Seatext library / BotRefund evidence

How to Detect and Avoid Fake Traffic That Causes Cheap Leads

Fake traffic inflates lead counts while wasting budget on clicks that never convert. Start by auditing your funnel from click to CRM outcome, then layer behavioral detection, placement exclusions, and verification steps to filter...

Built for advertisers who need clear, refund-ready traffic evidence.

Cheap leads often signal invalid traffic rather than a genuine performance win. When cost per lead drops but sales-qualified leads stay flat, bots, click farms, or low-quality placements are usually filling forms or triggering conversion pixels without human intent. The fix is a structured investigation that preserves attribution, isolates the source, and adds verification before the algorithm learns from the wrong signals.

Start with a four-layer audit before changing anything

Changing targeting or pausing campaigns before you document the evidence destroys the data you need for refund claims and root-cause analysis. Work through these layers in order:

  1. Platform delivery: Compare reach, link clicks, landing-page views, placements, and spend in Ads Manager. A cheap placement only helps if it produces contactable, qualified leads.
  2. Landing-page evidence: Measure page loads, redirects, consent behavior, form starts, completions, time-to-completion, and meaningful engagement (scrolling, field corrections). A click-to-session gap often has ordinary causes — app browsers, consent banners, slow loads — so rule those out first.
  3. Lead verification: Check email deliverability, phone connectivity, duplicate details, and explicit interest confirmation. For high-value offers, a confirmation step or booking flow beats the cheapest raw lead.
  4. Sales outcome feedback: Give sales a small, mandatory set of dispositions: verified, contacted, qualified, disqualified, duplicate, invalid details, no response. Feed these back to the platform via offline conversions so the algorithm optimizes for real outcomes.

Preserve the click identifier, campaign context, timestamp, URL parameters, CRM record, and any verification result before you adjust settings. This chain of custody is what ad platforms require for invalid-activity refunds.

Signals that separate bot traffic from low-quality humans

Not every bad lead is a bot. Treating every unresponsive contact as fraud can make you exclude a valuable audience. Look for repeatable technical and behavioral patterns:

  • Contactability: Disconnected numbers, invalid email domains, repeated addresses, or an unusual concentration of one country code.
  • Timing: Several leads arriving in short bursts, forms submitted immediately after landing, or conversions concentrated at unusual hours.
  • Session behavior: No scrolling, no field corrections, uniform click paths, and no meaningful time on the offer page.
  • Campaign patterns: A sharp lead-quality difference by placement, creative, audience expansion, device, or landing page.
  • CRM outcome: High reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement.

These signals come from comparing ad-platform data, website sessions, and CRM outcomes side by side. A single signal is rarely proof; clusters across layers are what justify action.

Where fake traffic enters Meta campaigns

Meta campaigns reach people across Facebook, Instagram, and eligible partner inventory at high volume. That reach brings accidental interactions, low-intent traffic, automated browsing, and deliberately fraudulent submissions through several channels:

  • Audience Network: Meta defaults to opting you into the Audience Network, which displays ads on thousands of third-party mobile apps and websites. Many publishers on this network use automated bots to click ads to generate artificial publisher revenue. Clicks from Audience Network historically show high CTRs and near-instant bounce rates.
  • Profile scrapers and directory bots: Thousands of bots crawl Facebook and Instagram to scrape profile directories, group posts, and page data. When they follow outbound links on posts and ads, they register as clicks.
  • Click farms and affiliate fraud: Low-cost labor or automated scripts submit forms to earn affiliate payouts, inflate publisher performance, scrape offers, or exhaust a competitor's budget.

Opting out of Audience Network is a fast first step, but it does not stop bots that click directly on Facebook or Instagram placements.

Why server-side logs miss advanced bots

Server-side audits examine IP addresses, request headers, and user-agent strings. They catch basic scrapers but struggle with advanced botnets that rotate residential proxies, mimic legitimate headers, and execute JavaScript. Client-side behavioral analysis fills this gap by observing what the browser actually does:

  • Ghost click detection: Catches click activity that happens without the natural sequence of human intent.
  • Trap behavior (honeypots): Watches for bots that respond to hidden or intentionally deceptive page elements.
  • Pointer behavior: Flags unnaturally straight, linear mouse movements that rarely appear in real sessions.
  • Motion behavior: Looks for the absence of humanlike mouse tremor — the tiny imperfections and jitter typical of human movement.
  • Speed behavior: Identifies interactions faster than a person could realistically perform (sub-millisecond inputs).
  • Path behavior: Detects grid-aligned movement patterns that snap to precise lines instead of natural curves.
  • Engagement behavior: Highlights sessions with no clicks or scrolling — too static to match a real browsing journey.
  • Session behavior: Catches visit lengths that are too short, too long, or too uniform to be human.

These signals are captured in the browser, not the server, so they survive proxy rotation and header spoofing. The evidence is tied to each click ID (GCLID, FBCLID) for platform dispute submissions.

