The Invalid Traffic Dilemma: Filter It Before the Bid, or Catch It After?

Not every bot is fraudulent. Not every human impression is valuable. Here’s what invalid traffic actually means.

Happy Das
By
Happy Das
Content Editor
If you’ve ever wondered who’s quietly obsessing over the weird, slightly uncomfortable dance between automation and actual human attention in adtech, that’s basically Happy Das. She’s...
- Content Editor
28 Min Read

On the surface, ‘invalid traffic’ feels like one of those ad tech concepts you could explain to your grandma in under a minute.

Ad goes to a human? Valid traffic. And when an ad goes to a bot, it is invalid traffic. Sprinkle in some fraud detection, sweep out the bots, and voilà—everyone gets to pat themselves on the back for building a beautifully accountable advertising ecosystem. Easy, right?

Except, um, basically none of that is true.

A search engine crawler can rack up invalid traffic without even trying to be sneaky. A real person can generate invalid traffic just by getting paid to click around. You can have a technically valid impression show up on some dreadful made-for-advertising (MFA) site and deliver approximately zero value to anyone. 

And then there are the bots rolling in with real residential IPs, real browsers, moving their little mouse cursors, scrolling, acting more engaged with your ad than I have ever been with any ad in my entire life.

So, no, ‘invalid traffic’ (or IVT, if you want to sound like you’re in the club) is not just a fancy way to say ‘bots.’ It’s the industry’s attempt to answer a much messier, more consequential question:

Should this activity be included in the numbers used to charge an advertiser, pay a publisher, or optimize a campaign?

And, as you might have guessed, that question is way harder to answer than anyone wants to admit. So let’s start with the basics, then follow an impression as it stumbles through the programmatic supply chain, collecting all sorts of invalidity along the way.

What Is Invalid Traffic?

The Media Rating Council has this very official-sounding definition of invalid traffic: basically, any traffic or media activity that doesn’t meet certain quality standards or just isn’t real enough to count. If it feels a bit vague, that’s because it is.

That wording matters enough. IVT can mess with impressions, clicks, engagement, viewability, installs, and conversions. Sometimes it’s malicious; sometimes it’s just someone with clumsy fingers; sometimes it’s a browser doing its own thing. The point is these events shouldn’t count in your ad measurement, period.

Google, in its infinite wisdom, tries to make it sound simpler: IVT is clicks and impressions that don’t come from actual human interest—think fraud, accidents, or the classic double-click. Supposedly, Google filters this stuff out before you get billed (where possible), and if they catch it later, you might get a credit.

Here are a few events that can qualify as IVT:

  • A known search crawler loads a page containing ads.
  • A browser preloads a page that the user never visits.
  • A person accidentally double-clicks an ad.
  • A publisher repeatedly refreshes an ad placement to inflate impressions.
  • Malware secretly generates ad requests from a real consumer device.
  • A seller disguises a junk streaming app as premium CTV inventory.
  • A group of real humans is paid to click ads and manufacture conversions.

Only some of these are what you’d call ad fraud. But all of them make your measurement data a little bit worse, every single time.

