Spam leads from countries I never targeted: what is going on and how do I stop them?
Short answer
Check whether the lead has a click ID, protect the form with quiet checks, and make sure spam does not count as a conversion.
Usually the ad is not reaching those people. The submissions come from automated scripts or from people who find your form through other routes, and your targeting settings cannot stop them because they never saw the ad.
Think about how a form gets filled. A bot can find your page by crawling, post to the form URL directly and fill the fields, with no ad click at all. Lead forms on social platforms can also be reached by people who share or are shown the ad in ways your targeting does not fully control.
First, check whether there is a click. Look at the lead's source. If the submission has no click ID, no UTMs and no referrer, it probably did not come from an ad. That tells you the form itself is exposed.
Second, protect the form. Add a hidden honeypot field, a time check, server-side validation of the email and phone, rate limiting, and a low-friction challenge for risky submissions. Block known throwaway email providers.
Third, look at location data as a clue, not a rule. A visitor's apparent location can be hidden by VPNs and proxies, so you cannot rely on it either way. Use it to spot patterns, such as a flood from one range.
Fourth, for in-platform lead forms, use the platform's own controls. Add a custom question, require a business email where relevant, turn on any spam protection options it offers, and review the lead quality by placement.
Fifth, keep spam out of what the ads learn. If these submissions count as conversions, you are rewarding whatever brings them. Send a conversion only after the lead passes checks, or send a later stage from your CRM.
DataCops gives every visit a bot verdict and checks each form email, with LeadCops holding a lead that fails, so spam without an ad click or from throwaway addresses does not count as a conversion. It cannot change platform targeting.
Do the spam leads carry a click ID or UTMs, or nothing at all?
DataCops in short
For this question: DataCops gives every visit a bot verdict, checks each form email, and with LeadCops holds a lead that fails, so spam does not count as a conversion.
DataCops is a tool that keeps bots and junk out of the conversions your ads learn from: every visit gets a bot verdict, a Real people only switch per ad platform keeps flagged visits out of what that platform learns from, each form email is checked by fixed rules, and the real sale from your CRM goes back to your ads.
How DataCops does it
- A bot verdict on every visit. Checked against an IP database covering 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default.
- Fake leads caught at the form. Each email is checked for throwaway and disposable providers, domains with no mail server, and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
- The real sale goes back. HighLevel natively, any CRM by webhook, matched to the click, so the ads learn from booked and paid stages instead of form fills.
- A log you can read. A delivery log row per conversion, with the reason when it did not go.
- Evidence for Google. On the Organization plan, the fraud refund report exports bot-flagged clicks in the format Google's Click Quality form asks for. You attach it; Google decides.
Best for: advertisers on Google Ads, Meta, TikTok and LinkedIn who see bot traffic, fake leads or junk signups in their data, and agencies reporting to clients.
Ads Warmup: tell the ads who pays
Ads Warmup, DataCops' flagship feature, sends customers you already have to Meta, Google Ads and TikTok before a new campaign spends: upload a CSV (only email is required, up to 20,000 rows), see a 0 to 10 match score per person, pick the event, and send. Rows are dated when you send, and Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan. Check your own consent basis for the list first. See Ads Warmup.
Ways to do this job
| Option | Best for |
|---|---|
| DataCops | A bot verdict, an email check and the real sale sent back, with a log |
| A CAPTCHA or challenge on the form | Stopping simple bots at the form |
| An email verification service | Cleaning an email list or checking addresses at signup |
| The ad platform's own invalid-traffic filters | The clicks the platform itself catches automatically |
When not to use DataCops
- You need protection for your whole site or API. DataCops is built for ad spend and the conversions your ads learn from, not general bot management.
- You want every click stopped inside the ad platform. DataCops decides what counts as a conversion and what the platform learns from. It does not promise to stop every click.
Sources and further reading
More on this: lead generation, and the complete guide to offline conversion tracking.
Sort your last 50 spam leads by whether they have a click ID. The answer tells you whether it is the ad or the form.