Seatext library / BotRefund evidence
What Steps Should I Take If I Suspect Ad Click Fraud? A Practical Action Plan
If you suspect click fraud, immediately pause the affected campaigns, gather behavioral evidence (GCLIDs, FBCLIDs, session data), document patterns like timed bursts or geographic clusters, file a formal refund request with Google or Meta...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Click fraud wastes budget, skews conversion data, and poisons the machine-learning models that optimize your campaigns. The moment you notice a pattern — budget draining at the same hour every day, clicks from a single city that never convert, or form fills completed in under a second — treat it as an active incident. The steps below move you from suspicion to documented proof to a platform refund request, with a verification checkpoint at each stage.
Step 1: Freeze the Bleeding — Pause or Isolate Affected Campaigns
Before you investigate, stop the financial loss. In Google Ads, pause the specific campaign or ad group showing the anomaly. In Meta Ads Manager, turn off the ad set or exclude the placement (often Audience Network) driving the suspicious volume. If you cannot pause because of volume commitments, apply a tight IP exclusion list for the offending ranges while you collect evidence. This buys you time without nuking your entire account.
Step 2: Confirm the Pattern — Separate Fraud from Poor Performance
Not every low-converting campaign is fraud. Look for the technical fingerprints that distinguish automated traffic from human disinterest. The most reliable indicators appear in combination:
- Consistent timing: Budget exhausts at the same hour daily, suggesting a script on a cron job.
- Geographic concentration: Spikes from a city or region matching a competitor's office location.
- Regular intervals: Clicks arriving every 5, 10, or 15 minutes like clockwork.
- High CTR with zero conversions: Competitors want to drain budget, not buy.
- Weekend and holiday activity: Fraud often runs outside business hours when no one monitors.
- Superhuman speed: Form submissions or button clicks under 1 ms, far faster than human reaction time.
- Absence of mouse tremor: Linear, grid-aligned pointer paths without the micro-jitter of a real hand.
If you see three or more of these together, treat it as probable fraud and move to evidence collection.
Step 3: Capture Forensic Evidence — Client-Side Signals Beat Server Logs
Server logs (IP, user-agent, referrer) are easily spoofed. Platforms require behavioral proof tied to the click IDs they issue. You need:
- GCLIDs (Google Click IDs) and FBCLIDs (Facebook Click IDs) captured at landing-page load, linked to the session.
- Full browser fingerprint: 106 signals covering network (WebRTC leaks, DNS routing, TCP TTL), evasion (CDP debugger leaks, automation properties), and behavior (mouse tremor, scroll depth, session duration variance).
- Timestamped session recordings or event logs showing the missing human micro-behaviors: no scroll, no field corrections, instant form submit.
BotRefund's script captures these automatically and tags each session with the platform click ID, producing a CSV or PDF report formatted for Google's and Meta's dispute portals.
Step 4: Do Not Contact the Suspected Competitor
Confrontation without a platform-verified report exposes you to defamation claims and gives the bad actor time to wipe logs or shift infrastructure. Keep the investigation internal. Share findings only with your legal counsel or the ad platform's invalid-traffic team.
Step 5: File the Platform Refund Request — Use Their Forms, Not Email
Google Ads: Open the Invalid Clicks Contact Form. Attach your evidence CSV, list the campaign IDs, date ranges, and the specific click IDs you flag. Google typically responds in 5–10 business days.
Meta Ads: Use the Meta Ad Refund Request form. Include FBCLIDs, placement breakdown (Audience Network vs. Feed), and the behavioral anomaly report. Meta's review window is similar.
Both platforms require the click IDs they issued. Without them, the request is rejected automatically.
Step 6: Implement Ongoing Detection — Stop the Next Wave Before It Starts
A one-time refund recovers past loss; continuous client-side detection prevents the next 20% drain. Deploy a lightweight script that:
- Scores every visitor in real time using the full 106-signal pattern (network, evasion, behavior).
