What Does NOT Work: Click Fraud Protection — the Detection Gap You Can't Close With Tools
Google's automated filtering removes obvious non-human clicks before you're charged, but its own documentation admits a harder category exists that requires manual investigation — and the only lever you get as an advertiser is IP exclusion, which doesn't touch fraud detection at all. This page exists to stop budget audits from assuming "Google already handles fraud" is a complete answer.
What Google's Automated Filtering Catches (and How Credits Work)
Invalid traffic covers clicks and impressions that aren't genuine user interest — intentional fraud as well as accidental/duplicate clicks (https://support.google.com/google-ads/answer/11182074). Google's automated systems filter invalid clicks in real time and you are never charged for what they catch (same source).
Google's official methodology splits invalid traffic into two tiers (https://support.google.com/google-ads/answer/2616016):
- General Invalid Traffic (GIVT) — roughly 80% of total invalid click traffic, per Google's estimate. Obvious, easily detectable non-human activity, caught via robots.txt compliance checks, the IAB/ABCe International Spiders & Robots List, publisher test-activity filtering, Google-internal IP removal, and pattern analysis. - Sophisticated Invalid Traffic (SIVT) — harder to identify, needs human intervention or deeper analysis (see next section).
Detection also relies on supervised machine learning (a Classification/Neural Network approach plus Logistic Regression) evaluating hundreds of data sources to predict invalid traffic (https://support.google.com/google-ads/answer/2616016).
Billing mechanics
invalid traffic caught before the invoice is generated simply adjusts your reports; traffic caught *after* invoicing shows up as a credit on a subsequent invoice, not a refund or retroactive correction (https://support.google.com/google-ads/answer/11182074, https://support.google.com/google-ads/answer/1704323). Clicks that land right before a billing cycle closes but get flagged invalid immediately after can produce a credit the following month (https://support.google.com/google-ads/answer/16826168). Credits reduce your balance on automatic/invoice payments or increase it on manual payments (https://support.google.com/google-ads/answer/1704323). The Invalid Activity Credit Report breaks these credits down by campaign and network, with click/interaction counts — but it is only available for Search and Performance Max campaigns (https://support.google.com/google-ads/answer/16826168), so Display and other formats give you no equivalent visibility into what was credited.
What It Does NOT Catch — the Gap That Matters for Budget Audits
Google's own documentation draws the SIVT/GIVT distinction precisely because SIVT — traffic from hijacked devices, adware, malware, misappropriated content — is harder to detect and needs human review, not just automated filtering (https://support.google.com/google-ads/answer/2616016). Google deliberately does not publish GIVT vs. SIVT totals separately, stating this is to prevent bad actors from reverse-engineering the filters to optimize invalid traffic around them (same source). That non-disclosure is itself informative for an audit: you cannot know from Google's reporting what share of your "clean" traffic is actually undetected SIVT.
Google's support documentation also implicitly acknowledges detection gaps by offering an investigation request for traffic you suspect wasn't caught (https://support.google.com/google-ads/answer/11182074) — see the last section.
Beyond what's officially confirmed, three claims are reported but not verified against Google's own documentation (unverified, reported by third-party/industry sources referenced in the notes):
- Distributed click fraud that rotates IP addresses and mimics human behavior well enough may evade the machine-learning detection — Google does not explicitly state what its SIVT detection catches or misses. - Low-volume competitor clicking spread across diverse IPs over time is plausibly hard for Google to distinguish from legitimate behavior, and may go unfiltered. - A meaningful share of Display placement traffic may be non-human and uncaught — Google does not quantify Display fraud rates anywhere in its official documentation.
When auditing an account for wasted spend, treat "Google already filters invalid clicks" as true only for the ~80% GIVT tier it explicitly claims to catch — not as a guarantee against the SIVT tier it explicitly says needs manual review.
