You bought a thousand clicks, but the leads look like you bought a hundred. Some visits were robots, some were people from countries the offer does not accept, some were repeat visits from the same addresses. Traffic filtering is the check of every visit before it reaches the offer, ending in a decision to let it through or screen it out, with a clear reason.
In short, traffic filtering is the selection of ad visits by network, browser, behavior and campaign rules: bots, fraud, duplicates, off-target geos and devices, and spy tools are blocked or labeled, while real targeted visitors pass on. The goal is not to cut as much as possible, but to stop feeding junk to your offer and your analytics.
What traffic filtering is and why you need it
An ad platform sells you clicks, but it does not guarantee that a person from your audience is behind each one. Without a filter, the whole mix lands on your landing page and in your stats. That has three consequences:
- money: the offer and the CPA network see junk visits, CR drops, and you draw conclusions about your funnel from corrupted numbers;
- analytics: bots leave clicks, bounces and sometimes form submissions, and your creative report starts lying;
- competitors: spy tools copy your landing page and creatives if nothing stops them.
Ad traffic filtering handles all three with one check. For a media buyer it is a normal part of the setup, alongside the tracker and the postback.
What a traffic filter screens out
| What gets filtered | What it looks like | Why it hurts |
|---|---|---|
| Bots and crawlers | data center networks, software instead of a browser, preview robots | inflate clicks, ruin CR |
| Fraud and click fraud | bursts of clicks from the same addresses, botnets, click farms | burn budget with no chance of converting |
| Off-target geo | a country the offer does not accept, a VPN masking the country | leads are not paid |
| Off-target devices and hours | desktop on a mobile offer, night visits when the call center works days | nobody to process the leads |
| Duplicates | repeat clicks and repeat leads from one visitor | inflate stats, get rejected by the network |
| Spy tools | services that harvest other people's ads and landers | copy your funnel |
Each group is caught by its own signals. Bot signals are covered in detail in bot traffic: signs and how to detect it, and spy tools in protecting your landing page from spy tools.
Untargeted traffic is a separate category that has nothing to do with fraud. A real person from Brazil on an offer for Germany has done nothing wrong, but the offer has no way to pay for them. Here the filter works as second-level targeting: a geo, device and schedule filter catches what the platform let through.
Traffic filtering layers: from network to behavior
A good traffic filtering system does not decide on a single signal. It checks a visit in layers, from cheap checks to expensive ones.
Layer 1. Network and request
This check happens before the page has even loaded: the IP address, its network (ASN) and provider, whether it belongs to a data center or proxy, browser headers, whether an ad click ID such as fbclid or gclid is present, country, device, time. This layer screens out simple invalid traffic: known robots, servers, blacklisted addresses. It touches real people the least.
Layer 2. Browser check
A small script is delivered to the page and checks whether the browser behaves like a browser: does JavaScript run, are there traces of automation, do the claimed version and the actual capabilities match. This is where bots pretending to be people get caught, such as headless browsers and auto-clickers.
Layer 3. Behavior
Mouse and finger movement, time on page, how natural the interaction looks. This layer is the most accurate against advanced bots, but also the riskiest: it adds a wait and sometimes mistakes a person with a slow phone for a bot.
A trust score instead of a single rule
Mature filters do not reject a visit for one weak signal. Some checks reject immediately: an obvious robot, a blacklisted address, a country outside the list. The other signals add up to a trust score: each suspicious signal adds a penalty, and only when the total crosses a threshold is the visit treated as a bot. That way a person on a VPN with a normal browser is not lost over one signal, while a server with no JavaScript and the wrong country is filtered out.
A step-by-step layered setup is covered in how to filter bot traffic from paid ads.
Where the traffic filter sits
Screening can happen in several places, and each has its limits.
- On the ad platform. Google, Meta and others drop part of invalid clicks themselves and do not charge for them. You do not control the rules and do not see who was filtered. More in invalid traffic: what it is and how it is counted.
- In the CPA network. The network's anti-fraud checks leads after the fact and can reject them, but by then the money for the click is already spent.
- On your site. Code on the landing page or a file on your server asks the filtering service for a decision before the page is shown. This is the only point where you set the rules yourself and see the reason for every visit.
- In the tracker. A tracker can label and distribute traffic, but its checks are usually limited to the network and the campaign rules.
The working setup is a filter on your site plus the built-in anti-fraud of the platform and the network.
How to measure what traffic filtering is worth
A filter you cannot verify is just faith. Here is how to tell whether it works.
- Look at reasons, not just the total. A figure like "30% filtered" says nothing. What matters is who was filtered: platform robots, data centers, the wrong geo, or real people caught by a strict rule.
- Compare the conversion rate of the visits that passed. If CR among passed visits rose after you turned the filter on and the absolute number of leads did not drop, the filter is removing junk.
