Traffic quality and fraud detection
How Ripples scores every visit, which visitors it removes from your numbers, and which it never removes.
Ripples checks every pageview for signs of automation and gives each visitor one verdict. Crawlers and proven automation are always removed. Traffic that is only suspicious stays counted until you switch on a filter. Signed-in users, paid clicks and conversion events are never removed.
How it works
Each pageview goes through the same steps on the server as it arrives:
- Protected visits are set aside and always counted: signed-in users, paid ad clicks, devices you marked as real, and every event that isn’t a pageview. Signed-in users and paid clicks are still scored so you can see their quality, but the score can’t remove them.
- If the user agent names a robot (Googlebot, GPTBot, AhrefsBot, uptime monitors, link unfurlers), the visit is a Crawler.
- Everything else is checked against about two dozen signals. Each signal that fires adds points to a bot score on a 0 to 100 scale.
- The score, and the kind of signal behind it, give the visitor a verdict: Looks human (under 20), Unusual (20 to 44), Suspect (45 to 59) or Automated (60 or more).
- Crawler and Automated leave your numbers. Suspect visitors and datacenter connections leave only if you switch those filters on.
- On Pulse, the Traffic quality section adds up the verdicts per campaign, source and channel and tells you whether that traffic looks real.
The bot score
Every pageview gets one number: the bot score, on a 0 to 100 scale. 0 means nothing was found against the browser. Each sign of automation adds points, and the total decides the verdict:
| Bot score | Verdict |
|---|---|
| 0 | Nothing found |
| 1 to 19 | Looks human |
| 20 to 44 | Unusual |
| 45 to 59 | Suspect |
| 60 or more | Automated, or Suspect if the visit looks like a person arriving |
A visitor’s score is their worst pageview over the period, not an average. The same number appears everywhere the product talks about credibility: the Credibility block on a person’s page, the tooltip behind a mark in People, the “Bot score” table in the Traffic quality section of Pulse, and ripples_person over MCP. Where you see “peak” it means this: the highest score any of that visitor’s pageviews reached.
The score is a plain sum, so a pageview that stacks several proof signals can go past 100. Nothing changes above 60, so treat anything higher as “Automated, and then some”.
How the score is built
There are two kinds of signal.
Proof signals are contradictions that no real browser produces, such as a browser that claims to be Firefox while running Chrome’s engine. Each is worth 60 to 70 points. Only proof signals can make a visitor Automated.
Hints describe a setup that is unusual but can belong to a person: a VPN, a datacenter address, a clock that disagrees with the IP location. Each is worth 5 to 25 points. However many hints fire, they can’t take a visitor past Suspect.
| Proof signal | Points |
|---|---|
| Chromium engine under a Firefox user agent | 70 |
| Reported browser contradicts the request headers | 70 |
| Chromium runtime with a blanked user agent | 70 |
| Browser automation framework detected | 70 |
| Chromium-only APIs under a Firefox user agent | 65 |
| Claims Firefox but is missing Firefox internals | 60 |
| Remote-controlled browser (WebDriver) | 60 |
| Hint | Points |
|---|---|
| One device presenting as many visitors (see fleets) | 25 |
| Connecting from a datacenter | 20 |
| Device clock doesn’t match the IP location | 20 |
| No real graphics hardware | 20 |
| Window has no browser interface (desktop) | 15 |
| Default automation window size, 1280 × 720 | 15 |
| No mouse, scroll or keyboard activity in the first seconds | 15 |
| Connecting through a VPN, proxy or Tor | 15 |
| No desktop or taskbar around the window (desktop) | 10 |
| No browser plugins (desktop) | 10 |
| Language headers are inconsistent | 10 |
| Missing standard browser request headers | 10 |
| Mouse movement looks synthesized | 10 |
| Only one language configured | 5 |
| Two CPU cores or fewer (desktop) | 5 |
A desktop with no browser interface and no taskbar gets 20 extra points on top of those two hints, because together they describe a headless browser in a virtual screen. That puts it at 45, which is Suspect.
Three rules sit on top of the points:
- The score is a plain sum, and a visitor is judged by their worst pageview, not an average.
- A visit that looks like a person arriving is capped at Suspect. If it has a referrer or UTM tags, is the second page of a session, or moved the mouse, even a proof signal makes it Suspect instead of Automated. A referrer takes one line of code to fake, so the visit is still flagged.
- The tracker reports raw facts about the browser and never scores itself. Weights and thresholds live on the server, and the server overwrites the verdict fields on every event, so a client can’t send in its own verdict.
Residential proxy fleets
A scraper that rents residential proxies can show thousands of IP addresses in dozens of countries, but it usually runs one browser build. Ripples hashes what a proxy can’t change: engine and version, OS, screen and window size, language, timezone and the browser’s reported environment.
