Ad-spend recovery for agencies: protect client budgets

15 min read

21.3% of onsite traffic is invalid (crawlers excluded). Ad spend recovery for agencies: protect client budgets, report transparently, prove your value.

Fanned stack of dashboard screens guarded by a green shield, representing an agency protecting multiple client accounts

Your clients judge you on results they can see, but a slice of their budget never reaches a real person. In 2025, fraud0's Unmasking the Shadows report found that 21.3% of all onsite traffic was invalid (search-engine crawlers excluded), across 1.2 billion sessions. For an agency, that figure isn't a threat. It's an opening. The waste exists whether or not anyone looks for it, so the agency that surfaces it first, reduces it, and recovers what slipped through becomes the partner clients trust most. This post shows how to turn invalid traffic from a hidden cost into a visible win.

Key Takeaways

  • Invalid traffic is an industry-wide reality, not an agency failing. In 2025, fraud0's Unmasking the Shadows found 21.3% of onsite traffic invalid (search-engine crawlers excluded), so surfacing it makes you transparent, not exposed.

  • Ad-spend recovery for agencies runs on two arcs: protect client spend (reduce future waste through detection and exclusion) and recover the residual (pursue evidence-based refunds). Detection cuts the leak; a brand-new bot's first click still slips through, so refunds stay essential.

  • Recovered money usually returns as account credit toward future spend, not cash, and refunds are never guaranteed. Outcomes depend on detected invalid activity and platform processes.

  • Done right, IVT protection is a growth lever: it builds client trust, differentiates your pitch, and turns a quiet problem into a reportable result.

Agency account manager presenting a clean dashboard to a client, split into a green valid-traffic segment and a smaller red invalid-traffic-recovered segment

Let's be clear about the framing from the start. Ad spend recovery is the combined practice of reducing future ad waste through detection and exclusion, then reclaiming budget already lost to invalid activity through evidence-based refunds. Surfacing that waste in a client's account isn't an admission that you missed something. The waste was always there, sitting inside platform-reported metrics that look healthy on the surface. You can't manage a leak nobody can see. So the agency that makes it visible is doing exactly what a good partner should: protecting the client's money and proving it. That's the spirit of this entire post.

To ground the rest of this guide, here's the vocabulary it leans on. Invalid traffic (IVT) is any ad interaction that doesn't come from a genuine, interested human, spanning bots, automated scripts, and accidental or manipulated clicks. Ad fraud is the deliberate generation of fake clicks, impressions, or conversions to siphon advertiser budgets, and it sits at the costly end of the invalid-traffic spectrum. Made-for-advertising (MFA) sites are low-quality pages built mainly to farm ad revenue rather than to reach real buyers, so impressions served there rarely convert. Together, these define the waste an agency learns to surface, reduce, and recover.

Why should agencies care about invalid traffic?

Invalid traffic touches every account an agency manages, and it concentrates harder than headline rates suggest. In 2025, fraud0's Unmasking the Shadows report found the aggregate 21.3% invalid rate climbed to 32.0% per individual user (search-engine crawlers excluded), across 1.2 billion sessions. So roughly a third of the user-level activity touching your clients' sites carries no business value. That's spend you're optimizing around blind.

Here's why it matters commercially, not just technically. Agencies live and die on retention, and retention runs on trust. For example, when a client suspects their budget is leaking and you can't explain where, the relationship cools. However, when you can name the waste, reduce it, and recover some of it, you become indispensable. As a result, the same data that worries clients becomes the proof that you're protecting them.

In 2025, fraud0's Unmasking the Shadows report analyzed 1.2 billion onsite sessions and found 21.3% of onsite traffic invalid (search-engine crawlers excluded), rising to 32.0% per individual user. For agencies managing client budgets, that means roughly a fifth of measured traffic, and up to a third per user, carries no business value.

