Spot the bots swarming your ads —
and stop them on the spot.
Retargeting’s invisible leak — re-showing ads to bots — gets stopped the moment they land. We judge by the device’s substance and behavior, not the claimed IP or browser name.
Is your ad budget paying “non-humans”?
Retargeting chases anyone who visited once and re-shows ads to them. If that first visit was a bot, you keep paying to chase the bot. Bots get smarter daily, spoofing IPs and browser names to slip past legacy defenses.
What changes once it’s in
From “leaking continuously” to “stopped on the spot.” Start by estimating your own potential leak below.
Ad budget keeps leaking to bots
- A bot’s first visit is counted as a “prospect”
- Retargeting re-shows ads chasing that bot
- Spoofed IP/browser name slips past legacy tools
- No visibility into why the waste happened
Caught on the spot, removed from targeting
- Human-or-bot judged the moment they land
- High-score bots removed from ad re-targeting
- Catches new bots that only faked the “name”
- Every flag comes with its reason
Theoretical estimate
How much could you be leaking?
Drag the sliders to estimate the upper bound of ad spend that could be wasted with no protection in place.
Estimated exposure (upper bound)
¥400,000
/ month
Per year ¥4,800,000
Estimated exposure = clicks × bot share × average CPC — a theoretical upper bound. The first bot visit is billed before it can be judged, so this is not a guaranteed saving. Actual impact varies by traffic mix and operations.
Judged by hard-to-fake “substance,” not the easy-to-fake “name”
Substance, not the name
IPs and browser names are trivial to fake. AdFraud Shield reads the device’s own characteristics, so it sees through bots that only faked the name.
Caught by behavior
It reads how human the scrolling, tapping and dwell feel — catching new bots that aren’t on any shared blocklist, right on the spot.
Shows why it flagged
A white box that discloses each verdict’s reasons. Unlike opaque legacy tools, you can explain it to agencies and clients as-is.
Cross-checked from many angles (2 are primary)
A single decisive tell, or several stacked, tips the verdict. Dodge one clue and another catches you.
Device “impersonation” checkPrimary
Sees a real-looking name but a “machine inside” — automation tools, headless browsers, server-side fake browsers.
Behavior analysisPrimary
Detects un-human motion: instant bounce, no interaction, a mechanical jump straight to the bottom.
Repeat-hit detection
The same device hitting the same page many times in a short window.
Server-origin traffic
“Vendor-like” visits coming from rented servers (data centers).
Location-spoofing check
Device clock and language that contradict a claimed “from Japan.”
Fake browsers & tools
Requests that aren’t even browsers, or empty / absurdly old “names.”
Decoys (invisible traps)
Machine-like processes that react to traps invisible to people.
Ad-click fraud detection
Visits that carry an ad click-ID yet bounce within about a second with zero interaction — the real-device click-farm pattern.
Plus 3 more (currently inactive)
Designed and implemented, but they need extra equipment at the network edge — not used in the current setup (disclosed openly).
The main line is real-time, on-the-spot protection
Works with TikTok / Meta / Yahoo! ads. It acts per device, not per IP, so it works even for TikTok traffic where many share one IP.
Judge
Flagged as a bot (and high score)
Signal
Notifies the ad measurement tag of a “fraud visit”
One-time setup
Build an exclusion list from the signal, add it to the campaign’s exclusions
Re-show stops
From then on, ads stop re-showing to that device
It only fires on “flagged AND high score,” and deliberately holds back on some to avoid false positives. Installing the tag alone won’t stop delivery — the one-time setup above is required. Pixel-based protection is also a Pro-and-above feature (Free / Starter get the detection report only).
Implemented (on standby while the customer’s ads are paused). Connect an active account and it resumes immediately.
Built to avoid sweeping up your real customers
It has exclusion logic so real readers arriving via in-app browsers (LINE / Instagram / Yahoo!) or shared mobile networks aren’t mistaken for bots by a shared IP.
An expectation derived from the ratio-guard design — not a measured value and not a guarantee. Zero false positives is impossible for any bot detector, and individual sites will vary. Because we disclose the reason for every single visit, you can verify the real number against your own data.
Avoiding false positives is the top priority. Dedicated exclusion logic protects shared lines and in-app browsers, and a guard auto-reverses any mistaken exclusion within 7 days.
Not a replacement — a complement that catches the leftovers
Legacy tools (the kind that match against a shared blocklist of previously-known bad actors) and AdFraud Shield complement each other. We catch the advanced, novel bots that pass through the existing net, with our own independent judgment.
| Dimension | AdFraud Shield | Legacy (shared-blocklist) competitor |
|---|---|---|
| When it protects | Judges on arrival → real-time suppression after one-time setupEdge | Mainly after-the-fact reports + shared-list matching |
| Catching new bots | Independent detection from on-the-spot behavior and device traits; strong against bots that rotate IPs/domainsEdge | Shared lists generally struggle to keep up when actors rotate IPs/domains often |
| Explaining a flag | Discloses each reason (white box)Edge | Detection internals are often undisclosed |
| Known-bot coverage | Small base early on; shared coverage will grow | Broad coverage from many deployments is a real strength |
Competitors’ internals and status are per each vendor’s public information; we don’t assert things we haven’t independently verified. We assume side-by-side use with your existing tools, starting from one store.
We collect “bot clues,” not people’s names
We don’t collect direct personal data like name, email, or phone. We handle only the technical clues needed to judge bots, on the site operator’s behalf, and auto-delete individual visit data after 7 days (compliant with Japan’s APPI).
Name, email, phone, purchase/payment information
Individual visit data is erased in 7 days; only aggregates are kept afterward. One exception: evidence records of invalid ad clicks (click IDs etc., IP anonymized) are kept up to 180 days for platform fraud reporting.
Notifying visitors and maintaining your own privacy policy remain the site operator’s responsibility.
Paste one line, ~5 minutes. No setup fee, no minimum term
<script async src="…adfraud-shield.min.js" data-site-id="…" data-endpoint="…"></script>Try one store first, side-by-side with your current tools?
Judged by substance and behavior, not the name. Every flag comes with its reason. Not a replacement — a complement that catches the leftovers.
Talk to us about a pilotFigures on this page are theoretical estimates; actual impact varies by traffic mix and operations. Eight signals are active in the current setup (11 are implemented in the engine; 3 are edge-dependent and inactive). We disclose value as separate figures: estimated exposure (upper bound) and confirmed protection (lower bound).