Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Lesson 7 of 8 · 9 min read · intermediate

This lesson counts towards the ClearTrust Traffic Quality & Fraud certificate. Enrol with your email to record your progress and scores.Get certified, free

Detecting and preventing invalid traffic

The signals that separate real visitors from fake ones, what can be done before and after the click, and a practical prevention routine for operators.

Detection is not one test. It is a set of small questions asked at different moments, each of which a real person passes without noticing and a fake one tends to fail somewhere. This lesson explains the questions, when they are asked, and how an operator turns them into a routine.

Catching invalid clicks

1/7
Arrivalvisit▭Incoming visithuman or not?✓Pre-click filterlists, IPs, devices!Blockedno ad is shown▤Feed pageads are served▦Ad clicklogged with signals✓Post-click auditbehaviour, conversions!Invalid clickcredited back★Advertiserpays only if valid▦Quality scoree.g. a TQI Score™
1
A visit arrives

Every click on a search ad starts as a visit from some device. Most are people; some are scripts, crawlers or hijacked phones. IVT detection is the work of telling them apart.

  1. A visit arrives: Every click on a search ad starts as a visit from some device. Most are people; some are scripts, crawlers or hijacked phones. IVT detection is the work of telling them apart.
  2. Line 1: easy catches, before the ad: Pre-click filtering checks what can be known instantly: declared bots, data-centre addresses, impossible device details. This routine layer is GIVT. Blocked visits never see an ad, so no advertiser is charged.
  3. Deeper signals: Harder cases need more: device fingerprinting to spot one machine posing as many, signs of a headless browser, or a residential proxy hiding the true origin. Visits that pass go on to the page.
  4. An ad is clicked and logged: The visitor clicks a sponsored result. The click is recorded with its context: time, device, the query, how long the page had been open, where the pointer or finger was.
  5. Line 2: judged after the fact: Post-click analysis looks at what only shows up in bulk: clicks that never convert, identical timing, the same few devices returning. Disguised, deliberate fraud of this kind is SIVT.
  6. Invalid clicks are refunded: A click judged invalid is credited back to the advertiser and removed from publisher earnings. A valid click is billed as normal, say $1.00. Two outcomes from the same button press.
  7. Each verdict sharpens the filter: Findings roll up into a traffic quality score per source or placement. ClearTrust’s TQI Score™, for example, combines 150+ filters into one number. A publisher who scores its own traffic can cut a bad source before the engine does it for them.

Before the click and after the click

Pre-click filtering

  • Runs when the visitor arrives, before feed ads are requested or shown
  • Uses what is known instantly: network, device, browser, arrival path
  • Can stop an ad request from being made at all
  • Protects your quality record because the bad click never happens
  • Limited: it must decide in milliseconds on little evidence

Post-click analysis

  • Runs on collected data, minutes to weeks later
  • Uses patterns: timing, repetition, outcomes, comparisons across sources
  • Can find what looked normal one click at a time
  • Drives decisions: pause a source, block a placement, dispute a bill
  • Limited: the click has already been counted and may be clawed back

Pre-click filtering and post-click analysis are partners. The first keeps obvious junk away from the feed. The second finds the subtle junk and feeds what it learns back into the first, as a blocklist entry or a new rule.

The families of signal

No single family is decisive. Detection works by combining them.
FamilyExamples of what is checkedCatches
NetworkHosting ranges, known proxy and VPN exits, mismatch between IP location and device time zoneData-center traffic, some residential proxy use
Device and browserWhether the claimed browser behaves like that browser, automation traces, impossible hardware combinationsHeadless browser bots, emulators
BehaviourScrolling, pointer or touch movement, time before the first click, where on the element the click landsScripts, accidental click layouts
PatternRepeated journeys, click rhythm, hour-of-day curve, the same device across many "users"Botnet and click farm activity
OriginReferrer consistency, landing path, whether the placement exists and carries the adTraffic laundering, referrer spoofing
OutcomeDwell time on the advertiser side, conversions, deductions at finalisationTraffic blending, incentivised and misled humans

Good systems score rather than simply block. Each signal adds or removes a little confidence, and the total decides. This matters because every signal has innocent explanations. Plenty of real people use VPNs. Plenty of real people click fast. A rule that blocks on one signal throws away real customers, and a rule that needs every signal to fire lets fraud through.

A prevention routine for operators

  1. Know your baselineRecord normal values for your clean traffic: Lander CTR, Ad CTR, share of mobile, hour-of-day curve, deduction rate. Fraud is only visible as a departure from normal.
  2. Tag everythingPass source, campaign, placement and creative through your tracker using a Click ID and Sub ID values, and map each source to its own Channel ID. Untagged traffic cannot be diagnosed.
  3. Test new sources smallGive any new source or placement a capped budget and its own channel until it has been through a full finalisation cycle.
  4. Filter on arrivalApply pre-click checks so clearly non-human visitors never trigger a feed request. Review what was filtered to make sure real users are not being lost.
  5. Review outcomes weeklyLook at RPC trend, provider quality feedback and estimated-versus-finalised gaps per source. Act on trends, not single days.
  6. Block narrowly, then widenExclude the specific placement or sub ID first. Use an allowlist for sources where only a few placements are trustworthy.
  7. Keep evidenceArchive creatives, lander versions, placement reports and quality scores with dates. You will need them for disputes with sellers and reviews by providers.

