Website Traffic

How to Spot Bought Traffic in Analytics

How to spot bought traffic in analytics: the referrer, duration, geo and conversion checks that separate a delivered campaign from a padded number.

S SparkCliks 0 21 min read
Share
How to Spot Bought Traffic in Analytics

You can spot bought traffic in analytics in about twenty minutes, but only if you know which numbers a delivery engine sets directly and which ones it cannot reach. Most buyers watch the session count go up and stop there. This audit goes further: whether you got the campaign you specced, whether the visits behaved the way the spec said, and whether any of it contaminated the reports you make decisions from.

What you are actually auditing

"Is this traffic real?" is the wrong opening question. Every vendor answers it the same way, and if you bought automated visits you already know the answer. Three narrower questions do have checkable answers.

QuestionWhere you check itWhat failure looks like
Did it arrive?Realtime report, sessions by day, server access logVolume well under plan, or a curve that stops early
Does it match the spec?Traffic acquisition, Tech details, Demographic details, ExplorationsCountry, device, referrer, session time or pages per visit ignoring a control you paid for
Did it contaminate anything?A segment excluding the campaign, plus your ad networkOrganic conversion rate moves, ad impressions rise

Fidelity is where most disputes live, because that is where a vendor sold you eight controls and honored five. Containment is where the damage lives, because a polluted conversion report outlives the campaign by months.

One check underneath all three goes almost unrun: compare your server access log entry count for the campaign window against the sessions analytics recorded. Allowing for caching, blocked tags and consent losses the two should move together, and analytics climbing while the logs stay flat means something is reporting visits your web server never served.

Set a baseline before the first visit lands

Traffic audits go inconclusive because nobody wrote down what the site looked like beforehand.

Freeze four exports covering the 28 days before launch. In GA4: Reports, then Acquisition, then Traffic acquisition, with sessions, engaged sessions, engagement rate, average engagement time per session and key events, split by session default channel group. Then Reports, then Tech, then Tech details for browser, device category and screen resolution. Then Reports, then User, then User attributes, then Demographic details for country and city. Then Search Console: Performance, then Search results, last 28 days, both the Queries and Pages tabs. That last export settles the argument in section nine and cannot be recreated later with the same window boundaries. Note your ad impressions for the same period if any targeted page carries an ad unit.

Pick a control set of three to five pages you will deliberately not target, with organic volume similar to the ones you will. When something moves on the targeted pages, the control set is the only thing telling you whether it moved because of the campaign or because of the season, a site change or an algorithm update. It also gives you a noise floor: an example working rule is that anything smaller than your largest week-to-week baseline swing means nothing, so if organic engagement rate wobbled between 41 and 47 percent across four baseline weeks, a reading of 45 percent afterwards is not a result.

Set data retention to 14 months under Admin, then Data settings, then Data retention. The 2 month default governs the event-level data that Explorations read, and an exploration built after retention expires shows nothing without explaining why.

Agree the tagging. Ask for a tag used nowhere else, for example utm_source=sparkcliks&utm_medium=paid_visits, or a dedicated referrer string. It costs nothing and turns every check below into a one-click segment. A vendor who will not tag their own traffic has told you something.

For the decisions upstream of all this, see how to buy website traffic without wasting your budget.

Free trial

Stuck on page two?

Real human clicks that lift your CTR and move you up the rankings.

Referrers and the direct traffic spike

Reports, then Acquisition, then Traffic acquisition, primary dimension switched to Session source / medium, with Landing page and query string as secondary. Direct is GA4's fallback bucket: no referrer header, no campaign parameters, or a source resolving to nothing else. A direct spike after buying traffic is usually one of four things.

