ClickSheriff Install ClickSheriff Free

How a finding is formed — and why it is not proof.

People call it click fraud. What software can actually observe is narrower and more useful: repeated patterns in the visits your landing page measured. Here is exactly how one is built, and where its authority ends.

Install ClickSheriff Free

What can and cannot be observed

In your Google Ads reports, an automated visit and a paying customer are the same line: one click, some cost. Nothing in that report tells you which was which. What a landing-page monitor can observe is different — not the click, but the visit that followed it: where the request came from, how it behaved on the page, and whether the same characteristics show up again tomorrow.

That distinction matters, because it sets the ceiling on what any such tool can honestly say. It can tell you that a pattern repeats. It cannot tell you the intention behind it.

The signals

  • Network origin. Whether the address belongs to a consumer connection, a mobile carrier, a privacy relay, or a hosting and cloud provider. On its own this proves nothing — real people browse through corporate VPNs and hosted browsers every day — but it is a meaningful prior.
  • Timing and volume. How many paid visits arrived from the same address, subnet or device signature within a day.
  • Recurrence. Whether the same address keeps arriving through a paid ad on many separate days. Returning customers usually come back directly or by bookmark, not through the ad each time.
  • Behaviour on the page. Seconds spent, scroll depth, pointer or touch movement. Measured only when the browser actually reported it — a missing measurement is treated as missing data, never as a bounce.
  • Browser self-description. Some clients report that they are driven by automation software. That is a strong tell precisely because a real browser has no reason to say it.
  • Click-ID reuse. Google mints a fresh click identifier per billed click. The same one arriving from several networks means a copied or forwarded landing URL, not several real clicks.

The two gates that stop a lone signal convicting anyone

The failure mode of every naive tool is the same: one rule fires, an address gets labelled, and a real customer on a VPN ends up on a list. ClickSheriff applies two gates instead.

First, behavioural corroboration. A network fact on its own — a hosting address, a missing click ID — can never produce a finding. Something the visitor did has to agree with it.

Second, independent-type corroboration. A finding is only called strong, and only offered for review, when at least two different kinds of signal agree. Two readings of the same signal do not count as two signals. The single exception is an invisible-link trap: a link no person using a browser can see or reach, which is self-evident when followed.

Below that bar, findings are still shown — labelled suspicious when the threshold was reached by one signal type, or needs review when something fired but stayed under it. They are visible on purpose, and they are not offered as something to act on.

What the finding is worth

Every assessment stores the ruleset version that produced it, the score, and the exact signals behind it — so a conclusion can be re-read months later and understood, rather than trusted. The evidence view also lists what argues against the finding: conversions from the same address, real time spent reading, how few days it actually appeared on.

Read both halves before you decide anything. That is not a disclaimer; it is the intended way to use the tool.

Questions

Straight answers.

Can a single signal ever produce a finding?

No, with one exception. Two different signal types must agree before anything is called strong. The exception is an invisible-link trap, which only an automated client can follow, and which is therefore self-evident on its own.

Does a strong finding mean someone committed fraud?

No. It means a pattern repeated in your measured traffic and two independent signals agreed on it. Intention cannot be observed from a web server, and no honest tool will claim otherwise.

What happens to a visitor who converted?

A conversion counts strongly against every other signal and clears the visit automatically. It also appears in the evidence view as a reason not to act, rather than being quietly dropped.

Why do I see findings the tool tells me not to act on?

Because hiding them would be worse. A single-signal match is real information; it is just not enough to justify excluding an address. Showing it, labelled honestly, lets you watch it rather than guess.

Give your paid traffic a clear baseline.

Install Free, confirm that measurement works, then let the evidence tell you whether anything needs your attention.

Install ClickSheriff Free