Seatext library / BotRefund evidence
Signs Your Landing Page Forms Are Being Targeted by Bots
Sudden spikes in submissions, nonsense or repeated data, submissions at inhuman speeds, high bounce rates from form pages, and CRM clutter with fake leads all signal bot activity. These patterns distort your ad platform...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
If your landing page forms suddenly flood with submissions that never turn into real conversations, bots are likely the cause. The clearest signals are submissions arriving faster than a human can type, identical field patterns across dozens of leads, sessions with zero scrolling or mouse movement, and a CRM full of contacts that bounce, disconnect, or vanish when sales reaches out.
These patterns matter because they do more than clutter your database. When bots trigger conversion pixels, Google and Meta's bidding algorithms learn to chase the bot fingerprint instead of real buyers. Your cost per acquisition rises while lead quality tanks. The good news: each of these signals leaves a forensic trail you can audit before you spend another dollar on bad traffic.
Why bots target your forms in the first place
Landing page forms are low-friction conversion points. A bot operator — whether a competitor clicking your ads, a publisher inflating Audience Network revenue, or an affiliate farming CPL payouts — only needs to load the page and hit submit. The payout is immediate: they collect a commission, drain your budget, or poison your pixel so the platform optimizes for more of the same traffic.
Meta's Audience Network is a common vector. Publishers on that network run scripts that click ads in their own apps to generate artificial revenue. Those clicks land on your landing page, trigger your form, and register as conversions. Source S5 notes that "Clicks originating from the Audience Network have historically shown high click-through rates (CTRs) and near-instant bounce rates." The same dynamic plays out on Google's Display Network and partner sites.
In B2B SaaS, affiliate programs that pay per trial signup create a direct incentive for automated registrations. Source S6 describes how "Rogue publishers configure scripts to register dummy account credentials, polluting your customer success metrics and CRM pipeline." The forms are standard, the fields are predictable, and the reward is cash per lead — no purchase required.
The diagnostic sequence: confirm bot activity before you react
Not every bad lead is a bot. A weak offer attracts real people who don't buy. Treating all unresponsive contacts as fraud makes you exclude valuable audiences. Start with a structured audit that compares ad-platform data, website sessions, and CRM outcomes. Source S7 recommends: "Start with a structured audit that compares ad-platform data, website sessions, and CRM outcomes before changing targeting or making a refund request."
Step 1: Preserve attribution before changing anything
Keep campaign, ad set, creative, placement, click identifier (GCLID, FBCLID), landing-page URL, and timestamp intact. If you pause campaigns or swap landing pages first, you lose the thread that ties a bad lead to its source.
Step 2: Cross-reference three data layers
- Ad platform: Placement-level lead volume, CPC, CTR, conversion rate by device and audience expansion setting.
- Website analytics: Session duration, scroll depth, mouse movement, focus events, keypress timing on the form page.
- CRM: Contact validity (email format, phone connectivity), sales outreach outcome (connected, disqualified, ghosted), time-to-first-activity.
Look for mismatches. High ad-platform conversion rate + near-zero scroll depth + zero CRM contactability = bot signature.
Step 3: Segment by placement and creative
Bot traffic often concentrates in specific placements. Source S7 flags "a sharp lead-quality difference by placement, creative, audience expansion, device, or landing page" as a campaign pattern worth investigating. If 80% of your junk leads come from one Audience Network placement, the fix is a placement exclusion — not a whole-campaign rewrite.
Step 4: Check timing clusters
Human leads arrive on a distribution. Bot leads arrive in bursts. Source S7 lists "several leads arriving in short bursts, forms submitted immediately after landing, or conversions concentrated at unusual hours" as timing signals. Plot submission timestamps by hour and minute. A spike of 20 submissions in 3 minutes at 3 AM is not organic.
Technical signatures that distinguish bots from humans
Behavioral telemetry catches what IP reputation and user-agent strings miss. Modern bots rotate residential proxies, spoof headers, and mimic browser fingerprints. But they struggle to fake the physical micro-behaviors of human input.
Superhuman input speed
A human needs seconds to tab through fields, type a company name, and enter a corporate email. Bots populate multiple inputs in milliseconds. Source S6 identifies "Superhuman Input Speed: Bots populate multiple form inputs instantly. A human user requires seconds to type their company details and email." Source S2 quantifies this: "Superhuman input speed (<1ms)." If your form analytics show field-to-field transitions under 100ms consistently, you're seeing script injection.
