HomeBlogAd Fraud

Click Fraud Prevention: Where Your Ad Budget Actually Leaks

Platform-reported invalid traffic is the floor, not the ceiling. A practical method for measuring your real exposure and closing the leaks in stages.

8 min readAd Fraud

Every advertiser has a number they do not know: the share of their spend that bought a click no human ever made. Platform-reported invalid traffic figures are usually the floor, not the ceiling. This is a practical guide to finding where the leaks are and closing them.

What actually counts as invalid

“Click fraud” is a broad label covering activity with very different economics. It helps to separate them, because they need different countermeasures:

  • Automated traffic. Crawlers, scrapers, monitoring services, and outright botnets. Some is benign and declares itself; the expensive kind does neither.
  • Click farms. Coordinated human or semi-automated clicking, often through residential or mobile connections, deliberately paced to look organic.
  • Competitor clicking. Low volume, high intent, frequently from a small pool of addresses, aimed squarely at exhausting a rival’s daily budget.
  • Publisher-side inflation. Traffic manufactured where the publisher is paid per click or impression.
  • Accidental clicks. Not fraud at all, but still worthless—fat-finger taps on mobile interstitials convert at approximately zero.

Only the first three are adversarial. The last two need different treatment: placement and targeting changes rather than blocking.

Why platform refunds are not the answer

Ad platforms do detect invalid traffic and do issue credits. Relying on that alone has three structural problems.

First, the detection is tuned to the platform’s risk, not yours. It catches what damages platform-wide trust; it is not calibrated to your particular offer, geography, or margin.

Second, credits arrive after the auction has already been distorted. If bot clicks pushed your bids up and your smart-bidding algorithm learned from polluted conversion data, a refund on the click cost does not undo the damage to your campaign’s optimisation.

Third, you cannot audit it. You receive a number, not a breakdown, and you cannot tune anything based on it.

Worth internalising

The cost of an invalid click is never just the click. It is the click, plus the auction distortion, plus the corrupted signal you fed to an automated bidding system that will now spend more of your money on similar traffic.

Measuring your real exposure

Before you filter anything, quantify the problem. You can do this with data you already have.

  1. Segment by source. Break down sessions by campaign, placement, and geography. Fraud is rarely evenly distributed; it concentrates.
  2. Look for impossible behaviour. Sessions under one second with a recorded scroll event. Identical viewport dimensions at improbable volume. Conversion paths completed faster than a human can read the form.
  3. Check IP concentration. Count distinct sessions per address and per /24 subnet. A long tail is normal; a spike is not.
  4. Compare declared and observed. A visitor whose IP geolocates to one country, whose browser reports another language, and whose system timezone reports a third is telling you something.
  5. Trend the ratio, not the count. Absolute volumes move with spend. The ratio of suspicious to total is the number that means something.

Run this for two weeks before making changes. You need a baseline you trust, or you will not be able to prove the filtering worked.

Building a filtering baseline

Resist the urge to switch everything on at once. A staged rollout produces a system you understand.

  • Stage one: observe. Run the filter in log-only mode. Nothing is blocked. You are checking that the traffic it would have blocked matches what your own analysis flagged.
  • Stage two: block the unambiguous. Datacenter ranges, declared crawlers hitting paid landing pages, known automation frameworks. These have very low false positive risk.
  • Stage three: score the ambiguous. Proxy and VPN traffic, geography mismatches, and reputation-flagged addresses go to a score, and you choose a threshold consciously.
  • Stage four: tune weekly. Review block reasons. Anything blocking a large share of traffic for a reason you cannot explain is a bug in your rules, not a discovery.

Metrics that prove it worked

Click volume will fall. That is the intended outcome, not a problem, and you need the metrics that show the difference between “fewer clicks” and “better clicks”:

MetricExpected directionWhat it tells you
Conversion rateUpThe denominator lost traffic that was never going to convert
Cost per acquisitionDownBudget is reaching people who can actually buy
Bounce rateDownFewer single-request, zero-engagement sessions
Average session durationUpRemaining sessions behave like people
Blocked shareStable after tuningA sudden change means an attack or a broken rule

If conversion rate does not improve after filtering removes a meaningful share of traffic, either the removed traffic was converting—so you have false positives—or your problem was never fraud. Both are useful findings.

Takeaways

  • Separate adversarial fraud from merely worthless traffic; they need different fixes.
  • Platform credits refund the click but not the auction distortion or the polluted bidding signal.
  • Measure a baseline for two weeks before you block anything.
  • Roll out in stages: observe, block the obvious, score the ambiguous, tune weekly.
  • Judge success on conversion rate and CPA, never on click volume.

See it on your own traffic

MaxGuard scores every visit against IP intelligence, device and behavioural signals, then blocks, routes, or allows it by your rules.

Request access

Keep reading