Seatext library / BotRefund evidence

BotRefund Bot Detection Settings: Which to Adjust for Better Accuracy

Adjust thresholds, concurrency limits, and whitelist/blacklist rules. Thresholds control sensitivity, concurrency limits handle coordinated bot spikes, and whitelist/blacklist rules refine by known sources. Start with thresholds, then move to concurrency based on traffic patterns,...

Built for advertisers who need clear, refund-ready traffic evidence.

To improve BotRefund's detection accuracy, adjust three settings: thresholds, concurrency limits, and whitelist/blacklist rules. Thresholds set how sensitive each of the 106 independent checks is. Concurrency limits catch bursts of automated activity. Whitelist and blacklist rules let you exclude or target specific IPs, user agents, or geographies. The right combination depends on your traffic mix and how many false positives you can tolerate.

BotRefund treats a single anomaly as evidence, not a verdict. It cross-checks each signal against browser, network, device, and behavior data before its AI decides. That means thresholds matter more for individual signals than for the overall decision. Tune them too low and you flag real users; too high and you miss sophisticated bots.

What BotRefund Bot Detection Settings Actually Do

BotRefund runs 106 independent checks that fall into categories like hardware fingerprinting, network patterns, biometric behavior, and session metrics. Each check produces an anomaly score. The settings you control decide how that score is interpreted and combined.

Three settings have the biggest influence on accuracy:

  • Thresholds: the score above which a single signal is considered suspicious.
  • Concurrency limits: how many similar actions or sessions can happen within a time window before triggering a flag.
  • Whitelist/blacklist rules: explicit allow or deny lists for IPs, user agents, or geographies.

These aren't independent levers. A threshold too aggressive raises false positives; a concurrency limit too loose lets coordinated bot farms slip through. The art is balancing them against your traffic profile.

Threshold Settings: The Sensitivity Dial

Every BotRefund check—like the CPU Concurrency Lie, Suspicious Ports, or Impossible Tab Speed—returns a score. The threshold decides whether that score counts as an anomaly. Raising the threshold means fewer signals get flagged, which lowers false positives but may let subtle bots pass. Lowering it catches more anomalies but risks flagging privacy tools, travel, or corporate networks that produce odd behavior.

Start with the default threshold. Run a live audit to see which signals are tripping for real users. If you're seeing false positives, raise thresholds for the specific checks that misfire. If you're missing bots, lower them, but expect more noise.

BotRefund's cross-checking helps here. Because the AI weighs the complete pattern, a single high score rarely causes a false verdict. Only when multiple independent signals agree does it label a visit as a bot. So thresholds should be set per signal, not as a global rule.

Concurrency Limits: Handling Coordinated Traffic

Bots often arrive in bursts. A bot farm may click your ads from many IPs in seconds, or a script may submit forms faster than a human could. Concurrency limits catch these patterns by counting how many identical actions happen within a short window.

Set concurrency limits based on your normal traffic volume. If your site gets 1,000 visits a minute, a spike of 50 clicks from one user agent in a second is suspicious. But if you're a low-traffic site, even 10 quick actions may be normal for a power user. Adjust the window and the count to match your baseline.

Watch for false positives during seasonal peaks or when a marketing campaign goes viral. BotRefund's session behavior check already catches unnatural visit lengths, so pair concurrency limits with session data to avoid blocking legitimately excited visitors.

Whitelist and Blacklist Rules: Precision Control

Whitelists let you always treat certain IPs, user agents, or geographies as human. Blacklists do the reverse—always flag them. These rules are useful for known partners, office IPs, or specific locations where you see repeated attacks.

But lists are a blunt instrument. An IP range may be shared by a VPN provider and a legitimate business. A blacklist that hits a cloud provider could block real customers who use that network. Use lists only when you have strong evidence, and review them often.

For accuracy, prefer BotRefund's AI pattern matching over hard lists. The system already cross-checks network and device signals. A whitelist can override that and let a sophisticated bot through if it comes from a trusted IP. A blacklist can block a real user on a shared network. Use lists for known bad actors, not for broad categories.

Decision Framework: Which Settings to Adjust First

Follow this order when tuning:

  1. Run the free bot audit (from BotRefund) to get a baseline of what's being flagged.
  2. Check thresholds for your top false positives. Raise them for signals that trip on privacy tools or corporate networks.
  3. Set concurrency limits using your normal traffic baseline. Adjust the window and count to match your own volume.
  4. Add whitelist/blacklist rules only after seeing repeated patterns. Keep them narrow and review monthly.

This sequence reduces false positives first, then narrows the bot net, then adds targeted precision. It also avoids the common mistake of over-tuning one setting while ignoring the others.

Key Facts You Should Know

FactValue
Independent checks used106
Claimed accuracy99%
Ad spend stolen by bots (claimed)Up to 20% on Google and Meta
Setup timeAbout 1 minute
Case study recovery (FinTrust)$140,000 refunded, 14% bot click rate, +18% conversion rate
Cross-check philosophySingle anomaly is not a verdict; signals are corroborated

These numbers come from BotRefund's public materials. They show why tuning matters: even a 1% error on high traffic can cost real money, and a poorly configured threshold can either leak budget or block paying customers.

Limitations: When Adjusting Settings Won't Help

No setting can make detection perfect. Advanced bots using headless browsers and AI can evade some checks. BotRefund's 106 signals help, but they are not a silver bullet.

Whitelists and blacklists become stale fast. IP ranges change, and user agents are easily spoofed. If you rely on lists too much, you'll see error rates climb as the internet shifts.

Thresholds only control when a signal is flagged; they don't determine the final verdict. The AI makes that call by weighing the full pattern. So don't expect a single slider to fix all accuracy issues. You need to monitor results and iterate.

Finally, these settings assume your traffic is genuinely mixed. If your site is entirely bot-driven or entirely human with no middle ground, tuning is less useful. In those cases, focus on refund recovery rather than micro-optimizing detection.

Frequently Asked Questions

What happens if my threshold is too low?

You'll flag privacy tools, corporate VPNs, and travel users as bots. False positives climb, and you may block real conversions. Start with defaults and raise thresholds only for signals that misfire on your audience.

How do I know the right concurrency limit?

Look at your analytics for normal visits per minute and maximum legitimate bursts. Set the limit above that peak but below the level where bots typically operate. Test with a known bot source if you can.

Can whitelisting my office IP hurt detection?

Yes. If a bot uses that IP range later, it will slip through. Whitelist only when you're certain the network is clean and monitor for changes. Better to rely on cross-checked signals than on static lists.

Do these settings affect refund claims?

Not directly. Refunds come from BotRefund's proof and negotiation with Google and Meta. But accurate detection improves the quality of that proof. Fewer false positives mean your refund report is more credible.

How often should I review my settings?

Monthly is a good rule. Traffic patterns change, new bot tactics appear, and legitimate user behavior shifts. Re-run the free audit and adjust based on what you see.

If you're unsure where your accuracy issue lies, start with a free audit. It will show you which signals are firing and give you a data-driven starting point.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more