Seatext library / BotRefund evidence
How to Use Exclusions Only Where Evidence Is Strong: A Practical Framework for Ad Traffic Quality
Apply audience, placement, or IP exclusions in Google and Meta only after a structured audit confirms repeatable patterns across multiple independent signals — behavioral, browser, network, and attribution — with high confidence (99%+). A...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
What "Strong Evidence" Means in Ad Traffic Quality
Strong evidence is a cluster of independent signals that all point to the same conclusion: the visit was automated, not human. BotRefund's detection model uses 110+ checks across browser consistency, device fingerprints, network context, pointer and scroll behavior, click and typing timing, rendering details, and navigation flow. No single check — not a fast form submit, not a data-center IP, not a missing mouse tremor — constitutes a verdict. The model weighs the complete pattern and only flags a session as invalid when the combined evidence reaches 99% confidence.
This standard matters because ad platforms optimize on the conversion events you send them. If you exclude a placement based on one weak signal, you remove real humans along with bots, shrink your reachable audience, and teach the algorithm to avoid similar users. The result is higher CPAs and a feedback loop that makes future traffic look worse.
The Risk of Premature Exclusions
Treating every unresponsive lead as fraud is the most common mistake. A weak campaign can attract real people who are not ready to buy. Excluding their audience segment, device type, or geographic region because a few leads didn't convert cuts off future buyers who share those traits. Meta and Google then optimize toward a narrower, often more expensive pool.
Premature exclusions also break attribution. If you pause a campaign or add a broad IP block before preserving click IDs, placement tags, and session recordings, you lose the evidence trail needed for a refund claim. Both platforms require click-level data tied to specific campaigns, ad sets, and timestamps. Once that chain is broken, recovery becomes nearly impossible.
Structured Audit Framework Before Excluding
Before any exclusion, run a structured audit that compares three data layers: ad-platform reports (clicks, spend, placements), website analytics (sessions, engagement, form events), and CRM outcomes (contacts reached, demos booked, revenue). The goal is to find repeatable gaps — not one-off anomalies.
- Preserve attribution first. Export click IDs (GCLID, FBCLID), campaign/ad set/creative/placement hierarchy, timestamps, and landing-page URLs before changing anything.
- Segment by signal, not by outcome. Group sessions by placement, creative, audience expansion setting, device, and landing page. Look for sharp lead-quality differences within the same campaign.
- Cross-reference behavioral clusters. Flag sessions that show multiple independent anomalies: superhuman input speed (<1ms), grid-aligned mouse paths, absence of scroll or field corrections, honeypot interactions, and clean-context iframe mismatches.
- Validate against CRM reality. A high reported lead count paired with zero calls connected, zero demos booked, and zero qualified opportunities is a stronger signal than any single browser check.
- Set a confidence threshold. Only build an exclusion list from sessions the detection model scores at 99% confidence. Lower-confidence sessions stay in a review bucket.
Signal Categories That Build Strong Evidence
Strong evidence comes from corroboration across categories. Each category below contributes independent facts; a verdict requires agreement across several.
| Category | What It Captures | Why It's Independent |
|---|---|---|
| Biometric & behavioral | Mouse tremor, scroll hesitation, typing rhythm, pointer curvature | Hard to fake at scale; automation tools rarely reproduce micro-variance |
| Browser & device consistency | Scrollbar width leak, clean-context iframe, canvas fingerprint, WebGL params | Automation frameworks patch APIs but often leave inconsistencies |
| Network & attribution | Data-center IP, VPN/proxy headers, click-ID mismatch, timestamp drift | Infrastructure signals are orthogonal to browser behavior |
| Interaction traps | Honeypot fields, ghost clicks, trap links | Only bots interact with elements humans cannot see |
| Session flow | Navigation sequence, dwell time variance, back-button use, multi-page journeys | Real users explore; bots follow linear scripts |
A session that triggers only a data-center IP but shows natural mouse tremor, varied scroll, and normal form timing is likely a corporate VPN user — not a bot. A session with superhuman speed, grid-aligned movement, honeypot hits, and no scroll is a different story. The model only flags the latter.
How to Implement Exclusions Safely
Once the audit produces a high-confidence list of invalid sessions, translate findings into platform exclusions without breaking future measurement.
- Map each flagged session to its click ID and placement. Build the exclusion list at the most granular level the platform allows: placement ID, publisher domain, or IP block.
- Apply exclusions in the ad platform, not via firewall. Platform-level exclusions keep attribution intact for remaining traffic and preserve the refund evidence chain.
- Exclude the signal, not the audience. If a specific placement on Audience Network shows 99% bot confidence, exclude that placement — not the entire Audience Network, not the whole country, not the device type.
- Document the evidence bundle. For each exclusion, store the session recordings, signal-by-signal reasoning, click IDs, and timestamps in a refund-ready report. This is what Google and Meta reviewers expect.
- Monitor the exclusion impact for 7–14 days. Watch CPA, lead volume, and CRM contact rate. If lead quality improves without volume collapse, the exclusion was precise. If volume drops sharply, the exclusion was too broad — roll back and refine.
