Click Fraud Protection: How Services Work and What Google Ads Does on Its Own

Click fraud protection cannot cancel the charge for a click, but it decides what happens next: whether fraud reaches your site, whether its IPs and placements get excluded, whether you get refunded. Here is how it works in practice.

Bots and Fraud10 min read
Click Fraud Protection: How Services Work and What Google Ads Does on Its Own
Contents
  1. How click fraud protection works: three layers
  2. What ad platforms do on their own
  3. What actually helps and what does not
  4. How to measure the effect of click fraud protection
  5. How to choose a click fraud protection service
  6. How ArtisanClo helps protect a campaign from click fraud
  7. In short

The word "protection" in click fraud protection is a little misleading. The click happens on the ad platform's side, and the platform charges for it before the visitor even reaches your site. So no service can "forbid" a fake click. What it can do is keep fraud away from your offer, get its IPs and placements excluded from your ads, and give you the data to get your money back.

Click fraud protection is a combination of three actions: recognize suspicious clicks by network, browser and behavior; keep them off the main page and out of your analytics; and remove their source from your ads and claim compensation. What click fraud is and how it looks in your stats is covered separately in click fraud: how to detect it. This article is about how the protection itself works.

How click fraud protection works: three layers

Any service or manual protection setup is made of the same parts. The difference is which of them are covered and how well.

Layer What it does What you get What you do not get
Click analysis collects data on ad visits and looks for anomalies an understanding of the scale and sources of fraud does not block anything on its own
Ad account exclusions passes IPs and placements to the platform so it stops showing ads to them fewer future paid clicks from the same source does not work against rotating addresses
On-site filter decides for every visit whether to show the main page clean offer and analytics, the offer's budget is not spent on bots does not refund a click that already happened

Let's take each layer in turn.

Click analysis

The service places a tracking script on the site or checks the visit on the server and records for every click: address and network, provider, device, browser, time, ad click ID (gclid, msclkid and others), on-page behavior. Typical red flags:

  • bursts of clicks from one address or subnet in a short time;
  • visits from data center networks and proxies;
  • browsers with signs of automation or no JavaScript;
  • instant exits with no scrolling or movement;
  • clicks carrying a click ID that repeats across different visitors.

The point of analysis is not a verdict like "fraud detected" but an answer to "where is it coming from". Without that, the other layers work blind.

Exclusions in the ad account

IPs and placements you found can be removed from ad delivery. Most click fraud protection services do this automatically through the platform's API or export a ready list. The method has limits: platforms cap the number of IP exclusions, and botnets and mobile proxies change addresses faster than you can add them. Against a competitor with a static IP an exclusion works great; against distributed fraud it works poorly. When blocking by address is justified is covered in IP blacklists in affiliate marketing.

On-site filter

The most reliable layer: a check before the main page is shown. A bot that won the auction and clicked still does not see the offer, does not leave a fake lead and does not ruin the conversion rate in your report. An on-site filter matters especially when fraud targets your forms rather than your spend; see bots submitting forms and fake leads.

What ad platforms do on their own

Before buying a service, figure out what the ad system already does. Its protection is free and works before you are charged.

  • Automatic invalid click filtering. Google filters part of suspicious clicks in real time and does not charge for them. Those detected later are compensated with a credit to your account.
  • Invalid clicks report. In campaign stats you can add columns with the number and rate of invalid clicks: that is what the platform has already recognized and not billed.
  • IP exclusions in campaign settings, with a cap on how many.
  • Placement exclusions in the Display Network and on YouTube: apps and sites that send junk.
  • Investigation request. If you see fraud the platform missed, you can contact support with data.

Google's click IDs and parameters are covered in Google Ads tracking: gclid, ValueTrack and offline conversions.

Other PPC platforms

Microsoft Advertising and other search and display networks work the same way: part of the clicks is filtered automatically and not billed, IP exclusions are available with a cap on their number, and in the partner network you can block specific sites and apps.

Tip. A platform's built-in protection covers only what the platform itself recognized. It does not know your rules and does not show whom it filtered. That is why you need your own visit log even if you trust the platform.

Built-in protection and external tools do not compete. The platform cuts what it sees on its side before charging you, while the on-site filter and the visit log show what actually reached you. Together they give the full picture: how much the platform recognized on its own, how much got past its filter and what else you can claim compensation for.

What actually helps and what does not

Measure Helps against Limits
On-site filter with a browser check bots, auto-clickers, server traffic the click is already paid for
Per-visitor click limit competitors and manual click fraud a limit that is too strict cuts real people
Uniqueness window removes repeats from analytics and duplicate leads does not stop the first click
IP exclusions in the ad account static addresses capped list, useless against botnets
Placement exclusions in display and partner networks inflation on partner sites needs regular review
Narrower targeting and schedule shrinks the field for fraud also shrinks useful reach
Sending conversions to the ad account the algorithm learns from people, not bots requires working tracking

The last point is often underrated. Automated bidding strategies optimize for events. If only real leads go to the ad account, the algorithm stops looking for an audience that resembles bots. How to set that up is covered in sending conversions to ad platforms.

