Seatext library / BotRefund evidence
Common Mistakes Brands Make When Handling Invalid Traffic
Brands often rely only on platform detection, wait too long to collect evidence, and confuse low-quality leads with fraud. These mistakes lead to denied refunds and wasted budget. A structured audit that preserves attribution...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Most brands handle invalid traffic reactively. They notice a spike in leads that don't convert, assume the platform will catch the fraud, and only later realize they lack the evidence needed for a refund. The three most costly mistakes are relying solely on Meta or Google's automated filters, delaying evidence collection until after campaign changes, and treating every bad lead as bot traffic without proper verification.
Platform detection catches only a fraction of invalid clicks. Google and Meta have no incentive to flag their own revenue. Refunds happen almost exclusively when an advertiser contests specific charges with specific evidence. Most marketing teams never do this — not because they don't care, but because producing court‑grade session records after the fact is difficult without the right tooling in place beforehand.
Why Invalid Traffic Handling Matters
Invalid traffic wastes budget and poisons conversion data. When bots trigger conversion events, Meta's and Google's machine learning systems optimize for more bot‑like behavior. This creates a feedback loop where your campaigns increasingly target non‑human visitors. Industry audits consistently place automated traffic between 9% and 20% of paid clicks. Bots click ads, browse landing pages, abandon carts, and sometimes even fill forms. To your billing statement, they are indistinguishable from customers.
The financial impact compounds. You pay for the click, you pay for the downstream optimization that chases more bad traffic, and your sales team wastes time on contacts that will never convert. Recovering that spend requires evidence that meets platform standards — evidence that disappears if you change campaign settings before preserving it.
Mistake 1: Relying Solely on Platform Detection
Meta and Google run automated systems that analyze traffic patterns at the server level. They look for rapid clicking, duplicate click signatures, known bad IPs, and abnormal patterns. These systems catch basic fraud but struggle with advanced botnets that mimic human behavior, use residential proxies, and rotate fingerprints.
Server‑side audits monitor IP addresses, request headers, and user‑agent data. While this catches basic scraper bots, it struggles to detect advanced botnets. Client‑side audits analyze the visitor's browser behavior — mouse movements, scroll depth, form interaction timing, and pointer tremor. Without browser‑level auditing, you pay for visits that never had conversion potential.
The platforms' incentives are misaligned. They bill the click when it happens. Whether that click was human is left to you to prove — after the fact, session by session. An 83% approval rate across filed claims shows refunds are possible, but only when you bring your own evidence.
Mistake 2: Delayed Evidence Collection
Evidence degrades fast. Click IDs, session recordings, and CRM dispositions must be captured at the moment of interaction. If you wait until the monthly performance review to investigate, the click identifiers are gone, the session data has aged out, and the platform's dispute window may have closed.
A practical investigation workflow starts with preserving attribution before changing the campaign. Keep campaign, ad set, creative, placement, and click identifier data intact. Compare ad‑platform data, website sessions, and CRM outcomes before changing targeting or making a refund request. The platforms have no incentive to flag their own revenue. Refunds happen almost exclusively when an advertiser contests specific charges with specific evidence.
BotRefund captures video proof for each flagged click and generates compliance‑ready refund reports. The typical setup takes about one minute with a single script tag. No ad‑account access is required.
Mistake 3: Confusing Low‑Quality Leads With Fraud
Not every bad lead is a bot. A weak campaign can attract real people who are not ready to buy. Treating every unresponsive contact as fraud can make a team exclude a valuable audience. Before calling traffic fraudulent, calculate the normal rate for your account: landing‑page sessions per click, contactable leads, verified leads, qualified opportunities, and revenue by campaign.
Signals worth investigating include contactability issues (disconnected numbers, invalid email domains, repeated addresses), timing anomalies (several leads arriving in short bursts, forms submitted immediately after landing), session behavior (no scrolling, no field corrections, uniform click paths), and campaign patterns (sharp lead‑quality differences by placement, creative, audience expansion, device, or landing page).
A low‑quality lead can be genuine but wrong for the offer. A suspicious session is a signal for investigation, not proof on its own. Look for clusters. Quality normally changes by placement, audience, creative, device, geography, landing page, and time. A sudden gap in one cluster is more useful than a site‑wide average.
Mistake 4: Changing Campaigns Before Preserving Attribution
When performance drops, the instinct is to pause placements, adjust audiences, or swap creatives. Each change severs the link between the original click and the downstream outcome. Without the click identifier, campaign context, timestamp, URL parameters, and CRM record, you cannot prove which specific charges were invalid.
Preserve the click identifier, campaign context, timestamp, URL parameters, CRM record, and any verification result before you change campaign settings. Avoid eliminating an entire audience from a small sample; use enough volume to see a consistent quality pattern. A cheap placement is not a win unless it produces contacts that can be reached and qualified.
Mistake 5: Not Distinguishing Between Traffic Types
Invalid traffic arrives through different channels, each requiring different detection. Meta Audience Network displays ads on thousands of third‑party mobile apps and websites where publishers use bots to generate artificial revenue. Profile scrapers and directory bots crawl Facebook and follow outbound links. Competitor click networks exhaust budgets deliberately. Accidental mobile taps count as invalid activity but aren't fraud.