Why Third-Party "Click Fraud Blocker" Tools Have Limited Effect
The only advertiser-side control Google *officially* documents for invalid traffic is IP exclusion (https://support.google.com/google-ads/answer/2456098) — not a native integration point for third-party fraud-blocking tools. The claims commonly made about such tools are not confirmed in Google's documentation (unverified, reported by industry sources in the notes):
- They can block a fraudulent visitor in real time instead of waiting for a retroactive credit — but they cannot control Display or Performance Max auctions, where Google alone handles ad serving and bidding with no third-party visibility or intervention point. - Vendors have a commercial incentive to report high "blocked fraud" volumes to justify subscription pricing, which can mean over-flagging legitimate traffic relative to Google's more conservative native filtering. - They may offer more granular detection than Google's filters, but they operate entirely outside Google's auction infrastructure, capping what they can actually prevent (as opposed to just report).
Net effect for an audit or a purchase decision: a third-party tool is, at best, a Search-only, after-the-fact detection layer — it is structurally unable to protect Display or Performance Max spend, which is exactly where undetected non-human traffic is most plausibly a problem (see previous section).
IP Exclusion: the Only Advertiser-Side Control — and Its Narrow Scope
Per https://support.google.com/google-ads/answer/2456098:
- You can exclude up to 500 IP addresses per campaign (campaign-level setting). Account-level IP exclusion is also supported, but Google's documentation does not state a numeric maximum for it — do not assume the 500 campaign-level cap also applies at account level.
- Wildcards are supported: an asterisk replaces the last 3 digits, e.g. 192.168.1.*, to exclude a whole block.
- Account-level IP exclusions apply to Performance Max, Demand Gen, Search, Shopping, Display, Discover, and YouTube campaigns.
- IP exclusions are not available for video campaigns, hotel campaigns, App campaigns, Smart Display campaigns, or Performance Max at the campaign level (Performance Max only supports it at the account level).
- If both account-level and campaign-level exclusions are set, Google merges the lists — every IP excluded at either level is blocked from that campaign.
- IP addresses can appear in different versions; you must exclude all versions of an address to actually block it.
Critical scope limit
Google states this feature's use case is preventing known sources — your own company's network, a known competitor — from seeing your ads. It is not a fraud-detection or automated-click-filtering mechanism. IP exclusion stops people you already know from viewing ads; it does nothing against unknown or IP-rotating invalid traffic, which is precisely the gap described above.
Reporting Invalid Activity to Google: Process and Realistic Expectations
If you suspect invalid traffic Google hasn't caught, you can request an invalid traffic investigation covering the past 60 days through Google's official process (https://support.google.com/google-ads/answer/11182074). When requesting one, share as much specific traffic information as possible; Google's specialist team uses multiple signals, including click and impression data, to trace the source during the investigation (same source).
What the notes could not confirm from official documentation (unverified): expected review turnaround time, and what a realistic approval/credit rate looks like. Set expectations accordingly — this is a manual, evidence-driven process with an unspecified timeline, not a guaranteed or fast remedy.
Remember the billing mechanics from the first section: even a successful investigation produces a credit on a future invoice, never an immediate refund or retroactive correction (https://support.google.com/google-ads/answer/11182074) — and, per the credit report's scope, that visibility only exists for Search and Performance Max (https://support.google.com/google-ads/answer/16826168).
Related
- How to Audit an Existing Google Ads Account (Priority Order) — the sequence that stops you from trusting broken data — when auditing wasted spend, this page is the reality check for step 3 (Search Terms / Auction Insights review): don't credit "invalid traffic filtering" with catching more than the GIVT tier Google actually claims. - What Does NOT Work: Performance Max Failure Modes — Performance Max is exactly the campaign type where advertiser-side fraud control is weakest (no IP exclusion at campaign level, no third-party tool visibility into the auction), compounding the failure modes documented there. - Google Ads Policy Taxonomy: What Gets an Ad Disapproved vs an Account Suspended — invalid traffic and policy violations are handled through separate mechanisms (automated credits vs. account enforcement); don't conflate a click-fraud credit request with a policy appeal.
Verified against
45 claims checked against these sources · 2 refuted and removed
Source: Sinapsi — verified compositional memory, queryable by LLMs. Query this wiki live from your assistant over MCP, or build your own verified wiki (public, or private for your team). CC BY 4.0 — reuse with attribution to Sinapsi.