Where it comes from

Invalid traffic is not one thing, and treating it as one is why most advertisers give up on the problem. It arrives from at least four directions, and they call for different answers.

  • Infrastructure. Scrapers, uptime monitors, price comparison crawlers, security scanners. Mostly harmless in intent, entirely useless to you, and cheap to identify because they run on cloud networks.
  • Competitors. Manual clicking is rarer than folklore suggests. Automated monitoring of competitor ads is not: tools that check your ad position several times a day, each check costing you a click.
  • Partners. An affiliate paid per click has an obvious incentive, and inflating volume is easy when nobody inspects the traffic. This is the expensive category, because the money moves directly from you to them.
  • Fraud networks. Rented devices and residential proxies, built to look like ordinary people. The hardest to catch and, for most advertisers, not the largest share.

Why your platform reporting will not tell you

Ad platforms do filter invalid traffic, and they are reasonably good at it. But they filter according to their own definitions, on their own side, and they show you the result rather than the working. You get a number labelled invalid, not the list of addresses, not the reasoning, not the ability to check it yourself.

They also have no visibility on the traffic you buy elsewhere. If you run ads on four platforms and an affiliate programme, five different filters apply five different standards, and none of them compares notes.

What is actually detectable

Be sceptical of anyone promising to catch everything. Three categories are reliably identifiable from the click alone.

Datacenter traffic is the clearest signal there is. Consumer internet access comes from consumer networks. When a click arrives from a cloud provider or a server farm, no person is behind it. This alone often accounts for the bulk of what gets flagged.

Verified crawlers can be confirmed rather than guessed, by checking the name attached to the address and confirming it resolves back to the same place. A user agent claiming to be a search engine proves nothing; the reverse lookup does.

Anonymising networks, commercial VPNs and public proxies, are known ranges. Some of that traffic is legitimate privacy-minded people, which is why it deserves review rather than automatic exclusion.

What resists detection from the address alone is the fourth category: residential proxies. The address genuinely belongs to a household, so it looks exactly like a customer. Catching that needs behaviour, not geography, and anyone claiming otherwise is guessing.

What to do with it

Flagging is worthless without an action attached. The point of a list of addresses is to load it into the exclusion settings of the accounts you buy from, so the same traffic stops costing you next month. Keep verified crawlers out of that list: excluding the address a platform uses to review your ads causes more damage than the clicks ever did.

Start by measuring for a month before changing anything. You need to know your baseline share before you can tell whether a placement is unusually bad.