The word "protection" in click fraud protection is a little misleading. The click happens on the ad platform's side, and the platform charges for it before the visitor even reaches your site. So no service can "forbid" a fake click. What it can do is keep fraud away from your offer, get its IPs and placements excluded from your ads, and give you the data to get your money back.
Click fraud protection is a combination of three actions: recognize suspicious clicks by network, browser and behavior; keep them off the main page and out of your analytics; and remove their source from your ads and claim compensation. What click fraud is and how it looks in your stats is covered separately in click fraud: how to detect it. This article is about how the protection itself works.
How click fraud protection works: three layers
Any service or manual protection setup is made of the same parts. The difference is which of them are covered and how well.
| Layer | What it does | What you get | What you do not get |
|---|---|---|---|
| Click analysis | collects data on ad visits and looks for anomalies | an understanding of the scale and sources of fraud | does not block anything on its own |
| Ad account exclusions | passes IPs and placements to the platform so it stops showing ads to them | fewer future paid clicks from the same source | does not work against rotating addresses |
| On-site filter | decides for every visit whether to show the main page | clean offer and analytics, the offer's budget is not spent on bots | does not refund a click that already happened |
Let's take each layer in turn.
Click analysis
The service places a tracking script on the site or checks the visit on the server and records for every click: address and network, provider, device, browser, time, ad click ID (gclid, msclkid and others), on-page behavior. Typical red flags:
- bursts of clicks from one address or subnet in a short time;
- visits from data center networks and proxies;
- browsers with signs of automation or no JavaScript;
- instant exits with no scrolling or movement;
- clicks carrying a click ID that repeats across different visitors.
The point of analysis is not a verdict like "fraud detected" but an answer to "where is it coming from". Without that, the other layers work blind.
Exclusions in the ad account
IPs and placements you found can be removed from ad delivery. Most click fraud protection services do this automatically through the platform's API or export a ready list. The method has limits: platforms cap the number of IP exclusions, and botnets and mobile proxies change addresses faster than you can add them. Against a competitor with a static IP an exclusion works great; against distributed fraud it works poorly. When blocking by address is justified is covered in IP blacklists in affiliate marketing.
On-site filter
The most reliable layer: a check before the main page is shown. A bot that won the auction and clicked still does not see the offer, does not leave a fake lead and does not ruin the conversion rate in your report. An on-site filter matters especially when fraud targets your forms rather than your spend; see bots submitting forms and fake leads.
What ad platforms do on their own
Before buying a service, figure out what the ad system already does. Its protection is free and works before you are charged.
Google Ads click fraud protection
- Automatic invalid click filtering. Google filters part of suspicious clicks in real time and does not charge for them. Those detected later are compensated with a credit to your account.
- Invalid clicks report. In campaign stats you can add columns with the number and rate of invalid clicks: that is what the platform has already recognized and not billed.
- IP exclusions in campaign settings, with a cap on how many.
- Placement exclusions in the Display Network and on YouTube: apps and sites that send junk.
- Investigation request. If you see fraud the platform missed, you can contact support with data.
Google's click IDs and parameters are covered in Google Ads tracking: gclid, ValueTrack and offline conversions.
Other PPC platforms
Microsoft Advertising and other search and display networks work the same way: part of the clicks is filtered automatically and not billed, IP exclusions are available with a cap on their number, and in the partner network you can block specific sites and apps.
Tip. A platform's built-in protection covers only what the platform itself recognized. It does not know your rules and does not show whom it filtered. That is why you need your own visit log even if you trust the platform.
Built-in protection and external tools do not compete. The platform cuts what it sees on its side before charging you, while the on-site filter and the visit log show what actually reached you. Together they give the full picture: how much the platform recognized on its own, how much got past its filter and what else you can claim compensation for.
What actually helps and what does not
| Measure | Helps against | Limits |
|---|---|---|
| On-site filter with a browser check | bots, auto-clickers, server traffic | the click is already paid for |
| Per-visitor click limit | competitors and manual click fraud | a limit that is too strict cuts real people |
| Uniqueness window | removes repeats from analytics and duplicate leads | does not stop the first click |
| IP exclusions in the ad account | static addresses | capped list, useless against botnets |
| Placement exclusions in display and partner networks | inflation on partner sites | needs regular review |
| Narrower targeting and schedule | shrinks the field for fraud | also shrinks useful reach |
| Sending conversions to the ad account | the algorithm learns from people, not bots | requires working tracking |
The last point is often underrated. Automated bidding strategies optimize for events. If only real leads go to the ad account, the algorithm stops looking for an audience that resembles bots. How to set that up is covered in sending conversions to ad platforms.
