Seatext library / BotRefund evidence
How to Tell If a Bad Lead Is a Bot or Just Low Intent
A bot lead leaves repeatable technical patterns — superhuman input speed, identical field structures, no scrolling, uniform click paths — while a low-intent lead is a real person who simply isn't ready to buy....
✓ Built for advertisers who need clear, refund-ready traffic evidence.
The fastest way to tell a bot from a low-intent human is to look for evidence that no person could produce. Bots complete forms in milliseconds, move pointers in perfectly straight lines, never scroll, and never hesitate. Low-intent humans still scroll, pause, correct typos, and show variable timing — they just don't convert. If your CRM shows high lead volume but zero connected calls, demos booked, or repeat engagement, check whether the drop-off happens at the form submit (suggesting bots) or after sales outreach (suggesting low intent).
The Core Difference: Motivation vs Fabrication
A low-intent lead is a real person who clicked your ad but isn't ready to purchase. They might be researching, comparing, or killing time. Their session looks human: imperfect mouse movement, reading pauses, occasional back-button use. A bot lead is fabricated — either fully automated scripts or human click-farms paid to submit forms. The motivation differs: bots exist to inflate metrics, scrape offers, earn affiliate payouts, or exhaust budgets. Humans exist to evaluate. That distinction matters because treating every unresponsive contact as fraud can make you exclude a valuable audience that simply needs nurture.
Signals That Point to Automated Traffic
Bot traffic tends to leave repeatable technical and behavioral patterns. The BotRefund blog identifies several clusters worth investigating:
- Contactability: disconnected numbers, invalid email domains, repeated addresses, or an unusual concentration of one country code.
- Timing: several leads arriving in short bursts, forms submitted immediately after landing, or conversions concentrated at unusual hours.
- Session behavior: no scrolling, no field corrections, uniform click paths, and no meaningful time on the offer page.
- Campaign patterns: a sharp lead-quality difference by placement, creative, audience expansion, device, or landing page.
- CRM outcome: a high reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement.
These signals come from the Meta Ads Invalid Traffic guide, which notes that "Meta Ads Invalid Traffic can look like a campaign-performance problem before it looks like fraud" and that "Ads Manager may report a steady cost per lead while the sales team receives unreachable contacts, copied messages, or enquiries that never progress."
Signals That Suggest Low-Intent Humans
Real people who aren't ready to buy still behave like people. They scroll the page, move the mouse with natural tremor, hesitate between fields, and sometimes abandon the form mid-way. Their sessions show variable dwell time — some read for two minutes, others bounce in ten seconds. They may fill partial forms, use autofill, or correct typos. In the CRM, these leads might answer the phone but say "not now," or they might ghost after one call. The pattern is inconsistency, not uniformity. If you see a mix of engaged and disengaged sessions from the same campaign, you're likely looking at audience quality variation, not bot fraud.
A Practical Investigation Workflow
The BotRefund blog recommends a structured audit before changing targeting or requesting refunds:
- Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, and click identifiers intact so you can trace bad leads back to their source.
- Cross-reference three data layers. Compare ad-platform data (Meta Ads Manager, Google Ads), website session data (GA4, heatmaps, session recordings), and CRM outcomes (contact rate, qualification rate, sales-cycle progression).
- Segment by placement and creative. A sharp quality drop on Audience Network or Reels placements often signals automated or accidental clicks.
- Check for superhuman speed. Form submissions under 1–2 seconds from page load are physically implausible for humans.
- Look for behavioral uniformity. Identical field-entry order, zero mouse movement, zero scroll events, and identical timestamps across multiple leads indicate scripts.
- Verify contactability independently. Run phone/email validation on a sample. If 80%+ are invalid, you have a bot or form-spam problem. If most are valid but unresponsive, you have an intent problem.
This workflow mirrors the "practical investigation workflow" from the Meta Ads Invalid Traffic article, which emphasizes starting with "a structured audit that compares ad-platform data, website sessions, and CRM outcomes before changing targeting or making a refund request."
Technical Detection Methods That Separate Bots from People
Modern bot detection relies on client-side behavioral analysis — running checks in the visitor's browser that automated tools struggle to fake. BotRefund uses 106 independent checks across categories including:
- Click behavior: Ghost click detection catches clicks without the natural sequence of human intent. Honeypot traps watch for bots responding to hidden page elements.
- Pointer behavior: Robotic linear mouse movements flag unnaturally straight paths. Absence of humanlike mouse tremor looks for the tiny imperfections and jitter typical of human movement.
- Speed behavior: Superhuman input speed (<1ms) identifies interactions faster than a person could perform.
- Path behavior: Grid-aligned movement patterns detect movement snapping to precise lines instead of natural curves.
- Engagement behavior: Absence of clicks or scrolling highlights sessions too static for real browsing.
- Session behavior: Unnatural session durations catch visits too short, too long, or too uniform to be human.
- Browser fingerprint anomalies: Checks like Scrollbar Width Leak and Clean Context Iframe reveal mismatches that automation tools create when patching or hiding browser APIs.