The wider web backs this up. In 2024, Imperva's Bad Bot Report concluded that bots made up 51% of all web traffic, the first year automated traffic overtook humans (Imperva, 2024 Bad Bot Report). When more than half the internet isn't human, some of it lands on every campaign you run. That's not a reason to panic. It's a reason to look, because you can't protect what you can't see.

Is surfacing invalid traffic bad for an agency's reputation?

No, and this is the misconception worth retiring. Invalid traffic is an industry-wide condition, not a sign an agency dropped the ball. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded). The waste exists across the whole market, so naming it makes you the transparent partner, not the one who got caught.

Think about how a client reads it. For instance, if invalid traffic surfaces and you raised it first, with data and a plan, you look proactive. In contrast, if it surfaces from somewhere else, or never at all, you look passive. The story you want is the first one. In other words, you're the agency that watches for waste, reports it honestly, and acts on it.

In our work supporting agencies, the fear we hear most is "won't this make us look bad?" The opposite tends to happen. Clients don't expect agencies to control whether bots exist on the internet. They expect agencies to notice, protect, and recover. Framing IVT as a shared external problem you're solving together is what turns an awkward conversation into a trust-building one.

The agencies that struggle with this aren't the ones with the most invalid traffic. They're the ones who treat it as a secret to manage rather than a service to offer. Reframe detection as a deliverable, not a disclosure, and the reputational risk inverts. Transparency about a problem nobody can fully prevent reads as competence, not failure.

How does invalid traffic protection make you the client's hero?

Protection turns an invisible cost into a reportable win, and that's where the value shows. In 2025, fraud0's Unmasking the Shadows report found invalid traffic ranged from 20.6% on Paid Social to 7.0% on Paid Search (search-engine crawlers excluded). When you can show a client where their waste concentrates and how you're reducing it, you're not just running ads. You're protecting their money on purpose.

Invalid-traffic rate by channel from fraud0 Unmasking the Shadows 2025: Owned/Direct 37.1%, Paid Social 20.6%, …

Source: fraud0, Unmasking the Shadows 2025.

The hero framing isn't spin. It's a real shift in what you bring to the table. Most agencies report clicks, conversions, and cost per result. Few can report how much invalid traffic they kept out of the funnel and what they recovered of the residual. That second story is rare, which is exactly why it differentiates you.

Ad spend recovery runs on two arcs that work together, not in sequence. The table below summarizes how each one shows up in the work you do for clients.

Arc

What it does

How it shows up for the client

Protect the spend

Detects invalid activity and excludes the sources, so more budget reaches real people

Less future waste, cleaner analytics, lower effective cost per real result

Recover the residual

Documents the invalid activity that still slipped through and supports an evidence-based claim

Account credit toward future spend where the platform approves it, never guaranteed

Neither arc replaces the other. Detection narrows the leak, yet a brand-new bot's first click has no history to match against, so recovery stays a permanent companion to protection rather than a fallback.

In 2025, fraud0's Unmasking the Shadows report measured invalid-traffic rates by channel, from 20.6% on Paid Social to 7.0% on Paid Search (search-engine crawlers excluded). Agencies that surface, reduce, and report this waste give clients visibility into spend protection that standard platform dashboards don't provide.

What does protecting client spend actually involve?

Protecting client spend means detecting invalid activity and excluding the sources behind it, so more of the budget reaches real people. Platform-reported metrics filter some invalid traffic, but not all of it. Onsite, first-party detection catches much of what platform filtering misses, then feeds exclusion lists back into the platforms that support them: Google Ads, Meta, Microsoft, DV360/CM360, and Criteo. For platforms without an audience-exclusion integration, such as TikTok and LinkedIn, the lever is pixel or tag control plus analytics hygiene.

The honest limit matters here. Protection reduces the leak, it never seals it. A brand-new bot's first click has no history to match against, so it can't be pre-blocked. That residual is real and permanent, which is why reducing waste and recovering the rest always run together. Choosing the right detection approach is its own decision, and our click fraud protection buyer's guide walks through what separates genuine protection from IP-blocking with a dashboard.