AspectInvalid traffic (IVT)Ad fraudLow-value advertising traffic
MeaningAd impressions, clicks, or other interactions that do not represent genuine user interest or valid advertising activity.Deliberate manipulation of advertising systems to generate revenue, steal budgets, or falsify performance.Traffic that provides little commercial value because users are unlikely to engage, convert, or deliver meaningful outcomes.
IntentMay be intentional or unintentional.Always intentional and deceptive.Usually not intentionally deceptive, the traffic may simply be poorly targeted, disengaged, or commercially irrelevant.
Traffic validityConsidered invalid for advertising measurement or billing.Considered invalid and fraudulent.Can be technically valid human traffic, although IVT or fraud may also contribute to it.
Human involvementCan include bots, automated tools, accidental clicks, duplicate clicks, or unusual human behaviour.Often involves bots, device farms, malware, domain spoofing, click injection, or coordinated human activity.Usually involves real users who have weak intent, low engagement, poor relevance, or little purchasing potential.
Common examplesSearch-engine crawlers, accidental mobile clicks, duplicate impressions, data-centre traffic, or non-malicious bots.Bot-generated clicks, fake app installs, ad stacking, pixel stuffing, click farms, domain spoofing, and device spoofing.Visitors from irrelevant regions, misleading traffic sources, users who immediately leave, poorly targeted audiences, or impressions with very low viewability.
Primary problemDistorts campaign measurements and may cause advertisers to pay for activity that should not count.Directly steals advertising spend and damages trust across the supply chain.Wastes budget and reduces campaign efficiency, even when the interactions are technically legitimate.
Detection focusValidity of impressions, clicks, sessions, devices, and user behavior.Evidence of deliberate manipulation, concealment, misrepresentation, or financial exploitation.Engagement, viewability, conversion rate, retention, audience relevance, and return on ad spend.
Relationship to the other termsThe broad umbrella category. It includes fraudulent and some non-fraudulent activity.Generally a deliberate subset of invalid traffic.A business-quality or performance label rather than a formal fraud classification; it may overlap with IVT but is not automatically invalid.
Typical responseFilter or exclude the activity from reporting, billing, and monetisation.Block the source, investigate the supply chain, withhold payments, and potentially suspend responsible accounts.Improve targeting, traffic acquisition, placements, content quality, viewability, and audience relevance.

If you want to make sense of this, you have to look at the two IVT categories the industry loves to talk about.

The Two Flavors of IVT

The MRC splits invalid traffic into two camps: General Invalid Traffic (which sounds like it just wants to be left alone) and Sophisticated Invalid Traffic (which feels like it should be wearing a monocle and quietly judging your taste in watches). But the actual difference? It’s all about how easy it is to spot.

General Invalid Traffic (GIVT)

GIVT can be identified through routine methods such as published lists or standardized checks.

Common examples include:

  • Known bots, spiders, and crawlers
  • Known invalid data-center traffic
  • Non-browser or unknown user agents
  • Pre-fetch and pre-render activity that never reaches a valid user
  • Repeated activity that violates reasonable frequency rules
  • Invalid placements, such as an ad delivered into a 1-by-1-pixel slot
  • Sessions that claim to render ads on devices incapable of displaying them

Imagine a crawler arriving with a user agent that essentially says, “Hello, I am a crawler.” Detecting it does not require an advanced behavioral model. A system compares the request against a list and filters the activity.

GIVT is not necessarily malicious. Search crawlers, monitoring tools, and internal testing systems perform legitimate jobs. They become invalid in this context because advertisers should not pay for the advertising activity they generate.

Sophisticated Invalid Traffic (SIVT)

SIVT cannot be reliably found with a simple lookup. Detection requires more advanced analytics, corroboration across multiple signals, or human investigation.

Examples include:

  • Bots disguised as normal browsers
  • Hijacked devices or sessions
  • Malware and unauthorized ad injection
  • Falsified impressions, clicks, locations, or viewability signals
  • Domain, app, or CTV bundle-ID spoofing
  • Hidden, stacked, or deliberately obscured ads
  • Cookie stuffing and attribution manipulation
  • Forced or deceptive clicks
  • Undisclosed incentivized activity
  • Organized human fraud farms

A sophisticated bot may present a current Chrome user agent, operate from a residential IP address, store cookies, scroll at irregular intervals, and click something every few visits. No single signal proves it is invalid. A detection system must examine the combination of device attributes, behavior, traffic patterns, and relationships across many sessions.

This is why the GIVT/SIVT distinction is useful. GIVT is primarily a filtration problem. SIVT is an adversarial detection problem.

The distinction can also change over time. The MRC explicitly acknowledges that an activity categorized as SIVT may eventually move into GIVT once the industry develops objective lists or standardized criteria for finding it. 

Today’s clever fraud technique can become tomorrow’s boring lookup table. That is progress, although it rarely makes for an exciting keynote presentation.

How an Ad Impression Becomes Invalid

Let’s follow a simplified programmatic display impression.

  1. A browser opens publisher.com.
  2. The publisher’s ad server creates an advertising opportunity.
  3. An SSP sends a bid request containing details such as the domain, placement, device, IP address, and publisher account.
  4. A DSP evaluates the opportunity on behalf of an advertiser.
  5. The DSP wins the auction and returns an ad.
  6. The browser begins rendering the ad.
  7. Ad servers, platforms, and verification vendors record their versions of the event.

