An advertiser sees a spike in conversions from a campaign, but the leads never close. Before blaming bots, the first place to look is IP and ASN data. This article walks through the specific checks that help you distinguish suspicious traffic from real users, using network-level signals that Google Ads and Meta do not expose in their standard reports.
Why IP and ASN Data Matter for Invalid Traffic Detection
IP addresses and Autonomous System Numbers (ASNs) reveal the network origin of each click. When a large share of clicks comes from a single ASN that hosts datacenters or VPNs, it signals potential invalid traffic. BlindaClick’s analysis shows that datacenter IPs often generate clicks with no real user intent, inflating costs and polluting conversion data.
Check 1: Identify Datacenter and Hosting ASNs
Start by extracting the ASN from your click logs. Common datacenter ASNs include Amazon AWS (AS16509), Google Cloud (AS15169), Microsoft Azure (AS8075), and OVH (AS16276). If more than 5% of your clicks come from these ASNs, investigate further. Use a tool like BlindaClick’s traffic audit to automatically flag these sources.
How to Run This Check
- Export click data from your ad platform (Google Ads, Meta Ads) including IP addresses.
- Use a WHOIS or ASN lookup tool to map each IP to its ASN.
- Calculate the percentage of clicks per ASN.
- Compare against your campaign’s target audience geography and device mix.
Check 2: Look for Abnormal Repeat Activity from a Single IP
A single IP generating multiple clicks within a short time window is a red flag. For example, 10 clicks from the same IP in one hour likely indicate a bot or automated script. Set a threshold based on your typical user behavior: for most B2B campaigns, more than 3 clicks per IP per day is suspicious.
Metrics to Monitor
- Click frequency per IP per hour/day.
- Time between clicks from the same IP.
- Ratio of clicks to conversions from that IP.
Check 3: Compare ASN Distribution Across Campaigns
If one campaign shows a high concentration of clicks from a specific ASN while others do not, that campaign may be targeted by invalid traffic. For instance, a campaign targeting “small business software” might attract bot traffic from a residential proxy ASN. Compare ASN distributions week over week to spot anomalies.
Check 4: Cross-Reference with Conversion Quality
IP and ASN data become more powerful when paired with conversion outcomes. If clicks from a certain ASN produce high bounce rates, short session durations, or zero downstream conversions, that ASN is likely delivering low-quality traffic. BlindaClick’s platform correlates ASN with conversion events to quantify the impact on your ROI.
What to Look For
- Conversion rate by ASN.
- Lead quality score (if available from CRM).
- Form completion time (under 10 seconds suggests automation).
Limitations of IP and ASN Checks
IP and ASN data alone cannot confirm fraud. Residential proxies and VPNs can mask true origins. Also, some legitimate users (e.g., remote workers) may come from datacenter IPs. Use these checks as diagnostic signals, not proof. Combine with other methods like user-agent analysis and behavioral patterns for a fuller picture.
Next Steps: Automate the Diagnosis
Manual IP and ASN checks are time-consuming. BlindaClick automates this process, providing real-time alerts when suspicious ASN activity exceeds your thresholds. Start a free diagnosis to see which ASNs are affecting your ad spend.
Frequently Asked Questions
Can IP blocking solve click fraud?
Blocking individual IPs is a temporary fix. Fraudsters rotate IPs easily. Focus on ASN-level exclusions in your ad platform or use a protection service that adapts to new patterns.
What is a normal ASN diversity for a campaign?
For a national campaign, you might see hundreds of ASNs. If 80% of clicks come from one ASN, that is abnormal and warrants investigation.
Does Google Ads already filter datacenter traffic?
Google applies basic invalid traffic filters, but they do not catch all datacenter or proxy traffic. Independent tools like BlindaClick provide additional layers of detection.
Leave a Reply