- Watch absolute leads. A drop in lead count after tightening the rules is the main sign that they are cutting real people.
- Run the filter in observation mode. Let it first only label whom it would have blocked, and compare that with conversions.
- Count the money. Suppose, as an illustration, the filter flagged 200 of 1,000 bought clicks as bots. At $0.25 per click, that is $50 of traffic that could never convert. A figure like that is an argument both for a request to the platform and for dropping the source.
Metrics are covered in detail in traffic quality: how to evaluate and check it.
Tip. The share of visits passed to the offer does not, by itself, rate either the traffic or the filter. With a paid source carrying a click ID, most visits can pass, and that is normal. Worry when almost nobody reaches the offer.
Filtering mistakes: how not to cut real people
The costliest filter mistake is not a missed bot but a blocked buyer. A bot costs one click; a blocked person costs a whole conversion.
- A hard per-IP click limit. Hundreds of subscribers sit behind one mobile address, and people often come back to complete an order. A one-click limit cuts both.
- Blocking IPv6 for no reason. Many mobile carriers hand out IPv6, and if the offer supports it, blocking cuts real people.
- Requiring a referrer for social traffic. In-app browsers often lose the referring source. Requiring it for this traffic cuts off half the audience.
- Blocking whole mobile carrier subnets. One clicker is not worth thousands of subscribers.
- Tightening by gut feeling. If a rule was enabled "just in case", check how much it blocked and whether there were conversions among the blocked visits.
- Testing with your own visits. Your test click from an office IP without the platform's click ID is not the same as a click from an ad. For your own tests, use an IP whitelist.
If a click went somewhere you did not expect, the reason is usually visible right away. That is covered in why a click went to the white page.
Tuning the traffic filter for different sources
Identical rules for every platform are a common cause of both missed bots and lost people. Sources differ in what they pass in the link, which networks visitors come from and what a normal visit looks like.
| Source | What is specific | What to account for in the filter |
|---|---|---|
| Search (Google Ads, Bing) | passes a click ID, almost all visitors use ordinary browsers | you can require JavaScript and look harder at visits without a click ID |
| Social (Facebook, TikTok) | lots of visits from in-app browsers, referrer is often lost | do not require a referring site, be careful with provider blocks |
| Native and push | many partner placements, repeat clicks, junk zones | higher per-IP click limit, a report by zone is a must |
| Popunder | many automatic opens and very short visits | browser and behavior checks matter more than network rules |
| Messengers and channels | no click ID at all | rules tied to a click ID do not work here |
So it makes sense to start from a ready rule set for the platform and then adjust it based on the click log, not the other way round. What is specific to each platform is collected in the traffic sources catalog.
How traffic filtering works in ArtisanClo
In ArtisanClo the filter connects to your site in one of two ways: a JS tag as the first line in the landing page's <head>, or a PHP file on your server (for WordPress there is a plugin that installs the same PHP method). The site stays with you; how to choose a method is covered in how to install a cloaker: JS tag or PHP.
From there, setup happens per flow:
| What | How it works |
|---|---|
| Strictness | a Soft / Balanced / Strict switch with values pre-tuned for the traffic source's platform |
| Soft | only IP blacklists and automated bots, no per-IP limits |
| Balanced | adds VPN, proxies, data center networks and a daily per-IP click limit |
| Strict | adds IPv6, required JavaScript, minimum time on page and a hard per-IP limit |
| Audiences | countries, devices, OS, browsers, languages, time zones, cities, regions; on Professional also networks, providers, referring sites |
| Duplicates | unique visitor with a window from one hour to 30 days, by IP or by IP plus browser |
The decision is made in order: hard rejections first, then audience rules, then the trust score. Every visit in the click log gets a reason, such as "VPN or proxy blocked", "Outside campaign hours", "Search or platform crawler" and dozens of others. Above the reasons, the stats show at which step visits were filtered: network and request, browser check, or the check never came back.
To test the filter without risk there is shadow mode: with the PHP file connection everyone goes to the offer, and the log shows whom the filter would have blocked. Tracker mode does the same permanently: bots are only labeled in reports. And if only a tiny share of visits reaches the offer over a day, or the pass rate drops sharply, you get a warning that the rules are probably cutting real people. The full list of capabilities is on the features page.
Summary
Traffic filtering is the screening of every ad visit before the offer: bots, fraud, duplicates, off-target geos and devices, and spy tools are blocked or labeled, and real targeted visitors pass. It works in layers (network, browser, behavior) and combines weak signals into a trust score. A filter's value is measured not by the share it blocks but by how much junk it removed without touching leads. Start with moderate strictness, test rules in observation mode and always look at the reasons behind decisions.



