Seatext library / BotRefund evidence

What Browser Fingerprinting Signals Does BotRefund Use?

BotRefund checks browser fingerprinting signals such as user agent, language, timezone, screen resolution, canvas fingerprint, WebGL, and CPU concurrency. It treats each signal as evidence rather than a verdict, then cross-checks the complete pattern...

Built for advertisers who need clear, refund-ready traffic evidence.

BotRefund uses browser fingerprinting signals such as user agent, language, timezone, screen resolution, canvas fingerprint, WebGL, and CPU concurrency. It also reads hardware and GPU details, network ports, and behavioral marks like mouse movement and click timing.

No single signal decides anything on its own. BotRefund collects each one as independent evidence and cross-checks the full pattern before it labels a visit as human or automated.

What browser fingerprinting means

A browser fingerprint is a collection of settings and hardware details a browser reveals about a device. User agent, screen size, installed fonts, graphics renderer, and processor cores all contribute. Together they often form a pattern unique enough to identify a browser without tracking cookies.

Think of it like a person’s handwriting. No two people write exactly alike. Similarly, no two browsers render the same image or report the same combination of system details. That uniqueness is what fingerprinting measures.

BotRefund uses this fingerprint as one layer of detection. The browser layer records what the device claims to be, while the network and behavior layers record what the visit actually does. The fingerprint might say one thing, but behavior might say another. That mismatch is a clue.

The fingerprinting signals BotRefund checks

BotRefund runs 106 independent checks per visit. Some are static; others are behavioral. Here is a breakdown of the key fingerprinting signals.

User agent, language, and timezone

  • User agent — the browser's self-reported name, version, and operating system.
  • Language — the list of languages the visitor accepts.
  • Timezone — the local time offset the device reports.

A normal browser keeps these loosely consistent. A browser on a phone in Tokyo usually reports a Japanese language list and a UTC+9 offset. A spoofed browser might claim Windows but report a Mac user agent. BotRefund looks for such contradictions.

Screen resolution and canvas fingerprint

Screen resolution is the visible display size. Canvas fingerprinting uses an invisible drawing test. The same image renders in slightly different pixels depending on the graphics stack. That variation is hard to fake precisely.

For example, two users with identical monitors may see the same colors. But the canvas element turns those colors into raw pixel data. Slight differences in anti-aliasing, font rendering, and GPU drivers create a unique pattern. Bots often use headless browsers that render the canvas differently.

WebGL and hardware details

WebGL exposes the graphics card model and renderer through the browser. It also reports GPU vendor, renderer name, and supported extensions. A normal browser reports hardware that matches the device. A bot might report a generic GPU or one that does not exist.

BotRefund also checks font lists and operating system details. This creates a profile of the device. The profile must be internally consistent. For instance, a device with 4 cores but 16GB of RAM is plausible. But a device that claims to be an iPhone and also reports a desktop GPU is not.

CPU concurrency

CPU concurrency reports how many processor cores a browser can use. The CPU Concurrency Lie check looks for a mismatch between that count and what the rest of the device profile claims. Virtual machines and spoofed profiles often contradict themselves here.

For example, a normal browsing session on a laptop might report 8 cores. A bot running in a low-end VM might report 2 cores, but the user agent claims a high-end gaming PC. That mismatch is a red flag. BotRefund documents this as one of its 106 independent checks.

Network and behavior checks

Fingerprinting is not limited to the browser. BotRefund also flags suspicious network ports, window.open tampering, ghost clicks, honeypot traps, robotic pointer movement, and superhuman input speed. These behavioral signals complement the static fingerprint.

Suspicious ports are those commonly used by proxies or VPNs. Window.open tamper detects scripts that open new windows in unexpected ways. Ghost clicks appear without a user action. Honeypot traps are hidden fields that bots fill but humans do not.

Pointer behavior is especially telling. Real humans move with small, natural jitters. Bots often move in straight lines or perfect arcs. BotRefund measures that movement. It also tracks input speed. A real person cannot type or click in under one millisecond. Bots can.

How BotRefund combines these signals

No single signal is conclusive. Instead, BotRefund treats each signal as a vote. It then cross-references the full set of votes against independent browser, network, device, and behavior data.

The system uses a prediction AI model. The model weighs the complete pattern rather than trusting any raw rule alone. That is why BotRefund claims 99% accuracy. Accuracy comes from corroboration, not one browser tell.

For instance, a user agent might be spoofed. That alone is not proof of a bot. But if the same visit also has a mismatched CPU concurrency, suspicious ports, and robotic pointer paths, the pattern becomes clear. The AI assigns a confidence score and flags the visit.

Why a single anomaly is never a verdict

Privacy tools, travel, corporate networks, and unusual devices can make a real person's browser look inconsistent. A blocked canvas read, a VPN, or a remote desktop session changes these signals for ordinary users.

