What can and cannot be observed
In your Google Ads reports, an automated visit and a paying customer are the same line: one click, some cost. Nothing in that report tells you which was which. What a landing-page monitor can observe is different — not the click, but the visit that followed it: where the request came from, how it behaved on the page, and whether the same characteristics show up again tomorrow.
That distinction matters, because it sets the ceiling on what any such tool can honestly say. It can tell you that a pattern repeats. It cannot tell you the intention behind it.
The signals
- Network origin. Whether the address belongs to a consumer connection, a mobile carrier, a privacy relay, or a hosting and cloud provider. On its own this proves nothing — real people browse through corporate VPNs and hosted browsers every day — but it is a meaningful prior.
- Timing and volume. How many paid visits arrived from the same address, subnet or device signature within a day.
- Recurrence. Whether the same address keeps arriving through a paid ad on many separate days. Returning customers usually come back directly or by bookmark, not through the ad each time.
- Behaviour on the page. Seconds spent, scroll depth, pointer or touch movement. Measured only when the browser actually reported it — a missing measurement is treated as missing data, never as a bounce.
- Browser self-description. Some clients report that they are driven by automation software. That is a strong tell precisely because a real browser has no reason to say it.
- Click-ID reuse. Google mints a fresh click identifier per billed click. The same one arriving from several networks means a copied or forwarded landing URL, not several real clicks.
The two gates that stop a lone signal convicting anyone
The failure mode of every naive tool is the same: one rule fires, an address gets labelled, and a real customer on a VPN ends up on a list. ClickSheriff applies two gates instead.
First, behavioural corroboration. A network fact on its own — a hosting address, a missing click ID — can never produce a finding. Something the visitor did has to agree with it.
Second, independent-type corroboration. A finding is only called strong, and only offered for review, when at least two different kinds of signal agree. Two readings of the same signal do not count as two signals. The single exception is an invisible-link trap: a link no person using a browser can see or reach, which is self-evident when followed.
Below that bar, findings are still shown — labelled suspicious when the threshold was reached by one signal type, or needs review when something fired but stayed under it. They are visible on purpose, and they are not offered as something to act on.
What the finding is worth
Every assessment stores the ruleset version that produced it, the score, and the exact signals behind it — so a conclusion can be re-read months later and understood, rather than trusted. The evidence view also lists what argues against the finding: conversions from the same address, real time spent reading, how few days it actually appeared on.
Read both halves before you decide anything. That is not a disclaimer; it is the intended way to use the tool.