Your campaign starts getting more clicks; CTR is going up; traffic is flowing into your campaigns at a rapid pace; everything appears to be moving in the right direction.
Then you take a deeper look.
There are no real improvements in conversion rates. Users seem to evaporate immediately after they click on something. Something about your traffic source looked perfectly fine yesterday, but today it looks completely different from everything else around it.
Sometimes, there will be a rational explanation. Sometimes there won’t be.
Detecting invalid traffic can often be tricky, and sometimes extremely difficult, because it does not always present itself in an obvious manner. Sophisticated types of fraudulent activity (e.g., mimicking normal device usage, browsing patterns and/or conversions) can pass a basic review of campaign metrics.
The key is knowing which indicators actually require further investigation. An important ability advertisers need is recognizing the particular indicators that may point to potential issues with fraudulent traffic, especially when several of those indicators appear simultaneously.
One strange metric doesn’t automatically mean fraudLet’s go over something simple to remember.
A high bounce rate by itself is not sufficient evidence to conclude that the traffic is invalid. Similarly, neither a sudden drop in conversions nor an unusual browser nor a user leaving your landing page after five seconds constitutes conclusive evidence.
In reality, real users act erratically all of the time.
Additionally, various factors, including your offer, ad copy, landing page, targeting, and tracking setup, can influence your campaign performance.
Therefore, it makes more sense to evaluate suspicious traffic based upon its overall pattern rather than trying to isolate a single metric.
However, there are certain indicators that are far more valuable than others when evaluating whether or not there may be suspicious traffic.
Repeated activity that looks too consistentHumans tend to act chaotically. They stop scrolling, browse at varying speeds, return to the site, click on the incorrect link, abandon web pages, switch devices, and simply don’t follow any type of consistent path.
Fraudulent activity tends to exhibit repetitive characteristics. Here are examples of suspicious patterns you may find:
- Clicks arriving in massive quantities within extremely short amounts of time.
- Actions being performed at abnormally precise intervals.
- Large numbers of interactions originating from the same IP address.
- Repeated traffic with identical device and user-agent data.
- The same series of actions repeated consistently.
These alone do not necessarily prove that the traffic is invalid. However, repetition becomes much more suspicious when the volume of activity is greater than would normally occur with typical user behavior.
When hundreds of seemingly independent users behave nearly identically, that warrants additional review.
The GEO doesn't match the campaignAnother indication of potential problems is traffic that does not align with your campaign targeting parameters.
For example, you may be running an advertising campaign specifically targeted at one geographic region and observe significant volumes of traffic coming from other regions. If a large share of the IP data points to data centers, proxy servers, or VPN infrastructure rather than the type of traffic you expected to receive, then it may also be worth a closer look.
While legitimate explanations exist for individual discrepancies (users travel; VPNs are widespread; IP geolocation is imperfect), systematic location mismatches raise questions about how the traffic was generated.
Technical details starting to look weirdOccasionally, suspicious traffic presents itself through smaller inconsistencies related to technical details.
You may encounter higher-than-normal session volumes from obscure or antiquated browsers; multiple users may have the exact same display resolution; referrer data may be absent or inconsistent; JavaScript or cookies may be disabled for an unusually large share of sessions.
You may also see patterns in user-agent data that do not match the rest of the traffic.
As before, context plays a role here. A single unusual browser is simply one anomaly. Several anomalies showing up in combination for the same traffic source tell a much different story.
One zone or subID performs totally differently from othersCampaign-level statistics can mask things. A source may appear “good” as long as you view it as a whole. However, a specific segment of that source, such as a zone, placement, or subID, may be acting completely differently from the others.
Perhaps the click-through rate for this segment is much higher than for the others while the cost per acquisition is significantly higher. Or maybe this segment is generating a high percentage of clicks but none of the real activity afterward. Or perhaps one placement is producing a totally new type of trend that you've never seen before.
This is where viewing campaign metrics separately becomes valuable.
View each source individually, along with each zone and subID, rather than just using the overall campaign average. Also ensure you are comparing them within the same attribution window. If you don’t, then timing differences will give you a misleading impression of what is happening.
It’s not about finding a source that acts similarly to every other source. Sources won’t act similarly. Your goal is to identify significant deviations and investigate whether they indicate a traffic-quality issue or another campaign-specific pattern.
Plenty of clicks but never anything after thatA user clicks an advertisement, views a website, performs a basic action, and leaves the site. This occurs naturally.
However, if the same thing keeps happening in almost exactly the same way at scale, it may be more interesting.
Even legitimate users may not take multiple paths throughout the site. Depending on the campaign, however, you should normally expect at least some users to take some form of subsequent action after the first visit. The types of subsequent actions will vary (e.g., browsing a second page, returning to the site, verifying their account, completing their profile, making a deposit, purchasing something, etc.).
Suspicious traffic can stop unusually early in these processes. As such, campaign metrics may appear healthy at the beginning of the funnel while disintegrating once viewed further down.
Conversions which do not act as conversionsAn increase in the conversion count does not always indicate that the traffic being generated is good.