SymptomLikely causeHow to confirm
Campaign volume arrives, all as DirectReferrer never set, or your referrer list ignoredAsk which referrer string is sent, then watch a live session in Realtime
Direct despite a correct referrerYour own referral exclusion list is catching itAdmin, then Data streams, then Configure tag settings, then List unwanted referrals
Split between Direct and "Unassigned"Source and medium values matching no channel definitionRead raw Session source / medium, not the channel group
One referrer with an implausible shareThe rotation is not rotatingCompare the distribution against the list you supplied

A referrer is a string the client sends, so read it as evidence of configuration, not of a journey. That is precisely why the check earns its place: it proves the vendor honored a setting you paid for. SparkCliks Website Traffic lists "Referrers: rotated through your list" as a campaign control, and counting the distribution here against your own list is how you audit that claim. Then open the referring URLs, because a page that does not exist, or exists without a link to you, is a label rather than a path.

The shape of the spike is its own tell. A real referral spike peaks sharply and decays over two to four days as the post ages down the feed. A delivery spike is close to rectangular: up to the daily cap, flat, then nothing when the credits run out. Neither shape is dishonest, but the rectangle is what a human reviewer notices, and no referrer setting fixes it. For what each channel is actually for, see organic, social and referral traffic.

Session duration and depth: read the shape, not the mean

GA4's headline metric here is average engagement time per session, counting only time your page spent in the foreground of a focused tab. It is not session duration, and it is not the dwell time SEO arguments are about. If those keep getting mixed up on your team, dwell time vs time on page vs session duration sorts out which stopwatch belongs to whom.

A real audience is heavy tailed: mostly short sessions, a few running past twenty minutes because somebody left a tab open, and a mean sitting well above the median because of them. A scripted population has no tail, because the engine gets a time budget and spends it. So a campaign average resembling your organic average tells you almost nothing. Look at the spread instead.

The hour of day curve is the cheapest way to see it. Open Explore, build a Free form exploration, set the dimension to Hour and the metrics to Sessions and Average engagement time per session, then set the range to the campaign days. A human audience in one target country makes a diurnal curve: a trough through local small hours, a morning climb, an afternoon plateau. A delivery scheduler often produces near-flat hourly buckets, or a peak at the wrong local hour for the country you bought. Convert before judging, because your property's reporting timezone is set under Admin, then Property details, and it is frequently not the timezone of the market you targeted.

The engaged session timer turns duration into a pass or fail. Under Admin, then Data streams, then Configure tag settings, then Adjust session timeout, GA4 lets you move the engaged session timer from its 10 second default up to 60 seconds. An engaged session is one that passes that timer, fires a key event, or records two or more page views. Set 60 seconds before launch and engagement rate becomes the share of sessions lasting at least a minute. If your spec promises visits of up to five minutes and that number sits near zero, the visits are far shorter than specced. The change is not retroactive and it moves engagement rate for the whole property, so make it deliberately and record the date.

The plan ratio test is arithmetic. Vendors publish page views and unique visits per plan, and the ratio between them is the pages per visit you should see. SparkCliks publishes the MINI Website Traffic tier at 60,000 page views and 20,000 uniques for $9.99 a month, a ratio of 3, matching its paid feature "up to 3 pages per visit". Divide plan page views by plan uniques, then compare against views per session for the campaign segment: landing at 1.1 when you paid for 3 is a support ticket with a number attached. One caveat first. GA4 counts a view when a page_view event fires, and on a single page app route changes only fire one if "Page changes based on browser history events" is on under Enhanced measurement.

Geography against what you targeted

GA4 derives location from the IP address at collection and then discards it, so geography tells you where the connection appeared to be, not where a person sat. A clean country match proves the delivery used addresses registered where you asked, and nothing beyond that. Reports, then User, then User attributes, then Demographic details, Country as primary, City as secondary.

  • Country against your setting. Thirty percent of sessions from somewhere you did not buy is a plain delivery failure. Geo targeting website traffic to specific countries covers the mechanisms that set a visit's country and how to verify each.
  • City concentration inside the right country. Real national traffic follows population and connectivity, so a United States campaign scatters across dozens of metros. One city holding 60 percent of a national campaign is an address pool footprint.
  • The "(not set)" city share. Some is always normal, because sub-country resolution fails routinely. A majority usually means the addresses resolve at country level only.
  • Language against country. GA4's Language dimension comes from the browser, not the IP, so a Germany campaign reporting 95 percent en-us is a setting nobody switched. SparkCliks lists "Language: set per campaign" next to "Country: pick it" as two separate controls, which makes this a fidelity gap rather than an unavoidable side effect.