Prevention that is not about bots

Much invalid traffic in this business is self-inflicted through design. Three habits remove most of it. Keep ads visibly labelled and clear of buttons, menus and close icons, so clicks are deliberate. Make sure the creative promises only what the page delivers. And let the visitor choose their own search term instead of pushing a higher-paying one. These are policy requirements as well as quality measures, and they cost nothing.

What advertisers do on their side

The advertiser’s side

1/8
Setupnew campaign★Advertiserbids on a keyword✓Campaign settingsearch partners on/off⇆Google.comthe main results page⇄Search partnersother sites with ads!Parked domainsremoved in Feb 2026▤Arbitrage pageone partner site▦Placement reportlists each site✓Exclusion listblocks chosen sites$Conversionsthe real test
1
An advertiser buys a keyword

A car leasing firm creates a search campaign in Google Ads and bids on “SUV lease deals”. It expects its ad to appear when people search for that on Google.

  1. An advertiser buys a keyword: A car leasing firm creates a search campaign in Google Ads and bids on “SUV lease deals”. It expects its ad to appear when people search for that on Google.
  2. One setting widens the reach: Search campaigns include an option to show ads on Google’s search partners as well as Google.com. It is switched on unless the advertiser turns it off. It is all or nothing: partners cannot be picked one by one, only excluded.
  3. The ad appears on an arbitrage page: A visitor on a partner site taps a related search for “SUV lease deals”. The firm’s ad appears in the results there, and a click costs it about $1.00 (illustrative), the same budget as a click on Google.com.
  4. Does it convert?: What matters to the advertiser is the conversion rate: do these clicks become enquiries? Some partner traffic performs well. Where it converts less, Google says it lowers the price automatically (smart pricing), and invalid clicks are credited back.
  5. Seeing where the ads ran: For years partner sites were a black box. Since 2025 Google has reported the individual partner sites where Search, Shopping, App and Performance Max ads appeared, so an advertiser can see each Placement by name.
  6. Excluding what does not work: A site that spends money without results can be added to an account-level placement exclusion list, and ads stop showing there. The blunt alternative is the opt-out: switch search partners off for the campaign.
  7. One whole category removed: Google went further with parked domains: advertisers were opted out by default in 2025, and on 10 February 2026 parked domains stopped being part of the search partner network altogether.
  8. Why arbitrageurs should care: Every exclusion removes a bidder from that page, and fewer bidders mean lower prices. A page that sends advertisers real customers keeps its demand. A page that does not is slowly switched off, one exclusion list at a time.

Advertisers are the other half of prevention. They can see partner performance separately, exclude individual placements with a placement exclusion, or leave partner networks entirely. Google's own change log shows the direction of travel: site-level placement reporting for search partners arrived in August 2025, and an Invalid Activity Credit Report in April 2026. Performance advertisers also use click-fraud tools of their own. ClearTrust's ClickTrust is one such product. The more clearly advertisers can see and reject bad placements, the faster a poor-quality source loses its income.

Key takeaways

  • Detection combines network, device, behaviour, pattern, origin and outcome signals; none is decisive alone.
  • Pre-click filtering keeps bad visitors from triggering feed ads; post-click analysis finds what slipped through and improves the filter.
  • A baseline of your own clean traffic is the reference that makes anomalies visible.
  • Tagging and separating every source is what turns a vague quality problem into a fixable one.
  • A third-party traffic-quality score is an early-warning and evidence tool alongside, not instead of, the feed's verdict.

Questions people ask

How is invalid traffic detected?

By combining many signals: whether the network is a data center or proxy, whether the device and browser behave consistently, how the visitor moves and clicks, whether journeys repeat in machine-like patterns, whether the claimed origin is real, and whether advertisers get any results. Systems score these together, because any single signal has innocent explanations.

What is the difference between pre-click and post-click fraud detection?

Pre-click detection checks a visitor on arrival and can prevent an ad from being requested or shown, so the bad click never occurs. Post-click detection analyses recorded clicks and outcomes later, finding patterns that single clicks do not reveal. Pre-click protects your quality record. Post-click tells you which sources to cut and updates your filters.

How do I stop bot traffic on my search arbitrage campaigns?

Buy from sources you can name, test each new one with a small capped budget in its own channel, filter obvious non-human visitors before the feed loads, and review click rates, RPC trends and deductions per source every week. Block specific bad placements quickly. No method removes all bots, so the aim is early detection and small exposure.

What is a traffic quality score?

A traffic quality score is a single rating that summarises how genuine and valuable a stream of traffic appears, built from many checks for bots, fake clicks and abnormal behaviour. Feed providers keep internal scores for their publishers, and independent vendors offer their own, such as ClearTrust's TQI Score. Scales differ between providers and cannot be compared directly.

Previous: How traffic quality is scored, and how revenue is clawed backNext: Famous cases and what they teach