If the visitor is a real person, the domain is accurately represented, and the ad renders as promised, we probably have valid traffic.

Now let’s ruin this perfectly good workflow.

The Visitor Was a Known Crawler

So, a bot from the official crawler database shows up, the publisher shrugs and serves the page anyway, the ad loads, and… surprise! This is GIVT, not real human activity, and it absolutely should not count toward your precious ad numbers.

Here’s the bit everyone loves to ignore: just because you see an ad load (especially during some automated test) does not mean anyone paid for that impression. Served is not the same as billed. There’s a whole filtration step that can quietly kick in after the ad shows up but before anyone gets invoiced.

This distinction became central to a very public 2025 disagreement. 

Adalytics reported that ads were being delivered to bots despite verification protections. DoubleVerify and IAS disputed the conclusions, arguing, among other things, that an ad rendering does not prove that it remained billable, that post-bid filtration still applies, and that the relevant pre-bid products may not have been enabled in every cited case.

If you squint past all the industry yelling, there’s a useful point hiding in there: you can’t judge IVT protection unless you know exactly where the detection happened, which product was even running, what the tag was supposed to do, and whether that impression ever made it into the billable pile. Otherwise, it’s just noise.

The Visitor Was Fake, but Looked Real

Suppose the request came from a bot operating through a compromised home router. The IP address belongs to a genuine household. The browser and device fields look plausible. The bot has a cookie history and behaves differently during each session.

This is SIVT. The fraudster’s job is to create enough evidence of humanity to survive the auction. The detector’s job is to find inconsistencies across signals without blocking real people who happen to browse strangely.

If you miss the bots, advertisers bleed money. If you block the wrong people, publishers lose out and real customers get locked out. So the classic move of ‘just block anything that looks weird’—yeah, not quite the genius solution it pretends to be.

The User Was Real, but the Inventory Was Fake

Now imagine a genuine person streaming video in an obscure app. The bid request identifies the app as a well-known premium streaming service. The viewer is real, the television is real, and an ad may genuinely play. The lie sits in the description of the inventory.

This is app or bundle-ID spoofing. The buyer believed it was bidding on one property and received another.

The MRC’s 2024 interim IVT update specifically strengthened guidance around domain, app and CTV bundle-ID mismatches. SIVT measurers are expected to compare declared property information with the actual delivery location of the ad when those signals are available.

The User Was Real, but the Activity Was Manufactured

A mobile user receives in-game currency for watching a video ad. Is that invalid?

Not automatically. Rewarded advertising can be legitimate when the advertiser knowingly buys rewarded inventory. The problem arises when incentivized activity is used to manipulate measurement or is sold without proper disclosure. The same human action can be valid in one commercial arrangement and invalid in another.

That sounds maddening until you remember that advertising measurement is not merely observing physics. It is enforcing the terms of a transaction.

Invalid Does Not Mean Fraudulent, and Valid Does Not Mean Valuable

This is the part of IVT that causes the most confusion.

A search crawler can be invalid but benign. A badly implemented ad can generate invalid impressions without anyone intending to cheat. Accidental clicks can also be invalid.

At the same time, some genuinely terrible advertising activity remains technically valid.

Consider a made-for-advertising site. A real person clicks a sensational headline on social media, lands on a slideshow, fights through a jungle of ads, and disappears 20 seconds later with a newfound hatred of the internet. The visitor was human. The ads may have rendered. The impressions may have met the technical definition of viewability.

MFA inventory can contain IVT, and some MFA properties use tactics that independently qualify as invalid. But the MRC does not permit measurement companies to label every impression invalid merely because it came from a low-quality property. Its 2024 guidance instead encourages property-level reporting of IVT while separating objective invalid activity from more subjective judgments about content quality.

The same principle applies to targeting. If a campaign intended for American adults reaches a teenager in another country, the impression may be off-target without being invalid. If a real person sees an ad and immediately ignores it, the impression may be worthless without being invalid.

IVT answers, “Should this event enter the measurement?” It does not fully answer, “Was this a sensible place to spend money?”

