How to Deal With Google Ads Click Fraud and Invalid Traffic
Google Ads click fraud is any click on your ads that does not come from a person with a genuine interest in what you offer, whether the source is a bot, a competitor or a publisher trying to inflate its own income. Google filters most of this activity before you are billed, but advertisers still see suspicious spikes, clicks that never convert and fake form submissions that make lead quality look worse than it is. Because so much of the damage lands on landing pages and forms, the problem is as much about where each click lands as it is about campaign settings. Both need attention as part of Google Ads management for B2B organisations.
Google groups this activity under the label invalid traffic. Its Ad Traffic Quality overview describes a dedicated team that uses live reviewers, automatic filters and machine learning to detect and filter as much invalid activity as possible. The sections below cover what counts as an invalid click, why Google issues credits rather than refunds, how to tell genuine fraud from ordinary changes in performance and what you can change on your campaigns and your website to reduce the impact.
What Counts as Invalid Traffic in Google Ads
Invalid traffic in Google Ads covers any click or impression that does not represent genuine interest in your business, which includes deliberate fraud as well as accidental clicks. The distinction matters because a good deal of what advertisers describe as click fraud is not malicious at all.
Google’s explanation of invalid activity includes accidental clicks caused by intrusive ad implementations, fraudulent clicking by competing advertisers and advertising botnets. It also lists less familiar techniques that sit on the publisher side of the network, several of which advertisers never see directly.
| Type of invalid activity | What happens |
|---|---|
| Accidental clicks | Users click an ad they did not intend to, often because of poor ad placement |
| Botnets | Automated programs on servers or hijacked computers generate invalid impressions and clicks |
| Clickjacking | Deceptive page elements trick users into clicking an ad they did not expect |
| Ad stacking | Several ads are layered in one space so only the uppermost ad is visible |
| Ad hiding | Ads are placed where they cannot be seen, such as behind content or inside invisible containers |
| Ad injection | Ads are inserted into pages without the publisher’s knowledge, often by browser plugins |
| Malware | Infected devices generate hidden or injected ads in the background |
Competitor clicking gets the most attention from advertisers, yet much of the list above originates with publishers and infected devices. Google says botnets can be programmed to act like real users, which is why it pairs automated filters with manual reviews and specialist research teams.
Why Google Gives Credits Instead of Refunds
Google does not refund invalid clicks, because in most cases you are never charged for them in the first place. Invalid traffic caught before the end of the billing cycle is removed from your campaign metrics and your bill, while invalid activity found after you have been invoiced comes back as a credit on a later invoice where Google considers it appropriate and possible.
Both effects are visible inside the account. Adding the Invalid clicks column to the campaigns table shows how many clicks were filtered before billing. Credits appear in the Billing summary under Adjustments with the label Invalid activity. Because campaign metrics are frozen at the end of each month, the Invalid Activity Credit Report in Report Editor is the place to see adjusted clicks and cost once credits have been applied.
A rising figure in the Invalid clicks column does not mean Google is failing to protect your budget. Those clicks have already been filtered and you have not paid for them.
The harder question is what happens to clicks Google did not flag. Third party click tracking tools often report far more suspicious activity than Google credits, partly because they count duplicate IP addresses and bot visits that Google has already excluded from billing.
That gap is where most frustration over refunds comes from. Google also states that there is no industry standard for a normal rate of invalid traffic, so a figure from one tool cannot be compared neatly with a figure from another.
How to Tell Click Fraud From Normal Changes in Performance
The quickest way to tell click fraud from an ordinary change in performance is to rule out changes you or the market have made before assuming anything malicious. Google’s resources for advertisers list changes to daily budget, maximum CPC, new general keywords, new country or language targeting and network settings as common causes, along with seasonal trends, news events and a competitor that stops advertising.
