Ad tech stocks
TEAD0.60▲ +17.40%CDLX2.69▼ -8.67%PSKY9.52▼ -7.80%186013.51▲ +7.48%U43.15▲ +5.42%APP276.19▼ -4.90%LFTO15.29▼ -3.20%STGW8.38▲ +2.95%MNTN10.46▲ +2.85%APPS11.40▲ +2.75%SFOR44.85▼ -2.50%RDDT145.90▲ +2.43%ZETA32.33▲ +2.41%CCO2.40▲ +2.30%NFLX68.02▼ -2.25%OMC75.26▲ +2.21%TRU62.39▲ +2.08%INUV0.57▲ +2.02%WPP382.90▲ +1.81%DSP12.51▲ +1.62%GOOGL338.65▼ -1.58%ILLM0.66▲ +1.54%SIRI25.48▼ -1.53%AAPL328.26▼ -1.43%SAX35.96▲ +1.41%SCOR4.75▲ +1.39%BIDU85.69▼ -1.36%SST2.58▼ -1.34%CART43.69▲ +1.32%035420191200.00▼ -1.29%4755681.70▼ -1.26%PUBM18.96▲ +1.23%SPOT493.31▲ +1.22%AZRN0.82▼ -1.20%ROKU150.64▼ -1.08%IHRT2.12▲ +0.95%TBLA3.33▼ -0.89%PUB95.34▲ +0.87%IBTA39.73▲ +0.84%NEXN8.93▼ -0.83%PINS18.75▼ -0.71%BABA106.92▼ -0.57%47511238.50▲ +0.57%HAVAS17.55▼ -0.57%META729.03▲ +0.53%MGNI25.38▲ +0.48%SNAP5.42▲ +0.46%OUT27.64▼ -0.40%24331308.00▲ +0.38%TTD12.13▼ -0.37%RAMP37.65▲ +0.35%0700431.00▼ -0.23%PERI8.68▼ -0.17%DEC24.68▲ +0.16%CRTO15.21▲ +0.07%WBD30.93▼ -0.06%SNOW339.72▲ +0.05%CPNG13.87▼ -0.04%DV13.48▼ -0.04%43243564.00▲ +0.03%VER12.08▲ 0.00%
Ticker byClearTrust

Lesson 7 of 8 · 10 min read · intermediate

This lesson counts towards the ClearTrust Invalid Traffic & Ad Fraud certificate. Enrol with your email to record your progress and scores.Get certified, free

How fraud gets caught

Pre-bid vs post-bid, the signals detectors read, honeypots, sample vs census measurement and threat intelligence: how invalid traffic is actually found.

Fraud detection is an arms race with a simple scoreboard: can you tell a real person from a fake one before, or at least soon after, money changes hands? No single test does it. Detection works by layering many imperfect checks at different moments in an ad's life, and by people who study fraud operations the way police study organised crime.

Think of a bank catching card fraud. Some transactions are declined instantly because the card is on a stolen list. Others go through but get flagged hours later because the pattern is odd (a coffee in Mumbai and a TV in London ten minutes apart). And sometimes investigators spend months mapping a whole gang. Ad fraud detection has exactly these three layers.

How invalid traffic gets caught

1/7
visit▭Incoming visithuman or bot?✓Known listsbots, spiders, data centers✓Device & network signalsIP, user agent, headless traits✓Behaviourmouse, timing, patterns▦Quality scoree.g. a TQI Score™!GIVT filteredroutine, list-based!SIVT flaggedneeds analytics★Clean bidsafe to buy
1
A visit arrives

Every impression starts as a visit from a device. Some are people; some are crawlers, scripts or hijacked phones pretending to be people.

  1. A visit arrives: Every impression starts as a visit from a device. Some are people; some are crawlers, scripts or hijacked phones pretending to be people.
  2. Layer 1: known lists: The easy catches: declared crawlers on the IAB/ABC Spiders & Bots List, known data-center IP ranges, non-browser user agents. The MRC calls this GIVT.
  3. Layer 2: device and network signals: Next, deeper checks: does the device claim to be an iPhone but behave like a Linux server? Is it a headless browser or a residential proxy? Inconsistencies are red flags.
  4. Layer 3: behaviour: Bots can fake a fingerprint, but it is hard to fake human behaviour at scale: timing, scrolling, click-to-install gaps, impossible volumes. Behavioural analysis catches SIVT.
  5. One score to act on: Signals are combined into a score buyers can act on in real time. ClearTrust’s TQI Score™, for example, rolls 150+ filters into a single number.
  6. Pre-bid: don’t buy it: With pre-bid filtering, bad traffic is never bought. Clean requests go through to the auction.
  7. Post-bid: prove it and claw it back: Post-bid measurement audits what was bought. Invalid impressions are reported, excluded from billing and, where contracts allow, refunded.