A build is flagged as a fleet when, within two hours, all of these hold:
- it appears as 50 or more visitors,
- from 5 or more countries,
- almost none of them (under 1%) continue to a second page,
- and 90% or more have a clock that disagrees with their IP location.
Every visitor on that build then gets the “One device presenting as many visitors” hint for the next 24 hours. Most of them also carry the clock mismatch, which brings them to 45 points: Suspect.
Networks
Whether an address is a datacenter comes from public registry data about which organisation owns it. VPN, proxy and Tor exits come from public range lists. Ripples buys no reputation scores and keeps no list of “bad” IPs. iCloud Private Relay and Cloudflare WARP are never flagged as either.
Verdicts
| Verdict | How a visitor gets it | Counted? |
|---|---|---|
| Looks human | Score under 20 | Yes |
| Unusual | 20 to 44, from hints only. Travellers on a corporate VPN, virtual desktops, privacy browsers. Mostly people. | Yes, and it can’t be filtered |
| Suspect | 45 or more from hints, or a proof signal on a capped visit | Yes, unless the Suspect filter is on |
| Automated | A proof signal on a visit that isn’t capped, so always 60 or more | No, always removed |
| Crawler | The user agent names a robot | No, always removed |
Unusual can’t be filtered because removing it would remove real people. Anything that rests on statistics alone stops at Suspect and stays counted until you choose otherwise.
Who is never removed
These visits are never removed by any filter, including the ones that are always on:
| Visit | Why |
|---|---|
| Signed-in users | Once someone identifies, their later visits stay, whatever their network looks like. Scrapers don’t log in. |
| Paid clicks | Any visit carrying gclid, gbraid, wbraid, dclid, gad_source, fbclid, ttclid, msclkid, twclid, rdt_cid, li_fat_id, mc_cid or irclid. Your payback numbers include every click you paid for. |
| Signups, custom events, revenue | Only pageviews are judged. identify, track and revenue events are never classified, so those counts are exactly what your app sent. |
| Server SDK events | Never classified. |
| Devices you marked as real | See the FAQ. |
Signed-in users and paid clicks are still scored in the background. Their findings appear on the person’s page and in the Traffic quality section, so a campaign full of automated clicks shows up as bad quality instead of disappearing from your reports.
Marks in People
Most visitors carry no mark. When one does, hover it to see the findings in plain words, for example “Device clock doesn’t match the IP location” or “Remote-controlled browser”.
| Mark | Meaning | Counted? |
|---|---|---|
| Looks automated | Suspect, and at least one finding describes a scripted or headless browser | Yes, unless the Suspect filter is on |
| Suspect | Suspect from network, clock and similar hints, which a traveller on a corporate network can also produce | Yes, unless the Suspect filter is on |
| Datacenter connection | Connected from a hosting or cloud network. Nothing else looked automated. | Yes, unless the Datacenter filter is on |
| VPN or proxy | Connected through a VPN, proxy or Tor exit. Nothing else looked automated. | Yes, always |
A signed-in user never shows the first two marks. The network marks still show, because they’re facts about the connection.
Filters
Filters are in Settings, Traffic filtering. Each switch shows its cost: how many visitors it would have removed in the last 30 days.
| Filter | Removes | Also catches | Default |
|---|---|---|---|
| Known crawlers | Robots that name themselves | An internal monitor, or a corporate proxy that rewrites the user agent to look like a robot | Always on |
| Automated browsers | The Automated verdict | A first-party desktop app with a fully custom user agent | Always on |
| Suspect visitors | The Suspect verdict | Travellers on corporate networks, cloud desktops, kiosks, privacy browsers. About 5% of a normal audience. | Off |
| Datacenter connections | Addresses owned by a hosting or cloud network | Cloud security proxies (Zscaler, Netskope), cloud desktops, VPNs that exit inside AWS or GCP | Off |
How filters behave:
- A filter applies to new traffic from the moment you save it. Past data isn’t rewritten in either direction.
- Protected visits are never removed, whatever the switch says.
- A removed visit isn’t deleted. It stays in Recently removed for 30 days with its verdict and findings, so you can check the classifier’s work.
The Traffic quality section
The section sits at the bottom of Pulse. For the whole project it shows:
- one read, with the share of visitors removed and the share counted but flagged;
- the period’s visitors in bands: Looks human, Unusual, Suspect, Automated and Crawlers. Outlined bands are counted, filled bands were removed;
- with a campaign, source or channel selected, a Bot score table: the slice’s visitors by their worst pageview’s score (0, 1 to 19, 20 to 44, 45 to 59, 60 or more) next to everyone else. “Automated, kept” is the 60-or-more row: browsers that stayed counted because they arrived from a link or a campaign, on a paid click, or signed in;
- a Quality by table that lists your campaigns, sources or channels, each with its own read;
- Findings in counted traffic: which findings fired most among the visitors who stayed in your numbers.
