For any organization running an online advertising campaign, invalid traffic (IVT) from bots is a massive and growing problem. To put a dent in the ad fraud caused by bots, bot detection is vital. After all, how can you stop bots if you can't detect them in the first place? A dedicated ad fraud solution is still your best tool for catching bots and stopping fraud before it drains your marketing budget. But not all solutions are equal, especially now that AI-driven bots and residential proxies have made single-signal detection far less reliable than it used to be. Some vendors claim certifications (like TAG certification, which can be looked up on TAG’s Website) they don't hold; others claim one "airtight" detection metric can catch everything, which isn't realistic against modern SIVT. Before committing to a vendor: Bot traffic isn't slowing down. If anything, AI has made it more voluminous and harder to spot with the naive methods that worked a few years ago. Marketers who update their detection playbook to account for AI-generated bots, AI agents, and proxy-based evasion will be far better positioned than those still relying on homegrown solutions or click protection alone. Before you can stem the tide of bots targeting your marketing efforts, it helps to understand what bots are, how they've evolved, and how to detect them, including the new generation of AI-powered bots reshaping the landscape. A "bot" is an automated software program designed to carry out a specific task that are increasingly taking the majority of internet traffic. According to the 2026 Thales Bad Bot Report, bots accounted for 53% of all global web traffic in 2025, with bad bots making up 40% of that total and good bots the remaining 13%. That means automated traffic has now outpaced human traffic for two consecutive years, while malicious bot activity alone has grown for seven years running. Bots generally fall into two categories: "good" bots and "bad" bots. What separates the two? A "good" bot performs benign, useful tasks. For example, a web browser might save a user's address information when they fill out an online form, then autofill it the next time, saving the user from typing it out manually. Search engine crawlers and uptime monitors are also classic "good" bots. A "bad" bot may do something similar on the surface but for nefarious purposes. For example, a bad bot might pull from a table of real consumers' stolen address information and use it to fill out online forms posing as a real visitor. The old good-bot/bad-bot binary no longer fully captures what's hitting your website. AI agents have emerged as a third category of automated traffic systems that interact directly with applications and APIs on a person's behalf. These agents retrieve information or complete tasks, like AI shopping assistants or research agents. The problem for marketers is it's often genuinely difficult to tell whether an AI agent's traffic is legitimate (a real user delegating a task) or malicious, since both types of automation move through the same channels, workflows, and infrastructure. Bots are generally classified as "invalid traffic" by marketers, since they're not valid targets for converting leads into customers. Invalid traffic can be further divided into two categories based on sophistication: If there's one thing that's changed the bot landscape since the early 2020s, it's generative AI on both sides of the fight. Generative AI has lowered the barrier to entry for building bots, letting less-skilled attackers launch more attacks, more often. It's also let more sophisticated attackers use AI to analyze failed attempts and refine their evasion tactics automatically, feeding a growing "Bots-as-a-Service" (BaaS) marketplace where anyone can rent access to pre-built, AI-hardened bot infrastructure. This shows up in the numbers: AI-enabled bot attacks surged roughly 12.5x year-over-year in the most recent reporting period, with the daily average of blocked attacks climbing from around 2 million to 25 million. In practice, that means the "spot the sloppy bot" methods marketers relied on obviously fake email formats. Robotic click timing, generic user agents are far less reliable today. Modern bot operators increasingly route traffic through residential proxies — real consumer IP addresses tied to home internet connections — to make bot traffic look like it's coming from an ordinary household user. Because residential IPs are typically viewed as trustworthy, this technique makes bots meaningfully harder to flag with IP-based rules alone, and it's now a standard evasion tactic rather than an edge case. A botnet is a massive collection of bots that can run on devices infected with malware that lets a bot controller remotely hijack a slice of each device's processing power. Botnets can also be a collection of phones in a rack run from a desktop. Botnets are used for all kinds of malicious activity: ad fraud, DDoS attacks, and self-propagation by infecting any networks or devices connected to an already-compromised machine. There are many varieties of bots used in modern ad fraud schemes, and the warning signs vary from one type to the next. Here's a rundown of the major categories, what they're used for, and early indicators to watch for. These bots are built to fill out online forms on behalf of their controller, recognizing form fields and populating them automatically. Two common examples: Spam bots repeatedly post the same (or similar) messages across websites and social platforms, sometimes used to spread negative reviews or fake stories about a business that real humans may eventually pick up and amplify. Left unchecked, this can do lasting damage to a brand's reputation. These bots manage social media accounts on someone else's behalf, whether by standing up new fake accounts or hijacking existing ones. Common applications include: Backlinks (links to your site from other sites) are an important ranking signal — but bad backlinks from spammy sites can actively hurt your search ranking. Bot programs can automate the process of flooding low-quality sites with links to a target's domain, either to blackmail a company ("pay up or we tank your rankings") or to sabotage a competitor. Regularly auditing your backlink profile and using Google's disavow tool remains a solid defense. These bots repeatedly load pages containing your ads to rack up fraudulent impressions, forcing you to pay for traffic that was never seen by a real person. More sophisticated versions use device spoofing between refreshes to simulate a variety of "viewers"; simpler ones just refresh as fast as possible. Click bots go a step further than impression bots, generating fraudulent clicks to drain pay-per-click budgets. They don't need to be sophisticated to work, though some fraudsters pair them with device spoofing to make the fraud less obvious. So how do you know if bots are targeting your campaigns or otherwise damaging your business? Here's where to start. Malicious bot activity tends to produce a few telltale oddities in your traffic or campaign results: Honeypot fields, form fields hidden from human view in the page's code but still readable by bots, remain a useful (if imperfect) tool for catching form bots. Because bots read the underlying code rather than the rendered page, they'll often fill in fields a human never sees. A submission that completes the honeypot field is a strong signal it's fake. If a lot of these trace back to one affiliate partner, that's a red flag worth acting on. However, AI-assisted form bots are increasingly built to interact only with the fields a human would actually see, which reduces (but doesn't eliminate) how reliable honeypots are as a standalone defense. The National Do-Not-Call (DNC) Registry lists people who've opted out of unwanted marketing communications. A high number of leads matching the DNC list can indicate bots are populating your forms with stolen consumer data. Regularly checking the registry helps catch lead gen fraud and supports TCPA compliance. Sending a verification email with a confirmation link helps ensure new leads are real people, not bots. Sophisticated fraudsters may control fake inboxes that click the link, but many still use real consumers' stolen email addresses, and those real owners typically won't click a verification email they didn't request. This adds friction, which can cost you some genuine leads who don't want the extra step. But it also gives you a documented opt-in, which is useful for demonstrating TCPA compliance. Bot traffic increasingly targets APIs directly rather than the visible parts of your website. API-directed attacks now account for a large and growing share of advanced bot activity. If your lead gen forms, pricing tools, or account systems expose an API, treat it as a bot attack surface, not just the front-end form. Protect yourself from malicious bots today by talking to one of our experts.
What Is a Bot?
Good Bot
Bad Bot
A New Category: AI Agents
What Is Invalid Traffic and How Does It Relate to Bots?
The AI Factor
Evasion Has Gotten Harder to Catch, Too
What About Botnets?
Types of Bots and Their Impacts
1. Form Bots
2. Spam Bots
3. Social Media Account Bots
4. Backlink Bots
5. Impression Bots / Page Refresher Bots
6. Click Bots
Bot Detection Basics
Watch for the Warning Signs
Use Honeypot Form Fields
Periodically Check the National Do-Not-Call Registry
Use Verification Emails to Confirm New Leads
Watch for API-Targeted Attacks

1 week ago
45






