Log in / Create free account🌐 ES☀️

Advanced training · Module 5 — Ad fraud — farms, apps, bots and IPs, and how an account defends itself

Apps, IPs and non-human traffic: the other three doors into fraud

⏱️ 10 min read · 🛡️ Fraud 🖼️ Display 🔎 Search · updated on 2026-08-22

🎧 Listen to the lesson · ≈ 5 min🔒 Subscribers only

Farms are the front door; there are three more: apps (accidental clicks on mobile inventory), IPs (repeated and malicious clicks in Search) and the non-human traffic that reaches your site and shows up nowhere in Google Ads but very much in your conversions and in Smart Bidding. This lesson covers all three.

Apps: the inventory where the finger slips

Signals in the placement report (mobileapp::…):

The defence:

  1. Exclude all apps at account level if you are not promoting an app (most businesses). You do it in content exclusions / account-level placement exclusions.
  2. If you do need apps (you promote one, or your audience is in certain categories): exclusion by category (games, children's, utilities) plus a list of specific apps.
  3. Reviewing the app report with the same scoring as domains: a filler app has a similar fingerprint (a developer with dozens of cloned apps, fake reviews).

IPs: repeated and malicious clicks

Google automatically refunds some repeated clicks; what it does not filter you can block with account-level IP exclusions (Admin → Account settings → IP exclusions; with a cap on the number of entries). It is useful for:

The limits: dynamic IPs change; mobiles share carrier IPs (excluding one carrier IP blocks thousands of legitimate users); Google only excludes traffic that arrives at the auction with that IP. Which is why the IP exclusion list is a supplement, not the foundation.

How to feed it sensibly: from your site's visitor fingerprints (below) — IPs that generate lots of ad clicks with no interaction whatsoever, at odd hours, from data centres — with frequency thresholds and an expiry (exclusions expire and get reviewed).

Non-human traffic on your site

Google Ads cannot see it; your site can. A visitor script (the same one that captures the GCLID for Lead Rating) can measure:

Signal Human Bot
Time to the first event (scroll, click) Seconds Zero or instant
Scroll and movement Irregular None, or perfectly linear
Resolution and user agent Varied and coherent Repeated, incoherent, headless
IP Residential Data centre, proxy, mass VPN
Filling in the form Tens of seconds Milliseconds, honeypot fields filled in
Pages per session Several, or a normal bounce Exactly one, always the ad's page
Time of day A human distribution Spikes at fixed hours

With those signals, every visit gets a probability of being non-human. Uses: feeding the IP exclusion list (with an expiry), discarding suspicious conversions (form spam that must never reach Google as a conversion), and spotting campaigns/placements whose traffic is mostly non-human (a reason to exclude the placement even if its content score was acceptable).

The form spam case

This is conversion fraud, not click fraud: bots that fill in forms fire real conversions as far as Google is concerned, Smart Bidding learns from them and optimises towards more bots. A layered defence: honeypot and validation in the form; lead scoring using the browsing fingerprint (a form filled in in 2 seconds from a data centre IP is worth 0); and not sending to Google as a conversion anything that fails the threshold — or sending it with zero value.

What not to do

💡 Ninja trick: in Ninja Shield each of these three doors has its own module: Visitor Shield measures the fingerprint of every visit to your site (with the Lead Rating snippet), IP Shield turns repeated fingerprints into IP exclusions with an expiry (respecting Google's limit), App Shield scores and excludes apps (including "inefficient app" detection by CPA), and Lead Shield stops spam reaching Google as a conversion. The account defends itself on all four sides, every night.

What you should remember

📎 Sources and further reading

⚠️ Free training with no support. Ninja Scripts support channels (email and Telegram) are only for the use of the scripts, not for Google Ads questions or questions about this training.

Pick up here

← BeforeSpotting farms and networks: the signals of a rubbish domain and how to group domains by their fingerprintAd fraud — farms, apps, bots and IPs, and how an account defends itselfAfter →Safe Sites, aggressiveness and calibration: protecting without losing reachAd fraud — farms, apps, bots and IPs, and how an account defends itselfRelacionadaThe campaign settings that can ruin you without you knowingInside the account — structure, campaigns, ad groups and MCCRelacionadaApp campaigns and the final map: which campaign type for each objectiveThe other campaign types — an introductory mapRelacionadaMistakes with Display, PMax and automated campaigns: the money that leaks out unseenBeginner mistakes — real anonymised casesRelacionadaWhat Google Ads is and where your ads show upHow advertising on Google works

Ver el temario completo

🎓
You're reading, in the open, a lesson from the subscribers' training

This page is read-only. With the Suite subscription you get the full academy — all three levels with audio, quizzes, favorites, highlights and certificates — plus the scripts working in your Google Ads account.

See the full Suite → Create my free account →
🥷

Subscriber feature

This option is part of the Ninja Scripts Suite subscription.

See the subscription →