Why does the recovery story differentiate your pitch?

Because almost nobody else tells it. The category is crowded with agencies promising better creative, smarter bidding, and tighter targeting. Far fewer can stand in front of a prospect and say they actively protect spend from invalid traffic and pursue recovery of what slips through. In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions were invalid (7.82% confirmed bots plus 1.92% suspected), so the problem is concrete, and a credible answer to it is a genuine edge. The industry scale backs that up too: Juniper Research has estimated advertiser losses to ad fraud at roughly $84 billion for 2023, projected to keep climbing. That's an industry estimate, not your client's invoice, but it frames the size of what you're protecting against.

How do agencies operationalize detection across clients?

Operationalizing detection means running it as a standard service layer, not a one-off audit. In 2025, fraud0's Unmasking the Shadows report found 31.4% of ad impressions landed on made-for-advertising (MFA) sites (search-engine crawlers excluded), placements built to farm ad revenue rather than reach buyers. To catch that consistently across a portfolio, detection has to be systematic, not heroic.

The practical model is to treat IVT protection like any other recurring deliverable. Onboard each client account into onsite, first-party detection. Surface the invalid activity as it happens. Push exclusions back into the campaigns. Then roll the findings into the regular reporting cadence the client already expects. The work scales because it's the same motion on every account.

In 2025, fraud0's Unmasking the Shadows report found 31.4% of ad impressions landed on made-for-advertising sites, paired with 38.5% average viewability (search-engine crawlers excluded). For agencies, running first-party onsite detection as a standing service layer across client accounts surfaces this waste systematically rather than account by account.

How should you report invalid traffic to clients?

Report it the way you report everything else: clearly, with numbers, and tied to money. A client doesn't need the technical detail of how a bot was scored. They need to know how much invalid traffic was detected, how much was excluded going forward, and what recovery was pursued on the residual. Plain language beats jargon every time.

In our experience, the reports that land best lead with the protective outcome, not the threat. "We kept this share of invalid traffic out of your funnel and pursued recovery on the rest" reads very differently from "your account has a fraud problem." Same facts, opposite emotional register. The first one builds trust; the second one creates alarm you then have to manage.

Clean client-facing report mockup showing three metrics: invalid traffic detected, excluded going forward, and recovery pursued, with green and red accents

What about analytics hygiene across the portfolio?

Analytics hygiene is the quiet compounding benefit. When invalid users pad volume and drag down engagement averages, every optimization decision built on that data tilts wrong. In the fraud0 data, invalid users averaged just 1.2 page views and 26-second sessions, versus 181 seconds overall. Clean the data and your bidding stops chasing audiences that look active but never buy. That improves performance for the client and makes your reporting honest.

How do agencies support refunds for client spend?

Refunds are the recovery arc: reclaiming budget already lost to invalid activity, with evidence. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded), which means some of the clicks a client was charged for were never real. Where that invalid activity is detected and documented, an agency can support a recovery claim through the platform's process on the client's behalf.

This is where honesty protects the relationship. Refunds aren't automatic, easy, or universal. They depend on what invalid activity is actually detected and on each platform's review and approval process. They're also not a fallback for when protection fails. Because no detection can pre-block a brand-new bot's first click, some invalid traffic always slips through, so pursuing recovery is a permanent part of the job, not a last resort.

In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions invalid (7.82% confirmed bots, 1.92% suspected). Where invalid activity is detected and documented, agencies can support evidence-based ad-spend recovery for clients through platform processes. Outcomes depend on the evidence and the platform's review, and platforms such as Google typically return money as account credit rather than cash.

What does an agency's role in a refund claim look like?

The agency is the evidence-builder and the navigator. You identify the invalid activity, document it with onsite, first-party records, and submit through the platform's defined channel on the client's behalf. The platform reviews the claim against its own standards, and where the activity qualifies, it issues an adjustment. There's no shortcut around that review, which is why setting expectations matters more than promising results.