Google classifies invalid activity as clicks or impressions not resulting from genuine user interest. This includes repeated manual clicks, automated tools, accidental taps, data‑center IPs, impression fraud, and competitor click fraud. Each type leaves different behavioral fingerprints. Superhuman input speed (<1 ms), robotic linear mouse movements, absence of human‑like mouse tremor, grid‑aligned movement patterns, and unnatural session durations are client‑side signals that server logs miss.
Mistake 6: Skipping the Four‑Layer Audit
A structured audit compares four layers before any refund request. First, platform delivery: compare reach, link clicks, landing‑page views, placements, and spend. Second, landing‑page evidence: measure page loads, redirects, consent behavior, form start, form completion, time to completion, and meaningful engagement. A click‑to‑session gap can have ordinary explanations such as app browsers, tracking consent, slow loads, or analytics configuration.
Third, lead verification: record whether an email is deliverable, a phone connects, duplicate details recur, and the prospect confirms interest. Add qualification questions that reveal fit, not just extra fields that make the form longer. Fourth, CRM outcome: a high reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement signals a quality problem worth investigating.
Decision Criteria for Choosing a Detection Approach
Not every brand needs the same level of detection. Use these criteria to decide which solution fits your budget and risk profile.
- Volume of spend. Brands spending over $50 K/month benefit from automated client‑side scripts that capture every click. Smaller budgets may start with manual log reviews.
- Technical resources. If you have a dev team, you can integrate custom JavaScript that sends session data to your own warehouse. If not, a SaaS script tag (like BotRefund) is faster.
- Regulatory constraints. GDPR‑heavy regions require consent before recording mouse movement. Choose a tool that respects privacy flags.
- Speed of refund. Platforms prioritize claims with click‑level evidence. Solutions that export GCLID/fbclid with timestamps reduce dispute time.
- Coverage. Server‑side logs alone miss residential proxies. Client‑side behavioral data fills that gap.
Match your selection to these factors. A mis‑aligned choice can add cost without improving refund rates.
Building a Proper Investigation Workflow
- Install client‑side detection before you need it. A single script tag captures behavioral evidence for every session. This creates the audit trail platforms require.
- Define your quality baseline. Calculate normal rates for sessions per click, contactable leads, verified leads, and qualified opportunities by campaign.
- Monitor for clusters, not averages. Quality changes by placement, audience, creative, device, geography, and time. Investigate sudden gaps in specific clusters.
- Preserve everything before acting. Click IDs, campaign context, timestamps, URL parameters, CRM records, and verification results must be frozen before you pause or adjust anything.
- Match evidence to platform requirements. Google and Meta each have specific evidence formats. Compliance‑ready reports with click IDs, behavioral proof, and timestamps increase approval rates.
- File disputes with specific charges. Contest individual click IDs with supporting evidence. Generic complaints are rejected.
Key Facts
| Metric | Detail | Source |
|---|---|---|
| Automated traffic share of paid clicks | 9%–20% (industry audits) | S6 |
| BotRefund refund claim approval rate | 83% across filed claims | S2, S6 |
| Setup time for detection | ~1 minute, one script tag | S2 |
| Ad‑account access required | No | S6 |
| Detection confidence | 99% for non‑human traffic | S6 |
| Platform detection limitation | Server‑side only; misses advanced botnets | S4 |
| Refund trigger | Advertiser must contest specific charges with specific evidence | S6 |
Limitations
This guidance applies to Meta and Google Ads campaigns where click‑based billing occurs. It does not cover programmatic display bought through DSPs, connected TV, or audio inventory where measurement standards differ. The four‑layer audit assumes you control the landing page and CRM. If you send traffic to third‑party funnels, evidence collection is harder. Broad industry statistics (e.g., Imperva's 2025 report that automated traffic represented more than half of web traffic) are context only — they do not mean half of your clicks are fraudulent. Measure your own sessions and leads.
FAQ
How much invalid traffic is normal?
Industry audits place automated traffic between 9% and 20% of paid clicks. Your account's baseline depends on vertical, geography, placement mix, and creative. Calculate your own normal rates before flagging anomalies.
Can I get refunds for past months without prior detection installed?
Only if you have click IDs, session data, and CRM dispositions preserved from that period. Platforms require specific evidence per charge. Without client‑side capture at the time of the click, retrospective proof is rarely sufficient.
Does blocking bots at the firewall prevent invalid clicks?
Firewalls and server‑side filters block known bad IPs and basic scrapers. They do not stop bots using residential proxies, rotating fingerprints, or human‑like behavioral emulation. Client‑side behavioral verification catches what server logs miss.
What evidence do Meta and Google actually accept?
Both platforms require click identifiers (GCLID for Google, fbclid for Meta), timestamps, behavioral proof (mouse movement, scroll, form interaction), and a clear link to the billed charge. Compliance‑ready reports that package this per‑click increase approval rates.
Should I pause Audience Network to stop bot traffic?
Pausing Audience Network removes a major bot source but also removes legitimate inventory. Audit placement‑level quality first. If a placement shows consistent contactability and CRM failure, exclude it. If quality varies by creative or audience, refine targeting instead.
How long does a refund dispute take?
Varies by platform and claim complexity. Google typically processes invalid activity credits automatically for detected patterns; manual claims take weeks. Meta's process is less transparent. Filing with complete evidence upfront avoids back‑and‑forth delays.
What's the cost of setting up proper detection?
BotRefund charges no upfront fee on enterprise recovery — fees come from recovered spend. Self‑serve tiers start free with a one‑minute script install. No credit card required for the audit.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.