A human hand pressing a thick fanned wad of banknotes into the open palm of a featureless white mannequin hand on a dark counter
Google Ads

You Are Paying for Clicks From People Who Are Not People

Most click fraud advice is sold by click fraud vendors. Here is what Google's two layers already catch, and why blocking IPs can cost you real customers.

Nora BennettPaid Media Strategist, BrandRocket14 min read · August 25, 2026

Somewhere in the last year you have probably watched a video, or read a post, that told you a third of your ad budget is being eaten by bots. It usually arrives with a chart. The chart has big numbers on it, and the numbers are always worse than you expected.

Then, about ninety seconds in, there is a link in the description.

That is worth noticing before anything else, because it is the single most reliable pattern in this entire subject. We went looking for the most-watched material on invalid traffic in Google Ads, and every substantial source we found was either published by a company that sells click-fraud software, or sponsored by one. In the best of them, the presenter says so out loud: he explains that the statistics he is about to show you were supplied by the vendor, because he does not have access to that data himself.

That does not make the numbers false. It makes them unaudited, which is a different thing, and it means you should not build a spending decision on top of them. So this piece does not use any of them. Everything below comes from Google's own documentation, from what is visible in your own account, and from network engineers who have no product to sell you in this category.

The companies telling you how much invalid traffic you have are the same companies selling you protection from invalid traffic.

Invalid Traffic Is Real. It Is Also Broader Than Fraud.

Start with what the thing actually is, because the word "fraud" does a lot of unhelpful work here.

Google's definition of an invalid click is a click "that isn't the result of genuine user interest." That covers deliberate attacks, certainly: a competitor clicking your ad to drain your budget, automated clicking tools, bots and scrapers working through a site at scale. But it also covers things nobody did on purpose. The second click of a double-click. A duplicate click when a page is slow and somebody taps again. Accidental taps that were never going to lead anywhere.

So the category is wider and more mundane than the word suggests. A meaningful share of what gets counted as invalid traffic is not an attack on your business at all. It is the ordinary friction of people using the internet with their thumbs.

That matters for your reaction to it. Somebody actively targeting your account is a problem you might need to escalate. A thousand accidental double-taps is not a conspiracy, and it is already handled.

Google Catches It in Two Passes, Not One

Here is the part that almost never survives into a sales pitch, and it is the most useful thing in this article.

Google does not make one attempt to catch invalid traffic. It makes two, at different times, and they work differently.

The first pass happens in real time, before you are billed. In Google's own words, most of its defenses "are applied in real-time to protect advertiser campaigns and prevent them from being billed for associated traffic." When the system decides a click is invalid as it happens, that click is filtered out before it reaches your bill. You are not charged, and you never see it in your cost.

The second pass happens after the invoice has already gone out. Detection keeps running on activity that has already been paid for. Google's documentation is direct about this: "some activity is identified after an invoice has been issued. Invalid activity credits are issued for associated advertiser spend, where appropriate and possible."

Note the word there. Credits, not refunds. Google states the distinction plainly: invalid clicks "will result in adjustments or credits, not a refund," and those credits "appear on subsequent invoices and in account transaction history reports as negative values." Money does come back to you. It comes back as a reduction on a later bill rather than as cash returned.

Two passes, running on different clocks. That is what Google means when it describes "a multi-layered approach to protect advertisers from invalid traffic."

Google is not asking you to take this on faith. It puts both numbers in your own account.

Go and Look at What Google Already Caught

This is the step to take before you spend a dollar on anything, and it costs nothing.

Both passes are reported to you, in two different places.

For the real-time pass, add the "Invalid clicks" column to your campaign reports. That number is the traffic Google's systems already identified and filtered before billing you. Google describes the presence of that data as evidence that its "security layers are actively protecting your budget," which is fair enough, though the more useful way to read it is simply as a measurement. It tells you the scale of what is being caught on your account specifically, rather than on an industry average in somebody's slide deck.

For the after-the-fact pass, look at your billing transaction history, where credits show up as negative line items. Google has also built a dedicated report that breaks those credits down properly. In your account, go to Report Editor, open the Template gallery, and select "Invalid Activity Credit Report: Search & PMax."