What barely helps:

  • A captcha on the landing page for everyone. It scares off people more than bots.
  • Blocking entire mobile subnets. Along with one clicker you cut thousands of subscribers.
  • A one-time cleanup. Fraud changes addresses and placements, so exclusions need regular review.

How to measure the effect of click fraud protection

Protection should pay for itself in numbers, not in feelings. Compare two equal periods, before and after, on these metrics:

  1. The share of suspicious visits in the log and how it splits by reason: network, browser, behavior.
  2. The invalid click rate in the ad account. If it went up after your requests, the platform has started recognizing the fraud.
  3. Cost per lead (CPA) at a stable lead volume.
  4. The absolute number of leads. If it fell along with the fraud, the protection is cutting real people.
  5. The amount of compensation from the platform over the period.

An illustration: you spend $2,000 a month on search, and the log shows that 15% of visits are repeat clicks from the same subnets and data center networks. That is about $300 of traffic that could never convert. After a click limit, exclusions and a support request the share drops to 5% while leads stay at the same level: the protection paid off. If the share dropped and leads dropped with it, the rules are too strict. Metrics for this kind of assessment are collected in traffic quality: how to evaluate and check it.

How to choose a click fraud protection service

There are many services, and they all promise roughly the same thing. A few questions separate a useful one from the rest.

  1. Does it show a reason for every click? A verdict like "fraud: 23%" without a breakdown can be neither verified nor used in a request to the platform.
  2. What does it do with a suspicious visit? Just count it, exclude IPs in the ad account, or also keep the visit off the main page.
  3. Can you turn on observation without blocking? A good service lets you first see whom it would block and only then enable the rules.
  4. How does it connect to your site? Code on the page or a file on the server, and do your pages stay with you.
  5. Can you export data? A log with addresses, times and click IDs is what you need for exclusions and for the platform's support team.
  6. Does it account for the platform's specifics? Traffic from search, social and native networks has a different "normal" visitor profile.
  7. Does it warn you about false positives? A service that never tells you it is cutting real people simply does not measure it.

A detailed checklist is in how to choose a traffic filtering service.

How ArtisanClo helps protect a campaign from click fraud

ArtisanClo covers the on-site filter layer and the analysis layer. It connects with a JS tag in the landing page's <head> or a PHP file on your server, and the site stays with you.

  • Every visit is checked by network, browser and behavior: data centers, VPNs and proxies, headless browsers, no JavaScript, unnatural interaction. Suspicious visits do not see the offer.
  • Clicks per IP per day limit (from the Professional plan): after the set number of visits, the next ones see a neutral page. You can add your own addresses to the IP whitelist.
  • Unique visitor with a window from one hour to 30 days. In modes with the tracker, a repeat lead from the same visitor lands in "Trash" marked as a duplicate.
  • IP blacklist: addresses and subnets are blocked straight from the click log, one at a time or in bulk.
  • Shared bot list: an address where a bot was confidently caught for any customer is filtered out in your flows too.
  • Click log with address, network, provider, click ID, campaign and the reason for the decision; XLSX export gives you material for exclusions in the ad account and for a request to the platform's support.
  • Tracker mode, with the PHP file connection, lets everyone through but labels bots: the report shows what part of the paid traffic was empty, with no risk of losing leads.
  • Conversion sending to Google Ads, Meta and TikTok (from Professional), so bidding optimizes for real people.

What is specific to each platform is collected in the catalog: Google Ads and Microsoft Bing.

In short

Click fraud protection cannot cancel the charge for a click; only the platform can do that. But it can recognize fraud, keep it off your offer and out of your analytics, remove its source from ad delivery and give you data for a refund. The built-in filters of Google Ads and other PPC platforms are the free first layer; IP and placement exclusions are the second; an on-site filter with a visit log is the third and the one you control best. Judge the effect by cost per lead and the absolute number of leads, not by the share of blocked traffic.

Frequently asked questions

01

How does click fraud protection work?

The service places code on your site or checks the visit on your server, collects data on every click from an ad and separates suspicious clicks by network, browser and behavior. It then either keeps that visit away from the main page, passes IPs and placements to the ad account for exclusion, or gives you data for a refund request.

02

Does Google Ads have built-in click fraud protection?

Yes. Google automatically filters part of invalid clicks and does not charge for them, and if it detects them later it credits the money back to your account. Manually you can exclude IP addresses in campaign settings and placements in the Display Network. The platform does not disclose details on which clicks it ruled invalid.

03

Is a click fraud protection service worth it on a small budget?

Work out how much money goes to suspicious clicks. If the fraud is visible and regular, even a small share of recovered budget pays for protection. If clicks are expensive but few, start with the platform's free tools and a visit log, and add a service once you see the problem in the numbers.

04

Can I block a competitor who keeps clicking my ads?

If the competitor clicks from a fixed address, you can exclude it in the ad account and keep it off the offer on your site. If they rotate addresses through mobile internet or proxies, a per-visitor click limit, a uniqueness window and network checks help. It is impossible to stop a person from clicking an ad entirely.

05

Does Microsoft Advertising protect against click fraud too?

Most large ad platforms, Microsoft Advertising included, filter invalid clicks on their side and do not bill for what they catch. Each offers its own exclusion tools for IPs and placements. In all cases, your own visit log shows what slipped past the platform's filter.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.