Seatext library / BotRefund evidence
What Evidence Do I Need to Prove Invalid Clicks to Google? A Readiness Checklist
Google requires click timestamps, IP addresses, user agent strings, referrer URLs, GCLID parameters, and server-side access logs that correlate with the suspicious click IDs from your Google Ads report. Behavioral evidence — mouse movements,...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Google requires click timestamps, IP addresses, user agent strings, referrer URLs, GCLID parameters, and server-side access logs that correlate with the suspicious click IDs from your Google Ads report. Behavioral evidence — mouse movements, scroll depth, click timing, and form interactions — separates sophisticated bots from real users. Most claims fail because advertisers submit only server logs, which miss client-side bot signatures.
Google's Official Evidence Requirements
Google's Click Quality Form asks for six specific fields. Each field maps to a data point your tracking must capture at the moment of the click. Missing any field forces the reviewer to guess, and guesses favor the platform.
- Click timestamp — exact date, hour, minute, and second in UTC.
- IP address — the visitor's public IP at click time.
- User agent string — full browser identification header.
- Referrer URL — the page that sent the visitor to your landing page.
- GCLID — the Google Click Identifier parameter appended to your landing page URL.
- Click ID from Google Ads report — the internal click ID Google assigns in your invalid activity report.
Server logs capture the first five automatically. The sixth comes from your Google Ads invalid activity report. You must join them on timestamp and IP or GCLID. A spreadsheet with one row per suspicious click is the minimum viable submission.
The Six Core Evidence Fields Google Reviewers Check
ClickFortify's template analysis confirms these six fields are what human reviewers at Google actually verify. Each field serves a distinct purpose:
| Field | Why It Matters | Common Gap |
|---|---|---|
| Timestamp (UTC) | Aligns your log entry with Google's billing record | Timezone mismatch between server and Google Ads account |
| IP Address | Flags data center, VPN, or known proxy ranges | Load balancer or CDN masks original IP |
| User Agent | Identifies headless browsers, outdated versions, or mismatched OS/browser combos | Bot spoofs common Chrome UA string |
| Referrer URL | Shows whether click came from Google search, partner site, or direct navigation | Referrer stripped by redirect chain or privacy settings |
| GCLID | Proves the click originated from a paid Google ad impression | Auto-tagging off, or GCLID dropped by landing page redirect |
| Google Click ID | Links your evidence to the exact line item in Google's invalid activity report | Report downloaded without click-level detail |
If your landing page redirects before your analytics script fires, you lose the GCLID. Fix the redirect order or capture the GCLID in a cookie before the redirect.
Client-Side vs Server-Side Evidence — Why Both Matter
Server-side logs see the request. Client-side scripts see the behavior. Google's automated filters catch basic patterns — rapid clicks from one IP, known data center ranges, duplicate click signatures. They miss sophisticated invalid traffic (SIVT) that mimics human IP diversity and timing.
BotRefund's detection layer captures behavioral signals that server logs cannot: ghost clicks without human intent sequence, honeypot trap interactions, robotic linear mouse movements, absence of humanlike mouse tremor, superhuman input speed under 1 millisecond, grid-aligned movement patterns, absence of clicks or scrolling, and unnatural session durations. These signals turn a suspicious IP into a proven bot session.
Without browser-level auditing, you pay for visits that load pages but never read, scroll, or convert. Client-side evidence is what converts a denied claim into an approved refund.
Behavioral Signals That Distinguish Bots from Humans
Not all non-human traffic looks the same. The evidence you submit should match the fraud type:
- Click farms — real devices, real residential IPs, but repetitive timing and zero scroll depth. Evidence: session duration clusters, identical click intervals, zero engagement events.
- Residential proxy botnets — malware on consumer devices, rotating IPs. Evidence: inconsistent user agent vs. IP geography, missing browser APIs, automated form fills.
- Headless browser scripts — Puppeteer, Playwright, Selenium. Evidence: missing chrome.runtime, navigator.webdriver flag, perfect linear mouse paths, zero tremor.
- Scraper bots — fast, no rendering, no JavaScript execution. Evidence: missing client-side cookies, no paint timing events, request-only logs.
Each type leaves a different fingerprint. Your evidence package should label the suspected fraud type and attach the matching behavioral proof.
Building Your Evidence Collection Workflow
A repeatable workflow beats ad-hoc scrambling every time Google's invalid activity report arrives.
- Enable auto-tagging in Google Ads so every paid click carries a GCLID.
- Capture GCLID on landing — write it to a first-party cookie before any redirect.