Advertisers need fraud measurement, supply quality controls, audience verification, and performance analysis because none of them substitutes for the others.

Pre-Bid Versus Post-Bid Detection

IVT can be addressed at two broad points in the transaction.

  1. Pre-bid detection evaluates the opportunity before the DSP places a bid. If the request appears invalid, the buyer avoids it. This is the cleanest economic outcome because no ad needs to be purchased.
  2. Post-bid detection evaluates activity during or after delivery. A verification tag can observe signals unavailable in the original bid request, investigate behavior across sessions, and remove invalid activity from reporting or support a later credit.

Pre-bid is not automatically superior. It must operate within the auction’s tight latency constraints and can evaluate only the signals available before delivery. Post-bid analysis has more evidence and time, but the transaction has already occurred and may require reconciliation.

GIVT often lends itself to pre-bid filtering because lists and rules are relatively fast. SIVT frequently benefits from post-bid analysis because sophisticated detection may require evidence collected over time. In reality, capable platforms layer both approaches.

The most important buyer question is not “Do you detect IVT?” Every vendor will answer yes, probably while showing you an impressive shield icon.

Ask instead:

  • Which GIVT and SIVT categories are covered?
  • Does detection operate pre-bid, post-bid or both?
  • Which channels and formats are included in the accreditation scope?
  • What proportion of traffic receives enough signals for an IVT decision?
  • How is unknown or unmeasurable traffic reported?
  • What happens to invalid events in billing and attribution?
  • How are disputes and credits handled?

Those questions are far less exciting than “Are you fraud-free?” They are also much more useful.

Why Two IVT Reports Never Agree

Suppose a DSP reports 1,000,000 purchased impressions. A verification vendor receives its tag on 900,000 of them. It collects enough information to make an IVT determination on 800,000. It classifies 40,000 as invalid.

Is the IVT rate 4%, 4.4% or 5%?

Potentially all three:

  • 40,000 divided by purchased impressions equals 4%.
  • 40,000 divided by tagged impressions equals roughly 4.4%.
  • 40,000 divided by impressions with a valid IVT decision equals 5%.

Now add pre-bid exclusions, late-arriving classifications, different time zones, duplicated events, unsupported environments, and platforms that observe different portions of the supply chain. Soon, several competent systems can report different numbers without any of them committing arithmetic fraud.

The MRC requires an IVT decision rate: the share of intended measured activity for which a vendor collected enough information to make a determination. Traffic without sufficient evidence should not silently default to valid or invalid. It should be reported as unknown.

This becomes especially important as privacy restrictions and technical environments reduce access to signals. The MRC’s 2024 guidance notes that limited IP addresses, less granular user agents and other restrictions can impair list-based and activity-based detection. It requires measurement organizations to assess those effects rather than simply treating missing information as proof of innocence.

When reconciling vendors, compare four things before comparing the headline IVT percentage:

  1. The population each system measured
  2. The denominator used for the rate
  3. The filtration stage represented
  4. The categories and environments covered

Otherwise, you may spend a week investigating a measurement discrepancy that was a denominator wearing a fake mustache.

What ads.txt Can and Cannot Do

ads.txt, app-ads.txt, sellers.json, and the SupplyChain object help buyers understand who is authorized to sell inventory and which companies participated in the transaction.

These standards can make certain supply-chain lies easier to identify. A DSP can compare the publisher and seller IDs in a bid request with public authorization files, inspect the declared chain of intermediaries, and reject paths that do not reconcile.

They do not prove a human saw an ad.

A perfectly authorized seller can still send bot traffic. A real publisher can have a broken implementation. A valid ads.txt entry can accompany a session generated by malware. Supply-chain transparency reduces specific forms of misrepresentation; it is not a universal IVT detector.

Think of it like checking the title on a car. A clean title provides useful evidence about ownership. It does not tell you whether the person driving it is sober.

AI Agents Are About To Make This More Confusing

Traditional IVT classification assumes an important relationship: advertising activity should correspond to a real person consuming media.

What happens when an AI agent browses the web on behalf of a real person?

