Seatext library / BotRefund evidence

How to Use BotRefund to Build a Baseline for Bot Detection

Install the BotRefund script on your landing pages, let it collect at least 7–14 days of paid traffic across all campaigns, then review the dashboard's signal breakdown to establish what normal human behavior looks...

Built for advertisers who need clear, refund-ready traffic evidence.

What a baseline means in bot detection

A baseline is a reference profile of how real visitors behave on your pages after clicking an ad. It captures the range of normal variation — scroll depth, mouse tremor, typing rhythm, session duration, navigation paths — so that automated traffic stands out as a statistical outlier rather than a guess. BotRefund builds this profile by running 106 independent checks on every session and feeding the combined pattern into an AI model that reaches 99% confidence when the evidence supports it.

Prerequisites before you start

  • Active Google Ads and/or Meta Ads accounts with click IDs (GCLID, FBCLID) passing through to your landing pages.
  • Ability to add a lightweight JavaScript snippet to the header of every landing page that receives paid traffic.
  • Access to your CRM or lead database to match BotRefund session IDs with downstream outcomes (calls connected, demos booked, qualified opportunities).
  • At least one full campaign cycle (typically 7–14 days) of stable spend so the baseline reflects your actual audience mix, not a test budget.

Step-by-step: Building your first baseline with BotRefund

  1. Install the snippet. Paste the provided script into the <head> of every landing page that receives paid clicks. The script loads asynchronously and does not block page render.
  2. Verify data flow. Open the BotRefund dashboard and confirm that sessions are appearing with click IDs, timestamps, and the full signal set (browser, network, device, behavior).
  3. Run a minimum collection window. Let the script record at least 7 days of traffic across all placements, creatives, audiences, and devices. Do not pause campaigns or change targeting during this window.
  4. Review the signal breakdown. In the dashboard, examine the distribution of each of the 106 checks — for example, scrollbar width leak, clean context iframe, ghost click detection, honeypot trap interactions, pointer behavior, motion behavior, speed behavior, path behavior, engagement behavior, and session behavior. Note the median and interquartile range for human sessions.
  5. Cross-reference with CRM outcomes. Export the session list and join it to your lead data. Confirm that sessions flagged as human by the model correspond to contacts that become calls, demos, or qualified opportunities. Sessions that the model flags as bot should show disconnected numbers, invalid emails, or no downstream activity.
  6. Lock the baseline. Once the human/bot separation aligns with CRM reality, save the current signal thresholds as your baseline. Future sessions will be scored against this profile.
  7. Enable suppression and reporting. Turn on conversion-event suppression for sessions that fall outside the baseline, and generate refund-ready reports (click IDs, campaign details, timestamps, session recordings, signal-by-signal reasoning) formatted for Google and Meta review teams.

Key signals BotRefund uses to establish normal behavior

BotRefund does not rely on a single tell. It combines 110+ behavioral, browser, hardware, network, and attribution signals. The following are representative checks that feed the baseline:

  • Scrollbar Width Leak — detects a mismatch between the reported scrollbar width and the browser's actual rendering context, which automated browsers often fail to replicate.
  • Clean Context Iframe — checks whether standard browser APIs behave consistently when probed from an isolated iframe; automation tools that patch or hide APIs often break under this test.
  • Ghost Click Detection — catches click activity that occurs without the natural sequence of human intent (e.g., no preceding hover, no focus change).
  • Honeypot Trap Interactions — watches for bots that respond to hidden or intentionally deceptive page elements.
  • Robotic Linear Mouse Movements — flags unnaturally straight pointer paths that rarely appear in real user sessions.
  • Absence of Humanlike Mouse Tremor — looks for the tiny imperfections and jitter typical of human movement.
  • Superhuman Input Speed (<1ms) — identifies interactions that happen faster than a person could realistically perform.
  • Grid-Aligned Movement Patterns — detects movement that snaps to precise lines or blocks instead of natural curves.
  • Absence of Clicks or Scrolling — highlights sessions that stay too static to match a real browsing journey.
  • Unnatural Session Durations — catches visit lengths that are too short, too long, or too uniform to be human.

Each signal is kept as independent evidence — not a verdict — and cross-checked against the others before the AI model weighs the complete pattern.

Reading the baseline dashboard: what to look for

  • Signal consistency. Human sessions show variation across signals; bot clusters often share identical anomalies (e.g., same scrollbar width, same iframe context, same pointer path).
  • Placement-level splits. A sharp lead-quality difference by placement, creative, audience expansion, device, or landing page often reveals where invalid traffic concentrates.
  • Timing anomalies. Several leads arriving in short bursts, forms submitted immediately after landing, or conversions concentrated at unusual hours.
  • Contactability gaps. Disconnected numbers, invalid email domains, repeated addresses, or an unusual concentration of one country code.
  • CRM outcome mismatch. A high reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement.

