Traffic quality and fraud detection

How Ripples scores every visit, which visitors it removes from your numbers, and which it never removes.

Ripples checks every pageview for signs of automation and gives each visitor one verdict. Crawlers and proven automation are always removed. Traffic that is only suspicious stays counted until you switch on a filter. Signed-in users, paid clicks and conversion events are never removed.

How it works

Each pageview goes through the same steps on the server as it arrives:

  1. Protected visits are set aside and always counted: signed-in users, paid ad clicks, devices you marked as real, and every event that isn’t a pageview. Signed-in users and paid clicks are still scored so you can see their quality, but the score can’t remove them.
  2. If the user agent names a robot (Googlebot, GPTBot, AhrefsBot, uptime monitors, link unfurlers), the visit is a Crawler.
  3. Everything else is checked against about two dozen signals. Each signal that fires adds points to a bot score on a 0 to 100 scale.
  4. The score, and the kind of signal behind it, give the visitor a verdict: Looks human (under 20), Unusual (20 to 44), Suspect (45 to 59) or Automated (60 or more).
  5. Crawler and Automated leave your numbers. Suspect visitors and datacenter connections leave only if you switch those filters on.
  6. On Pulse, the Traffic quality section adds up the verdicts per campaign, source and channel and tells you whether that traffic looks real.

The bot score

Every pageview gets one number: the bot score, on a 0 to 100 scale. 0 means nothing was found against the browser. Each sign of automation adds points, and the total decides the verdict:

Bot scoreVerdict
0Nothing found
1 to 19Looks human
20 to 44Unusual
45 to 59Suspect
60 or moreAutomated, or Suspect if the visit looks like a person arriving

A visitor’s score is their worst pageview over the period, not an average. The same number appears everywhere the product talks about credibility: the Credibility block on a person’s page, the tooltip behind a mark in People, the “Bot score” table in the Traffic quality section of Pulse, and ripples_person over MCP. Where you see “peak” it means this: the highest score any of that visitor’s pageviews reached.

The score is a plain sum, so a pageview that stacks several proof signals can go past 100. Nothing changes above 60, so treat anything higher as “Automated, and then some”.

How the score is built

There are two kinds of signal.

Proof signals are contradictions that no real browser produces, such as a browser that claims to be Firefox while running Chrome’s engine. Each is worth 60 to 70 points. Only proof signals can make a visitor Automated.

Hints describe a setup that is unusual but can belong to a person: a VPN, a datacenter address, a clock that disagrees with the IP location. Each is worth 5 to 25 points. However many hints fire, they can’t take a visitor past Suspect.

Proof signalPoints
Chromium engine under a Firefox user agent70
Reported browser contradicts the request headers70
Chromium runtime with a blanked user agent70
Browser automation framework detected70
Chromium-only APIs under a Firefox user agent65
Claims Firefox but is missing Firefox internals60
Remote-controlled browser (WebDriver)60
HintPoints
One device presenting as many visitors (see fleets)25
Connecting from a datacenter20
Device clock doesn’t match the IP location20
No real graphics hardware20
Window has no browser interface (desktop)15
Default automation window size, 1280 × 72015
No mouse, scroll or keyboard activity in the first seconds15
Connecting through a VPN, proxy or Tor15
No desktop or taskbar around the window (desktop)10
No browser plugins (desktop)10
Language headers are inconsistent10
Missing standard browser request headers10
Mouse movement looks synthesized10
Only one language configured5
Two CPU cores or fewer (desktop)5

A desktop with no browser interface and no taskbar gets 20 extra points on top of those two hints, because together they describe a headless browser in a virtual screen. That puts it at 45, which is Suspect.

Three rules sit on top of the points:

  • The score is a plain sum, and a visitor is judged by their worst pageview, not an average.
  • A visit that looks like a person arriving is capped at Suspect. If it has a referrer or UTM tags, is the second page of a session, or moved the mouse, even a proof signal makes it Suspect instead of Automated. A referrer takes one line of code to fake, so the visit is still flagged.
  • The tracker reports raw facts about the browser and never scores itself. Weights and thresholds live on the server, and the server overwrites the verdict fields on every event, so a client can’t send in its own verdict.

