Seatext library / BotRefund evidence
How to Use BotRefund to Identify Suspicious Sessions
Learn how to add the BotRefund snippet, interpret its risk score, review suspicious sessions, and use the export as evidence for Google Ads and Meta refund claims.
✓ Built for advertisers who need clear, refund-ready traffic evidence.
To use BotRefund to identify suspicious sessions, you first add the BotRefund tracking snippet to every page of your site. The snippet runs in the visitor's browser and collects behavioral data such as mouse movement speed, click timing, and scroll activity.
Overview: Why behavioral detection matters
IP‑based filters can be evaded by rotating addresses or using residential proxies. Behavioral signals are harder to fake because they reflect how a real person moves, clicks, and reads a page. BotRefund looks at over a hundred independent browser actions instead of relying only on network data.
Source S1 notes that Meta campaigns often show normal cost per lead while sales teams receive unreachable contacts, a pattern that can hide automated traffic. Source S4 explains that default network filters miss advanced proxies, so client‑side behavioral audits are needed to catch fake clicks that poison conversion tracking.
Detection mechanics: the 106 checks and risk score
BotRefund runs 106 independent checks. Examples include click behavior (ghost click detection), pointer behavior (robotic linear mouse movements), speed behavior (super‑human input speed under 1 ms), path behavior (grid‑aligned movement), engagement behavior (absence of clicks or scrolling), and session behavior (uniform click paths, no field corrections).
Two specific checks described in the source pack are the Scrollbar Width Leak (S3) and the Clean Context Iframe (S5). Each looks for a mismatch that a real browsing session does not normally create, such as altered browser APIs or unexpected scrollbar dimensions.
A single anomaly is not enough to label a visitor as a bot. BotRefund treats each signal as evidence, cross‑checks it with other browser, network, device, and behavior data, and feeds the full pattern into an AI prediction model. This corroboration is why the vendor claims up to 99 % accuracy (S3, S5).
The risk score shown in the dashboard is a weighted sum of the 106 checks. Higher scores indicate stronger evidence of non‑human behavior, but the exact weighting is proprietary; the model decides which combinations matter most.
Setup: adding the snippet and verifying collection
You need access to the website’s HTML or a tag manager, a BotRefund account, and permission to run JavaScript on your pages. No server changes are required.
- Log in to BotRefund and copy the tracking snippet from the Setup page.
- Paste the snippet just before the closing tag on every page, or add it through your tag manager as a custom HTML tag.
- Publish the change and verify that the snippet loads by opening the browser console and looking for the BotRefund object.
- In the BotRefund dashboard, enable Session recording and set the sensitivity level to Standard (the default catches the most common bot patterns).
- Allow at least 24 hours for data to accumulate before reviewing results.
Source S2 notes that the snippet can be added in about one minute and that a free bot audit is available without a credit card.
Using the dashboard to review suspicious sessions
After data collection, open the Sessions tab and apply the Suspicious filter. Each flagged session shows a risk score, a timestamp, and a replay button.
Click the replay to watch the visitor’s mouse movements, clicks, and scrolls. Look for the patterns BotRefund highlights: super‑human speed, grid‑aligned pointer paths, missing scroll activity, or uniform click paths that lack natural hesitation.
Use the Export button to download a CSV or PDF report that includes the session ID, risk score, and the raw signal values. This report can be attached to a refund request with Google Ads or Meta.
The risk score is a weighted sum of the 106 checks; higher scores mean the session deviates more from typical human behavior across many signals.
Preparing refund claims for Google Ads and Meta – common pitfalls and workflow
A common mistake is to submit BotRefund data alone. Ad platforms require their own invalid activity reports to corroborate the evidence. Another pitfall is mismatched timestamps; always preserve the original attribution before changing campaigns or pausing ads.
Workflow:
- Preserve attribution: export the Google Ads or Meta click report for the same date range before making any changes.
- Download the BotRefund export of flagged sessions (session ID, timestamp, risk score).
- Match BotRefund timestamps or session IDs to the platform’s click identifiers (GCLID for Google Ads, Meta click ID).
- If the same clicks appear in both lists as invalid, you have corroborated evidence.
- Submit the BotRefund export together with the ad‑platform report to start a refund claim.
Source S6 explains that Google offers invalid activity credits but the process is not automatic; understanding how to file a claim is key to recovering money. BotRefund helps navigate this process with an advertised 83 % success rate.
Source S1 adds that Meta advertisers should look at contactability, timing, session behavior (no scrolling, no field corrections, uniform click paths), campaign patterns, and CRM outcomes to separate normal lead‑quality variation from automated activity.
Source S8 shows a real‑world example: the neobank FinTrust suppressed conversion events for automated browser emulation signals, protected lead quality, and recovered $140,000 in ad spend.
Source S7 notes that BotRefund can prepare reports in a format that Google and Meta can review, supporting negotiations with both platforms.
Limitations, best practices, and frequently asked questions
BotRefund works best on sites that receive at least a few hundred sessions per day. Very low traffic may not generate enough data for reliable scoring (S2).
The tool relies on JavaScript execution; visitors who block scripts or use browsers that strip the snippet will not be scored (S2). Non‑web environments such as mobile apps or server‑to‑server API calls are outside BotRefund’s scope; a different fraud solution is needed for those channels.
Because privacy tools, travel networks, or unusual devices can produce unexpected behavior for genuine people, BotRefund treats each signal as evidence, not a verdict, and cross‑checks it with other data (S3, S5).
Practical tips:
- Start with the Standard sensitivity setting; after reviewing a few flagged sessions, adjust up or down based on the rate of false positives you observe.
- Use tag managers to deploy the snippet quickly and to pause or remove it without editing code.
- Schedule automatic exports of the Suspicious report (CSV or PDF) so you have ready‑to‑submit evidence for regular refund cycles.
- When a replay looks legitimate, exclude that session from the export and consider lowering the sensitivity or adding a whitelist rule if available.
- Keep a log of matched GCLIDs or Meta click IDs to speed up the refund claim process.
FAQ:
- Why does BotRefund look at mouse movement instead of just IP addresses? Because many bots rotate IPs or use residential proxies; behavioral clues are harder to fake (S1, S4).
- How long does it take to see results after installing the snippet? You can start seeing flagged sessions within a few hours, but waiting 24 hours gives a more stable risk score (S2).
- What does the risk score mean? It is a weighted sum of the 106 checks; higher scores indicate stronger evidence of non‑human behavior (S2, S3, S5).
- Can I adjust which signals BotRefund uses? Yes, in the dashboard you can enable or disable specific checks, but the default set is optimized for most ad‑fraud scenarios (S2).
- Is there a cost for the free bot audit? No. The audit is free and requires no credit card; you only pay if you choose a paid plan for continuous protection (S2).
- What should I do if BotRefund flags a session that looks legitimate? Review the replay carefully; if you are still unsure, exclude that session from the report and consider lowering the sensitivity (S2).
- How do I handle false positives in my refund claim? Exclude the questionable sessions from the export, keep a record of why they were removed, and rely on the remaining corroborated evidence.
- Can I integrate BotRefund with Google Tag Manager? Yes, add the snippet as a custom HTML tag and publish through the container (S2).
- Is it possible to automate the export of suspicious sessions for regular reporting? Yes, use the Export button to schedule CSV or PDF downloads, or use the API if available (not detailed in sources but implied by export functionality).
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.