← Back to blog

August 2, 2026

Click fraud: the silent drain on digital marketing

Click fraud rarely announces itself. It shows up as a campaign that looks fine on every dashboard and converts like nothing. Here is how it works, why display is the softest target, and what you can actually do about it inside Google Ads.

Click fraud is unusual among marketing problems in that the metrics it damages are the ones that look healthy. Impressions go up. Clicks go up. Cost per click often goes down, because fraudulent inventory is cheap. The only number that suffers is the one at the end, and by the time anyone traces it back, the budget is spent.

That is why it stays invisible for so long. Nobody investigates a campaign that is hitting its click targets.

What counts as click fraud

The term covers a spread of behaviour with very different intent behind it.

Bot traffic. Automated scripts that load pages and click ads. The crude versions are easy to filter — obvious data centre IPs, impossible click rates, no mouse movement. The sophisticated versions run on residential proxies, emulate human timing, and are genuinely hard to distinguish from real users at the impression level.

Click farms. Actual people, paid very little, clicking ads. Every signal is human because a human produced it. Filtering these on behavioural grounds is close to impossible; you catch them through pattern analysis at the placement level instead.

Competitor clicking. A competitor repeatedly clicking your search ads to exhaust the daily budget. Real, but usually small and largely handled by Google's automated invalid-click filters.

Publisher self-clicking. A site owner clicking ads on their own inventory. Crude, well policed, mostly a historical problem.

Impression laundering and domain spoofing. The most commercially damaging of the set. Ad requests are misrepresented as coming from a premium site when they originate somewhere worthless. You are billed for a placement you never actually received.

Google filters a meaningful share of the crude end of this automatically and credits invalid clicks back. What survives the filter is the sophisticated end — and the sophisticated end is precisely where the money is.

Why display is the softest target

Search click fraud is constrained. Someone has to search a query, and the inventory is Google's own. The economics of faking it at scale are poor.

Display is a different structure entirely. Your ads appear across an enormous, mostly unfamiliar long tail of sites. The publisher gets paid per impression or click. The advertiser usually cannot name more than a handful of the domains their budget reached last month. That combination — huge surface area, direct financial incentive, near-zero advertiser visibility — is what makes display the natural home for this.

The result is that click fraud and placement quality are not really two problems. They are the same problem seen from two angles. Fraudulent and near-fraudulent clicks overwhelmingly come from a specific kind of site, and those sites have recognisable characteristics.

The overlap with made-for-advertising sites

Made-for-advertising sites exist to generate ad revenue rather than serve readers. Thin, scraped, or AI-generated content. Extreme ad density. Traffic bought rather than earned.

They are not all fraudulent in the legal sense. Many are technically compliant. But they sit exactly where invalid traffic concentrates, for a simple structural reason: a site whose entire business model is ad impressions has every incentive to acquire traffic as cheaply as possible, and the cheapest traffic available is not human.

This is useful, because it makes the problem tractable. You do not have to build bot detection. You have to stop buying the inventory where bots live. Those are very different engineering problems, and only one of them is something an advertiser can actually do.

Signals that your budget is going somewhere wrong

Before running any tooling, a placement report will usually tell you plenty on its own.

Click-through rates that are too good. Display CTR is typically low. A placement running several multiples above your account average is not a discovery, it is a warning.

Traffic that arrives and vanishes. Near-100% bounce rates, sub-two-second sessions, one page per visit. Cross-reference the placement report against analytics and the pattern is usually stark.

Clicks without any downstream behaviour. No scroll, no secondary page, no micro-conversion, ever. Real interest leaves a trace even when it does not convert.

Domains nobody recognises. Generic keyword-stuffed names, unfamiliar TLDs, near-misspellings of real publishers. Open a few. It takes thirty seconds to know what you are looking at.

Enormous impression volume from one placement. A single unfamiliar domain delivering a large share of your impressions deserves scrutiny before it deserves budget.

Cost concentrating in the long tail. Sort the report by cost descending and check how much sits below the recognisable names. In unaudited accounts this is regularly a much larger share than anyone expects.

What to actually do about it

The tooling most advertisers reach for first is verification and IVT detection from a vendor. That is worth having, but it is detection after the fact, and in our experience it consistently under-performs on GDN and PMAX specifically — those platforms have a different placement model to programmatic DSP buying, and tools built for the latter miss domains that GDN serves routinely.

The higher-leverage move is exclusion at the source.

  1. Pull your placement report. Google Ads → Reports → Predefined reports → Other → Campaign URL performance. Last 90 days minimum.
  2. Score every domain, not just the expensive ones. MFA characteristics, ad density, content quality, redirect behaviour. The long tail is the point.
  3. Build one exclusion list from the results. Keep the evidence attached so each decision is defensible later.
  4. Apply it at the account level. Since Google's January 2026 rollout, one list applied once covers every Display and PMAX campaign in the account, including ones created afterwards. The full walkthrough is here.
  5. Re-run it quarterly. New junk domains appear continuously. A list built once and never revisited decays fast.

Manual review works up to a few hundred domains and then stops working, which is what automated placement scoring is for.

What to expect afterwards

Be ready for the reporting to look worse before it looks better.

Removing fraudulent and low-quality placements removes clicks. Volume metrics drop. Cost per click frequently rises, because you stopped buying the cheap worthless inventory that was dragging the average down. If your team is measured on traffic volume or CPC, this reads as a regression, and someone will say so.

The metrics that improve are further down: conversion rate, revenue per visit, cost per acquisition. In one campaign we ran on a cleaned versus uncleaned placement list for a large European brand, the cleaned list produced 52% fewer visits and 7x more revenue per visit. Fewer clicks, considerably more money.

Decide in advance which numbers you are optimising, and tell whoever reads the dashboard what is about to happen. Otherwise the audit gets reversed by someone looking at the traffic chart.

The silent drain stays silent precisely because the metrics it damages are not the ones on the front page of the report. Go and look at the placement list.