Each signal is kept as evidence — not a verdict — and cross-checked against independent browser, network, device, and behavior data. BotRefund's AI prediction model weighs the complete pattern instead of trusting a raw rule, achieving 99% accuracy through corroboration.
Server-Side vs Client-Side Audits
Server-side audits examine IP addresses, request headers, and user-agent strings from log files. They catch basic scrapers and known data-center ranges but struggle with advanced botnets that rotate residential proxies and mimic legitimate headers. Client-side audits analyze the visitor's actual browser behavior — mouse movement, scroll depth, input timing, API consistency — which is far harder to spoof at scale. The Facebook Ad Bot Detection guide explains that "server-side audits look at server log files... While this catches basic scraper bots, it struggles to detect advanced botnets. Client-side audits analyze the visitor's browser..." For lead-quality investigations, you need both: server-side for traffic source context, client-side for behavioral proof.
Why the Distinction Changes Your Next Steps
If the problem is bots, your actions are: suppress conversion events for automated sessions so ad algorithms stop optimizing for fraud, submit forensic evidence to Google/Meta for invalid-activity credits, and add client-side detection to block future bot clicks. BotRefund's case study with FinTrust shows this recovered $140,000 in ad spend (14% average bot click rate) and increased conversion rates by 18% by ensuring "Facebook & Google AI trained only on verified bank accounts." If the problem is low intent, your actions are: refine audience targeting, improve creative messaging, add qualification steps before the form, and build nurture sequences for early-stage researchers. Mixing the two responses — e.g., blocking traffic sources that actually contain real but unready buyers — wastes reach and inflates acquisition costs.
Limitations and When This Framework Doesn't Apply
- Human click-farms: Paid humans submitting real forms with real data pass behavioral checks. They require CRM-level pattern analysis (duplicate IPs, identical responses, geographic anomalies).
- Privacy tools and corporate networks: VPNs, anti-fingerprinting browsers, and enterprise security stacks can produce anomalous signals for genuine users. BotRefund notes that "privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people" and keeps signals as evidence, not verdicts.
- Low-volume campaigns: Statistical patterns need volume. With 20 leads/month, you can't reliably distinguish a bot cluster from a bad week.
- Offline conversion imports: If you import CRM stages as conversions, the ad platform optimizes for those events. Bots that trigger later-stage imports (rare but possible) poison optimization deeper in the funnel.
Key Facts
| Metric | Detail | Source |
|---|---|---|
| Bot click share of ad budget | Up to 20% of Google and Meta ad budget | S2, S8 |
| Detection accuracy (BotRefund) | 99% via 106 cross-checked signals + AI | S4, S6 |
| FinTrust recovery | $140,000 refunded, 14% bot click rate, +18% conversion rate | S5 |
| Refund approval rate | 83% across client claims submitted to ad platforms | S2, S8 |
| Setup time | ~1 minute to add to website, no credit card | S2, S8 |
| Google invalid activity examples | Repeated manual clicks, automated tools/bots, accidental mobile taps, data-center IPs, impression fraud, competitor click fraud | S7 |
FAQ
How fast is too fast for a human form submit?
Under 1–2 seconds from page load to form submit is physically implausible. BotRefund flags "superhuman input speed (<1ms)" as a primary signal. Real humans need time to read, decide, type, and click.
Can low-intent leads look like bots in aggregate?
Yes. A campaign targeting a broad audience may attract many quick bounces that resemble bot traffic in aggregate metrics. The difference appears at the session level: low-intent humans still show variable scroll, mouse movement, and dwell time. Bots show uniformity.
What if my CRM shows valid contacts but zero sales?
That's an intent or sales-process problem, not a bot problem. Check whether leads match your ICP, whether sales follows up fast enough, and whether your offer is competitive. Bots rarely produce valid, reachable contacts at scale.
Do I need client-side detection if Google/Meta already filter invalid clicks?
Platform filters catch known patterns (data-center IPs, rapid clicking, duplicate signatures) but miss advanced botnets using residential proxies and behavioral mimicry. Google's own documentation admits detection is "far from perfect." Client-side evidence is required for refund claims the platforms didn't auto-credit.
How do I get a refund for bot clicks?
Collect forensic evidence: session recordings, behavioral signals, click IDs (GCLID/FBCLID), timestamps, and IP context. Submit via the platform's invalid-activity dispute process. BotRefund automates this with audit-ready reports and reports an 83% approval rate across client claims.
What's the cost of doing nothing?
Bots poison conversion pixels, causing ad algorithms to optimize for fraud patterns. This raises CAC, lowers ROAS, and compounds as the algorithm seeks more "converting" traffic that looks like the bots. The FinTrust case study recovered 14% of spend — that's the typical leak rate.
When should I suspect human click-farms instead of bots?
When contacts are reachable, data looks real, but leads never progress and show geographic or temporal clustering (e.g., 50 leads from one city in one hour). ClickCease research confirms "fake leads can come from humans rather than bots... from click farms, low-quality lead vendors."
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.