Seatext library / BotRefund evidence

Which Metrics Should I Focus On When Analyzing Session Behavior?

Prioritize session duration, bounce rate, pages per session, scroll depth, form interaction patterns, and conversion events. These metrics reveal whether visitors are genuine prospects or automated traffic, and they feed directly into the evidence...

Built for advertisers who need clear, refund-ready traffic evidence.

When you analyze session behavior, focus on six core metrics: session duration, bounce rate, pages per session, scroll depth, form interaction patterns, and conversion events. Together they separate real human engagement from the uniform, frictionless paths that bots and low‑intent traffic leave behind. Platforms like Google and Meta only refund invalid clicks when you can show session‑by‑session evidence — these metrics are the foundation of that evidence.

Why Session Behavior Metrics Matter

Ad platforms bill every click the moment it happens. Whether that click came from a person is left to you to prove after the fact. Industry audits consistently place automated traffic between 9% and 20% of paid clicks, and invalid click rates on Google Search range from 4% for well‑protected accounts to over 35% for high‑CPC keywords. If you cannot demonstrate which sessions were non‑human, you pay for all of them — and your optimization algorithms may learn from the contaminated sample, sending more budget toward traffic that looks like bots.

The metrics below are the ones BotRefund’s 110‑signal engine weighs most heavily when it builds the refund‑ready reports that Google and Meta reviewers accept. Each metric maps to a specific behavioral pattern that automated traffic struggles to fake consistently.

Core Metrics and What They Reveal

Session Duration and Time on Page

Real visitors spend variable time reading, comparing, or hesitating. Bots often hit a page and trigger a conversion event in seconds. Meaningful time on the offer page — not just a timestamp — is a primary signal. A session that lands and converts in under five seconds with zero scroll events is a strong candidate for invalid traffic.

Bounce Rate and Engagement Rate

A high bounce rate alone doesn’t prove fraud; a weak campaign can attract real people who aren’t ready to buy. But bounces paired with zero scroll, zero field interaction, and instant form submission form a repeatable pattern. Compare bounce rates by placement, device, and audience expansion to spot clusters where engagement collapses.

Pages Per Session

Genuine prospects often navigate — product pages, pricing, FAQ, contact. Automated scripts frequently follow a single, uniform click path: land → click CTA → submit form. Pages per session below 1.2 combined with identical navigation sequences across many sessions signals scripted behavior.

Scroll Depth

Human visitors scroll. They pause, scroll back, or stop at specific sections. Bots either don’t scroll at all or scroll at a perfectly uniform speed to the bottom. Zero scroll events or identical scroll velocity curves across sessions are high‑confidence bot indicators.

Form Interaction Patterns

This is where the evidence gets granular. Track: form start rate, time to completion, field corrections (backspacing, re‑selecting dropdowns), and field order. Real users hesitate, correct typos, and sometimes abandon. Bots submit instantly, never correct, and often fill fields in the exact DOM order. Unusually fast form completion with zero corrections is a hallmark of automated submission.

Conversion Events Without Prior Engagement

A conversion event — lead submit, purchase, signup — that has no preceding page engagement (no scroll, no mouse movement, no intermediate clicks) is a red flag. Platforms treat the conversion as valid unless you show the session lacked the friction humans naturally create.

Segmentation: Where the Signal Gets Clearer

Site‑wide averages hide the problem. Quality normally changes by placement, audience, creative, device, geography, landing page, and time of day. A sudden gap in one cluster — e.g., Instagram Stories placement delivering 40% of leads but 90% of disconnected phones — is more actionable than a blended metric. Preserve the click identifier, campaign context, timestamp, URL parameters, and CRM record before you change any campaign settings.

Trade‑off Table: Metric Categories vs. Investigation Effort

Metric Category Setup Effort Diagnostic Power Refund Evidence Value Common Blind Spot
Session duration / time on page Low — standard analytics Medium — catches obvious speed bots Medium — supports but rarely sufficient alone Slow human readers look like bots
Bounce rate / engagement rate Low — standard analytics Low alone, high when segmented Low — platform expects deeper proof High bounce can be poor UX, not fraud
Pages per session Low — standard analytics Medium — reveals single‑path scripts Medium — shows lack of exploration Single‑page landing pages skew this
Scroll depth & velocity Medium — needs client‑side script High — hard for bots to fake naturally High — visual, session‑level proof Requires consented tracking
Form interaction (start, time, corrections, order) Medium — custom event instrumentation Very high — strongest behavioral fingerprint Very high — direct evidence of non‑human submission Complex forms need careful event design
Conversion without prior engagement Medium — join analytics + CRM Very high — clear anomaly Very high — core of refund claim Must rule out app‑browser / consent gaps

Takeaway: Start with the low‑effort metrics (duration, bounce, pages/session) to identify suspect clusters. Then layer client‑side scroll and form instrumentation on those clusters to build the session‑by‑session evidence platforms require.

Step‑by‑Step Investigation Workflow

  1. Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, click ID, timestamp, and landing‑page URL intact.
  2. Pull platform delivery data. Compare reach, link clicks, landing‑page views, and spend by placement. A cheap placement isn’t a win unless it produces contactable leads.
  3. Measure landing‑page evidence. Capture page loads, redirects, consent behavior, form start, form completion, time to completion, and meaningful engagement (scroll, mouse movement). Investigate ordinary click‑to‑session gaps — app browsers, tracking consent, slow loads, analytics misconfiguration — before concluding the gap is bot traffic.
  4. Verify leads in the CRM. Record email deliverability, phone connectivity, duplicate details, and prospect confirmation. Add qualification questions that reveal fit, not just extra fields.
  5. Feed sales dispositions back to the platform. Use a small, mandatory set: verified, contacted, qualified, disqualified, duplicate, invalid details, no response. This teaches the algorithm which leads actually matter.
  6. Build the refund‑ready report. Combine click IDs, campaign details, timestamps, session recordings, and signal‑by‑signal reasoning in the format Google and Meta reviewers use.