Short visits and repeat clicks from one IP address need the same caution. Google notes that a zero second visit or a high bounce rate does not necessarily mean someone left the instant the page loaded. IP addresses are not unique to individuals either, since some internet providers rotate addresses among their users. Companies and universities often route all of their traffic through proxy servers too.
Cookie consent adds another layer for UK advertisers. The ICO’s guidance on cookies and similar technologies requires consent for cookies that are not strictly necessary, so analytics tools will not record every visitor who declines. A gap between clicks in Google Ads and sessions in your analytics is expected under PECR and is not evidence of fraud on its own.
Genuine warning signs look different. Clicks bunched at odd hours with no engagement, traffic from locations you do not target, repeated visits from the same user agent and form submissions filled with nonsense data are all worth investigating, particularly when several appear together.
How to Request an Invalid Traffic Investigation
You can ask Google to investigate invalid traffic it has not filtered by submitting a request through the Click Quality Form with evidence from your account and your website. Google only reviews recent activity, so it pays to act while the pattern is fresh.
Google sets out the information it expects and the list is longer than most advertisers anticipate. The sequence below follows that list in the order it is easiest to collect.
-
1
Rule out account changes
Check change history for budget, bid, keyword, audience and location edits. A setting change explains many sudden spikes before fraud needs to be considered.
-
2
Record the account details
Note your customer ID, the exact dates of the suspicious activity and the campaigns and ad groups affected. List any keywords that appear to be driving the unusual traffic.
-
3
Pull website evidence
Export web server logs showing IP addresses, user agents and the GCLIDs for the suspect visits. With auto tagging switched on, only log entries carrying a GCLID came from your ads.
-
4
Add lead details where relevant
If the problem is junk enquiries, prepare a spreadsheet with the GCLID for each lead. Add your own assessment of each one, such as the outcome of calling or emailing them.
-
5
Explain the trend and submit
Summarise why the traffic looks wrong, such as a spike in clicks without more conversions or clicks from outside your targeted locations. Send everything through the Click Quality Form.
Investigations typically take several working days because specialists review a large volume of data by hand. You receive an email with the findings and any additional credits, although Google will not confirm whether individual clicks were judged valid or invalid.
Web server logs are the item most marketing teams struggle to supply, since they rarely have direct access to the server. On a WordPress website this is a hosting question, so it is worth agreeing log access and retention with whoever manages your hosting before you need it.
Setting expectations matters as much as the evidence. An investigation is a review of patterns rather than a line by line audit, so the strongest requests show a clear change in behaviour that ordinary campaign activity cannot explain.
Practical Ways to Reduce Click Fraud in Your Campaigns
The most reliable way to reduce click fraud is to narrow who can see your ads, since tighter targeting leaves less room for invalid traffic to get through. Location options, negative keywords, match types and IP exclusions do most of the work.
Changing location settings from Presence or interest to Presence means ads only show to people in or regularly in your targeted areas. Reviewing the search terms report and adding irrelevant terms as negatives keeps ads away from queries that attract curiosity rather than intent. Moving important keywords from broad match to phrase or exact match tightens the link between a search and your ad.
IP exclusions are the most direct control. Google Ads lets you exclude IP addresses for an individual campaign or across the whole account. Account level exclusions are the more useful option for most advertisers because they also cover Performance Max, which does not support campaign level IP exclusions.
- Target people in or regularly in your locations
- Review search terms every week
- Exclude IP addresses you can evidence
- Check placements for clicks with no engagement
- Show ads to anyone interested in your locations
- Leave broad match running without negatives
- Exclude IP addresses on a hunch
- Assume every repeat click is fraud
Placement reports deserve their own review on Display and Performance Max activity. Excluding websites and apps that send clicks with no engagement usually does more than chasing individual IP addresses, which change often and can be shared by genuine prospects.
Our Google Ads management includes a weekly review of search term reports, with irrelevant searches added to negative keyword lists before they eat into budget. That routine work does more to protect spend than any single exclusion list.
