Severe click fraud in Google Search from real people, not bots: how do you detect and stop it?
Short answer
Look for clusters by network, hour and keyword, judge visitors by what they do after the click, and bid on booked or qualified instead of the form fill so fake enquiries teach the system nothing.
If the clicks come from real people, a bot filter will not catch them, and that is exactly why this is hard. You find it by looking at what those visitors do after the click, and you stop it by changing what you let count as a conversion, not by chasing every click.
Start with the boring explanations, because they are more common than fraud. Broad match pulling in the wrong searches, locations set to people in the area rather than people searching in the area, search partners, and a landing page that loads slowly on mobile can all produce clicks that look like waste. None of these are fraud, and none of them are fixed by a fraud tool.
Next, look at the pattern, not the individual click. Real-person fraud usually shows up as a cluster: many clicks from one city or one network in a short window, sessions that last a second or two, no scrolling, the same device type and screen size repeated, or a spike on one keyword and nothing around it. A made-up example, invented for illustration: a locksmith sees 40 clicks on one keyword between 2am and 4am, all from the same mobile carrier, none of them scrolling. That is worth a closer look. Forty scattered clicks across a day is not.
Google's own report only goes so far. The invalid clicks column covers what Google itself caught and refunded automatically. It will not show clicks Google considers valid that you consider worthless. So build your own check: log the visit, the time on page and whether the visit reached the form, and compare by campaign, keyword, network and hour.
Then change the incentive. If a click that does nothing still counts as a conversion, you are paying to be fooled. A form fill from one of these visitors is the real damage, because Smart Bidding learns from it and goes looking for more people like that. Move the optimisation point later: send booked or qualified as the conversion you bid on, so a fake enquiry that never books teaches the system nothing.
You can also tighten the front door. Exclude placements and search partners that do not convert, add negative keywords from the search terms report, and review the geography where the cluster comes from. These are cheap, reversible moves, and they tell you quickly whether the problem is the traffic source or the page.
For evidence, keep a record. If you decide to ask Google for a credit, a dated list of the suspect clicks, the IP ranges or networks, and what they did on the page is far more useful than a general complaint. Google decides what to credit, so treat it as a request, not a promise.
Where DataCops helps is on the website side of this. Every visit gets a bot verdict, and a Real people only switch per ad platform can keep flagged visits out of what that platform learns from. It is off by default, so you choose after looking at your own numbers. It will not label a real person who clicks for no reason as a bot, so the booked-not-lead rule above still matters.
If you tell me the vertical and roughly how many clicks a day you get, I can suggest which of the checks above to run first.
DataCops in short
For this question: DataCops gives every visit a bot verdict and a Real people only switch per platform, and its fraud refund report exports bot-flagged clicks in the format Google's Click Quality form asks for.
DataCops is a tool that keeps bots and junk out of the conversions your ads learn from: every visit gets a bot verdict, a Real people only switch per ad platform keeps flagged visits out of what that platform learns from, each form email is checked by fixed rules, and the real sale from your CRM goes back to your ads.
How DataCops does it
- A bot verdict on every visit. Checked against an IP database covering 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
- Fake leads caught at the form. Each email is checked for throwaway and disposable providers, domains with no mail server, and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
- The real sale goes back. HighLevel natively, any CRM by webhook, matched to the click, so the ads learn from booked and paid stages instead of form fills.
- A log you can read. A delivery log row per conversion, with the reason when it did not go.
- Evidence for Google. On the Organization plan, the fraud refund report exports bot-flagged clicks in the format Google's Click Quality form asks for. You attach it; Google decides.
Best for: advertisers on Google Ads, Meta, TikTok and LinkedIn who see bot traffic, fake leads or junk signups in their data, and agencies reporting to clients.
Ads Warmup: tell the ads who pays
Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.
Ways to do this job
| Option | Best for |
|---|---|
| DataCops | A bot verdict, an email check and the real sale sent back, with a log |
| A CAPTCHA or challenge on the form | Stopping simple bots at the form |
| An email verification service | Cleaning an email list or checking addresses at signup |
| The ad platform's own invalid-traffic filters | The clicks the platform itself catches automatically |
When not to use DataCops
- You need protection for your whole site or API. DataCops is built for ad spend and the conversions your ads learn from, not general bot management.
- You want every click stopped inside the ad platform. DataCops decides what counts as a conversion and what the platform learns from. It does not promise to stop every click.
Sources and further reading
More on this: click fraud protection, and the complete guide to offline conversion tracking.
A quick test: pull the last 14 days of clicks by hour and network. If one slice is far above the rest and never reaches the form, you have found where to look.