Seatext library / BotRefund evidence

How to Use BotRefund to Avoid Common Mistakes in Ad Fraud Detection

BotRefund helps advertisers detect invalid traffic on Google and Meta campaigns using 100+ behavioral and technical signals, then builds refund-ready reports that platforms accept. To avoid common mistakes, preserve attribution before changing campaigns, cross-reference...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund works by installing a lightweight script on your landing pages that captures 106 independent browser, network, device, and behavioral signals per session. The system cross-checks these signals through an AI model that reaches 99% confidence when evidence supports it, then packages findings into reports structured for Google and Meta invalid-traffic review teams. The most common mistakes advertisers make are changing campaigns before preserving click IDs, relying only on server-side logs, treating every poor lead as fraud, and submitting unstructured evidence that platform reviewers reject.

What BotRefund Does

BotRefund is a client-side detection and evidence layer for paid search and social campaigns. It sits on your landing pages and records each visitor's behavioral fingerprint — mouse movement, scroll patterns, typing rhythm, browser API consistency, hardware signals, and network context. Unlike server-side filters that only see IP addresses and headers, BotRefund observes what the visitor actually does in the browser. This catches advanced botnets, headless browsers, and click farms that rotate IPs and spoof user agents but cannot perfectly replicate human micro-behaviors.

The output is not a simple block list. Each flagged session gets a signal-by-signal explanation showing exactly which checks fired and why the AI classified the visit as automated. These session records are then assembled into refund-ready reports that include click IDs (GCLIDs for Google, fbclids for Meta), campaign hierarchy, timestamps, and session replays — formatted the way platform review teams expect to see them.

Prerequisites Before You Start

  • Active Google Ads or Meta Ads campaigns with click tracking enabled (auto-tagging for Google, Meta Pixel for Facebook/Instagram).
  • Access to your website's or tag manager to install the BotRefund script before the closing tag.
  • CRM or lead database access to match ad-platform lead counts against actual sales outcomes (calls connected, demos booked, qualified opportunities).
  • Admin access to ad accounts for submitting invalid-activity claims once reports are generated.
  • At least 2–4 weeks of traffic before expecting statistically meaningful detection; the system needs volume to establish baselines.

Step-by-Step: Using BotRefund to Avoid Common Mistakes

  1. Install the script before launching or changing campaigns. Place the BotRefund snippet in the of every landing page that receives paid traffic. This ensures click IDs (GCLID, fbclid, msclkid) are captured from the first visit. Mistake avoided: changing targeting or pausing campaigns before attribution data is preserved.
  2. Run a free bot audit to establish a baseline. BotRefund offers a free audit that scans recent traffic and returns a sample report. Use this to see your current invalid-traffic rate and identify which placements, creatives, or audiences show the strongest bot signals. Mistake avoided: guessing where fraud lives without data.
  3. Cross-reference three data layers weekly. Compare (a) ad-platform reported leads, (b) BotRefund-flagged sessions tied to click IDs, and (c) CRM outcomes (contact rates, qualification rates, revenue). Look for gaps: high reported leads but low CRM contactability, or sharp quality differences by placement. Mistake avoided: treating every unresponsive lead as fraud when some audiences simply convert slower.
  4. Suppress flagged conversion events in-platform. Use BotRefund's conversion-signal protection to stop poisoned conversion data from training Google's or Meta's bidding algorithms. This prevents the platforms from optimizing toward bot-like behavior patterns. Mistake avoided: letting pixel poisoning compound wasted spend over months.
  5. Generate refund-ready reports monthly. When the dashboard shows clustered invalid traffic with high-confidence signals, export the structured report. It includes click IDs, campaign/ad set/ad details, timestamps, session recordings, and signal-by-signal reasoning — formatted for Google's invalid activity credit system and Meta's traffic quality review. Mistake avoided: submitting screenshots or raw logs that reviewers cannot process.
  6. File claims through the correct platform channel. For Google, use the invalid activity credit request form with the BotRefund report attached. For Meta, work through your ad representative or the traffic quality appeal flow. BotRefund's team can assist with claim wording and follow-up. Mistake avoided: assuming refunds are automatic; Google and Meta both require advertiser-initiated claims for most non-automatic credits.
  7. Verify the outcome and iterate. After credits are issued (or denied), check the refund amount against the flagged spend in your report. Adjust targeting exclusions, placement blocks, or audience settings based on which segments showed the highest bot rates. Mistake avoided: treating one claim as a fix instead of an ongoing quality loop.

Key Facts

MetricDetailSource
Detection signals106 independent browser, network, device, and behavioral checksS3, S5
Confidence threshold99% when session evidence supports itS2, S3, S5
Client recovery rate83% of 2,500+ audited brands recover funds from Google and MetaS2
Typical budget wasteBot clicks steal up to 20% of Google and Meta ad budgetsS2
Report formatClick IDs, campaign hierarchy, timestamps, session recordings, signal-by-signal reasoning — structured for platform review teamsS2, S6
Case study resultFinTrust recovered $140,000 (14% of ad spend) with 18% average bot click rateS8
Google detection scopeServer-level patterns only (rapid clicks, duplicate signatures, known bad IPs); misses client-side evasionS6
Meta traffic typesFacebook, Instagram, and eligible partner inventoryS1

Common Mistakes and How BotRefund Addresses Them

Mistake 1: Changing campaigns before preserving attribution

Advertisers often pause low-performing ad sets or shift budgets the moment lead quality drops. This severs the link between the click ID and the downstream session data. BotRefund's first workflow step is "preserve attribution before changing the campaign" — capture GCLIDs and fbclids while the campaign is live so evidence remains intact for later claims.