How Google and Meta handle invalid activity credits

Both platforms run automated filters, but they catch only a fraction of invalid traffic. Google's systems analyze rapid clicking, duplicate click signatures, known bad IP ranges, and abnormal server-level patterns. Meta classifies traffic as valid or invalid but relies heavily on advertiser-reported evidence for refunds beyond automatic filters.

Key differences:

  • Google: Issues automatic credits for some invalid activity. For the rest, you file a claim with evidence. Refunds apply to clicks and impressions.
  • Meta: Automatic filtering is less transparent. Refunds typically require a manual claim with click-level evidence tied to specific campaigns and placements.

In both cases, the platform's incentive is to bill the click first and investigate later. The burden of proof sits with the advertiser. Behavioral evidence captured at the browser level — video replays, click IDs, timestamps, and interaction logs — is what moves a claim from "denied" to "approved."

Practical steps to reduce fake traffic today

  1. Opt out of Audience Network in Meta campaign settings unless you have proven it delivers qualified leads.
  2. Add a honeypot field to forms — a hidden input that humans never see but bots often fill.
  3. Require a confirmation step (email verification, SMS code, or booking link) for high-value leads.
  4. Exclude known data-center IP ranges via Google Ads IP exclusions and Meta's block lists where available.
  5. Set up offline conversion import with sales dispositions so the algorithm optimizes for qualified leads, not form submissions.
  6. Deploy client-side behavioral detection that records interaction evidence per click ID for refund claims.
  7. Audit placement reports weekly for sudden CTR spikes, bounce-rate anomalies, or lead-quality drops by placement.

Each step reduces the surface area for invalid traffic. The detection layer (step 6) is what turns suspicion into recoverable evidence.

Key facts

MetricDetailSource
Automated traffic share of web traffic (2025)More than half per ImpervaS6
Bot click share of paid clicks (industry audits)9%–20%S7
BotRefund detection confidence99%S7
Refund claim approval rate83%S2, S7
Setup time for detection script~1 minute (one script tag)S2, S7
Refund lookback window (Google Ads)Dating back to 2017S2
No ad-account access requiredYesS7

Limitations and when this advice does not apply

  • Low-volume accounts: If you receive fewer than 50–100 leads per month, cluster analysis is statistically weak. Focus on verification steps (honeypot, confirmation) rather than pattern detection.
  • Brand-search campaigns: Invalid traffic is rare on exact-match brand terms. The ROI of detection is lower there.
  • Offline-only conversions: If your conversion happens entirely offline (phone call, walk-in), click-level behavioral evidence cannot be tied to the outcome without call-tracking integration.
  • Single-platform budgets: The refund process differs between Google and Meta. If you run only one, learn that platform's specific claim requirements.

Terminology

  • Click ID (GCLID / FBCLID): Unique identifier appended to landing-page URLs by Google and Meta. Required to tie a specific click to behavioral evidence and refund claims.
  • Pixel poisoning: When bots trigger conversion events, the platform's machine learning optimizes targeting for bot-like behavior, degrading performance for real users.
  • Honeypot: A hidden form field or link that humans cannot see but automated scripts interact with, revealing non-human traffic.
  • Offline conversion import: Uploading CRM disposition data (qualified, disqualified, etc.) back to the ad platform so bidding algorithms optimize for downstream quality.
  • Client-side detection: JavaScript running in the visitor's browser that records mouse movement, scroll depth, timing, and interaction sequences — evidence that survives proxy rotation.

FAQ

How much budget am I likely losing to fake traffic?

Industry audits consistently place automated traffic between 9% and 20% of paid clicks. Your actual loss depends on placement mix, audience expansion settings, and whether you run on Audience Network. A free behavioral audit quantifies it for your specific account.

Can I just block bad IPs and be done?

IP blocking catches only the most basic bots. Advanced botnets rotate residential proxies daily. Behavioral detection in the browser is necessary because it observes what the user actually does, not where the request comes from.

Will adding CAPTCHA hurt my conversion rate?

A visible CAPTCHA can add friction. Invisible behavioral challenges (honeypots, timing thresholds, motion analysis) filter bots without interrupting humans. Reserve user-facing CAPTCHA for high-fraud placements only.

How long does a refund claim take?

Google automatic credits appear within weeks. Manual claims on either platform typically resolve in 2–6 weeks if evidence is complete. Incomplete evidence (missing click IDs, no behavioral logs) causes denials or delays.

Do I need to give BotRefund access to my ad accounts?

No. The detection script runs on your website. It captures click IDs and behavioral evidence client-side. Refund claims are filed by you or your agency using the exported reports; no ad-account permissions are required.

What if my leads look real but never buy?

That is a lead-quality problem, not necessarily fraud. Low-intent humans, mismatched offers, and poor follow-up all produce the same symptom. Use the four-layer audit to distinguish: if session behavior is human (scrolling, corrections, time on page) but sales outcomes are zero, fix the offer or the sales process before blaming traffic.

When should I escalate to a managed detection service?

If you spend over $10,000/month on Google and Meta combined, the time to manually audit placements, compile evidence, and file claims exceeds the cost of automated detection and managed recovery. Below that threshold, the DIY steps above cover most cases.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more