaign. No → Continue.
  3. Does the landing page URL contain campaign-specific parameters or belong to a single-campaign landing page? Yes → Attribute to that campaign. No → Continue.
  4. Does the device fingerprint match a stored fingerprint from a recent ad click (within attribution window)? Yes → Attribute to that campaign. No → Continue.
  5. Does the session show bot signals? Superhuman input speed (<1ms), no scrolling, linear mouse paths, grid-aligned movement, uniform session durations. Yes → Filter as invalid traffic. No → Continue.
  6. Does the session behavior match a known campaign audience profile (geo, device, time of day, navigation pattern)? Yes → Attribute with confidence score. No → Continue.
  7. Is the session part of a burst pattern (multiple similar sessions in minutes)? Yes → Investigate as potential bot cluster. If confirmed, filter. No → Continue.
  8. Can you verify contactability? For lead forms: valid phone, deliverable email, unique address. If unverifiable, flag for CRM outcome tracking rather than immediate attribution.
  9. Default: Label as "unassigned" and route to a holding bucket. Review weekly. If CRM outcomes show zero conversions from this bucket, treat as invalid and filter retroactively.

This checklist prevents both over-attribution (crediting bots) and under-attribution (dropping real customers). Adjust thresholds based on your traffic volume and risk tolerance.

Limitations of Indirect Attribution

Indirect attribution is not foolproof. It works best when you have a clear campaign hypothesis and a high volume of sessions to compare. Limitations include:

  • Privacy settings: Apple's App Tracking Transparency and Google's Consent Mode can strip identifiers, making fingerprinting less reliable.
  • Shared devices: A single device may be used by multiple people, mixing campaign signals.
  • Cross-device journeys: A user may see a campaign on mobile but convert on desktop, breaking the session link.
  • Bot traffic mimicking humans: Advanced bots use residential proxies and human-like behavior, so they may pass fingerprinting checks.
  • Attribution window mismatch: A click may occur outside your fingerprint TTL but still influence the conversion.
  • Channel overlap: A user may click a Meta ad, then later click a Google ad, then convert direct. Last-click attribution assigns to direct; data-driven models split credit. Your indirect method must align with your chosen model.

When indirect attribution fails, the safest approach is to label the session as “unassigned” and use a bot detection tool to exclude it from your analytics.

Trade-offs Between Attribution Precision and Coverage

Every attribution method balances precision (correctly assigning sessions to their true campaign) against coverage (assigning a campaign to as many sessions as possible). High-precision methods like click IDs cover only sessions that retain the ID. Low-precision methods like referrer-based rules cover more sessions but misattribute some.

Fingerprinting sits in the middle. It covers sessions that lose click IDs but retain browser identity. Its precision depends on fingerprint stability and the uniqueness of your audience. In B2B with low traffic, fingerprints may be unique enough for high precision. In high-volume consumer traffic, collisions increase.

Probabilistic matching lets you tune this trade-off. Raise the similarity threshold for higher precision, lower it for higher coverage. Monitor the "unassigned" bucket size. If it grows, your thresholds may be too strict. If CRM outcomes show poor quality from attributed sessions, thresholds may be too loose.

Decide your priority. For budget allocation, precision matters more — you don't want to shift spend to a campaign that only looks good because of misattributed bot traffic. For audience building, coverage may matter more — you want to reach all potential customers even with some noise.

Follow-Up Questions for Your Team

After implementing indirect attribution, schedule a monthly review with these questions:

  • What percentage of sessions are now "unassigned"? Is it trending up or down?
  • Do attributed sessions from fingerprinting convert at rates similar to click-ID sessions?
  • Are any campaigns showing sudden quality drops that correlate with a new referral source?
  • Has the bot detection tool flagged sessions that were previously attributed to campaigns?
  • Are there referral domains sending traffic that don't map to any known campaign? Could they be new partners or scrapers?
  • Does the CRM outcome data (calls connected, demos booked) validate the attribution decisions?
  • Are privacy changes (new browser versions, OS updates) reducing fingerprint match rates?
  • Should the attribution window or fingerprint TTL be adjusted based on sales cycle length?

Document answers and adjust rules quarterly. Attribution is not set-and-forget.

Key Facts About Session Attribution

FactDetail
Bot share of budgetBot clicks steal up to 20% of Google and Meta ad budgets, according to BotRefund data.
Refund success rate83% of BotRefund customers successfully get a refund from Google and Meta billing disputes.
Common bot sourceMeta Audience Network placements have historically shown high CTRs and near-instant bounce rates, indicating bot activity.
Detection methodClient-side audits (behavioral analysis) catch advanced botnets that server-side IP filters miss.
Bot complexityResidential proxy botnets use real consumer IP addresses, making them hard to detect by IP alone.

Frequently Asked Questions

Why can't I just use UTM parameters for every session?

UTM parameters only work when you manually tag your links. Many sessions come from direct visits, bookmarks, or untagged social shares, so they lack UTM data.

What is device fingerprinting and how does it help?

Device fingerprinting collects a unique set of browser and device attributes (screen size, installed fonts, timezone) to identify a user across sessions. It can link a session back to a previous campaign exposure even without a click ID.

How do I know if a session is a bot and not a real user?

Look for superhuman input speed (less than 1ms), no scrolling, linear mouse paths, and uniform session durations. Real users have variable behavior, tiny mouse tremors, and natural scrolling.

Can I automate this attribution process?

Yes, tools like BotRefund combine behavioral detection with campaign pattern analysis to automatically flag and classify questionable sessions, making attribution easier.

What is the cost of bot detection tools?

Pricing varies. BotRefund offers a free bot audit and tiered pricing based on ad spend, from under $10,000/month to over $1M/month. Some tools have free trials or flat monthly fees.

Does indirect attribution work for all campaign types?

No. It works best for brand awareness, lead generation, and retargeting campaigns where the audience is defined. It's less effective for local or hyper-targeted campaigns with small audiences.

How often should I review my attribution rules?

Review monthly for high-volume accounts, quarterly for lower volume. Update when you add new campaigns, change landing pages, or see shifts in the unassigned bucket.

What if a session matches two campaigns equally?

Assign to the most recent click within the attribution window, or split credit evenly if your model supports fractional attribution. Flag for manual review if the campaigns have very different ROI.

Can I use server-side logs instead of client-side fingerprinting?

Server-side logs (IP, user-agent, referrer) are easier to collect but less precise. They miss behavioral signals and are vulnerable to proxy rotation. Use them as a fallback, not a primary method.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more