Consider a campaign which begins to generate a large number of registrations. On paper, this looks great! Yet hardly anybody verifies their email addresses. Few people finish creating profiles. There are no repeat visits, deposits, purchases, etc.
That difference means something. Fraudulent activity can sometimes produce simple conversion events, but it may fail to reproduce the behavior that would typically follow the conversion event.
Therefore, advertisers should refrain from evaluating the first conversion event alone. If you have access to deeper-funnel data, utilize it.
A registration with no follow-through activity tells a very different story from a user who later becomes an active customer.
How about high bounce rates and extremely quick site visits?Both are worth examining. By themselves, they are weak signals of potential issues.
There are obviously many things to consider when users consistently spend only a few seconds on a site and/or view only one page without scrolling before leaving right away. Same goes for campaigns with lots of clicks and virtually no target actions.
Neither scenario directly indicates fraudulent activity.
Poor landing pages can cause both scenarios to occur. Poor offers, creative mismatches, slow page loading times, misleading ad copy, bad targeting, or simply uninterested audiences can also lead to both scenarios.
Advertisers tend to make the opposite error here: identify a poor-performing metric and immediately point fingers at the traffic source.
Check the entire funnel prior to doing so. If a landing page is broken, then stopping five traffic channels probably isn’t going to help much.
Look at all the signalsTypically, a stronger indication of potential fraudulent traffic is not one suspect metric. It is when numerous metrics signal the same issue.
For example, let us say we have a source that simultaneously shows:
- High volume of repetitive clicks.
- Traffic from unusual geographic locations.
- Identical technical attributes present in numerous sessions.
- Very short time spent on-site.
- No downstream activity.
- Simple conversions never proceed beyond that single step.
If we see one oddball statistic from a given source which is otherwise behaving normally in terms of producing downstream activity… we really don’t need to freak out. Simply keep monitoring and determine if the behavior ceases or develops into a recurring pattern.
Generally speaking, this is better than treating all anomalies as definitive evidence of fraudulent traffic.
You think the traffic looks suspicious? Here’s how to handle itIf you notice several signs that point to potential invalid traffic, don’t try to figure everything out on your own. Reach out to your ad network first. If you work with
RollerAds and have an account manager, share the issue with them directly. Or contact the support team and provide as much information as you can about what you’re seeing. Any reputable ad network should help you investigate the issue and understand what is actually happening.
There are also a few things you can check yourself to speed things up.
1. Check the funnelCheck each part of the chain (domain, URL, redirect, etc.) users follow from the ad to the landing page. Make sure each link works properly. Follow the route that a real user follows. Sometimes what might appear to be suspicious traffic could be a technical glitch somewhere inside the funnel. It’s always best to figure out whether or not it is a tech problem before spending hours investigating something else.
2. Forward your tracking information to the ad networkWhen you have a tracker installed, this is when it will come into play. Tracker stats, click logs, IP and user-agent info, and landing page CTR can add to what the network has to go on when investigating suspicious traffic. While we may still be able to investigate this without the extra data provided, the more data you can provide, the less of a pain it will be for us to narrow down what happened. This is also why implementing tracking prior to launching a campaign is way easier than attempting to rebuild everything once something happens.
Don’t wait for suspicious traffic before implementing proper trackingProper tracking is usually used as an optimization tool. Optimization is certainly a major function of tracking.
However, tracking also provides advertisers with a record of what happened when their traffic behaved unexpectedly.
Without source-level data, you'll likely only see that a campaign performed poorly.
With a tracker, you have a greater opportunity to see where and when performance changed, what segment(s) were involved, and what the suspicious sessions had in common.
That makes a world of difference between having a hunch and providing an ad network with something tangible to investigate.
What happens when you report suspicious traffic?Reputable ad networks have a strong incentive to protect traffic quality. Their reputation depends on the quality of the traffic they provide, so they screen sources before adding them to the platform and continuously monitor them afterward. Still, no system is perfect, and invalid traffic can sometimes slip through.
That’s why it’s worth knowing what to do if something looks wrong. Think of it as a precaution rather than an expectation: you may never need it, but having a clear process in place can save you time and money if an issue does arise.
If you suspect fraudulent traffic, contact your ad network as soon as possible and share the evidence you have. A responsible network should investigate the source, help determine what happened, and take appropriate action when invalid traffic is confirmed. Depending on the network’s policies and the circumstances, this may include blocking the source and addressing any resulting financial impact.
The important thing is not to panic or try to solve the problem alone. Keep your tracking data, report unusual activity promptly, and work with your ad network to get to the bottom of it.
Closing thoughtsAt RollerAds, we treat traffic quality as an ongoing process, not a box to tick once a campaign is launched. Our systems continuously monitor traffic for suspicious patterns, while our team regularly updates the metrics and detection methods we use to identify potential invalid activity.
No anti-fraud system can make the risk disappear completely. What matters is having the tools and people in place to spot unusual activity, investigate it, and act when necessary.
If something about your traffic doesn’t look right, reach out to us. Share what you’re seeing, and our team can help you investigate the issue and understand what’s behind it.
If traffic quality and fraud prevention are important to your campaigns,
talk to the RollerAds team. We’re here to help you make informed decisions about your traffic.