Residential proxy fleets

A scraper that rents residential proxies can show thousands of IP addresses in dozens of countries, but it usually runs one browser build. Ripples hashes what a proxy can’t change: engine and version, OS, screen and window size, language, timezone and the browser’s reported environment.

A build is flagged as a fleet when, within two hours, all of these hold:

  • it appears as 50 or more visitors,
  • from 5 or more countries,
  • almost none of them (under 1%) continue to a second page,
  • and 90% or more have a clock that disagrees with their IP location.

Every visitor on that build then gets the “One device presenting as many visitors” hint for the next 24 hours. Most of them also carry the clock mismatch, which brings them to 45 points: Suspect.

Networks

Whether an address is a datacenter comes from public registry data about which organisation owns it. VPN, proxy and Tor exits come from public range lists. Ripples buys no reputation scores and keeps no list of “bad” IPs. iCloud Private Relay and Cloudflare WARP are never flagged as either.

Verdicts

VerdictHow a visitor gets itCounted?
Looks humanScore under 20Yes
Unusual20 to 44, from hints only. Travellers on a corporate VPN, virtual desktops, privacy browsers. Mostly people.Yes, and it can’t be filtered
Suspect45 or more from hints, or a proof signal on a capped visitYes, unless the Suspect filter is on
AutomatedA proof signal on a visit that isn’t capped, so always 60 or moreNo, always removed
CrawlerThe user agent names a robotNo, always removed

Unusual can’t be filtered because removing it would remove real people. Anything that rests on statistics alone stops at Suspect and stays counted until you choose otherwise.

Who is never removed

These visits are never removed by any filter, including the ones that are always on:

VisitWhy
Signed-in usersOnce someone identifies, their later visits stay, whatever their network looks like. Scrapers don’t log in.
Paid clicksAny visit carrying gclid, gbraid, wbraid, dclid, gad_source, fbclid, ttclid, msclkid, twclid, rdt_cid, li_fat_id, mc_cid or irclid. Your payback numbers include every click you paid for.
Signups, custom events, revenueOnly pageviews are judged. identify, track and revenue events are never classified, so those counts are exactly what your app sent.
Server SDK eventsNever classified.
Devices you marked as realSee the FAQ.

Signed-in users and paid clicks are still scored in the background. Their findings appear on the person’s page and in the Traffic quality section, so a campaign full of automated clicks shows up as bad quality instead of disappearing from your reports.

Marks in People

Most visitors carry no mark. When one does, hover it to see the findings in plain words, for example “Device clock doesn’t match the IP location” or “Remote-controlled browser”.

MarkMeaningCounted?
Looks automatedSuspect, and at least one finding describes a scripted or headless browserYes, unless the Suspect filter is on
SuspectSuspect from network, clock and similar hints, which a traveller on a corporate network can also produceYes, unless the Suspect filter is on
Datacenter connectionConnected from a hosting or cloud network. Nothing else looked automated.Yes, unless the Datacenter filter is on
VPN or proxyConnected through a VPN, proxy or Tor exit. Nothing else looked automated.Yes, always

A signed-in user never shows the first two marks. The network marks still show, because they’re facts about the connection.

A person page for an anonymous visitor marked Looks automated, on Chrome on a Linux desktop. The session lists eight pageviews, most with a robot icon, and a session score of 75. One pageview is open on the right: its Credibility block shows score 55, verdict Suspect, and two findings: No browser window and no desktop around it, and No browser plugins.
A person's page. Click any pageview to see its score, its verdict and the findings behind them. Here a headless window with no plugins adds up to 55 points: Suspect, and marked Looks automated because the tells describe a machine.

Filters

Filters are in Settings, Traffic filtering. Each switch shows its cost: how many visitors it would have removed in the last 30 days.