One detail to flag with clients up front: recovered money usually returns as an account credit toward future spend, not cash back to a card. The terms get used loosely, but the distinction is real for the client's books. A credit lowers future media cost rather than topping up the bank. Frame it accurately and a credit reads as a genuine win. Frame it as "cash back" and you set up a disappointment. The full mechanics live in our ad-spend refund guide.

What evidence makes a client's claim reviewable?

Evidence is what separates a claim that's reviewed seriously from one that isn't. A platform can't act on a hunch. It needs documentation showing the invalid activity, when it happened, and how it was identified, ideally from first-party, onsite detection logged in real time rather than reconstructed later from a platform report. That's the raw material your service layer should already be producing.

The agencies that do this well don't treat documentation as a separate project. They make it a byproduct of detection. If your protection layer logs invalid activity with the attributes that distinguish a bot from a buyer as it happens, the evidence for a claim is already sitting there. That turns refund support from a heavy lift into a natural extension of the protection you're already running.

Refunds for clients aren't limited to invalid traffic either. An ad-account audit across accounts can also surface billing errors, overdelivery, and out-of-geo spend. See ad-spend overbilling.

What does ad-spend recovery look like for a real advertiser?

Recovery isn't theoretical, and it works the same way whether you run it in-house or through an agency. Consumer-health brand Uriach worked with fraud0 to clean up its campaigns and secure ad refunds, combining the protect-the-spend and recover-the-loss motions into one program. Where invalid activity was detected, evidence supported the recovery process.

The point of an example isn't to promise the same outcome to every client. It's to show the mechanism running end to end: detect, exclude, document, recover. Results depend on what invalid activity is present and on the platform processes involved. For an agency, it's a useful template for how to structure the same program across a portfolio. Read the full story in our how Uriach recovered wasted spend.

How do you start offering ad-spend recovery to clients?

Start with measurement, because you can't protect or recover what you can't see. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded) across 1.2 billion sessions, yet most of that waste never appears on a standard dashboard. First-party, onsite detection on a client account is the entry point to both arcs, and it's how you turn a suspicion into a number you can act on.

From there, the path is practical. Pick one or two accounts, run detection, see what surfaces, and report it the way this post described: protective outcome first, plain language, tied to money. If the data supports it, document the invalid activity and pursue recovery. Then scale the same motion across the portfolio as a standing service layer.

A quick reality check, though. Not every client account has a large recoverable loss, and not every claim succeeds. That's fine. The value to the client isn't only the recovered credit. It's the visibility, the protection going forward, and the trust that comes from an agency that watches for waste instead of ignoring it.

This is exactly where fraud0 fits for agencies. We make wasted client spend visible through onsite, first-party detection, then support evidence-based recovery where invalid activity is found. No guarantees on the outcome, just clarity on the problem and a documented path to act on it, so you can show every client you're protecting their budget and recovering what you can. For the full two-arc playbook behind this, see how advertisers recover wasted ad budget from end to end.

Frequently asked questions

Frequently asked questions

Frequently asked questions

What is ad spend recovery for agencies?

Ad spend recovery for agencies is the practice of protecting client budgets from invalid traffic and recovering what slips through. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded). It runs on two arcs: reducing future waste through detection and exclusion, and pursuing evidence-based refunds for the documented residual.

Will surfacing invalid traffic make my agency look bad to clients?

+

How does invalid traffic protection help client retention?

+

Can an agency get refunds for clients on invalid clicks?

+

Is recovered ad spend returned as cash or credit?

+

How do agencies scale invalid traffic detection across many clients?

+

Does platform filtering already protect my clients' spend?

+

Latest Posts

Latest Posts

Latest Posts

Explore all →

Explore all →

Protect your marketing from bots and invalid traffic

Take back control over your marketing and data and try fraud0.

Cta Image

Protect your marketing from bots and invalid traffic

Take back control over your marketing and data and try fraud0.

Cta Image

Protect your marketing from bots and invalid traffic

Take back control over your marketing and data and try fraud0.

Cta Image