Verification: Did the Exclusion Work Without Collateral Damage?
Verification is a single, repeatable check: compare the pre-exclusion and post-exclusion CRM contact rate (calls connected / leads received) for the same spend level. A successful exclusion raises contact rate while keeping lead volume stable or slightly lower. A failed exclusion drops lead volume without improving contact rate — you removed real humans.
Run this check weekly for the first month, then monthly. Keep the evidence bundle for each exclusion so you can defend or refine it later. If a platform reviewer asks why you excluded a placement, you hand them the session-level report with 99% confidence scores, not a spreadsheet of IP addresses.
Limitations and When This Approach Doesn't Apply
- Brand-new campaigns with no history. You need baseline data to spot anomalies. Run at least 2–3 weeks of clean measurement before building exclusion lists.
- Low-volume campaigns (<50 leads/week). Statistical noise dominates; clusters won't be reliable. Focus on improving creative and offer first.
- Platforms without click-ID passthrough. Some programmatic or third-party networks don't expose the identifiers needed to tie a session to a specific paid click. Exclusions there are guesswork.
- Privacy-regulated traffic where fingerprinting is restricted. Certain jurisdictions or browser settings limit the signals available. Confidence scores will be lower; treat those sessions as "review" not "exclude."
- Sophisticated human fraud (click farms). Real people paid to click and fill forms pass behavioral checks. This requires CRM-outcome correlation, not just browser signals.
Key Facts
| Fact | Detail | Source |
|---|---|---|
| Detection confidence threshold for exclusion | 99% confidence from corroborated multi-signal model | S1, S2, S4, S7 |
| Independent signals used | 110+ across browser, device, network, behavior, attribution | S2, S4, S7 |
| Client refund recovery rate | 83% of 2,500+ audited brands recover funds from Google and Meta | S2 |
| Evidence format accepted by platforms | Refund-ready reports with click IDs, timestamps, session recordings, signal-by-signal reasoning | S1, S2 |
| Single-anomaly policy | "A single anomaly is not a bot verdict" — cross-checked before flagging | S4, S7 |
| Attribution preservation step | Export click IDs, campaign hierarchy, timestamps before any campaign change | S1 |
| Typical bot budget impact | Up to 20% of Google and Meta ad budget lost to bot clicks | S2 |
Key Terms
- Click ID (GCLID/FBCLID): Unique identifier Google or Meta appends to the landing-page URL; ties a session to a specific paid click.
- Placement: The specific inventory slot where an ad appeared (e.g., Facebook Feed, Instagram Stories, Audience Network publisher domain).
- Pixel poisoning: When invalid conversions train the platform's optimization algorithm to seek more low-quality traffic.
- Honeypot: A hidden form field or link that real users never see; interaction signals automation.
- Clean Context Iframe: A detection check that loads the page in an isolated iframe to reveal patched or hidden browser APIs.
- Scrollbar Width Leak: A mismatch between reported and actual scrollbar dimensions that automation frameworks often fail to replicate.
FAQ
How many flagged sessions do I need before excluding a placement?
There's no fixed count. The decision threshold is confidence, not volume. If 20 sessions from the same placement all score 99% confidence with corroborated signals, that's sufficient. If 200 sessions score 60%, exclude none — investigate further.
Can I use the same exclusion list for Google and Meta?
Only if the evidence is platform-specific. A publisher domain that's fraudulent on Meta's Audience Network may be clean on Google Display. Build separate lists per platform using each platform's click IDs and placement IDs.
What if a legitimate user gets caught in a 99% confidence exclusion?
At 99% confidence, the false-positive rate is ~1%. If you see a pattern of real users (e.g., corporate VPN + privacy browser) hitting the same signals, create a "review" segment instead of an exclusion and feed those sessions back to the model for recalibration.
How often should I refresh exclusion lists?
Monthly for stable campaigns; weekly during high-volume launches or seasonal peaks. Bot operators rotate infrastructure; a placement clean in January may be compromised in March.
Do exclusions hurt my quality score or ad rank?
Platform-level exclusions (placement, publisher domain) do not affect quality score. IP exclusions at the account level are neutral. Broad audience exclusions (e.g., entire countries, device types) can shrink reach and raise CPAs — avoid them unless evidence is overwhelming.
What's the difference between BotRefund's report and Google/Meta's automatic invalid-activity credits?
Platform auto-credits catch only server-side patterns (rapid clicks, known bad IPs). They miss client-side automation that mimics human timing but fails browser/behavior checks. BotRefund's client-side evidence captures the latter and formats it for manual review, which is why the 83% recovery rate exceeds platform auto-credits.
Can I implement this without BotRefund?
You can run the audit framework manually: export click IDs, match to analytics sessions, review CRM outcomes, and look for behavioral anomalies in session recordings. It's labor-intensive and misses the 110-signal cross-check. Most teams start manual, then adopt a detection layer when volume justifies it.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.