That report is worth a few minutes of your time because it separates the credits by campaign and network and adds columns most owners have never seen: credited clicks, credited interactions, credited amount, and then a set of adjusted figures. Adjusted cost is your invoiced cost minus the credit. There is also adjusted CTR, adjusted average CPC, and adjusted cost per conversion, all recalculated with the invalid activity stripped out.

One limitation to know: that report currently covers Search and Performance Max campaigns only. If your spend is concentrated in Display or video, it will not tell you the whole story.

What you get out of this exercise is the thing the fear is missing. You stop asking "how much invalid traffic does the industry have" and start knowing how much your account had, what Google caught, and what it credited back.

What the Tool Vendors Are Right About

An honest piece has to concede the strong version of the other argument, and there is one.

Google's own wording is careful. It says it will "try to automatically filter" invalid clicks. That is not a promise of perfection, and no serious person claims the filtering is complete. Some invalid traffic gets through both passes. That is true.

The more serious version of the problem is not the wasted click at all. It is the invalid conversion.

If a bot fills in your contact form, or a junk submission lands as a lead, your conversion tracking records it as a success. Every automated bidding system in Google Ads then optimizes toward the pattern that produced it, because it has no way of knowing a human was never involved. The machine does exactly what you told it to do and goes looking for more of the same. A wasted click costs you the price of the click. A wasted conversion teaches your bidding to buy more wasted clicks, and that compounds.

Google even documents an oddity here worth knowing about: in rare cases a click can be judged invalid and removed while the conversion attributed to it is not, which is why conversions can occasionally exceed clicks in your reports.

This is the real cost, and it is why the subject deserves attention rather than dismissal. We have written before about how a conversion number can climb while your actual sales do not, and invalid activity is one of the ways that gap opens up.

A wasted click costs you the price of the click. A wasted conversion teaches your bidding to go and buy more of them.

Then They Reach for the IP Block

So the problem is real. The question is what the tools do about it, and this is where a small business can get hurt.

Strip away the dashboards and the vast majority of click-fraud products come down to one core action: identify suspicious IP addresses and block them. Google gives you the machinery for this. You can exclude up to 500 IP addresses per campaign, you can use an asterisk to wildcard the last three digits and block a whole block of addresses, and there are now account-level exclusions that apply across every campaign type you run.

It sounds precise. It is not, because the assumption underneath it stopped being true years ago.

An IP address is not a person. Cloudflare, who have no click-fraud product to sell you and who see an enormous share of the world's web traffic, put it plainly: "a single IPv4 address may represent hundreds or even thousands of users due to widespread use of Carrier-Grade Network Address Translation (CGNAT), VPNs, and proxy middleboxes."

Carrier-grade NAT is the reason. The world ran short of IPv4 addresses, so internet providers and mobile carriers stopped giving every subscriber their own and started putting large numbers of customers behind a single shared public address. Cloudflare's assessment of what that does to blocking is unambiguous: these techniques "assume a one-to-one relationship between IP addresses and users," and in shared environments "this assumption breaks down because multiple subscribers can appear under the same public IP. Blocking the shared IP therefore penalizes many innocent users along with the abuser." The UK regulator Ofcom made the same point about blocklisting a carrier's address, warning it risked "potentially affecting an entire subscriber base."

Then add VPNs. Surveys disagree on exactly how common they now are, which is itself informative: one 2025 survey of American adults put usage at 32 percent, another the same year put it at 47 percent. Whether it is a third or a half, it is an enormous number of ordinary people, and they are not hiding from you. They are on a corporate network, on hotel wifi, on a phone, or simply private by habit.

And here is the detail that should decide the argument. One of these vendors, in its own sponsored video, lists "proxy VPN traffic" among the categories it blocks. The tool is not accidentally catching VPN users. It is designed to treat them as invalid.

There is a third problem underneath both. Residential IP addresses are typically dynamic, reassigned by the provider over time. The address you block today because it behaved badly may belong to a different household next month. Your exclusion list does not know that, and it never expires.