What barely helps:
- A captcha on the landing page for everyone. It scares off people more than bots.
- Blocking entire mobile subnets. Along with one clicker you cut thousands of subscribers.
- A one-time cleanup. Fraud changes addresses and placements, so exclusions need regular review.
How to measure the effect of click fraud protection
Protection should pay for itself in numbers, not in feelings. Compare two equal periods, before and after, on these metrics:
- The share of suspicious visits in the log and how it splits by reason: network, browser, behavior.
- The invalid click rate in the ad account. If it went up after your requests, the platform has started recognizing the fraud.
- Cost per lead (CPA) at a stable lead volume.
- The absolute number of leads. If it fell along with the fraud, the protection is cutting real people.
- The amount of compensation from the platform over the period.
An illustration: you spend $2,000 a month on search, and the log shows that 15% of visits are repeat clicks from the same subnets and data center networks. That is about $300 of traffic that could never convert. After a click limit, exclusions and a support request the share drops to 5% while leads stay at the same level: the protection paid off. If the share dropped and leads dropped with it, the rules are too strict. Metrics for this kind of assessment are collected in traffic quality: how to evaluate and check it.
How to choose a click fraud protection service
There are many services, and they all promise roughly the same thing. A few questions separate a useful one from the rest.
- Does it show a reason for every click? A verdict like "fraud: 23%" without a breakdown can be neither verified nor used in a request to the platform.
- What does it do with a suspicious visit? Just count it, exclude IPs in the ad account, or also keep the visit off the main page.
- Can you turn on observation without blocking? A good service lets you first see whom it would block and only then enable the rules.
- How does it connect to your site? Code on the page or a file on the server, and do your pages stay with you.
- Can you export data? A log with addresses, times and click IDs is what you need for exclusions and for the platform's support team.
- Does it account for the platform's specifics? Traffic from search, social and native networks has a different "normal" visitor profile.
- Does it warn you about false positives? A service that never tells you it is cutting real people simply does not measure it.
A detailed checklist is in how to choose a traffic filtering service.
How ArtisanClo helps protect a campaign from click fraud
ArtisanClo covers the on-site filter layer and the analysis layer. It connects with a JS tag in the landing page's <head> or a PHP file on your server, and the site stays with you.
- Every visit is checked by network, browser and behavior: data centers, VPNs and proxies, headless browsers, no JavaScript, unnatural interaction. Suspicious visits do not see the offer.
- Clicks per IP per day limit (from the Professional plan): after the set number of visits, the next ones see a neutral page. You can add your own addresses to the IP whitelist.
- Unique visitor with a window from one hour to 30 days. In modes with the tracker, a repeat lead from the same visitor lands in "Trash" marked as a duplicate.
- IP blacklist: addresses and subnets are blocked straight from the click log, one at a time or in bulk.
- Shared bot list: an address where a bot was confidently caught for any customer is filtered out in your flows too.
- Click log with address, network, provider, click ID, campaign and the reason for the decision; XLSX export gives you material for exclusions in the ad account and for a request to the platform's support.
- Tracker mode, with the PHP file connection, lets everyone through but labels bots: the report shows what part of the paid traffic was empty, with no risk of losing leads.
- Conversion sending to Google Ads, Meta and TikTok (from Professional), so bidding optimizes for real people.
What is specific to each platform is collected in the catalog: Google Ads and Microsoft Bing.
In short
Click fraud protection cannot cancel the charge for a click; only the platform can do that. But it can recognize fraud, keep it off your offer and out of your analytics, remove its source from ad delivery and give you data for a refund. The built-in filters of Google Ads and other PPC platforms are the free first layer; IP and placement exclusions are the second; an on-site filter with a visit log is the third and the one you control best. Judge the effect by cost per lead and the absolute number of leads, not by the share of blocked traffic.