Settings, Traffic filtering. Known crawlers and Automated browsers are locked on and removed 38 and 13 visitors. Suspect visitors and Datacenter connections are off and would remove 121 visitors (2.7%) and 249 visitors (5.5%). A note says impact is measured over the last 30 days as a share of 4,522 judged visitors, and that one visitor can match both filters.
The two optional filters show what they would remove before you switch them on.
FilterRemovesAlso catchesDefault
Known crawlersRobots that name themselvesAn internal monitor, or a corporate proxy that rewrites the user agent to look like a robotAlways on
Automated browsersThe Automated verdictA first-party desktop app with a fully custom user agentAlways on
Suspect visitorsThe Suspect verdictTravellers on corporate networks, cloud desktops, kiosks, privacy browsers. About 5% of a normal audience.Off
Datacenter connectionsAddresses owned by a hosting or cloud networkCloud security proxies (Zscaler, Netskope), cloud desktops, VPNs that exit inside AWS or GCPOff

How filters behave:

  • A filter applies to new traffic from the moment you save it. Past data isn’t rewritten in either direction.
  • Protected visits are never removed, whatever the switch says.
  • A removed visit isn’t deleted. It stays in Recently removed for 30 days with its verdict and findings, so you can check the classifier’s work.
The Recently removed list with one Automated row opened. Its findings are Remote-controlled browser (WebDriver), No browser window and no desktop around it, Window has no browser interface, No desktop or taskbar, No browser plugins, and Missing standard browser request headers. The details show the network, a Chrome 99 on Windows user agent, a 1600 by 1600 screen, no referrer and a score of 125, above a This is a real visitor button.
Recently removed, with one visit opened. Every removal shows its findings, network, device and score, and the button that marks the device as real. IP addresses in this screenshot are replaced with documentation addresses.

The Traffic quality section

The section sits at the bottom of Pulse. For the whole project it shows:

  • one read, with the share of visitors removed and the share counted but flagged;
  • the period’s visitors in bands: Looks human, Unusual, Suspect, Automated and Crawlers. Outlined bands are counted, filled bands were removed;
  • with a campaign, source or channel selected, a Bot score table: the slice’s visitors by their worst pageview’s score (0, 1 to 19, 20 to 44, 45 to 59, 60 or more) next to everyone else. “Automated, kept” is the 60-or-more row: browsers that stayed counted because they arrived from a link or a campaign, on a paid click, or signed in;
  • a Quality by table that lists your campaigns, sources or channels, each with its own read;
  • Findings in counted traffic: which findings fired most among the visitors who stayed in your numbers.
The Traffic quality section for the last 30 days, 4,353 visitors. The read says Your visitors look like real people: 1.1% removed, 12% counted but flagged. A band bar shows 86.4% Looks human, 9.8% Unusual, 2.6% Suspect, 0.3% Automated and 0.9% Crawlers. Below it, a Quality by Source table: Google Search reads Clean, Direct and a partner site read Mixed, and Ad network A reads Low with 62% bounced and 0% signed up. Sources under 50 visitors read Too early.
Quality by source on a real project, with names changed. Search traffic reads Clean. Ad network A reads Low: its visitors pass the bot checks, but 62% bounce and none sign up.

Click a row, or filter Pulse to a campaign, source or channel, and the section compares that slice with everyone else. You get the read with up to three supporting facts, the slice’s peak scores next to the rest of your traffic, and a table comparing bounce, pages per visit, signups, activation, payments and network mix.