Before the bid vs after the ad

Pre-bid filtering

  • Runs on the bid request, in milliseconds, before any money is spent
  • Uses lists and reputation: IPs, devices, apps, domains, sellers
  • Great for GIVT and known-bad sources
  • Blind to how the ad actually renders
  • Prevents waste instead of refunding it

Post-bid measurement

  • Runs when the ad renders and afterwards, via tags or SDKs
  • Reads the live environment and behaviour over time
  • Needed for most SIVT
  • Money is already spent; enables blocking, reporting and refunds
  • Feeds new bad sources back into pre-bid lists

Pre-bid filtering is offered inside DSPs, often powered by verification vendors' data, and by SSPs screening their own supply. Post-bid measurement uses a tag that runs with the ad (on the web) or the Open Measurement SDK (in apps). A post-bid tag can also block, swapping the ad for a blank if the environment looks invalid; the share of impressions blocked is reported as a block rate. The best programmes use both and connect them, so everything learned after the bid improves what is rejected before it.

The signals detectors read

Sophisticated detection is the art of finding contradictions between signal families.
Signal familyExamplesWhat it reveals
NetworkIP reputation, data-center and proxy ranges, ASN, IP-to-device ratiosWhere traffic really comes from
Device and browserFingerprints, user agent, screen, fonts, graphics, sensors, automation tracesWhether the device is what it claims and whether it is automated
BehaviourScrolls, dwell time, click timing, session paths, time-of-day patternsWhether activity looks like a messy human or a tidy machine
Supply chainads.txt, sellers.json, schain, declared vs observed domain or appWhether the inventory is what the seller said
Population and timeSudden traffic spikes, identical clusters, impossible ratiosCoordinated schemes invisible at the single-impression level

Individually, most signals are weak. A VPN user and a proxied bot share an IP pattern. A power user and a bot both click fast. What catches SIVT is corroboration: many weak signals pointing the same way, across millions of events. That is what the MRC means by multi-point corroboration. Machine-learning models and anomaly detection do the heavy lifting, while human analysts investigate clusters the models surface.

Honeypots and threat intelligence

A honeypot is a trap: a page, app, ad slot or cookie set up so that no real person would ever interact with it. Anything that does is automatically suspect, and its fingerprint can be studied. Researchers also run infected machines in controlled labs, reverse-engineer malware, and follow the money through ad accounts and shell companies. HUMAN's Satori team, Google, DoubleVerify's Fraud Lab and others have disclosed most of the big schemes this way, often in coordination with platforms and law enforcement, because disrupting a scheme's infrastructure or cash-out stops it everywhere at once.

Sample vs census measurement

A census approach measures every impression. A sample approach measures a subset and projects the result. Sampling is cheaper, but fraud is clustered, so a small sample can miss a concentrated scheme or misjudge a small publisher. MRC standards expect measurers to disclose their methods, and for blocking or refunds you generally want impression-level (census) data, since you cannot refund impressions you never measured. When comparing vendors' IVT rates, always ask whether figures are census or sampled and over which environments.

False positives are real costs

A detector that flags too much punishes honest publishers and throws away real customers, such as people on corporate VPNs, shared family devices or mobile networks in India or Indonesia where many users share one IP address. Good vendors measure their false-positive rates, publish how their categories map to MRC definitions, and let publishers dispute findings. Precision matters as much as recall.

Accreditation: who checks the checkers

MRC accreditation means an independent auditor has examined a vendor's methods, controls and data against MRC standards for specific metrics in specific environments, for example "SIVT detection for desktop and mobile web display" but not necessarily CTV. Accreditation is not a guarantee of catching everything; it is evidence that the process is documented, consistently applied and audited. TAG's programmes, covered in the next lesson, certify companies' anti-fraud practices rather than their measurement.

Key takeaways

  • Pre-bid filtering prevents waste using lists and reputation; post-bid measurement sees rendering and behaviour and catches most SIVT.
  • Detectors combine network, device, behaviour, supply-chain and population signals; corroboration beats any single signal.
  • Honeypots, malware labs and threat-intelligence investigations uncover and dismantle large schemes.
  • Census measurement is better than sampling for clustered fraud and refunds; always check MRC accreditation per environment.

Questions people ask

What is the difference between pre-bid and post-bid fraud detection?

Pre-bid detection checks the bid request before an ad is bought, rejecting traffic from known-bad IPs, devices, apps, domains or sellers in milliseconds. Post-bid detection runs when and after the ad renders, reading the device environment and behaviour to catch sophisticated invalid traffic. Pre-bid prevents waste; post-bid finds what pre-bid misses, supports blocking and refunds, and feeds new bad sources back into pre-bid lists.

How do ad verification companies detect bots?

They collect many signals, such as IP reputation, device fingerprints, browser properties, behaviour, timing and supply-chain data, and look for contradictions, like a supposed smart TV behaving like a phone or thousands of users with identical patterns. Machine-learning models find anomalies, honeypots attract bots, and threat researchers reverse-engineer malware. MRC accreditation confirms a vendor's methods are audited for specific environments.

What is a honeypot in ad fraud detection?

A honeypot is a trap set up so that no genuine person would interact with it, such as a hidden page, ad slot, link or unused app. Any traffic that reaches it is almost certainly automated, so researchers can study its fingerprint, trace where it came from and add those signals to detection models. Honeypots are one of several tools used to discover new bot operations.

Previous: Made-for-advertising sites and traffic arbitrageNext: Protecting your spend (and your inventory)