Common Mistakes That Weaken Your Case

  • Treating every unresponsive contact as fraud. Low‑quality leads can be genuine but wrong for the offer. Excluding a valuable audience based on a small sample hurts more than it helps.
  • Relying on server‑side logs alone. Server logs see IPs, headers, and user agents. They miss advanced botnets that rotate residential proxies and mimic browser fingerprints. Client‑side audits analyze the visitor’s browser environment — mouse movement, scroll, device sensors — and catch what server logs cannot.
  • Changing campaign settings before preserving evidence. Once you pause a placement or adjust targeting, the original click‑to‑session chain is harder to reconstruct.
  • Using industry averages as proof. Imperva reported automated traffic represented more than half of web traffic in 2025; that does not mean half of your Meta clicks are fraudulent. Measure your own sessions and leads.
  • Ignoring the click‑to‑session gap. A gap can have ordinary explanations. Investigate consent banners, slow loads, and app‑browser behavior before filing a claim.

When This Advice Does Not Apply

  • Pure brand‑awareness campaigns where conversions aren’t the goal — session behavior matters less than reach and frequency.
  • Accounts with very low volume (under a few hundred clicks/month) — statistical clusters won’t form reliably.
  • Sites without form or conversion events — the form‑interaction signals that carry the highest evidence value don’t exist.
  • Campaigns running entirely on platform‑owned inventory (e.g., Meta Instant Forms) where you cannot instrument the landing page.

Key Facts

Fact Source
Automated traffic represents 9%–20% of paid clicks across industry audits S5
Invalid click rates on Google Search range from 4% to over 35% depending on keyword competitiveness S7
BotRefund combines 110+ behavioral, browser, hardware, network, and attribution signals S2
99% confidence in flagged bot traffic; 83% approval rate on filed refund claims S2
Session behavior signals: no scrolling, no field corrections, uniform click paths, no meaningful time on page S1
Four‑layer audit: platform delivery, landing‑page evidence, lead verification, sales outcome feedback S6
Click‑to‑session gaps can stem from app browsers, consent, slow loads, or analytics config — not just bots S6
Refunds happen almost exclusively when advertisers contest specific charges with specific evidence S5

Terminology Quick Reference

  • Click ID (GCLID / FBCLID): Unique identifier appended to the landing‑page URL by Google or Meta. Preserves attribution for each paid click.
  • Pixel poisoning: When conversion pixels fire on bot traffic, the platform’s optimization algorithm learns to target more similar (non‑human) traffic.
  • Client‑side audit: Analysis that runs in the visitor’s browser — capturing mouse movement, scroll, device sensors, and browser fingerprint — rather than relying only on server logs.
  • Refund‑ready report: Evidence package formatted to match the invalid‑traffic review templates used by Google and Meta, including click IDs, timestamps, session recordings, and signal‑by‑signal reasoning.
  • Sales dispositions: Standardized outcome codes (verified, contacted, qualified, disqualified, duplicate, invalid details, no response) fed back to the ad platform to retrain its optimization.

FAQ

How many sessions do I need before the metrics become reliable?

Aim for at least 300–500 sessions per segment (placement × device × audience) before drawing conclusions. Smaller samples produce false positives — a handful of fast converters can look like a bot cluster but may just be motivated buyers.

Can I use Google Analytics 4 alone, or do I need a dedicated script?

GA4 gives you session duration, bounce, pages/session, and basic scroll (via enhanced measurement). It does not capture form field corrections, field order, mouse movement, or device sensors. For refund‑grade evidence you need a client‑side script that records those micro‑behaviors session by session.

What if my landing page is a single‑page form (no navigation possible)?

Pages per session loses diagnostic value. Double down on scroll depth, time to form start, field corrections, and submission velocity. Compare those metrics against a known‑human control group (e.g., organic traffic to the same page).

How do I handle the click‑to‑session gap caused by iOS app browsers or consent banners?

Measure the gap explicitly: timestamp the click ID arrival, then timestamp the first client‑side event. If the median gap is 2–4 seconds and consistent, it’s likely technical. If a subset shows zero gap but also zero engagement, investigate those sessions first.

When should I file a refund claim vs. just adjusting targeting?

Adjust targeting when a placement shows low lead quality but human engagement patterns (scroll, corrections, variable time). File a claim when you have session‑level evidence of non‑human behavior — uniform paths, zero scroll, instant submissions — tied to specific click IDs. Platforms only refund the latter.

Does BotRefund require ad‑account access?

No. The platform works with one script tag (~1 minute install) and does not need ad‑account credentials. It captures behavioral evidence on your site, matches it to click IDs, and builds the refund‑ready report you submit to Google or Meta.

What’s the typical recovery timeline?

Most claims are reviewed within 2–6 weeks after submission. BotRefund’s 83% approval rate across 2,500+ audits comes from formatting evidence exactly as platform reviewers expect and supporting the negotiation with documentation and arguments their teams need.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more