If after launching a campaign the CTR looks great, there are lots of clicks but no leads, the first suspect is bot traffic. Sometimes rightly, sometimes not: a bad offer or a broken form produces a similar picture. To stop guessing, it helps to know the signs of bot traffic at different levels — from a single visit to a weekly summary.
What bot traffic is and where it comes from
Bot traffic is any visit made by a program rather than a person. It is not necessarily malicious. An ad link gets visits from:
- ad platform robots — they check the landing page and build link previews;
- ad verification services and spy tools — they collect creatives and landing pages from other people's campaigns (protection is covered in protection from spy services);
- scanners and crawlers — they index everything publicly visible;
- fraud traffic — fake impressions and clicks on pay-per-click and pay-per-impression platforms;
- click fraud — deliberate clicks by competitors or botnets, covered in click fraud (and for Yandex search ads, in bot protection for Yandex Direct).
The ad industry splits such traffic into two types. GIVT (general invalid traffic) is cut by simple rules: known crawlers, data center networks. SIVT (sophisticated invalid traffic) disguises itself as human. This split will matter below: the two types have different signs.
Network-level signs of a bot
The first thing you see about a visit is its IP address and network.
Hosting or cloud network
An ordinary person goes online through a home ISP or a mobile carrier. If a visit came from a cloud hosting network, it is almost certainly a server — a script, a scanner or a proxy. Which network an address belongs to is determined by its ASN, the autonomous system number. More in VPN, proxy and data center IP detection.
VPN and proxy
Real people use VPNs too, so a VPN alone is not a verdict. But combined with other signs — a time zone mismatch, a non-native browser language, no ad click parameter — it is a strong signal.
Repeats from one address
Dozens of clicks from one IP in a day are classic fake traffic and scraping. A real person makes two or three visits: opened, came back, refreshed. Beyond that, questions start.
No ISP
If the address has no identifiable ISP, it is usually a server address, not a subscriber.
Request- and browser-level signs of a bot
Odd or incomplete headers
Simple scripts send a minimal set of headers, an outdated or template user agent, and no language. A browser does not do that: it always sends a full and consistent set.
No JavaScript
A program instead of a browser — curl, HTTP request libraries, many scrapers — does not run scripts. If the in-browser check never returned an answer, that is one of the most reliable signs of automation.
Traces of automation
A headless browser runs JavaScript but leaves traces: automation flags, missing usual plugins and fonts, a declared version that does not match actual capabilities. These are signs of SIVT — covered in detail in headless browsers and browser fingerprinting.
Inconsistency
- the browser time zone does not match the IP country;
- the system language does not match the geo;
- the screen is "mobile" but the capabilities look like a desktop server;
- it claims to be an iPhone but behaves like Chrome on Linux.
Individually, such things happen to travelers and in corporate networks. Together — no.
Behavioral signs of a bot
| Sign | Human | Bot |
|---|---|---|
| Time on page | Seconds to minutes, varies | Zero, or identical to the millisecond |
| Mouse and finger movement | Uneven, with pauses | None, or perfectly straight |
| Scrolling | In jerks, with backtracking | None, or uniform |
| Button click | After reading | Instantly or never |
| Repeat visits | Rare | Serial, on a schedule |
Behavioral signs are the strongest, but they take time: you cannot collect behavior in a fraction of a second.
Signs of bot traffic in campaign stats
When you cannot dig into individual visits, look at aggregates. Here is what should raise a flag:
- Clicks but no conversions at all. Not a drop, but zero on meaningful volume.
- Spikes at odd hours. Night-time peaks in a geo where everyone is asleep are a common sign of automation.
- One placement (zone, site) delivers disproportionately many clicks. In native and push, that is what fraudulent placements look like.
- High CTR with zero engagement. People click, but nobody reaches the form.
- Conversions but no approvals. Fake leads get through the form but are rejected by the network — keep an eye on conversion statuses.
- Uniform traffic. One phone model, one browser version, one resolution across hundreds of "different" visitors.
Tip. Pass the placement, zone or site ID in a campaign parameter — for example,
sub1={zoneid}. Then the report shows right away which placements bring bots, and you can turn them off in the ad network itself.
Signs often mistaken for bots
Not every oddity is a bot. Common false alarms:
- Social in-app browsers and WebViews. They can have unusual user agents and traits resembling automation, and the referrer is often lost.