Absence of UI focus states
Real users click into a field, the browser fires a focus event, the cursor blinks, they type. Headless form fillers (Puppeteer, Playwright, Selenium) often set field values directly via DOM without triggering focus, blur, or change events in the natural sequence. Source S6 notes "Lack of UI Focus States: Sessions where inputs are populated without mouse coordinate swaps, focus triggers, or page scroll telemetry suggest script inputs."
Missing mouse tremor and natural curves
Human mouse movement has micro-jitter — tiny imperfections from hand tremor. Bot paths are often mathematically straight or grid-aligned. Source S2 lists "Absence of humanlike mouse tremor" and "Grid-aligned movement patterns" as detection signals. If session replays show pointer paths that snap to perfect lines or jump between coordinates without curves, that's automation.
No scroll, no dwell, no corrections
Real visitors scroll, hesitate, backspace, re-read. Bot sessions often show zero scroll events, uniform dwell times, and zero field corrections. Source S7 flags "no scrolling, no field corrections, uniform click paths, and no meaningful time on the offer page" as session behavior signals.
Honeypot trap interactions
Hidden fields that humans never see (CSS display:none, off-screen positioning, aria-hidden) are invisible to people but visible to scrapers parsing the DOM. When a honeypot field gets a value, you know the submitter read the HTML, not the rendered page. Source S2 describes "Honeypot trap interactions: Watches for bots that respond to hidden or intentionally deceptive page elements."
How bot contamination corrupts your marketing data
The damage compounds beyond wasted click spend. When bots trigger your conversion pixel, they send a "success" signal to the ad platform's bidding algorithm. The algorithm then optimizes to find more users who look like that bot — same device, same geo, same time-of-day, same behavioral fingerprint.
Source S4 explains the mechanism: "The algorithm interprets these bot sessions as 'successful conversions' and automatically shifts your campaign's bidding parameters to acquire more users matching that exact bot fingerprint." This is pixel poisoning. Your smart bidding campaigns (Performance Max, Advantage+ Shopping, Advantage+ Leads) start buying more bot traffic because the math says it converts.
The result: your reported cost-per-lead looks great, but your sales team talks to ghosts. Source S1 documents this exact pattern: "High volume of robotic form submission spam on landing pages, polluting HubSpot CRM data and exhausting search advertising conversion credit." The case study found "19% fake leads" and recovered "$18,200" in ad spend.
Retargeting and lookalike audiences suffer too. Source S4 notes that "fake cart additions poison retargeting and lookalikes" — the same principle applies to form submissions. Your lookalike seeds become bot profiles. Your retargeting pools fill with non-buyers. The contamination spreads across your entire funnel.
Common false positives: what looks like bots but isn't
Before you block traffic or demand refunds, rule out these look-alikes:
- Low-intent real users: Clicked by accident, bounced fast, never filled the form. They show low dwell but no form submission.
- Form autofill: Browser password managers and address autofill can populate fields fast. But they still trigger focus events, and the user usually reviews before submit.
- Accessibility tools: Screen readers and voice input produce atypical but human interaction patterns. They trigger focus and scroll events differently.
- QA and internal testing: Your own team or agency running test submissions. Use a test UTM parameter or IP exclusion.
- Legitimate high-volume periods: A viral post, PR hit, or sale can cause genuine submission spikes. Check if the leads have real contact info and varied timestamps.
The differentiator is the combination: superhuman speed + zero scroll + zero corrections + invalid contact info + burst timing. One signal alone is weak. Three together is diagnostic.
When to escalate: from detection to refund recovery
Once you've confirmed bot patterns, you have two parallel tracks: stop the bleeding and recover what you've lost.
Stop the bleeding: client-side suppression
Server-side filters (IP blocklists, user-agent rules, WAF rules) catch basic scrapers but miss residential proxy botnets that rotate IPs and spoof headers. Source S3 states: "Server-side audits look at server log files. They monitor IP addresses, request headers, and user-agent data. While this catches basic scraper bots, it struggles to detect advanced botnets."
Client-side behavioral telemetry runs in the browser. It sees the mouse tremor, the focus sequence, the keypress timing, the scroll depth — signals the server never receives. Source S2 describes BotRefund's approach: "Catches click activity that happens without the natural sequence of human intent" and "Flags unnaturally straight pointer paths that rarely appear in real user sessions." When the script detects a bot, it suppresses the conversion pixel fire so the ad platform never receives the false success signal.
Recover wasted spend: evidence-backed disputes
Google and Meta have refund processes for invalid traffic, but they require evidence. Platform-side filters (Google's invalid click detection, Meta's traffic quality systems) catch some fraud but miss sophisticated bots that mimic human behavior well enough to pass their server-side checks.
