Seatext library / BotRefund evidence

How to Use BotRefund to Detect Pixel Poisoning

Pixel poisoning occurs when automated bot traffic corrupts your Meta Pixel conversion data, causing bidding algorithms to optimize for fake leads. BotRefund detects this by deploying client-side behavioral checks — 110+ signals including scrollbar...

Built for advertisers who need clear, refund-ready traffic evidence.

Pixel poisoning happens when bots click your Meta ads, land on your site, and trigger conversion events — form submissions, button clicks, or page views — that feed false signals back to Meta's optimization engine. The result: your campaigns optimize for traffic that never converts, your cost per lead rises, and your sales team chases ghost contacts.

BotRefund detects pixel poisoning by installing a lightweight script on your landing pages. That script runs 110+ independent behavioral, browser, hardware, and network checks on every session. Each check produces a single piece of evidence — not a verdict. The system then cross-checks all signals against each other and feeds the complete pattern into an AI model that classifies the visit as human or bot with 99% confidence. When bot traffic is confirmed, BotRefund compiles a refund-ready report with click IDs, timestamps, session recordings, and signal-by-signal reasoning formatted for Meta's review teams.

What Pixel Poisoning Actually Is

Pixel poisoning is the corruption of your Meta Pixel's conversion data by non-human traffic. When bots trigger conversion events — lead forms, purchases, add-to-carts — the Pixel records them as real conversions. Meta's delivery system then optimizes toward the audiences, placements, and creatives that produced those poisoned events. You pay for more of the same junk traffic, and your reported cost per lead looks deceptively healthy while actual sales outcomes flatline.

Source S4 explains that bots "load pages but do not read, scroll, or convert" yet still fire conversion pixels, which "raises your customer acquisition costs (CAC) and lowers your campaign ROAS." Source S8 adds that fake leads are "a major drain on sales team resources, ad budgets, and optimization algorithms."

How BotRefund's Detection Works

BotRefund uses client-side auditing — code that runs in the visitor's browser — rather than relying solely on server logs. Server-side audits only see IP addresses, headers, and user agents, which advanced botnets spoof easily. Client-side checks observe actual behavior: mouse movement, scroll patterns, typing rhythm, browser API consistency, and hardware signals.

Source S2 lists the signal categories: "click behavior, trap behavior, pointer behavior, motion behavior, speed behavior, path behavior, engagement behavior, session behavior." Each category contains multiple specific checks. For example, the Scrollbar Width Leak check (Source S3) detects a mismatch between reported and actual scrollbar dimensions that automation tools struggle to replicate. The Clean Context Iframe check (Source S5) spots when automation frameworks patch browser APIs but fail to hide those patches from a cross-origin iframe probe.

No single signal proves a bot. Source S3 states: "A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people." BotRefund keeps each signal as evidence, cross-checks it against independent browser, network, device, and behavior data, then weighs the complete pattern with an AI predictor.

Step-by-Step: Using BotRefund to Detect Pixel Poisoning

  1. Install the BotRefund script on every landing page that receives Meta ad traffic. The script loads asynchronously and does not block page rendering.
  2. Verify pixel firing in BotRefund's dashboard. Confirm your Meta Pixel events (Lead, Purchase, CompleteRegistration, etc.) are being captured alongside BotRefund's session data.
  3. Run a baseline audit. Let traffic accumulate for 7–14 days. BotRefund will classify each session and flag those with high bot probability.
  4. Review flagged sessions. Each flagged session shows: click ID (fbclid), campaign/ad set/ad, timestamp, session recording, and the specific signals that triggered the classification (e.g., "superhuman input speed <1ms," "grid-aligned mouse movement," "absence of humanlike mouse tremor").
  5. Correlate with CRM outcomes. Export the flagged click IDs and match them against your CRM. Look for the patterns Source S1 describes: "disconnected numbers, invalid email domains, repeated addresses," "several leads arriving in short bursts," "forms submitted immediately after landing," and "high reported lead count paired with no calls connected, demos booked, or qualified opportunities."
  6. Generate a refund-ready report. BotRefund compiles the evidence into the format Meta's review teams expect: click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning. Source S2 confirms: "We turn each finding into a refund-ready report with click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning. The evidence is structured in the format platform teams use to review invalid traffic claims."
  7. Submit the claim to Meta. Use the report to file an invalid traffic refund request. BotRefund's team can assist with the negotiation; Source S2 notes they have "worked through more than 2,500 audits and know how to present bot evidence to Google and Meta."