Click a row, or filter Pulse to a campaign, source or channel, and the section compares that slice with everyone else. You get the read with up to three supporting facts, the slice’s peak scores next to the rest of your traffic, and a table comparing bounce, pages per visit, signups, activation, payments and network mix.
| Read | What it says | Triggered by any of |
|---|---|---|
| Clean | “Your visitors look like real people.” With a filter on: “These visitors behave like the rest of your traffic.” | None of the triggers below |
| Mixed | “These visitors are mixed. Some of them are real.” | 5% or more suspect or removed; bounce rate 10+ points above the rest; 15% or more Unusual |
| Low | “Most of these visitors are not worth paying for.” | 15% or more suspect or removed; 20% or more with a peak score of 45+; 20 or more visitors per device build (at 100+ visitors); bounce 25+ points above the rest with half the signup rate or less; 30% or more from datacenters, VPNs or mismatched clocks, with 25% or more Unusual |
| Junk | “These visitors look automated or bought.” | 40% or more suspect or removed; 40% or more with a peak score of 45+; bounce 30+ points above the rest with zero signups from 200+ visitors, coming mostly from datacenters, VPNs or a few device builds |
A slice or a table row with fewer than 50 measured visitors gets no read. It shows “Too early” instead.
Filters decide what is in your numbers. The Traffic quality section only describes it and has no controls. Switching a filter moves visitors between bands, so it can't make a campaign look better.
Where to find it
| Place | What you get |
|---|---|
| Pulse | The Traffic quality section, per period and per filter |
| People | The mark beside a name, with findings on hover |
| A person’s page | Verdict, bot score and findings, for the person and for each pageview |
| Settings, Traffic filtering | The filters with their 30-day cost, and Recently removed |
| MCP | ripples_overview carries the quality payload, ripples_person the per-pageview verdict, score and findings, and ripples_configure sets the filters |
What Ripples doesn’t do
- Block traffic. Ripples observes visits. It doesn’t sit in front of your site and can’t refuse a request.
- Dispute clicks or claim refunds. It gives you the evidence for that conversation with an ad network.
- Use third-party reputation scores, or canvas or audio fingerprinting.
- Remove people for privacy choices. VPN, proxy and Tor are findings you can see, never a filter.
- Catch paid humans. People paid to click are real people to a classifier. The bounce and signup comparison is how you spot them: they leave after one page and never sign up.
FAQ
My ad campaign looks like bots. Why are those clicks still counted?
Paid clicks are never removed, so your spend and payback maths covers every click you paid for. They are still scored. Filter Pulse to the campaign: a Low or Junk read, with its supporting facts, tells you what you bought.
How do I show an ad network that its traffic was fake?
Filter Pulse to the campaign and take the read and its facts: share suspect or removed, bounce and signup gap against the rest, visitors per device build. Then open a few of that campaign’s visitors in People. Each person’s page lists the findings for every visit, in plain words.
Will people on a VPN or a corporate network be removed?
Not by default. A VPN, a datacenter address and a mismatched clock are all hints. Together they usually land in Unusual, sometimes Suspect, and both are counted. They’re removed only if you switch on the Suspect or Datacenter filter.
Can bots inflate my signups or revenue?
Ripples never removes identify, track or revenue events, so those counts are exactly what your app sent. If a bot submits your signup form, that signup is counted, because Ripples only judges pageviews. The Traffic quality read will still show a campaign whose visitors look automated.
I switched on the Suspect filter. Why didn’t last month change?
Filters apply to new traffic from the moment you save them. Past data isn’t rewritten in either direction.
A colleague or our own uptime monitor keeps getting removed. How do I fix it?
Go to Settings, Traffic filtering, Recently removed. Find the visit and choose “This is a real visitor”. That device build is counted from then on, including for the always-on filters.
Why is there no score slider or “count everything” switch?
Turning the always-on filters off would only add back crawlers and proven automation, which nobody wants counted. A slider means tuning a model you can’t see. If Ripples is wrong about a specific device, mark it as real.
Are Googlebot and AI crawlers counted anywhere?
They’re removed from your visitor numbers and shown in the Crawler band of the Traffic quality section, so you can see how much crawling your site gets.
Can I see the raw score for a visitor?
Yes. The Credibility block on a person’s page shows their bot score (the worst pageview) and the findings behind it, and each pageview in the session timeline shows its own. ripples_person returns the same over MCP.