Device, browser and returning visitor mix

Reports, then Tech, then Tech details, cycling the primary dimension through Device category, Browser, Browser version and Screen resolution.

Screen resolution is the most revealing dimension here. Real audiences spread across dozens of resolutions with a long tail of odd sizes: half-height windows, external monitors at strange scaling, phones nobody has replaced. An automated fleet draws its viewport from a pool, so if three resolutions carry over 90 percent of campaign sessions while your organic baseline needs fifteen rows to reach the same share, that is a pool. Not proof of dishonesty, and not something a vendor can fix. It is proof the traffic is separable, which is what the containment checks need. Browser version says the same more slowly, since real audiences straggle across versions for months while a fleet built from one image reports one or two. Device category is a plain spec check: configure mixed devices, receive 100 percent desktop, and that is a control you did not get.

New versus returning is a construction artifact, not a quality signal. GA4 decides it from the first-party _ga cookie plus the first_visit event, so any engine using a fresh isolated browser profile per session produces close to 100 percent new users by construction. Reading that as fraud is a mistake, and so is reading a returning share as quality, because reused profiles manufacture returning users just as easily. What the ratio genuinely costs you is measurement: for the length of the campaign your returning-user count means nothing and any audience built on new-user rules is polluted. The check that matters is the control comparison, because your organic segment's returning-user count should be unchanged, and if it fell the campaign is displacing your measurement rather than adding to it.

Conversions: the number that should not move

Bought visits should produce approximately zero conversions, and vendors being straight about it say so. SparkCliks' own Website Traffic FAQ states that the traffic "does not make purchases".

MetricExpected directionRed flag
Key events from the campaign segmentFlat, at or near zeroAny real volume of form fills, signups or purchases
Site-wide conversion rateFalls, mechanicallyNothing. This is arithmetic, not a quality decline
Organic-segment conversion rateUnchanged versus baselineAny move outside your baseline's week-to-week swing
Ad impressions on targeted pagesUnchangedImpressions rising in step with the delivery curve

Conversions from purchased traffic are a problem, not a bonus. Fake leads burn sales time, poison lookalike and value-based audiences, distort lead scoring, and in a payments context can resemble card testing closely enough to attract a processor's attention.

Site-wide conversion rate will fall, so say so first. The denominator grows by tens of thousands of sessions and the numerator does not move. Warn whoever reads the weekly dashboard, because a mechanical dilution explained afterwards sounds like an excuse. Then build the containment segment on day one: in any standard report, use Add comparison with the condition Session source / medium does not exactly match your campaign source, and make that the default view for the campaign period.

Check your ad account whatever the vendor promises. Automated traffic counted as ad impressions is invalid traffic under every major ad network's rules, and the penalty lands on your account rather than the vendor's, usually as withheld earnings or a suspension. Treat any blanket "safe for ad programs" line as a claim, then verify it by pulling your network's impression report for the campaign days and seeing whether the curve matches. If it does, stop the campaign or move it to pages with no ad units. This is the one check where being wrong costs money instead of clarity.

GA4 bot filtering and what it does not catch

GA4 automatically excludes traffic from known bots and spiders using the IAB and MRC International Spiders and Bots List. It is on by default, cannot be switched off, and produces no report of what it removed. Draw the right conclusion from that. If your purchased traffic shows up in your reports, all you have learned is that it is not on a list cataloging declared crawlers and known automation signatures. Automation driving a current browser build with an ordinary user agent was never going to be on it. Surviving GA4 bot filtering is not a quality signal, and no vendor should sell it as one.

What you can add is separability rather than detection. A campaign tag you control is the most useful item on this page: utm_source and utm_medium values used nowhere else turn every check here into a saved segment instead of an inference. Failing that, a query parameter such as ?src=trafficaudit persists in the Page path and query string dimension, though it splits your landing page rows and on some stacks bypasses a cache, so pick something your CMS ignores. Data filters under Admin, then Data settings, then Data filters suit your own office and are close to useless against a delivery engine whose addresses rotate. None of this proves humanity, and it does not need to.

