Seatext library / BotRefund evidence
How to Use BotRefund to Identify Suspicious Visits: A Step-by-Step Investigation Guide
BotRefund identifies suspicious visits by deploying a client-side script that captures 110+ behavioral, browser, hardware, network, and attribution signals per session. You install the script, let it collect visit data, then review the dashboard...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
To use BotRefund for identifying suspicious visits, you add its tracking script to your landing pages, allow it to record visitor sessions, and then examine the resulting evidence — click IDs, timestamps, session replays, and signal-by-signal reasoning — that shows which visits are automated. The system cross-checks over 100 independent signals (mouse movement, scroll behavior, browser API consistency, timing, network context, and more) and only flags a visit as bot traffic when multiple signals align, producing a report formatted for Google and Meta refund claims.
What BotRefund Actually Does
BotRefund is a client-side auditing layer that sits on your website and observes every paid-visit session after the click. Unlike server-side filters that only see IP addresses and headers, it records browser-level behavior: pointer paths, scroll depth, typing rhythm, iframe context, and hundreds of other micro-signals. Each session receives a verdict — human or bot — backed by a cluster of corroborating evidence, not a single rule. The output is a refund-ready report that includes click identifiers (GCLID, FBCLID), campaign metadata, timestamps, session recordings, and a signal-by-signal explanation that platform reviewers can evaluate.
Key Signals BotRefund Monitors
The platform groups its 110+ checks into behavioral, browser, hardware, network, and attribution categories. The following signals are drawn from the client source pack and represent the concrete evidence layers you can review:
- Pointer behavior: Robotic linear mouse movements, absence of humanlike mouse tremor, grid-aligned movement patterns.
- Speed behavior: Superhuman input speed (under 1 millisecond) for clicks, scrolls, or form submissions.
- Engagement behavior: Absence of clicks or scrolling, sessions that stay too static to match a real browsing journey.
- Session behavior: Unnatural session durations — too short, too long, or too uniform to be human.
- Trap behavior: Honeypot trap interactions — bots responding to hidden or intentionally deceptive page elements.
- Click behavior: Ghost click detection — click activity that happens without the natural sequence of human intent.
- Browser integrity checks: Scrollbar Width Leak (mismatch between reported and actual scrollbar dimensions), Clean Context Iframe (automation tools patching or hiding browser APIs that break under cross-context inspection).
- Attribution signals: Click IDs, campaign, ad set, creative, placement, device, and timestamp preserved per session.
These signals are not used in isolation. As the documentation states, "A single anomaly is not a bot verdict. Privacy tools, travel, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps this signal as evidence — not a verdict — and cross-checks it against independent browser, network, device, and behavior data."
Step-by-Step: Setting Up BotRefund to Identify Suspicious Visits
- Create an account and add your domain. Sign up at BotRefund, verify your domain, and choose the sites or subdomains you want to audit.
- Install the tracking script. Paste the provided JavaScript snippet into the
<head>of every landing page that receives paid traffic (Google Ads, Meta Ads, or both). The script loads asynchronously and does not block page rendering. - Verify data collection. Visit your own page with a test click (use a UTM-tagged URL or click your own ad in preview mode). Confirm the session appears in the BotRefund dashboard within a few minutes, showing a session recording and signal breakdown.
- Let traffic accumulate. Run your campaigns normally for at least 7–14 days to gather a representative sample across placements, creatives, audiences, and devices. Do not pause or restructure campaigns during this baseline period — preserving attribution is critical for later refund claims.
- Review the dashboard. Open the sessions view. Filter by verdict (bot/human), confidence score, campaign, placement, or date range. Each flagged session shows a replay, a list of triggered signals, and the click ID that ties it to your ad platform.
- Export a refund-ready report. Select the sessions you want to contest and generate the report. It packages click IDs, campaign details, timestamps, session recordings, and signal-by-signal reasoning in the format Google and Meta reviewers expect.
- Submit the claim. File the invalid-traffic or invalid-activity claim in Google Ads or Meta Ads Manager, attaching the BotRefund report. BotRefund's team can also handle the negotiation on your behalf.
Understanding the Evidence: From Signals to Verdicts
BotRefund's 99% confidence claim comes from corroboration, not any single check. The AI prediction model weighs the complete pattern across browser, network, device, and behavior evidence. For example, a session might show superhuman input speed (<1ms) and grid-aligned mouse paths and no scroll activity and a Scrollbar Width Leak anomaly. When four independent signals align, the probability of a false positive drops sharply. The platform explicitly avoids rule-based verdicts: "Accuracy comes from corroboration, not one browser tell."
This matters because server-side filters (IP reputation, user-agent lists, data-center blocklists) miss advanced botnets that rotate residential proxies, mimic real user-agents, and execute JavaScript. Client-side observation catches the execution environment itself — the browser APIs, rendering quirks, and human micro-behaviors that automation frameworks struggle to replicate perfectly.
Practical Investigation Workflow
The source pack outlines a structured audit workflow that pairs BotRefund evidence with your own CRM and ad-platform data:
- Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, and click identifiers intact while you investigate. Pausing or restructuring destroys the link between a flagged session and the click you paid for.
- Compare three data layers. Ad-platform data (reported leads, cost per lead), website sessions (BotRefund recordings, engagement metrics), and CRM outcomes (calls connected, demos booked, qualified opportunities, repeat engagement).