- Corporate networks and mobile carriers. Many people behind one address — and suddenly there are "ten clicks from one IP".
- IPv6. It is normal for many mobile carriers.
- Fast buyers. A person who has already seen the offer or decided to buy in advance can hit the button in a couple of seconds. Short time on page alone does not prove automation.
- Forwarded links. A friend sent the link in a messenger — the visit has no ad parameter and no referrer, yet it is a real and often very warm visitor.
- A high pass rate to the offer. That is not a sign of bots. With paid traffic carrying a verified click parameter, a very large share of visits can reach the offer, and that is normal. On the contrary, if very few get through, check whether the filter is cutting real people.
That is why mature systems do not cut a visit over one soft sign but add them up into a trust score. The more independent signs agree, the more confident the conclusion, and the lower the chance that a buyer ends up on the safe page.
How to detect bot traffic in ArtisanClo
In ArtisanClo every visit goes through checks in order — network and request, browser check, behavior — and gets a decision with an explanation. The click log shows why a visit was filtered out or let through; the click card shows the network (VPN, proxy, data center), device, browser, ad parameter, checks passed and conversions.
Reasons are grouped in a way that makes analysis easy:
- Bot / automation — platform robots, ad verification services, spy services, robot browsers, programs instead of browsers;
- Infrastructure traffic — data centers, hosting, proxy networks;
- Campaign rule — your own setting fired: geo, device, schedule, per-address click limit, VPN, trust score, blacklist.
In Statistics, above the reasons, you see the shares of the three "Where they were cut" steps — mirroring the GIVT/SIVT split: network and request, browser check and check never came back. The first is simple invalid traffic, the second is bots pretending to be people, the third is programs without JavaScript.
And the dashboard has a traffic quality score — an assessment of the traffic itself, in which the share of real visitors (excluding platform checks) weighs the most. If the traffic gets worse, the score shows what exactly became the weak spot. How to assess traffic quality yourself, layer by layer, is covered in a separate article. More on analyzing individual decisions in why a click went to the White Page.
What to do once you find signs of bot traffic
- Identify the source. Bots come from a specific placement, zone or campaign — find it through your parameters.
- Turn off junk placements in the network itself. A filter protects the landing page, but you still pay for the click.
- Tighten protection selectively. If the bots come from data centers, turn on datacenter ASN blocking; if they are headless, use the browser check and the live interaction check.
- Block repeating addresses. Your own IP blacklist comes in handy for specific persistent visitors.
- Request a refund from the platform. Many networks refund proven invalid traffic — a log with reasons serves as evidence.
The general approach to setting up protection is described in how to filter bots.
Quick traffic check: a 15-minute checklist
If you have no time to dig into every visit, go through the list. Each item is a separate question to the visit log or a report for the last day or two.
- What share of visits came from hosting and data center networks? For ad traffic from social networks and search this share should be small. If it is noticeable, find the source: a specific campaign, placement, zone.
- Are there addresses with dozens of visits? Sort by address. A couple of visits is normal; series are not.
- How many visits did not run the check script? That is exactly how programs without JavaScript get filtered. A large share points to scrapers and simple bots.
- Do visit geos match targeting geos? Foreign countries in the log are reviewers, VPNs or bots.
- How are visits distributed by hour? A flat "shelf" around the clock in one country is a bad sign: a real audience sleeps.
- Are devices uniform? A hundred visits with the same model and browser version is not an audience but a script.
- How do conversions behave? Compare CR and approval rates by source: if one source has leads but nearly all are rejected, form-filling fraud is likely. What to do when bots submit forms on your site is covered separately.
If two or three items give a worrying answer, the traffic almost certainly contains a noticeable share of bots. Then decide what to do about it: filter on your side, turn off the placement or demand a refund. A list of traffic sources and their specifics is in the traffic source catalog.
In short
Bot traffic gives itself away at four levels: network (hosting, VPN, repeats from one address), browser (no JavaScript, traces of automation, inconsistency), behavior (zero time, no movement) and stats (clicks without conversions, spikes, uniformity). No single sign proves a bot — the combination decides. And do not confuse a high pass rate with weak protection: if anything, the opposite signals a problem.