Key Signals That Indicate Pixel Poisoning

Signal CategoryWhat It DetectsWhy It Matters for Pixel Poisoning
Speed behaviorSuperhuman input speed (<1ms)Bots submit forms or click buttons faster than humanly possible, firing conversion pixels instantly
Pointer behaviorRobotic linear mouse movements, grid-aligned patternsAutomation tools move in straight lines or snap to coordinates; humans produce curves and micro-jitter
Motion behaviorAbsence of humanlike mouse tremorReal users have microscopic hand tremor; headless browsers and scripts do not
Trap behaviorHoneypot trap interactionsHidden form fields or invisible links that only bots interact with, revealing automated form submission
Engagement behaviorAbsence of clicks or scrollingSessions that fire conversion pixels without any prior page engagement
Session behaviorUnnatural session durations (too short, too long, too uniform)Bot sessions often have identical or implausible time-on-page
Browser consistencyScrollbar Width Leak, Clean Context IframeAutomation frameworks leak browser fingerprint inconsistencies when mimicking human behavior

Source S1 lists additional investigation signals: "Contactability: disconnected numbers, invalid email domains, repeated addresses, or an unusual concentration of one country code. Timing: several leads arriving in short bursts, forms submitted immediately after landing, or conversions concentrated at unusual hours. Campaign patterns: a sharp lead-quality difference by placement, creative, audience expansion, device, or landing page."

From Detection to Refund: The Evidence Chain

Detecting pixel poisoning is only half the job. To recover budget, you need evidence Meta will accept. BotRefund structures each finding as a session-level case file:

  • Click ID (fbclid/gclid) — ties the session to a specific paid click
  • Campaign hierarchy — campaign, ad set, ad, placement, creative
  • Timestamp — exact moment of each conversion event
  • Session recording — visual replay of mouse, scroll, and keyboard activity
  • Signal breakdown — each of the 110+ checks with pass/fail and raw values
  • AI confidence score — 99% threshold for inclusion in refund reports

Source S2 emphasizes: "Reports in the format Google and Meta accept. We turn each finding into a refund-ready report with click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning. The evidence is structured in the format platform teams use to review invalid traffic claims."

Source S6 notes that Google's automated systems catch only a fraction of invalid activity; the same principle applies to Meta. Advertisers who supplement platform detection with client-side evidence recover significantly more.

Limitations and When This Approach Does Not Apply

  • Low traffic volumes — statistical confidence requires sufficient sessions. Very small campaigns may not generate enough data for 99% confidence classifications.
  • Non-Meta/Google channels — BotRefund's refund-ready reports are formatted for Google and Meta. Other platforms may not accept the same evidence structure.
  • First-party fraud — if real humans submit fake leads intentionally (e.g., incentive fraud), behavioral signals will classify them as human. This is a lead-quality issue, not bot traffic.
  • Script blocking — aggressive ad blockers or privacy extensions may prevent the BotRefund script from loading, creating blind spots.
  • Attribution changes mid-campaign — Source S1 warns: "Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, click identifier." Changing UTM structures or pixel events mid-audit breaks the evidence chain.

Terminology Quick Reference

Pixel poisoning
Corruption of conversion pixel data by bot-triggered events, causing ad algorithms to optimize for non-converting traffic.
Client-side audit
Detection running in the visitor's browser, observing actual behavior (mouse, scroll, typing, browser APIs) rather than server logs alone.
Refund-ready report
Evidence package formatted to match the specific requirements of Google's or Meta's invalid traffic review teams.
fbclid
Facebook Click Identifier — the unique parameter Meta appends to ad click URLs, essential for tying a session to a specific paid click.
Signal
A single independent check (e.g., scrollbar width, mouse tremor) that contributes one piece of evidence; not a verdict on its own.
Cross-check
Comparing a signal against independent browser, network, device, and behavior data to rule out false positives from privacy tools, VPNs, or unusual devices.

FAQ

How long does it take to see results after installing BotRefund?

Plan for 7–14 days of traffic accumulation before the first meaningful audit. High-volume campaigns may produce actionable flagged sessions in 3–5 days.

Does BotRefund block bots in real time or only detect them?

Detection and evidence collection are the core product. Source S4 mentions "block pixel poisoning in real time" as a capability, but the primary value for pixel poisoning is the forensic evidence needed for refunds. Real-time blocking can be configured but does not replace the refund workflow.

What if Meta rejects the refund claim?

BotRefund's team supports negotiation. Source S2 states they "format the data, write the claim, and support the negotiation with the documentation and arguments their reviewers need to return money to advertisers." The 83% recovery rate across 2,500+ audits reflects this end-to-end approach.

Can I use BotRefund alongside Cloudflare or other WAF/CDN bot protection?

Yes. Source S7 explains: "Many advertisers do not need to replace their edge layer; they need a marketing-focused system that keeps attribution intact, observes the visitor journey, and creates a clear record for an ad-platform review." Edge protection and client-side evidence serve different purposes.

What happens to my page load speed?

The script loads asynchronously and is designed not to block rendering. Specific performance metrics are not published in the source pack; test in your staging environment before full deployment.

Does BotRefund work for Google Ads pixel poisoning too?

Yes. Source S6 covers Google Ads invalid activity credits, and Source S2 notes BotRefund works with both Google and Meta. The detection signals are platform-agnostic; the report formatting adapts to each platform's requirements.

How much budget do I need for this to be worthwhile?

Source S2 mentions an "Under $10,000/mo" tier, suggesting the service scales down to smaller spend levels. The ROI threshold depends on your current invalid traffic rate — Source S2 states "Bot clicks steal up to 20% of your Google and Meta ad budget."

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more