You need forensic logs: click IDs (GCLID, FBCLID), timestamps, behavioral signatures, and a clear narrative tying the invalid clicks to specific campaigns. Source S2 claims "83% refund success rate for high-volume advertisers" and "Recover bot-click refunds from Google Ads spend dating back to 2017." Source S8 describes generating "compliance-ready refund reports" with "Auto-capture FBCLIDs for dispute evidence."
The refund window matters. Google typically allows 60 days for invalid click reports; Meta's window varies. Document continuously so you're not scrambling at the deadline.
Key facts at a glance
| Metric | Value | Source |
|---|---|---|
| Average bot click rate on ad spend | Up to 20% | S2 |
| Fake lead percentage identified in B2B case study | 19% | S1 |
| Ad spend recovered in Digitopia case study | $18,200 | S1 |
| Conversion rate increase after bot suppression | +22% | S1 |
| Refund success rate for high-volume advertisers | 83% | S2 |
| Superhuman input speed threshold | <1ms | S2 |
| Refund lookback window (Google Ads) | Dating back to 2017 | S2 |
Limitations and when this advice doesn't apply
- Low-traffic sites: If you get 5 form fills a month, statistical patterns won't emerge. Manual review works better.
- No ad spend: Organic form spam exists but doesn't trigger pixel poisoning or refund eligibility. The remediation is different (CAPTCHA, honeypot, rate limiting).
- Server-side only analytics: If you cannot add client-side JavaScript (strict CSP, AMP pages, privacy regulations), behavioral telemetry is unavailable. You're limited to IP/UA analysis.
- Non-standard form implementations: React/Angular/Vue forms that bypass native DOM events may not emit the focus/keypress signals detection scripts expect. Custom integration needed.
- GDPR/CCPA constraints: Behavioral fingerprinting may count as personal data processing. Legal review required before deploying client-side tracking in regulated jurisdictions.
Terminology quick reference
- Pixel poisoning: Bots triggering conversion pixels, causing ad algorithms to optimize for bot-like traffic.
- Client-side telemetry: JavaScript running in the visitor's browser that captures mouse, keyboard, scroll, and focus events.
- Headless browser: A browser without a GUI (Puppeteer, Playwright) used for automation; detectable via missing renderer signals.
- Honeypot field: A hidden form input that humans never see but bots fill, revealing automation.
- GCLID/FBCLID: Google Click ID / Facebook Click ID — unique parameters appended to landing page URLs for attribution.
- Invalid traffic (IVT): Google and Meta's term for non-human interactions (bots, scrapers, click farms) eligible for refund.
- Residential proxy: A proxy network routing traffic through real residential IPs, making IP blocklists ineffective.
FAQ
How fast is "too fast" for human form completion?
Under 1 second for a multi-field form (name, email, company, phone) is physically implausible. Source S2 flags "Superhuman input speed (<1ms)" for individual interactions. For a full form, anything under 3-5 seconds warrants scrutiny, especially if repeated across many sessions.
Can't I just use reCAPTCHA or hCaptcha?
CAPTCHAs stop basic bots but add friction for real users (conversion rate drops 10-30% in many tests). Advanced bots use CAPTCHA-solving services (2Captcha, Anti-Captcha) that employ human solvers. Behavioral telemetry catches the automation before the CAPTCHA even loads.
What's the difference between a bot and a low-quality lead?
A low-quality lead is a real person who isn't ready to buy. They scroll, hesitate, maybe fill the form partially, and their contact info works. A bot shows zero engagement signals, superhuman speed, and fake contact data. Source S7 emphasizes: "Not every bad lead is a bot, and that matters. Treating every unresponsive contact as fraud can make a team exclude a valuable audience."
How far back can I claim refunds for bot clicks?
Google Ads typically allows 60 days for invalid click reports, but Source S2 notes recovery "from Google Ads spend dating back to 2017" for established accounts with historical evidence. Meta's window is less public; document continuously and file quarterly.
Do I need to install code on every landing page?
Yes. Behavioral telemetry must run on the page where the form lives. If you use multiple landing page builders (Unbounce, Webflow, WordPress, custom), each needs the script. Source S2 claims "Add BotRefund to your website in about one minute."
Will blocking bots hurt my Quality Score or ad relevance?
No. Suppressing conversion pixels for bot sessions prevents the algorithm from learning the wrong signals. Your reported conversion count drops, but the remaining conversions are real. Over time, the algorithm optimizes for actual buyers, improving true ROAS.
What if my forms are behind a login or in a gated portal?
Bots rarely reach authenticated forms unless they have credential stuffing lists. The risk shifts to account takeover and fake account creation. Different detection signals apply (login velocity, credential reuse, device fingerprinting). This article covers pre-login landing page forms.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.