- Log server requests — timestamp, IP, user agent, referrer, GCLID cookie value, request ID.
- Deploy client-side behavioral tracking — mouse move, scroll, click, focus, form events with timestamps.
- Join server and client logs on request ID or session ID daily.
- Pull Google Ads invalid activity report weekly — download click-level detail, not summary.
- Match suspicious click IDs to your joined logs using timestamp + IP + GCLID.
- Package evidence — one CSV per claim, one row per click, all six core fields plus behavioral flags.
- Submit via Click Quality Form — attach CSV, note fraud type, reference behavioral evidence.
- Track claim status — log submission date, claim ID, outcome, credit amount.
Step 4 is where most advertisers stop. Server logs alone rarely meet Google's "compliance-grade" threshold for SIVT. The 83% approval rate BotRefund sees across filed claims comes from adding client-side behavioral evidence to every flagged click.
Common Mistakes That Get Claims Denied
| Mistake | Result | Fix |
|---|---|---|
| Submitting only Google's auto-filtered credits | Leaves 50%+ of invalid traffic unclaimed | File manual claims for SIVT Google missed |
| Timezone mismatch between server logs and Google Ads | Reviewer cannot align click to billing record | Store all timestamps in UTC; convert Google report to UTC |
| CDN or load balancer strips original IP | IP shows your infrastructure, not visitor | Configure X-Forwarded-For header logging; verify at origin |
| GCLID lost in redirect chain | Cannot prove click came from paid ad | Capture GCLID before redirect; pass via cookie or query param |
| No client-side behavioral data | Cannot distinguish sophisticated bots from humans | Deploy lightweight browser script capturing mouse, scroll, timing |
| Submitting aggregate stats instead of click-level rows | Reviewer rejects — cannot verify individual clicks | One row per suspicious click ID; no summaries |
| Waiting too long to file | Google's lookback window expires; logs rotated | Weekly report pull; 60-day log retention minimum |
Key Facts
| Metric | Value | Source |
|---|---|---|
| Global digital ad fraud projection (2026) | Over $100 billion | S1 |
| Average invalid click rate across Google Ads campaigns | 11% to 14% | S1 |
| Google's automated filters catch rate | Less than 50% of invalid traffic | S1 |
| BotRefund detection confidence | 99% | S2, S7 |
| BotRefund refund claim approval rate | 83% | S2, S7 |
| Refund lookback window supported | Google Ads spend dating back to 2017 | S2 |
| Typical automated traffic share of paid clicks | 9% to 20% | S7 |
| Setup requirement | One script tag, ~1 minute, no ad-account access | S7 |
Limitations & When This Advice Doesn't Apply
- Low-volume accounts — under $1,000/month spend may not justify the evidence collection effort. Google's automatic credits often cover the bulk.
- Brand-only campaigns — competitor click fraud is rare on exact-match brand terms. Invalid clicks here are usually accidental mobile taps.
- No landing page control — if you cannot add a script tag (e.g., affiliate offers, third-party funnels), you cannot collect client-side evidence.
- Google Ads Express / Smart campaigns — limited reporting granularity makes click-level matching difficult.
- Non-Google platforms — this checklist targets Google's Click Quality Form. Meta, Microsoft, and TikTok have different evidence requirements.
FAQ
How far back can I claim refunds for invalid clicks?
Google typically allows claims for the past 60 days. BotRefund recovers spend dating back to 2017 by leveraging platform dispute channels that accept older evidence when behavioral proof is strong.
Do I need to give Google access to my ad account?
No. The Click Quality Form is a standalone submission. BotRefund also operates without ad-account access — one script tag on your site is sufficient.
What if my claim is denied?
Denials usually cite insufficient evidence. Re-file with client-side behavioral data attached. Each click needs mouse movement, scroll, and timing logs that prove non-human interaction.
How long does Google take to review a claim?
Typically 5–10 business days. Complex SIVT claims with behavioral evidence may take longer but have higher approval rates.
Can I automate evidence collection?
Yes. Server log joins can be scheduled. Client-side behavioral capture requires a persistent script. BotRefund automates both and generates the CSV package formatted for Google's form.
What's the difference between invalid clicks and click fraud?
Invalid clicks include accidental taps, duplicate clicks, and fraud. Click fraud is intentional — competitors or bots draining budget. Google treats both as invalid activity, but fraud evidence requires behavioral proof of automation.
Does this work for Performance Max and Demand Gen campaigns?
Yes. These campaign types still generate GCLIDs and appear in the invalid activity report. The evidence requirements are identical.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.