The platform charges you per click and shows you a number of clicks. That number doesn't tell you whether there was a person behind it, or whether that person had any intention of reading you. To know that you have to look at what happens after the click, on your own site, ad by ad.
A click is not a person
Between the click the platform counts and the customer you want there are three filters nobody hands you:
- Did the page even load, or did they leave first?
- Was it a person or a program?
- If it was a person, did they come for something or just tap out of curiosity?
Only the second can be fully automated; the other two are interpretation, which is why it pays to have a method before looking at the numbers.
The signals that give a bot away
None of them works on its own; together they rarely fail:
| Signal | What you see |
|---|---|
| No interaction | Not a single scroll, mouse move or tap in the whole visit |
| Absurd dwell time | Fractions of a second, or an identical time on every visit |
| Time zone that doesn't fit | The browser reports a time zone from another continent on a Spain-only campaign |
| Mail scanner pattern | Several hits on the same address within seconds, from mail or security provider ranges, and nothing else |
| Impossible browser | Ancient versions, odd screen sizes or known automation fingerprints |
💡 Ninja tip: the cheapest and most reliable signal is the first one. A visit with no interaction at all and under two seconds doesn't need any further judgement: it read nothing, person or program. Filter on that before arguing about bots.
Legitimate bots count too (and they aren't customers)
Not every program hitting your landing page is suspicious. OpenAI
visits your page to evaluate the ad and the content it points to,
and documents its crawlers asking that you don't block them in
robots.txt. If your site shuts them out, you're shutting yourself out.
That said, those visits are not campaign traffic. Measured in our own account on the night of 17/09/2026, the first night the campaign served, we got around 40 visits from OpenAI crawlers and another 25 from automated link checks (the kind any tool makes to verify that ad URLs respond, ours included). Added to the real traffic, the volume looked bigger and the quality looked even worse.
Filter the three things separately: known crawlers, your own checks and people. Otherwise your first week will give you a false portrait.
How we score each visit
In our tool each visit gets a score from 0 to 100 and is then aggregated by ad. These are the thresholds we use today:
| Rule | Value |
|---|---|
| Counted as a bot | From 70 points |
| No opinion given | Under 10 visits in the period |
| 🔴 Alarm | ≥ 50 % bot visits |
| 🟡 Watch | ≥ 20 % bots, or ≥ 60 % with no interaction |
⚠️ These thresholds are PROVISIONAL. They were calibrated on years of Google Ads traffic and have not been recalibrated on ChatGPT yet. There is a concrete reason to be suspicious: the ChatGPT app opens websites in its in-app browser, where short visits with no interaction are far more normal than on a desktop browser. A quick bounce in the app is not a bot. If you copy these numbers, copy them as a starting point and adjust them with your own data.
Bad traffic is almost never fraud
This is the idea that saves the most money: when traffic arrives and doesn't perform, the explanation is nearly always a bad fit between ad, moment and device, not a fraudster.
Our first day serving, 17/09/2026, on the Clicks objective:
| Figure | Value |
|---|---|
| Impressions (per OpenAI) | 4,024, nearly all in the mobile apps |
| Clicks billed that day (per OpenAI) | 0, and therefore €0 spend |
| People on the site (measured by us, bots excluded) | 19 |
| On mobile | 16 of 19 |
| Between 2:00 and 5:00 | 17 of 19 |
| Dwell time (median) | 2 seconds |
| Left without reading anything | 37 % |
| Sign-ups | 0 |
For reference, that same month the visits reaching our site from social media lasted almost three minutes with a 10 % bounce rate. The difference isn't subtle.
And they weren't bots: they were people, in the mobile app, in the small hours, seeing an ad offering a free trial of a Google Ads script — that is, a desktop, working-hours task. The decision, taken that same afternoon as an experiment with a review date, was to limit the campaign to desktop and working hours (Mon-Fri, 9:00-18:00). The full case is in the lesson "ChatGPT Ads case study: late-night mobile traffic, and how to move to office hours and desktop only".
Note the detail that throws you: the platform closed the day with zero clicks and we measured 19 people. Neither number, on its own, describes what happened.
How to watch it ad by ad
- A different parameter of your own per ad in the URL: without that there is no quality by ad, only a useless average.
- One row per ad with visits, % bots, % with no interaction, median dwell time and forms submitted.
- Always look at volume before percentages: 3 bad visits out of 5 is not a signal.
- Cross quality with cost: a cheap ad whose traffic doesn't read stops being cheap.
What to take away
- The platform counts the click; you measure the quality, afterwards.
- No interaction and under two seconds: nothing was read, person or program.
- OpenAI's crawlers are legitimate and you should let them in, but they aren't customers: filter them, and filter your own link checks too.
- Our thresholds (bot ≥ 70, minimum 10 visits, alarm ≥ 50 %, watch ≥ 20 % or ≥ 60 % with no interaction) are provisional.
- Bad traffic is nearly always bad fit, not fraud: before shouting "bots", look at the device and the hour.