Features Pricing Guides Security About Contact Sign in WhatsApp us Start free
Google Ads Click fraud Traffic quality

Google Ads IP exclusion for bot traffic: a practical guide

IP exclusion is the one action in Google Ads that actually stops a known bad source from costing you money again — everything else in click fraud protection is about detection and reporting. This covers how it works, where to set it, and the two decisions that matter most: which level to exclude at, and whether to automate the exclusion or review it first.

What IP exclusion actually does

Google Ads lets you supply a list of IP addresses that should never be served your ads. Once excluded, that address stops generating clicks and impressions against your account entirely — it's a forward-looking block, not a refund for anything already charged. You set it under Settings → Excluded IP addresses, either for the whole account or for individual campaigns.

Google Ads caps the list at 500 IP addresses per campaign or account. This is a hard limit, which means IP exclusion works best as a targeted response to identified bad sources — not a blanket filtering strategy. If you're hitting the cap regularly, the underlying traffic quality problem is bigger than exclusion alone can solve.

Account level or campaign level?

This is the first real decision, and it depends on what you actually know about the traffic:

  • Account-level exclusion blocks the IP from every campaign you run. Use this when the traffic is clearly not a real prospect for anything you sell — a known bot signature, a data centre IP range, or a source that's hit multiple unrelated campaigns with identical behaviour.
  • Campaign-level exclusion blocks the IP only from the specific campaign it abused. Use this when you're less certain, or when the same physical location could plausibly be a real customer for a different product line — a shared office IP that's clearly bot traffic on your "instant quote" landing page might still be a legitimate visitor to an unrelated campaign.

When in doubt, start at the campaign level. It's the more conservative choice, and moving from campaign-level to account-level later is easy; the reverse — realising an account-wide block caught a real customer — is harder to notice and undo.

Automatic or reviewed?

The second decision is whether a suspicious IP gets excluded the moment it's flagged, or whether it goes into a review queue for a human to confirm first. Both are defensible, and the right choice depends on how confident your detection signal is and how much traffic volume you're dealing with.

  • Review first is the safer default for most advertisers, especially early on. A flagged IP sits in a queue with the reasons it was flagged shown in plain language — submission timing, repeat count, user-agent signature — and a person decides before anything is pushed to Google Ads. This costs a few minutes a day but avoids the one failure mode that actually costs money: excluding a real customer's office or shared network by mistake.
  • Automatic exclusion makes sense once you have a high-confidence signal and enough volume that manual review can't keep up — for example, an IP that has triggered a honeypot field or hit an aggressive rate limit multiple times in one day. Even then, keep a log of what was excluded and when, so an exclusion can be reversed if it turns out to have been wrong.

The mistake that undermines the whole exercise

Excluding IPs without also making sure fraudulent leads never get reported to Google as conversions addresses only half the problem. If a bot submission slips through and gets marked "won" in your CRM, that conversion data trains Google's bidding algorithm to find you more traffic exactly like the IP you just excluded — from a different address next time. IP exclusion and conversion data hygiene have to work together; neither one alone is sufficient. See how to stop fake clicks on Google Ads for where this fits into the full picture.

Where to find the IPs to exclude in the first place

IP exclusion is only as good as the list feeding it, and there are a few real sources worth checking before assuming you need dedicated bot-detection tooling:

  • Your own server or form logs — if the same IP address appears against dozens of submissions in a short window, with near-identical field values, that's usually enough evidence on its own.
  • Google Ads' own placement and audience reports — for Display and Video campaigns specifically, the placement report can surface sites and apps generating suspiciously high click volume with no corresponding engagement, which is a different signal from IP-level fraud but worth excluding at the placement level alongside any IP work.
  • A honeypot or timing-trap field on your landing page form, which flags the IP the moment it's caught rather than requiring you to notice a pattern manually after the fact — this is the fastest route from "suspicious" to "excluded" because the evidence is unambiguous by construction.

Cross-referencing more than one of these sources before excluding an IP is worth the extra few minutes, particularly at the account level — a single log entry that looks odd in isolation is a much weaker basis for a permanent block than the same IP showing up flagged by a honeypot and appearing repeatedly in server logs on the same day.

Reading the exclusion list correctly

A growing exclusion list is not, by itself, evidence that protection is working well — it might mean detection is too aggressive and is quietly excluding real visitors on shared or dynamic IPs (common on mobile networks and some corporate connections, where many different people share one visible address). If your lead volume drops noticeably after a wave of exclusions, check the list for ranges that look like a mobile carrier or a large office network rather than a clearly automated source, and remove anything uncertain.

A useful habit is reviewing the exclusion list itself on a schedule — monthly is reasonable for most accounts — rather than only ever adding to it. IP ranges get reassigned, mobile carriers rotate addresses among customers, and an exclusion that was correct six months ago can end up quietly blocking a genuine prospect today. Treat the list as something that needs periodic maintenance, not a one-way ratchet.

What IP exclusion cannot do

Worth stating plainly, because it's easy to over-rely on this one tool: IP exclusion only stops traffic from addresses you've already identified. It does nothing about a new IP the same operator switches to tomorrow, and it does nothing at all against a genuinely distributed attack spread across hundreds of different addresses, each making only a handful of requests — a pattern designed specifically to stay under any single-IP threshold. For that kind of traffic, the earlier layers described in stopping fake clicks on Google Ads — honeypots, timing checks, behavioural scoring — matter more than exclusion, because they catch the behaviour rather than the address. Treat IP exclusion as one part of a layered approach, not the whole strategy.

Where this fits with plan-level features

IP exclusion depends on having already identified fraudulent traffic — it's the enforcement step that follows the detection layers described in stopping fake clicks on Google Ads. Claudphic Ads handles the proposal, review-or-auto choice, and the actual push to Google Ads per landing page, off by default so you decide what to turn on and where. Details on which plan includes it are on the pricing page.

Want this running without spreadsheet exports?

Claudphic Ads captures the click ID automatically and uploads the conversion the moment you mark a lead Won. From ₹999/month, with a free trial.

Read next

← All guides

Call now Start free →