Traffic quality filtered to Ad network A, 980 visitors in 30 days. The read says Most of these visitors are not worth paying for, with the facts 62% bounced after one page (everyone else: 22%) and 0 of 980 signed up (everyone else: 20%). 95.5% of the slice Looks human. The peak-score table shows the slice close to everyone else. The comparison table shows 1.5 pages per visit against 5.7, and 0% signed up and 0% paid against 19.6% and 2.4%.
The same ad network, clicked. 95% of its visitors look human to the classifier, so nothing is removed. The comparison with the rest of the project is what gives it away: one and a half pages per visit, and 0 signups out of 980.
ReadWhat it saysTriggered by any of
Clean“Your visitors look like real people.” With a filter on: “These visitors behave like the rest of your traffic.”None of the triggers below
Mixed“These visitors are mixed. Some of them are real.”5% or more suspect or removed; bounce rate 10+ points above the rest; 15% or more Unusual
Low“Most of these visitors are not worth paying for.”15% or more suspect or removed; 20% or more with a peak score of 45+; 20 or more visitors per device build (at 100+ visitors); bounce 25+ points above the rest with half the signup rate or less; 30% or more from datacenters, VPNs or mismatched clocks, with 25% or more Unusual
Junk“These visitors look automated or bought.”40% or more suspect or removed; 40% or more with a peak score of 45+; bounce 30+ points above the rest with zero signups from 200+ visitors, coming mostly from datacenters, VPNs or a few device builds

A slice or a table row with fewer than 50 measured visitors gets no read. It shows “Too early” instead.

Filters decide what is in your numbers. The Traffic quality section only describes it and has no controls. Switching a filter moves visitors between bands, so it can't make a campaign look better.

Where to find it

PlaceWhat you get
PulseThe Traffic quality section, per period and per filter
PeopleThe mark beside a name, with findings on hover
A person’s pageVerdict, bot score and findings, for the person and for each pageview
Settings, Traffic filteringThe filters with their 30-day cost, and Recently removed
MCPripples_overview carries the quality payload, ripples_person the per-pageview verdict, score and findings, and ripples_configure sets the filters

What Ripples doesn’t do

  • Block traffic. Ripples observes visits. It doesn’t sit in front of your site and can’t refuse a request.
  • Dispute clicks or claim refunds. It gives you the evidence for that conversation with an ad network.
  • Use third-party reputation scores, or canvas or audio fingerprinting.
  • Remove people for privacy choices. VPN, proxy and Tor are findings you can see, never a filter.
  • Catch paid humans. People paid to click are real people to a classifier. The bounce and signup comparison is how you spot them: they leave after one page and never sign up.

FAQ

My ad campaign looks like bots. Why are those clicks still counted?

Paid clicks are never removed, so your spend and payback maths covers every click you paid for. They are still scored. Filter Pulse to the campaign: a Low or Junk read, with its supporting facts, tells you what you bought.

How do I show an ad network that its traffic was fake?

Filter Pulse to the campaign and take the read and its facts: share suspect or removed, bounce and signup gap against the rest, visitors per device build. Then open a few of that campaign’s visitors in People. Each person’s page lists the findings for every visit, in plain words.

Will people on a VPN or a corporate network be removed?

Not by default. A VPN, a datacenter address and a mismatched clock are all hints. Together they usually land in Unusual, sometimes Suspect, and both are counted. They’re removed only if you switch on the Suspect or Datacenter filter.

Can bots inflate my signups or revenue?

Ripples never removes identify, track or revenue events, so those counts are exactly what your app sent. If a bot submits your signup form, that signup is counted, because Ripples only judges pageviews. The Traffic quality read will still show a campaign whose visitors look automated.

I switched on the Suspect filter. Why didn’t last month change?

Filters apply to new traffic from the moment you save them. Past data isn’t rewritten in either direction.

A colleague or our own uptime monitor keeps getting removed. How do I fix it?

Go to Settings, Traffic filtering, Recently removed. Find the visit and choose “This is a real visitor”. That device build is counted from then on, including for the always-on filters.

Why is there no score slider or “count everything” switch?

Turning the always-on filters off would only add back crawlers and proven automation, which nobody wants counted. A slider means tuning a model you can’t see. If Ripples is wrong about a specific device, mark it as real.

Are Googlebot and AI crawlers counted anywhere?

They’re removed from your visitor numbers and shown in the Crawler band of the Traffic quality section, so you can see how much crawling your site gets.

Can I see the raw score for a visitor?

Yes. The Credibility block on a person’s page shows their bot score (the worst pageview) and the findings behind it, and each pageview in the session timeline shows its own. ripples_person returns the same over MCP.