- Look for the signal clusters that matter. Contactability issues (disconnected numbers, invalid email domains, repeated addresses), timing anomalies (bursts of leads, immediate form submission after landing, unusual hours), session behavior (no scrolling, no field corrections, uniform click paths), campaign-pattern gaps (sharp lead-quality differences by placement, creative, audience expansion, device, or landing page), and CRM outcome mismatches (high reported lead count with zero downstream progress).
- Segment by placement and creative. Invalid traffic often concentrates in specific placements (e.g., Audience Network, Reels, third-party publisher inventory) or creative formats. Use the click ID and placement data in BotRefund reports to isolate the worst offenders.
- Decide: suppress, exclude, or claim. You can suppress conversion events for flagged sessions so your bidding algorithms stop optimizing for bots, exclude placements/audiences that consistently deliver invalid traffic, or file refund claims with the platform using the BotRefund report.
Limitations and When This Approach Doesn't Apply
- Client-side only. BotRefund cannot see traffic that never executes JavaScript (e.g., pure HTTP scrapers that don't render the page). Those are caught by server-side logs and platform-level filters.
- Requires script installation. You must control the landing page code. If you send traffic to a third-party form or a platform-hosted instant experience where you cannot inject scripts, BotRefund cannot observe those sessions.
- Not a real-time blocker. The primary product is audit and refund evidence, not a WAF that blocks bots at the edge. It can suppress conversion signals for flagged sessions, but the visit still loads the page.
- Privacy and compliance. Session recordings capture user behavior. Ensure your privacy policy and consent flows cover this data collection, especially under GDPR, CCPA, or similar regulations.
- Platform approval is not guaranteed. Google and Meta make final refund decisions. BotRefund's 83% client recovery rate reflects historical outcomes, not a guarantee.
- Minimum traffic thresholds. Very low-volume campaigns may not generate enough sessions for statistically meaningful signal clusters.
Key Facts
| Fact | Detail | Source |
|---|---|---|
| Detection confidence | Up to 99% when session evidence supports it | S2, S3, S7 |
| Independent signals analyzed | 110+ behavioral, browser, hardware, network, and attribution checks | S2, S3 |
| Client refund recovery rate | 83% of 2,500+ audited brands recover funds from Google and Meta | S2 |
| Report format | Refund-ready with click IDs, campaign details, timestamps, session recordings, signal-by-signal reasoning | S2 |
| Bot budget impact estimate | Bot clicks steal up to 20% of Google and Meta ad budget | S2 |
| Case study result (FinTrust) | $140,000 refunded, 14% average bot click rate, 18% conversion rate increase | S8 |
| Detection categories | Pointer, speed, engagement, session, trap, click, browser integrity, attribution | S2, S3, S5 |
| Platform negotiation support | Formats data, writes claim, supports negotiation with Google and Meta reviewers | S2 |
Terminology Quick Reference
- Click ID (GCLID / FBCLID): Unique identifier appended to landing-page URLs by Google Ads and Meta Ads, linking a session to a specific paid click.
- Pixel poisoning: When bot conversions feed false signals into ad-platform optimization algorithms, causing them to bid more for similar low-quality traffic.
- Invalid activity credit (Google) / Invalid traffic refund (Meta): Platform reimbursement programs for clicks/impressions deemed non-genuine.
- Client-side audit: Analysis running in the visitor's browser, capturing behavior, rendering, and API evidence that server logs cannot see.
- Server-side audit: Analysis of web-server logs (IP, headers, user-agent) — useful for basic scraper detection but blind to advanced browser automation.
- Signal cluster: Multiple independent anomalies aligning on the same session, raising confidence that the visit is automated.
- Refund-ready report: Evidence package structured to match the evidentiary standards of Google and Meta review teams.
FAQ
How long does it take to see results after installing the script?
Sessions appear in the dashboard within minutes of a visit. For a statistically useful sample, plan on 7–14 days of normal campaign traffic before drawing conclusions or filing claims.
Does BotRefund block bots in real time?
No. Its core function is forensic evidence collection and refund-ready reporting. It can suppress conversion events for flagged sessions so your bidding algorithms ignore them, but it does not prevent the page from loading.
Can I use BotRefund on Meta Instant Experiences or third-party lead forms?
Only if you can inject the tracking script into the page. Meta Instant Experiences and many third-party form hosts do not allow custom JavaScript, so those sessions cannot be observed client-side.
What if Google or Meta rejects the refund claim?
BotRefund's team supports the negotiation with additional documentation and arguments. Historical data shows an 83% recovery rate across 2,500+ audits, but approval is ultimately at the platform's discretion.
How does BotRefund differ from Cloudflare or other edge bot protection?
Edge providers (Cloudflare, Akamai, etc.) focus on infrastructure protection — DDoS mitigation, WAF rules, CDN delivery. BotRefund focuses on the marketing layer: preserving attribution, observing the post-click visitor journey, and producing evidence formatted for ad-platform refund claims. The two can coexist; many advertisers keep their edge provider and add BotRefund for the evidence layer.
Is there a minimum spend requirement?
The source pack does not specify a minimum spend. The Enterprise tier is noted for budgets under $10,000/mo, suggesting the product serves a range of spend levels. Contact sales for current packaging.
What happens to the data if I pause a campaign?
BotRefund preserves the evidence after a campaign is paused. The session recordings, click IDs, and signal data remain accessible for refund claims filed later.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.