Mistake 2: Relying only on server-side logs

Server logs show IPs, user agents, and request headers. Advanced bots rotate residential proxies, spoof Chrome user agents, and mimic human request timing. They fail at client-side execution: canvas rendering, WebGL parameters, mouse tremor, scrollbar width consistency, iframe context integrity. BotRefund's 106 checks operate in the browser where these evasion attempts break down.

Mistake 3: Treating every bad lead as bot fraud

Not every unresponsive contact is automated. Real people submit forms with typos, use throwaway emails, or change their minds. BotRefund distinguishes by looking for repeatable technical patterns: superhuman input speed (<1ms), grid-aligned mouse paths, absent scroll behavior, identical field structures across sessions. A single anomaly is never a verdict; the AI weighs the complete pattern across browser, network, device, and behavior evidence.

Mistake 4: Submitting unstructured evidence to platforms

Google's invalid activity credit system and Meta's traffic quality team review thousands of claims. They expect click IDs, campaign metadata, timestamps, and a clear signal narrative. Raw analytics exports or security logs get rejected. BotRefund automates the report format both platforms accept, including session replays reviewers can watch.

Mistake 5: Letting poisoned conversions train bidding algorithms

When bot conversions fire your Meta Pixel or Google Ads conversion tag, the platforms learn to find more traffic that looks like those bots. BotRefund's conversion-signal protection suppresses flagged events in real time so only verified human conversions train the optimization models.

Mistake 6: Expecting automatic refunds

Google issues some invalid activity credits automatically, but the majority — especially for sophisticated botnets — require an advertiser-initiated claim with evidence. Meta's process is similarly manual. BotRefund's 83% recovery rate across 2,500+ audits comes from knowing how to package and argue claims that reviewers approve.

Limitations and When This Advice Doesn't Apply

  • Brand awareness / video view campaigns where the goal is impressions, not clicks or conversions. BotRefund optimizes for click and conversion fraud detection.
  • Traffic from non-Google/Meta sources (TikTok, LinkedIn, programmatic DSPs). The refund-ready reports are structured for Google and Meta review processes; other platforms have different evidence requirements.
  • Sites blocking third-party scripts via strict CSP or ad blockers that prevent the detection script from loading. A portion of traffic will remain unobserved.
  • Very low volume campaigns (< 500 clicks/month). Statistical confidence requires enough sessions to establish behavioral baselines and detect outliers.
  • Advertisers without CRM outcome data. Without matching ad leads to sales results, you cannot validate which flagged sessions represent actual waste versus slow-converting audiences.

Terminology

  • Click ID (GCLID, fbclid, msclkid) — Unique identifier appended to landing page URLs by ad platforms. Links a specific ad click to the subsequent session. Essential for refund claims.
  • Pixel poisoning — When bot conversions fire your tracking pixel, causing the platform's optimization algorithm to target more bot-like traffic.
  • Invalid activity credit — Google's term for refunds issued for clicks/impressions deemed non-genuine. Can be automatic or claim-based.
  • Traffic quality appeal — Meta's process for advertisers to contest lead quality and request refunds for invalid traffic.
  • Client-side detection — Analysis running in the visitor's browser (JavaScript), capturing behavioral and environmental signals invisible to server logs.
  • Signal — One independent check (e.g., scrollbar width leak, clean context iframe, mouse tremor) that contributes evidence toward the AI's classification.
  • Cross-checked context — BotRefund's method: no single signal triggers a verdict; the AI evaluates how all 106 signals fit together for each session.

FAQ

How long until I see results after installing BotRefund?

Detection starts immediately, but meaningful patterns emerge after 2–4 weeks of traffic volume. The free audit can scan historical data if click IDs were already captured.

Does BotRefund block bots in real time?

It suppresses conversion events for flagged sessions in real time (preventing pixel poisoning). It does not block page loads or show CAPTCHAs; the focus is evidence collection for refunds and algorithm protection.

What if Google or Meta denies my claim?

BotRefund's team assists with claim wording and follow-up. The 83% recovery rate reflects cases where evidence was sufficient for approval. Denials typically occur when flagged spend is too low to meet platform thresholds or when evidence gaps exist (e.g., missing click IDs).

Can I use BotRefund alongside Cloudflare or other WAFs?

  • Yes. Cloudflare operates at the network edge (DDoS, WAF, CDN). BotRefund operates at the marketing layer (onsite behavior, attribution, refund evidence). They solve different problems and can run simultaneously.
  • How much does BotRefund cost?

    Pricing is tiered by monthly ad spend. The site shows an "Under $10,000/mo" tier and an Enterprise tier. Exact pricing requires a quote; the free audit is available at any spend level.

    What happens to my data?

    Session recordings and signal data are stored for report generation and claim support. BotRefund's privacy approach treats each signal as evidence, not a verdict, and cross-checks against privacy tools, corporate networks, and unusual devices to avoid false positives.

    Do I need technical skills to install and use it?

    Installation is a single script tag in — manageable via Google Tag Manager or direct HTML edit. The dashboard is designed for marketing teams; no SQL or log analysis required. Refund claim assistance is included.

    Further reading and comparison sources

    These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

    Learn more

    Visit the website for more information.

    Learn more