Ad tech stocks
TEAD0.58▲ +13.19%186013.51▲ +7.48%PSKY9.79▼ -5.18%CDLX2.80▼ -4.77%DSP12.70▲ +3.17%U42.19▲ +3.07%SAX36.50▲ +2.93%MNTN10.46▲ +2.85%OMC75.61▲ +2.68%APP282.96▼ -2.57%INUV0.58▲ +2.49%STGW8.34▲ +2.46%IHRT2.05▼ -2.38%CCO2.40▲ +2.34%WPP384.90▲ +2.34%SIRI25.39▼ -1.89%RDDT145.07▲ +1.85%LFTO15.53▼ -1.74%CPNG13.63▼ -1.69%TBLA3.31▼ -1.64%PUB96.04▲ +1.61%APPS11.28▲ +1.58%NFLX68.48▼ -1.58%SST2.58▼ -1.53%TRU62.02▲ +1.47%SCOR4.75▲ +1.39%035420191200.00▼ -1.29%4755681.70▼ -1.26%AZRN0.82▼ -1.20%ZETA31.92▲ +1.11%PUBM18.92▲ +1.00%HAVAS17.80▲ +0.85%PINS18.73▼ -0.82%GOOGL341.74▼ -0.68%ROKU151.32▼ -0.63%SNOW341.70▲ +0.63%AAPL330.96▼ -0.62%47511238.50▲ +0.57%BIDU86.44▼ -0.50%SFOR45.80▼ -0.43%24331308.00▲ +0.38%BABA107.82▲ +0.26%0700431.00▼ -0.23%RAMP37.60▲ +0.23%PERI8.67▼ -0.23%CART43.04▼ -0.19%IBTA39.47▲ +0.18%OUT27.70▼ -0.18%VER12.10▲ +0.17%DEC24.68▲ +0.16%CRTO15.18▼ -0.13%TTD12.19▲ +0.12%NEXN8.99▼ -0.11%META725.80▲ +0.09%SNAP5.41▲ +0.09%DV13.48▼ -0.04%SPOT487.50▲ +0.03%43243564.00▲ +0.03%WBD30.95▼ -0.02%ILLM0.65▲ 0.00%MGNI25.26▲ 0.00%
Ticker byClearTrust

Invalid traffic & fraud

Honeypot

In ad fraud research, a honeypot is a decoy, such as a trap website or hidden form field, that no genuine person should touch, used to expose bots and fraud.

The short answer, from the AdTech Sumo glossary

A honeypot works on a simple principle: create something real people will never visit or interact with, then watch who shows up. Anything that does is almost certainly automated or fraudulent.

In advertising, researchers and verification firms set up decoy websites with no promotion, then see whether their domain begins appearing in bid requests they never sent, revealing domain spoofing. Others buy small amounts of traffic from vendors to a decoy site and measure how much is bots, or run test ad campaigns to see which sources deliver clicks that never behave like people. On forms, a hidden field invisible to humans but filled in by bots is a classic honeypot for lead generation fraud.

Honeypots produce very clean evidence, because the baseline of legitimate activity is zero. They are also useful for studying botnet behaviour and malvertising, and have helped expose major schemes. They should be used ethically: the goal is observation and defence, not luring real users.

Think of it like this

A honeypot is like leaving a fake wallet on a park bench with a tracker inside: nobody honest will take it, so whoever does tells you a lot.

An example

A research team registers a brand-new, unpublicised domain. Within two weeks it appears in 300,000 bid requests across four exchanges, all from sellers claiming to represent it: proof of spoofing by those sellers.

Related terms

Sources: MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)