Lesson 8 of 8 · 10 min read · intermediate
Protecting your spend (and your inventory)
A practical anti-fraud checklist for buyers and sellers: supply controls, contract clauses, refunds, TAG certification and how to judge vendors.
Everything in this track leads here. You now know what invalid traffic is, how it is made and how it is caught. This lesson turns that into practice for two audiences: buyers (advertisers and agencies) who want every dollar, euro or rupee to reach a real person, and sellers (publishers, app developers and platforms) who want to prove their audience is real and keep their revenue safe.
Protecting ad spend is like protecting a warehouse. You lock the doors (supply-chain controls), install cameras (measurement), sign contracts with delivery firms that say who pays for losses (contract clauses), and choose a reputable security company (vendors). No single measure is enough; together they make you a hard target, and fraudsters move on to easier ones.
The buyer's checklist
- Buy only authorised supplyRequire your DSP to reject sellers not authorised in ads.txt or app-ads.txt, require complete schain, and review spend by seller ID from sellers.json. Cut long reseller chains with supply path optimization.
- Turn on pre-bid protectionApply pre-bid IVT and MFA filters in every DSP you use, including for CTV and in-app, not just open-web display.
- Measure post-bid with an accredited vendorTag campaigns with a vendor accredited by the MRC for SIVT in the environments you buy. Ask for census, impression-level data.
- Prefer certified partnersFavour exchanges, SSPs and publishers with the TAG Certified Against Fraud seal, and buy through TAG Certified Channels where possible.
- Watch outcomes, not just deliveryCompare conversions, site visits and sales by supply source. Traffic that clicks but never converts, or converts in impossible patterns, needs investigation.
- Allow-list for high-risk goalsFor performance and CTV campaigns, start from a vetted allow-list of apps, sites and channels rather than the open market.
The seller's checklist
- Keep ads.txt, app-ads.txt and sellers.json accurate; remove partners you no longer work with.
- Never buy traffic from sources you cannot audit; if you buy traffic at all, measure it separately and disclose it to buyers.
- Run a pre-serve IVT filter and share your own IVT reports with buyers proactively.
- Monitor for unexplained spikes, new traffic countries, and sudden changes in ad refresh or session length.
- Pursue TAG certification and use MRC-accredited measurement so buyers can trust your numbers.
Refunds and clawbacks: what is realistic
Refunds and clawbacks are how money moves back when invalid traffic is found after the fact. Search and social platforms typically credit advertisers automatically for invalid clicks they detect. In programmatic, it is harder: by the time a monthly report is produced, the SSP may already have paid the publisher, and the publisher may be gone. Clawbacks then depend on payment terms and contracts at every hop. The practical lessons are to measure in near real time, dispute quickly (often within 30 to 60 days), and agree in advance which vendor's numbers settle the bill.
Contract clauses that matter
| Clause | What it should say |
|---|---|
| IVT definition | IVT means GIVT and SIVT as defined in the current MRC guidelines |
| Measurement of record | Which MRC-accredited vendor's data decides disputes, and for which environments |
| Threshold and make-good | Invalid impressions are never billable; above an agreed IVT rate, the buyer may pause or terminate |
| Refund window | Time limits and process for claiming credits, passed through to every intermediary |
| Transparency | Log-level or seller-level reporting, full schain and disclosure of any sourced traffic |
| Certification | Partners maintain TAG Certified Against Fraud status and relevant MRC accreditations |
Certification works partly because it forces good habits and partly because certified channels exclude the worst actors. TAG also runs regional programmes, such as in Europe and Asia-Pacific, and has published similar benchmarks there. Certification is a strong signal, not an insurance policy.
How to evaluate a fraud or verification vendor
| Question | Good answer |
|---|---|
| Which MRC accreditations do you hold? | Named metrics (GIVT, SIVT) by environment: desktop, mobile web, in-app, CTV |
| Pre-bid, post-bid or both? | Both, with post-bid findings feeding pre-bid lists |
| Census or sample? | Census for the traffic you are billed on |
| How do your categories map to MRC? | A clear mapping to GIVT and SIVT categories |
| What is your false-positive process? | Measured error rates and a way for publishers to dispute |
| What threat research do you publish? | Named, disclosed schemes and industry cooperation |
| Can I export impression-level data? | Yes, so you can reconcile with your ad server and claim refunds |
A monthly routine
Protection is a habit, not a project. Once a month, review IVT and MFA rates by seller, app and domain; compare platform-reported conversions with your own sales data; check that your ads.txt entries or your DSP's authorised-seller settings are current; file refund claims inside the agreed window; and remove the worst five sources, whatever their CPM. Small, steady pruning compounds.
Finally, remember that fraud is a business. It follows the easiest money. Every control you add raises the cost of stealing from you. You do not need to make fraud impossible, only to make your budget or your inventory harder to exploit than the next one.
Key takeaways
- Buyers should combine authorised supply (ads.txt, sellers.json, schain), pre-bid filters and MRC-accredited post-bid measurement.
- Sellers protect revenue with accurate authorisation files, no unaudited sourced traffic and proactive IVT reporting.
- Contracts should define IVT by MRC standards, name the measurement of record, and set refund windows and thresholds.
- Evaluate vendors on MRC accreditation by environment, pre- and post-bid coverage, census data and false-positive handling.
Questions people ask
How do I protect my ad budget from fraud?
Buy only from sellers authorised in ads.txt or app-ads.txt, require complete schain, use pre-bid IVT and MFA filters in your DSP, and measure with an MRC-accredited vendor for SIVT in every environment you buy. Favour TAG-certified partners, use allow-lists for CTV and performance campaigns, and write IVT definitions, refund windows and a measurement of record into your contracts.
Can you get a refund for ad fraud?
Often, but it depends on the channel and contract. Search and social platforms usually credit invalid clicks automatically. In programmatic, refunds rely on your DSP, SSP and publisher terms, and money may already have been paid out. Measure in near real time, dispute quickly, typically within 30 to 60 days, and agree in advance which accredited vendor's data decides billing.
What is TAG Certified Against Fraud?
TAG Certified Against Fraud is a certification from the Trustworthy Accountability Group for companies that follow its anti-fraud guidelines, such as using ads.txt, filtering data-center traffic and working with accredited measurement. TAG's 2024 US Fraud Benchmark study reported IVT below 1% in TAG Certified Channels for a fourth consecutive year. Certification signals good practice but does not guarantee fraud-free inventory.