Block a bot and you can see exactly what you saved. Block a customer and you simply never hear from them again.

That asymmetry is the whole reason these tools always appear to be working. Every blocked click is reported back to you as money saved, in a dashboard designed to show you exactly that. The customer who was quietly prevented from seeing your ad generates no line item, no alert, and no report. They just do not arrive, and there is nothing in your account that will ever tell you they were coming.

A tool that blocks too aggressively and a tool that is working perfectly produce identical-looking dashboards.

What Google Tells You to Do Instead

Google publishes its own list of steps for advertisers worried about suspicious activity, and it is notable for what it leads with. IP exclusion is on the list, but it is last, and the examples around it are narrow and specific.

Tighten your location targeting. Google's specific recommendation is to set location options to "Presence: People in or regularly in your targeted locations," rather than the broader interest-based setting, and to explicitly exclude areas generating unwanted traffic. Google also says outright that if your goal is geographic, you should use location exclusion rather than IP exclusion. Most of what looks like fraud to a local business is really an account happily advertising to the whole country.

Work your search terms report. Review what people actually typed to trigger your ads and add the irrelevant ones as negative keywords. This is the highest-value habit in a small account and it deals with a large share of what gets mistaken for fraudulent traffic.

Tighten your match types. If you are running broad match, phrase or exact will pull your ads back toward searches that resemble what you sell.

Use IP exclusion narrowly, for addresses you have actually identified. Google's own worked example is excluding your own office network, so your staff checking the site do not cost you clicks. That is the right shape for this tool: a small, known, deliberate list. Not a subscription that adds addresses on your behalf according to rules you cannot inspect.

Two practical notes if you do use it. Campaign-level IP exclusions are not available for video, hotel, App, Performance Max or Smart Display campaigns, so if that is where your spend sits, this lever barely applies to you. And Google warns that addresses can appear in more than one version, so a partial exclusion may not do what you think.

If you want help getting this right rather than guessing at it, this is exactly the kind of work our Google Ads management is built around: finding where the money actually goes before changing anything.

When to Escalate to Google

If you have done the above and still see a pattern you cannot explain, a sharp spike in clicks with no conversions, or a run of obviously fake form submissions, you can ask Google to investigate directly through its Click Quality Form.

Submit it properly and it works better. Include your customer ID, the date range of the suspicious activity, the campaigns, ad groups and keywords involved, the domain if you think the traffic came from a specific site, and a short explanation of why the activity looks wrong to you. If you have IP addresses, user agents or referrers, include those too. A vague report gets a vague answer.

Do this promptly rather than months later. Credits are tied to billing periods, and activity from long ago is harder for anyone to investigate.

So Should You Buy Something?

Sometimes. The honest answer depends on where your money is going.

It can be worth it if you are spending seriously on Display, video or Performance Max, where you are exposed to a much wider pool of placements than a search-only advertiser. It is also worth considering if you have already done the free work above, have a documented and repeating pattern, and have escalated to Google without resolution.

It usually is not worth it for a small search-only account. Search is the most controlled surface Google has, your own Invalid clicks column will show you what is being caught, and a monthly subscription can easily cost more than the leak it is fixing. Run that arithmetic honestly. If you spend two thousand dollars a month, a hundred-dollar tool has to recover five percent of your budget just to break even, before it has made you a single additional dollar.

And whatever you choose, insist on seeing what it blocked. A tool that shows you the individual blocked clicks can be checked against your own account. One that only reports a total saved is asking for the same faith the vendor told you not to place in Google.

The Question Worth Asking

The useful question was never "am I being defrauded." It is unanswerable in that form, which is precisely why it sells so well.

The answerable version is this: how much invalid traffic did Google already catch on my account, how much did it credit back, and is what remains larger than the cost of the cure? Two of those three numbers are sitting in your account right now, free, and most owners have never looked at either.

Look first. Then decide whether you have a problem worth paying to solve.

Nora Bennett · Paid Media Strategist, BrandRocket

Paid media strategist at BrandRocket. Spends her days inside Google Ads and Meta accounts, helping small businesses get more out of every dollar they spend.