The cross-check that settles "organic"

"Organic traffic" means two different things depending on who is selling it.

  1. A visit arriving at your page with a search engine referrer string set, so analytics files it under Organic Search.
  2. A visit that began as a query on a results page, where a person read the listings and clicked yours.

Only the second is visible to Google Search Console, which counts the click that happens on the results page. Your analytics tool never sees the results page at all, and that asymmetry is the whole test.

  1. Search Console, then Performance, then Search results. Use the date picker's Compare tab, not two separate exports, and compare the campaign window against the equivalent preceding period. Record clicks for both.
  2. GA4, then Reports, then Acquisition, then Traffic acquisition, filtered to Session default channel group is Organic Search. Same two windows through the comparison date picker. Record sessions for both.
  3. Compute two deltas: the change in Search Console clicks, and the change in GA4 organic sessions.
What you seeWhat it meansWhat to do
Both rise, roughly in proportionThe visits came through a results pageNothing. This is the honest version of organic delivery
GA4 organic rises, clicks flatSessions labeled organic, no results page in the journeyFine if that is what you bought, a dispute if the vendor said otherwise
Clicks rise, GA4 organic flatA collection problem on your side, not a traffic problemCheck consent mode, tag firing and blockers before blaming anyone
Neither movesDelivery failed, or it landed in another channelRecheck raw Session source / medium values

These two tools never agree exactly. Search Console deduplicates clicks within a query and session, lags two to three days, defaults to Pacific Time, and covers one search engine only, while GA4 loses sessions to consent choices and blockers. Never read the absolute gap between them. Read the change in each. For the report paths in more detail, how to measure organic CTR in Google Search Console walks the same screens.

Applied to our own product line, here is what the test would show. SparkCliks SERP Clicks is the product where a person runs the query, scrolls the results and clicks the listing, and its plan features say it shows in Google Analytics and Search Console, so a SERP Clicks campaign should move both numbers. Website Traffic and Realistic Traffic load your pages directly with a referrer you configure, so they can register as organic in analytics without passing through a results page, and Search Console will not move. Neither behavior is a scandal: they are different products at different prices doing different jobs. Selling the second while implying the first would be dishonest, and this check is how you find out which you were sold, from any vendor including this one.

Healthy versus suspicious, side by side

"Healthy" here means matches what you bought. It does not mean indistinguishable from organic. No automated visit is indistinguishable from an organic one if you look in the right places, and a vendor promising otherwise is overselling.

SignalMatches specWorth a support ticket
Daily volume and curveTracks the plan's daily range, flat and predictableUnder plan, stopping early, or thousands of sessions in minutes
Referrer setMatches your list, spread across itOne host dominating, or everything in Direct
Views per sessionClose to plan page views divided by plan uniquesFar below the ratio you paid for
Engagement timeVaries session to session, with visible spreadEvery session within a second or two of one value
Hour of dayA curve fitting the target country's local timeFlat buckets, or a peak at the wrong local hour
Country and cityYour setting, scattered across many metrosExcluded countries, or one city carrying the country
LanguageMatches the market you targeteden-us on a campaign you configured otherwise
Screen resolutionsA small pool, expected and separableThe same pool described as real human variance
New usersNear 100 percent, a profile artifactA vendor citing it as proof of reach
Key events and ad impressionsAt or near zero, impressions unchangedSignups from the campaign, or impressions tracking delivery

Two rows get misread in opposite directions. A small pool of screen resolutions is normal for automated traffic and only becomes a red flag when a vendor calls it human variance. A near-total new-user share is likewise normal, and only becomes a problem when somebody builds a reach claim on it.

For what your engagement numbers should look like before you judge them, website traffic vs realistic traffic sets out the difference between a visit that loads and a visit that scrolls and clicks. And if bounce rate moved and somebody is about to draw a ranking conclusion from it, bounce rate is not a ranking factor explains why the search engine never saw that number.

Your first 48 hours

Run these in order. The ones that matter most sit at the front, where a misconfigured campaign is still cheap to stop.

  1. