Farms are the front door; there are three more: apps (accidental clicks on mobile inventory), IPs (repeated and malicious clicks in Search) and the non-human traffic that reaches your site and shows up nowhere in Google Ads but very much in your conversions and in Smart Bidding. This lesson covers all three.
Apps: the inventory where the finger slips
Signals in the placement report (mobileapp::…):
- Anomalous CTR (3-10% in Display, where normal is < 0.5%): accidental clicks.
- Sessions of 0-2 seconds in Analytics from those apps.
- Filler categories: casual and children's games, torches, wallpapers, cleaners, "rewards" apps.
- Zero conversions off hundreds of clicks.
The defence:
- Exclude all apps at account level if you are not promoting an app (most businesses). You do it in content exclusions / account-level placement exclusions.
- If you do need apps (you promote one, or your audience is in certain categories): exclusion by category (games, children's, utilities) plus a list of specific apps.
- Reviewing the app report with the same scoring as domains: a filler app has a similar fingerprint (a developer with dozens of cloned apps, fake reviews).
IPs: repeated and malicious clicks
Google automatically refunds some repeated clicks; what it does not filter you can block with account-level IP exclusions (Admin → Account settings → IP exclusions; with a cap on the number of entries). It is useful for:
- Competitors or specific individuals draining your budget (identified by IP on your own site).
- Your own staff and offices (noise in the data).
- Known data centre and proxy ranges.
The limits: dynamic IPs change; mobiles share carrier IPs (excluding one carrier IP blocks thousands of legitimate users); Google only excludes traffic that arrives at the auction with that IP. Which is why the IP exclusion list is a supplement, not the foundation.
How to feed it sensibly: from your site's visitor fingerprints (below) — IPs that generate lots of ad clicks with no interaction whatsoever, at odd hours, from data centres — with frequency thresholds and an expiry (exclusions expire and get reviewed).
Non-human traffic on your site
Google Ads cannot see it; your site can. A visitor script (the same one that captures the GCLID for Lead Rating) can measure:
| Signal | Human | Bot |
|---|---|---|
| Time to the first event (scroll, click) | Seconds | Zero or instant |
| Scroll and movement | Irregular | None, or perfectly linear |
| Resolution and user agent | Varied and coherent | Repeated, incoherent, headless |
| IP | Residential | Data centre, proxy, mass VPN |
| Filling in the form | Tens of seconds | Milliseconds, honeypot fields filled in |
| Pages per session | Several, or a normal bounce | Exactly one, always the ad's page |
| Time of day | A human distribution | Spikes at fixed hours |
With those signals, every visit gets a probability of being non-human. Uses: feeding the IP exclusion list (with an expiry), discarding suspicious conversions (form spam that must never reach Google as a conversion), and spotting campaigns/placements whose traffic is mostly non-human (a reason to exclude the placement even if its content score was acceptable).
The form spam case
This is conversion fraud, not click fraud: bots that fill in forms fire real conversions as far as Google is concerned, Smart Bidding learns from them and optimises towards more bots. A layered defence: honeypot and validation in the form; lead scoring using the browsing fingerprint (a form filled in in 2 seconds from a data centre IP is worth 0); and not sending to Google as a conversion anything that fails the threshold — or sending it with zero value.
What not to do
- Excluding mobile carrier IP ranges.
- Trusting the "Invalid clicks" column as a measure of total fraud.
- Blocking bots on your site in a way that also blocks Googlebot or AdsBot (it sinks your Quality Score and Merchant Center).
- Leaving IP exclusions with no expiry: IPs rotate.
💡 Ninja trick: in Ninja Shield each of these three doors has its own module: Visitor Shield measures the fingerprint of every visit to your site (with the Lead Rating snippet), IP Shield turns repeated fingerprints into IP exclusions with an expiry (respecting Google's limit), App Shield scores and excludes apps (including "inefficient app" detection by CPA), and Lead Shield stops spam reaching Google as a conversion. The account defends itself on all four sides, every night.
What you should remember
- Apps: anomalous CTR, zero-second sessions, filler categories → exclude all apps (or by category) at account level.
- IPs: account exclusions as a supplement; fed by visitor fingerprints, with an expiry; never carrier ranges.
- Non-human traffic is measured on your site: time to first event, scroll, UA, IP, form speed → a probability per visit.
- Form spam = conversion fraud: score the lead and do not send it to Google.