Let’s say you ask an agent to find and book a flight. The agent opens websites, compares options, and completes a transaction. It represents genuine human intent. It may even produce a valuable conversion. But if it renders ten display ads that the human never sees, should those impressions be billable?

Under the current logic of ad measurement, probably not. The commercial value belongs to the eventual customer action, not to fictional attention created while the software performed the research.

Known AI crawlers can fit comfortably within GIVT when they identify themselves and are captured by standardized lists. Browser-using agents are more difficult. They may operate ordinary browsers, originate from consumer devices, and behave with explicit human authorization. They are not necessarily malicious, yet the ads delivered to them may still lack a human audience.

The industry has spent years teaching machines to distinguish humans from bots. It must now distinguish among malicious automation, benign crawling, and authorized agents acting on behalf of humans. Whoever volunteered to update the taxonomy is in for an enjoyable few quarters.

How To Reduce IVT Without Pretending You Can Eliminate It

There is no button that makes a campaign fraud-free. A sensible IVT strategy combines technology, supply decisions, and operational discipline.

For Advertisers and Agencies

  • Buy through supply paths you can explain.
  • Confirm the exact scope of pre-bid and post-bid protection.
  • Monitor the IVT decision rate, not only the reported IVT rate.
  • Separate IVT from MFA, audience quality, and poor campaign performance.
  • Keep placement, domain, app, and supply-path reporting wherever possible.
  • Define credit and discrepancy procedures in contracts before a problem appears.
  • Treat inexplicably strong performance as worthy of investigation, not celebration.

For Publishers

  • Understand where traffic comes from, especially from paid traffic acquisition partners.
  • Keep ads.txt, app-ads.txt, and seller records accurate.
  • Segregate internal testing and monitoring activity.
  • Audit refresh behavior, ad density, and implementation errors.
  • Watch for sudden changes in geography, devices, engagement, and revenue.
  • Do not wait for an SSP or platform to discover a traffic problem on your behalf.

For Platforms and Measurement Vendors

  • Preserve clear distinctions between served, measured, filtered and billed activity.
  • Disclose coverage limitations and unknown traffic.
  • Evaluate property, app, and supply-path inconsistencies alongside user signals.
  • Maintain both routine GIVT filtration and adaptive SIVT research.
  • Provide enough evidence for customers to reconcile discrepancies without revealing a detection playbook to fraudsters.

You Can’t Eliminate IVT, but You Can Stop Paying for It

Invalid traffic is not the only villain here. It’s more like a grab bag of things the ad industry has collectively decided to pretend don’t count: helpful crawlers, accidental clicks, botnets, spoofed inventory, and, of course, the occasional organized human mischief. 

The GIVT/SIVT framework at least admits this challenge exists. Some of the junk gets caught by the usual lists and rules. The rest is where you’re left squinting at spreadsheets, making educated guesses, and updating your playbook every other week. And, spoiler: neither bucket tells you if what’s left is any good, on target, or remotely worth what you paid.

That said, the industry is never, ever going to get rid of IVT for good. Every time you catch one trick, the attackers just invent a new one. Privacy rules and platform updates keep moving the goalposts. New devices pop up and create fresh blind spots. And now, AI agents are busy blurring the already-fuzzy line between actual humans and machines pretending to care about your ad.

But just because “fraud is inevitable” doesn’t mean we all get to shrug and call it a day. Buyers can (and should) demand to know what was checked, what got filtered out, what’s still a mystery, and what made it onto the invoice. Publishers? Time to own your traffic sources and setups. Platforms: please make it possible to audit where the money went.

The goal here is not to prove that every single impression came from a real, wide-awake human who gazed lovingly at your creative. If that were the bar, digital advertising would collapse before lunch.

A realistic goal is to understand what you bought, see which activity is showing up in the numbers, and stop paying for events that shouldn’t count.

Share This Article
Content Editor
Follow:
If you’ve ever wondered who’s quietly obsessing over the weird, slightly uncomfortable dance between automation and actual human attention in adtech, that’s basically Happy Das. She’s the one poking at the machinery behind digital ads, data, platforms, strategy, all the stuff that supposedly helps brands “reach people”. In other words: she’s trying to make sense of the mess, so you don’t have to.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *