You searched for how to stop click fraud, so let's be honest from the first line. You can't stop all of it. What you can do is reduce invalid clicks sharply with IP and placement exclusions, negative audiences, and monitoring, then document what slips through and pursue recovery. In 2025, fraud0's Unmasking the Shadows report measured 7.0% of Paid Search traffic as invalid (search-engine crawlers excluded), the lowest of any channel and still real money. This guide walks you through both halves: cut the leak, then recover the residual.
Key Takeaways
You can't pre-block every fake click. A brand-new bot's first click has no history to match against, so it gets through. Reduce sharply, then recover the rest.
In 2025, fraud0's Unmasking the Shadows report found 7.0% of Paid Search traffic invalid (search-engine crawlers excluded), the lowest channel rate but still wasted budget.
The workflow is four steps: spot the signals, exclude the sources (IP, placement, negative audiences), set up monitoring, then document invalid clicks as evidence for refunds.
Google Ads filters invalid clicks at the platform level, but it can't see what traffic does once it reaches your site. Onsite, first-party detection narrows that gap.
Recovered money from Google usually returns as account credit toward future spend, not cash. Outcomes depend on detected invalid activity and platform review.

Click fraud is the literal term people search, and it's worth naming plainly. Click fraud is the practice of generating invalid clicks on paid ads, whether through bots, automated scripts, click farms, or repeat-offender sources that burn budget meant for real prospects. Invalid clicks are clicks that Google or onsite detection flags as non-genuine because they come from automation or manipulation rather than a real buyer. Google calls this whole category invalid activity. However you name it, the goal stays the same. For example, a botnet hammering one campaign and a single click farm both waste the same dollars, so you reduce how much you pay going forward, then recover what you can of what's already gone. Let's get tactical.
Can you actually stop click fraud on Google Ads?
No, not completely, and any tool that promises otherwise is overselling. You can reduce invalid clicks sharply through exclusions and monitoring. However, a brand-new bot's first click has no history to match against, so it can't be pre-blocked. In 2024, Imperva's Bad Bot Report found bots made up 51% of all web traffic, the first year automation overtook humans. As a result, some always gets through.
Here's the honest mechanism. Filtering and exclusion work by recognizing patterns, for example an IP that's clicked before, a placement that sends junk, or an audience signature that screams automation. That recognition is powerful, but it's backward-looking. The first time a fresh bot hits your ad, your system has nothing to compare it to. Specifically, it clicks, it costs you, and only then does it become a pattern you can exclude next time.
In 2024, Imperva's 2024 Bad Bot Report found automated bots made up 51% of all web traffic, the first year bots overtook human traffic. Because a previously unseen bot's first click can't be matched against any history, click fraud protection reduces invalid clicks sharply but never eliminates them, which is why documenting the residual for refunds stays essential.
That's not a reason to skip protection. Instead, it's the reason protection and recovery have to run together. Bot detection is the practice of identifying automated, non-human traffic in real time from its behavior, device attributes, and engagement patterns, rather than from the click alone. You recover wasted ad budget by doing both, namely cutting the leak you can see and reclaiming the residual you can't pre-block. Reduce, then recover. Therefore, treat them as one workflow, not two.
How do you spot click fraud in Google Ads?
Spotting invalid clicks starts with reading the right signals together, because Google won't flag everything for you and no single metric settles it. Bots tend to land, cost you a click, and leave without engaging. So watch for clusters of tells at once: shallow non-converting sessions, repeat hits from the same IP ranges, high CTR with near-zero conversions, and junk leads. Notably, it's the pattern across signals, not any one number, that points to invalid activity.
Start inside Google Ads itself. The platform reports invalid clicks it has already filtered, shown as a separate column you can add to your campaign view. A sudden spike there, or a steady high percentage on one campaign, is worth investigating. However, remember that column only shows what Google caught at the platform level, not what reached your site.
What signals point to invalid clicks?
Several patterns repeat across accounts, and learning them sharpens your eye. For instance, watch for these tells:
Click-through rates that look too good. An unusually high CTR with near-zero conversions often means automated clicks, not eager buyers.
Traffic spikes from unexpected regions. Clicks from geographies you don't target or serve are a classic flag.
Repeat clicks from the same IP ranges. One source hammering your ads is rarely a real shopper.
Sessions far shallower than your site average. Disproportionately short, single-page, non-converting visits are one soft signal among many, never a verdict on their own. Treat them as one input to weigh, not a threshold to filter on (the table below carries fraud0's aggregate engagement figures for context).
Conversions that never become customers. Form fills with junk data or leads that vanish point to fake activity.
Side by side, the contrast is stark. The table below pairs each signal with what a healthy session looks like, so you know what you're comparing against. Read these as directional patterns, not pass/fail thresholds. Real detection scores many signals together, never one cutoff:
Signal | Invalid pattern | Healthy benchmark |
|---|---|---|
Engagement vs your site average | Far below your normal, single-page, no conversion | In line with your typical sessions |
CTR vs conversions | High CTR, near-zero conversions | Proportional to conversions |
Source IPs | Repeat hits from same ranges | Distributed, varied |
Lead quality | Junk data, vanishing leads | Real, contactable buyers |
For aggregate context: across fraud0's 2025 data, invalid users averaged 1.2 page views and 26-second sessions versus 181 seconds overall (search-engine crawlers excluded). That's an account-wide average showing how much less invalid users engage, not a per-visit number to look up.
In our work helping advertisers read these signals, the single most reliable tell isn't any one metric. It's the gap between platform-reported success and real-world results: great-looking clicks, healthy CTR, and a sales team that says the leads are garbage. That mismatch is where invalid traffic usually hides.

Source: fraud0, Unmasking the Shadows 2025.
How do you exclude bots and invalid sources in Google Ads?
Exclusion is where reduction actually happens, and Google Ads gives you several levers. In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions invalid (7.82% confirmed bots plus 1.92% suspected), so junk doesn't stop at the click. Specifically, excluding known-bad sources before they reach your campaigns again is the core of cutting future waste.
The principle is simple. Once you've identified a source that sends invalid clicks, you stop paying for it next time by adding it to an exclusion. The catch, again, is that exclusions are backward-looking. As a result, they cut the repeat offenders, not the first-timers. That's still a large share of the problem, because invalid traffic concentrates.
How do you set up IP exclusions?
IP exclusions block specific addresses from seeing and clicking your Search ads. Inside your Google Ads account, you add offending IP addresses under campaign settings, and Google stops serving your ads to them. According to Google Ads Help, you can exclude a limited number of IP addresses per campaign, so reserve the list for your worst, most persistent offenders rather than trying to block the entire internet.
The limitation is real and worth stating. Sophisticated bots rotate IP addresses constantly, so a static block list ages fast. IP exclusions handle the obvious repeat offenders well. However, they don't handle a botnet that never reuses an address. This is exactly why a manual list alone leaves a gap that automated, onsite detection is built to close.
How do you use negative audiences and placement exclusions?
Negative audience lists and placement exclusions widen your reach beyond single IPs. You can exclude audience segments that consistently produce invalid activity, and on Display and partner networks you can exclude specific placements and sites that send junk traffic. In other words, this is where a detection tool earns its keep, because it identifies the sources, then feeds exclusion lists back into your account automatically.
In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions invalid (7.82% confirmed bots, 1.92% suspected) and 31.4% of ad impressions landing on made-for-advertising sites. Excluding invalid sources through IP exclusions, negative audiences, and placement exclusions reduces repeat invalid clicks, but a previously unseen bot's first click still gets through, leaving a residual to recover.
Most advice treats exclusion lists as a one-time setup. They're not. An exclusion list is a living asset that decays the moment you stop feeding it, because the bot population keeps changing. Notably, the advertisers who reduce invalid clicks most aren't the ones with the longest static block list. Instead, they're the ones whose exclusions update continuously from fresh onsite detection. As a result, a list you built last quarter is already out of date.
How do you set up click fraud monitoring on Google Ads?
Monitoring is what turns a one-time cleanup into ongoing reduction. In 2025, fraud0's Unmasking the Shadows report found that 5.19% of bot users drove 17.67% of bot sessions, so a small set of repeat offenders does outsized damage. In particular, catching them as they return, and feeding that back into exclusions, is the whole point of continuous monitoring.
Google Ads gives you a baseline. Add the invalid-clicks column to your reports, set up automated alerts for unusual spikes, and review the data on a regular cadence rather than only when results look off. Consequently, this catches the platform-level signals. However, what it misses is everything that happens after the click, on your own site, where the clearest evidence of invalid behavior actually lives.
Why does onsite detection catch what the platform can't?
This is a vantage-point limit, not a flaw in Google. The platform sees the click and the pre-click signals it can measure, but it can't watch what a visitor does once they land on your site. Onsite, first-party detection can. Specifically, it observes session behavior, device and browser attributes, and engagement patterns that distinguish a bot from a buyer in real time.
In our experience, the richest evidence of invalid activity almost always comes from onsite behavior, not the ad click. A click looks identical whether it's a person or a script. The session afterward, the impossible mouse path, the form filled with garbage in milliseconds, the total absence of real engagement, is where the bot reveals itself. fraud0's scoring weighs many of these behavioral signals together, never a single duration cutoff. Platform filtering can't see that, so pairing it with onsite detection is what narrows the gap. For a full breakdown of how to choose a tool, see a click fraud protection buyer's guide.

How do you document invalid clicks for a refund?
Once you've reduced the leak, you recover the residual, and that requires evidence. Ad spend recovery is the process of documenting confirmed invalid activity and submitting it to the ad platform so it can review the spend and, where it agrees, issue a credit. In 2025, fraud0's Unmasking the Shadows report found 7.0% of Paid Search traffic invalid (search-engine crawlers excluded), so even Google's lowest-risk channel carries recoverable waste. A refund claim isn't a complaint. Instead, it's a documented submission, and the documentation is what makes it reviewable.
The mechanics follow a process. According to Google Ads Help, advertisers can report suspected invalid activity for investigation, and where Google's review confirms it, the platform issues an adjustment. We won't invent the amounts, timeframes, or success rates, because those depend on Google's review and your specific account. However, what we can be specific about is what strong evidence looks like.
In 2025, fraud0's Unmasking the Shadows report measured 7.0% of Paid Search traffic as invalid (search-engine crawlers excluded), the lowest of six channels but still wasted spend. Because exclusions can't pre-block a brand-new bot's first click, documenting that residual invalid activity with first-party onsite evidence is what makes an ad-spend recovery claim reviewable by the platform.
Strong evidence is logged in real time, onsite, with the attributes that separate a bot from a buyer. It records what the invalid activity was, when it happened, and how it was identified, rather than being reconstructed weeks later from a platform report. In particular, that distinction matters, because a review process can act on concrete, time-stamped detection far more readily than on a hunch about a CTR that looked high.
One honest note on outcomes. Where Google agrees, the recovered money typically returns as account credit toward future spend, not cash back to your card. That's still a real win, namely lower future media cost, but it's worth setting that expectation with stakeholders early. The same workflow applies beyond Google, too: you can protect Meta, Microsoft, and TikTok campaigns using the same detect-exclude-document loop.
How do you put it all together?
The four steps form one continuous loop, not a checklist you finish once. In 2025, fraud0's Unmasking the Shadows report found 7.0% of Paid Search traffic invalid (search-engine crawlers excluded), and that residual never reaches zero, so the loop keeps running. Spot the signals, exclude the sources, monitor continuously, document what slips through. Reduce, then recover.
Walk it end to end. First, you spot invalid clicks through behavioral signals and the platform's invalid-clicks column. Then you exclude the repeat offenders with IP, audience, and placement exclusions. Meanwhile, you monitor continuously so fresh sources get added before they drain more budget. Finally, you document the residual, the first-clicks no exclusion could catch, as evidence for a recovery claim. As a result, each step feeds the next.
The reason both halves matter comes back to the new-first-click problem. Exclusions are powerful but backward-looking, so they sharply reduce invalid clicks without ever sealing the leak. In contrast, refunds recover what reduction can't pre-block. Run only the first half and you write off the residual. Conversely, run only the second and you keep paying for repeat offenders you could have excluded. Together, therefore, they're how the math actually works in your favor.