Why Fake Leads Are a Website Problem
Fake leads are a website problem because Google’s invalid traffic filters stop you paying for bad clicks but do not stop bots or people submitting junk through your forms. Most traffic checks happen after an ad has served, so lead quality is a shared responsibility between the platform and the advertiser.
Google has been clear on this for some time. Responding to complaints about fake Performance Max leads, Google Ads Liaison Ginny Marvin recommended server side validation, double opt in confirmation and reCAPTCHA, as reported by Search Engine Roundtable. She also pointed advertisers towards offline conversion imports or enhanced conversions for leads, using the Qualified and Converted lead categories.
Each safeguard closes a different gap. reCAPTCHA filters out basic bots, while a double opt in only counts a lead as valid once the person clicks a confirmation link sent to their email address. Server side validation checks email domains and phone number formats before a submission reaches your CRM, which matters because sophisticated bots can bypass checks that run only in the browser.
Fake submissions also distort automated bidding. If every form fill counts as a conversion, bidding optimises towards whatever produced those submissions, so feeding qualified lead data back into the account is the most effective long term defence. Recording the IP address, GCLID, referrer and user agent against each submission gives you the evidence trail an investigation needs.
Form handling sits with the people who build the website rather than the person running the ad account. Our web development team builds firewall protection, malware scanning and IP blocking into its security work. The same thinking applies to lead forms on paid landing pages and our guide to PPC landing pages that convert covers form design for paid traffic in more detail.
What the UK Is Doing About Ad Fraud
Ad fraud is now a named priority for the government’s Online Advertising Taskforce, which is setting up an Ad Fraud and Standards working group jointly chaired by IAB UK and government. The Taskforce’s 2025 progress report records that members agreed in November 2025 to focus on fraudulent advertising. The same report notes that four in every five pounds of advertising budget is now spent online.
The new group is aimed mainly at scam advertising and the wider supply chain rather than individual disputes over clicks. It does show that ad fraud is being treated as a question of trust across the UK market, which matters for public sector bodies and regulated organisations that have to account for the value of every campaign.
Monitoring Click Quality Over Time
Click quality should be monitored as a routine part of account management rather than investigated only after a bad month. A weekly look at invalid clicks, search terms, location reports and lead quality catches most problems while a setting change can still fix them.
Priority Pixels clients on paid media retainers see this in our reporting dashboard, where Anomaly Callouts flag campaigns whose spend or conversion volume has moved outside its normal range. Spotting that shift early is what makes a credible investigation request possible.
The same discipline applies beyond Google. Our Microsoft Ads audits review account structure, keyword choices, targeting settings and conversion tracking to find budget waste. A Google Ads audit, often called a health check, does the same for Google accounts and is a sensible first step if you suspect invalid traffic is distorting your results.
FAQs
Does Google refund money lost to click fraud?
Google does not issue refunds for invalid traffic, because clicks it catches before the end of the billing cycle are removed from your bill. Invalid activity found after you have been invoiced is returned as a credit, labelled Invalid activity in your billing summary.
Can I stop a competitor clicking on my Google Ads?
Google already filters fraudulent clicking by competing advertisers. If you can identify specific IP addresses generating suspicious clicks, you can exclude them at campaign or account level. Shared IP addresses mean an exclusion can also block genuine prospects, so only exclude addresses you can evidence.
Why do my Google Ads get clicks but no conversions?
Clicks without conversions are more often caused by broad keywords, weak message match, a slow or confusing landing page or broken conversion tracking than by fraud. Rule those out first, then look for signs such as clicks from untargeted locations or visits with no engagement before requesting an investigation.
Are fake form submissions treated as invalid clicks?
No, Google’s invalid traffic filters cover ad interactions rather than what people or bots do on your website afterwards. Fake leads need safeguards on the website itself, such as reCAPTCHA, double opt in confirmation and server side validation of submitted details.