Common mistakes when setting a baseline

  1. Collecting during a campaign change. Pausing ads, swapping creatives, or adjusting audiences mid-collection pollutes the baseline with transitional traffic.
  2. Ignoring CRM ground truth. The dashboard model is 99% accurate when session evidence supports it, but you must verify against actual sales outcomes — calls, demos, qualified opportunities — before locking thresholds.
  3. Treating every anomaly as fraud. Privacy tools, corporate networks, travel, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps each signal as evidence, not a verdict; the baseline should reflect the cluster of corroborated anomalies.
  4. Using too short a window. Less than 7 days often misses weekly seasonality (weekday vs. weekend behavior) and under-represents low-volume placements.
  5. Forgetting attribution preservation. Before changing any campaign, keep campaign, ad set, creative, placement, and click identifiers intact so refund reports remain valid.

Verifying your baseline is accurate

After locking the baseline, run a one-week verification: compare the bot-flagged sessions in the dashboard with your CRM's disqualified leads. If the overlap is high (the FinTrust case study showed a 14% bot click rate and an 18% conversion-rate increase after suppression), the baseline is working. If you see many false positives — human sessions flagged as bot — review the signal breakdown for that segment and adjust the collection window or check for new device/browser combinations that were not represented in the original sample.

Limitations and when the baseline may shift

  • New browser versions or privacy tools can change the distribution of signals like scrollbar width or iframe context; plan to re-baseline quarterly or after major browser releases.
  • Campaign structure changes (new geos, new languages, new landing page layouts) introduce behavioral patterns the original baseline never saw.
  • Seasonal traffic spikes (Black Friday, product launches) may temporarily alter session duration and scroll depth distributions; consider a separate seasonal baseline.
  • BotRefund does not replace server-side fraud filters. It adds a marketing-layer evidence layer that preserves attribution and produces refund-ready reports; edge protection (CDN, WAF) serves a different job.
  • Refund approval is not guaranteed. Across 2,500+ brands audited, 83% of clients recover funds from Google and Meta, but each platform's review team makes the final decision.

Key facts

MetricDetailSource
Bot detection confidence99% when session evidence supports itS2
Independent checks per session106+ behavioral, browser, hardware, network, and attribution signalsS2, S3, S5
Client refund recovery rate83% of 2,500+ audited brands recover funds from Google and MetaS2
Report formatRefund-ready with click IDs, campaign details, timestamps, session recordings, signal-by-signal reasoningS2
Typical bot click rate foundUp to 20% of Google and Meta ad budgetS2
Case study result (FinTrust)$140,000 refunded, 14% bot click rate, 18% conversion rate increaseS8
Signals worth investigatingContactability, timing, session behavior, campaign patterns, CRM outcomeS1

Terminology

  • Click ID (GCLID/FBCLID) — unique identifier appended by Google or Meta when a user clicks an ad; required to tie a session to a specific paid click for refund claims.
  • Pixel poisoning — when bot conversions feed the ad platform's optimization algorithm, causing it to bid more for similar low-quality traffic.
  • Invalid traffic (IVT) — Google and Meta's term for clicks or impressions not resulting from genuine user interest (automated tools, accidental clicks, competitor click fraud).
  • Refund-ready report — evidence package formatted to the specifications Google and Meta reviewers expect, including session recordings and signal-by-signal reasoning.
  • Suppression — preventing a conversion event from firing for sessions the model flags as bot, so the ad platform's algorithm trains only on verified human actions.

FAQ

How long does it take to build a reliable baseline?

Plan for 7–14 days of stable paid traffic across all campaigns. Shorter windows risk missing weekly seasonality and low-volume placements.

Do I need to change my landing pages or forms?

No. The script runs in the browser and observes behavior; it does not modify your page, add CAPTCHAs, or block visitors.

What if my traffic volume is low?

Low volume extends the collection window. You need enough human sessions to define the normal range for each signal — typically a few hundred verified human sessions per major placement/device combination.

Can I use BotRefund alongside Cloudflare or another WAF?

Yes. BotRefund operates at the marketing layer (onsite behavioral investigation, conversion-signal protection, refund-ready reporting) while edge providers handle DDoS, CDN, and WAF rules. They serve different jobs and can coexist.

What happens after I submit a refund report?

BotRefund formats the evidence, writes the claim, and supports the negotiation with Google and Meta reviewers. The platforms make the final credit decision; historically 83% of audited clients recover funds.

Does the baseline automatically update?

Not automatically. Re-baseline quarterly or after major changes (browser releases, new geos, landing page redesigns) to keep the reference profile current.

What if I see a sudden spike in bot-flagged sessions?

Check the signal breakdown for that spike — often a single placement, creative, or audience expansion is the source. You can pause that segment, suppress its conversions, and generate a targeted refund report for the affected click IDs.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more