- Auto-excludes confirmed bots via the platform's API (Google Ads IP exclusion list, Meta custom audience exclusion).
- Logs every flagged session with its click ID for future disputes.
- Runs in ~1 minute install, no credit card, and covers historical Google Ads spend back to 2017.
Verification Checkpoint: Did the Refund Come Through?
After the platform's review window, check your billing summary for a "Invalid activity" credit line. If approved, the credit appears as a negative line item. If denied, request the specific reason code, supplement with additional behavioral logs (e.g., new sessions from the same IP block showing identical automation fingerprints), and re-file. BotRefund users see an 83% approval rate on high-volume accounts because the evidence package matches the platform's exact evidence schema.
Key Facts at a Glance
| Metric | Detail | Source |
|---|---|---|
| Typical budget loss to bots | Up to 20% of Google and Meta ad spend | S2 |
| Refund success rate (high-volume) | 83% approval across client claims | S2 |
| Detection signals analyzed | 106 browser, network, hardware, behavior signals | S1 |
| Historical recovery window (Google) | Spend dating back to 2017 | S2 |
| Install time | About one minute, no credit card required | S2 |
| Evidence captured automatically | GCLIDs, FBCLIDs, full behavioral fingerprint | S6, S4 |
Common Mistakes That Kill Refund Claims
- Relying only on IP exclusions: Residential proxy botnets rotate clean consumer IPs daily.
- Submitting server logs without click IDs: Platforms reject evidence that cannot be tied to their own billing records.
- Waiting too long: Google and Meta have lookback limits; file within 60 days of the suspicious activity.
- Treating all low-quality leads as fraud: Real users with low intent still count as valid traffic; exclude only sessions with automation fingerprints.
When This Process Does Not Apply
- Brand-new accounts with under $1,000/mo spend — platform review teams prioritize higher-volume advertisers.
- Fraud originating from your own team (internal testing, QA scripts) — exclude your office IPs first.
- Invalid traffic on platforms without a formal dispute process (some DSPs, programmatic exchanges).
FAQ
How long does a refund take once I file?
Typically 5–10 business days for Google, 7–14 for Meta. Complex cases with large volumes can take 30 days.
Can I get refunds for clicks from months ago?
Google allows disputes on spend back to 2017 if you have the click IDs and behavioral evidence. Meta's window is shorter, usually 60–90 days.
What if the platform denies my claim?
Request the denial reason code. Most denials cite "insufficient evidence." Add new sessions from the same fingerprint cluster, re-export the report, and re-file. Persistence with better data often flips the decision.
Does blocking bots hurt my legitimate traffic?
Client-side behavioral detection scores the full 106-signal pattern, not single flags. False-positive rates are near zero because a real human cannot simultaneously lack mouse tremor, have superhuman click speed, and show WebRTC leaks.
How much does ongoing protection cost?
BotRefund's free tier covers detection and evidence capture. Paid tiers scale with ad spend and add auto-exclusion API calls and dedicated dispute support.
Can I use this for Amazon Ads or TikTok?
The evidence-collection method (click IDs + behavioral fingerprint) works on any platform that issues a click identifier and has a dispute form. BotRefund's current auto-exclusion APIs support Google and Meta; other platforms require manual exclusion uploads.
How BotRefund Helps
BotRefund installs in about a minute and immediately starts capturing the 106-signal behavioral fingerprint for every paid click. It ties each session to the platform's own click ID (GCLID or FBCLID), auto-generates the CSV/PDF evidence package formatted for Google's and Meta's dispute portals, and — on paid plans — pushes confirmed bot IPs to the platforms' exclusion APIs in real time. The free tier gives you the detection and evidence; you only pay when you need automated exclusion and hands-on dispute support. Limitation: the auto-exclusion API works for Google Ads and Meta Ads today; other channels require manual CSV upload.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.