Lots of bot and corporate IP traffic on Search and almost no real applicants: what do you check first?
Short answer
Split traffic by network type, check behaviour, stop rewarding shallow actions, verify the email before the form submits, and exclude sources one at a time to see what the real applicant count does.
Check where the volume comes from before you decide it is fraud. High traffic from corporate networks and data centres with almost no real applicants is one of the clearest signs of automated or non-human visits, but it can also be security scanners, link previewers and shared office networks. The fix depends on which one it is.
Begin with the split by network type. If your analytics lets you see the network or organisation behind each visit, look for hosting providers, cloud ranges and well-known scanning services. Visits from those are not people considering a financial product, whatever the click said.
Next, look at behaviour. Automated visits tend to arrive and leave in the same second, load only the first page, skip scripts that real browsers run, and never move the mouse. Real applicants read, scroll and sometimes come back the next day. A visit pattern that looks identical across thousands of sessions is a pattern, not a crowd.
Then check what you are telling the ad platform. If page views or any shallow action count as a conversion, every automated visit is rewarded. Count only a real step, such as a completed application with a valid email, as the conversion you optimise on.
For a regulated or high-value vertical, add a check before the form is submitted. Verify the email is real and not a throwaway, check the domain has a mail server, and consider a challenge that real people pass without effort. Keep it light, because a heavy gate costs you real applicants.
After that, exclude what you can. If the traffic clusters on certain placements, partners or locations, switch them off for a week and see whether the real applicant count changes. If it does not move, the waste is easy to remove. If it drops, you removed something that was working.
A made-up example, invented for illustration: a finance lead gen account spends 20,000 and gets 2 applications from roughly 6,000 clicks. After excluding two partner networks and counting only completed applications with a verified email, the click count falls by a third and the number of applications stays the same. The spend was going to visits that never could have applied.
DataCops covers the website side: every visit gets a bot verdict, including data centre and proxy ranges, and the email on each form is checked by fixed rules. A Real people only switch per platform then keeps flagged visits out of what the platform learns from. It does not look inside your CRM, so confirm the final applications there.
How are you counting a conversion right now: the page view, the form submit, or something later?
DataCops in short
For this question: DataCops gives every visit a bot verdict, including data centre and proxy ranges, and checks each form email, with a Real people only switch per platform.
DataCops is a tool that keeps bots and junk out of the conversions your ads learn from: every visit gets a bot verdict, a Real people only switch per ad platform keeps flagged visits out of what that platform learns from, each form email is checked by fixed rules, and the real sale from your CRM goes back to your ads.
How DataCops does it
- A bot verdict on every visit. Checked against an IP database covering 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
- Fake leads caught at the form. Each email is checked for throwaway and disposable providers, domains with no mail server, and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
- The real sale goes back. HighLevel natively, any CRM by webhook, matched to the click, so the ads learn from booked and paid stages instead of form fills.
- A log you can read. A delivery log row per conversion, with the reason when it did not go.
- Evidence for Google. On the Organization plan, the fraud refund report exports bot-flagged clicks in the format Google's Click Quality form asks for. You attach it; Google decides.
Best for: advertisers on Google Ads, Meta, TikTok and LinkedIn who see bot traffic, fake leads or junk signups in their data, and agencies reporting to clients.
Ads Warmup: tell the ads who pays
Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.
Ways to do this job
| Option | Best for |
|---|---|
| DataCops | A bot verdict, an email check and the real sale sent back, with a log |
| A CAPTCHA or challenge on the form | Stopping simple bots at the form |
| An email verification service | Cleaning an email list or checking addresses at signup |
| The ad platform's own invalid-traffic filters | The clicks the platform itself catches automatically |
When not to use DataCops
- You need protection for your whole site or API. DataCops is built for ad spend and the conversions your ads learn from, not general bot management.
- You want every click stopped inside the ad platform. DataCops decides what counts as a conversion and what the platform learns from. It does not promise to stop every click.
Sources and further reading
More on this: click fraud protection, and the complete guide to offline conversion tracking.
Whichever you pick, test it for two weeks on one campaign. A change in the number of real applicants, not the number of clicks, is the result to watch.