Consider a business traveler. They might be on a corporate VPN with a different timezone. Their browser might have a language list that does not match their location. Their canvas could be blocked by privacy software. All these anomalies would occur without any bot activity.

That is why the fingerprint is evidence, not a verdict. Each signal adds one objective fact, and BotRefund tests whether other signals support the same story. If one signal is odd but everything else lines up, the visit is likely human. If many signals disagree, the risk rises.

The diagnostic sequence in practice

BotRefund processes each visit in a three-stage sequence. This sequence is described in its documentation as follows:

  1. Independent evidence. Each check produces one objective fact about the visit, such as a CPU core count or a canvas render result.
  2. Cross-checked context. BotRefund asks whether other browser, network, and device signals agree with that fact.
  3. AI prediction. The model weighs the complete pattern rather than trusting any raw rule alone.

An example will clarify. A visit arrives with a user agent for an iPhone 14. The CPU concurrency reports 4 cores. That is plausible. The canvas fingerprint matches known iPhone 14 values. The timezone is UTC+5, which does not match the IP location. But the pointer movement is natural and the session lasts 3 minutes. The AI sees a real person using a VPN.

Another visit arrives with the same user agent. The CPU concurrency reports 2 cores. The canvas is blank. The pointer moves in perfect straight lines at 50 pixels per second. The session lasts 0.2 seconds. The AI sees a headless browser. The verdict is bot.

Why fingerprinting matters for ad spend

When bot clicks hit paid ads, they inflate costs and corrupt conversion data. If fingerprinting is ignored, those clicks look like real visitors. Google and Meta keep charging for them. BotRefund states that bot clicks can steal up to 20% of Google and Meta ad budget.

The financial impact is direct. An advertiser might see a cost per acquisition of $50. But if 20% of those clicks are bots, the real cost is $62.50. The ad platform also trains on bad conversions. That degrades campaign optimization.

Worse, the advertiser may make bad decisions. They might raise bids on a placement that is full of bots. They might pause a winning ad set because the conversion data is polluted. Fingerprinting helps identify the problem so the advertiser can act.

BotRefund uses the fingerprint evidence to file refund claims. The system captures video proof of each bot click. That documentation supports negotiations with Google and Meta.

Limitations and edge cases

Fingerprinting cannot reliably identify a bot on its own. Real users on VPNs, public Wi-Fi, or privacy browsers will look unusual. BotRefund accounts for this by keeping each signal as evidence rather than a trigger.

Fingerprinting also says nothing about intent. A scraped page, a load-test script, and a legitimate visitor can share some signals. For example, a load-test script may use a real browser engine. It will pass fingerprint checks. But it might have superhuman click speeds or no scroll activity. The behavior layer will catch that.

Finally, fingerprinting is only one gate. Refund decisions with Google and Meta depend on documented proof of invalid clicks, not just a fingerprint score. BotRefund must provide a complete audit trail.

Frequently asked questions

What is a browser fingerprint?

A set of browser and device characteristics that together can identify a visitor without cookies, such as screen resolution, fonts, GPU, and timezone.

Which BotRefund signal is most important?

None alone is decisive. The value comes from how the signals corroborate one another before the AI model makes a prediction.

Can a VPN cause a false positive?

Yes, in theory. Corporate networks, travel, and privacy tools can make a genuine person look inconsistent, which is why BotRefund does not treat a single anomaly as a bot verdict.

Does BotRefund use behavior too?

Yes. It tracks ghost clicks, honeypot traps, pointer paths, motion tremor, input speed, and session duration alongside the static fingerprint.

How many checks does BotRefund run?

BotRefund reports 106 independent checks that build the full picture of a visit.

How does the fingerprint support a refund claim?

The checks produce documentation that BotRefund uses to prove bot clicks when negotiating with Google and Meta.

What is the CPU Concurrency Lie?

It is a check that detects mismatches between the reported processor core count and the device profile. Bots and virtual machines often show such contradictions.

What are some examples of behavioral signals?

Ghost clicks, honeypot interactions, robotic linear mouse movements, absence of human tremor, input speed under one millisecond, and grid-aligned movement patterns.

How fast is the setup?

BotRefund can be added to a website in about one minute. No credit card is required for the initial free audit.

AreaWhat BotRefund checks
Browser layerUser agent, language, timezone, screen resolution, canvas, WebGL
Hardware layerCPU concurrency, GPU, graphics, fonts, operating-system details
Network layerSuspicious ports, connection and location coherence
Behavior layerGhost clicks, honeypot traps, pointer movement, motion tremor, input speed, path pattern, engagement, session duration
Decision ruleSingle anomaly is not a verdict; signals are cross-checked
Total checks106 independent checks per visit (BotRefund claim)
Reported accuracy99% based on corroboration (BotRefund claim)
SetupAbout one minute to add, no credit card required

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more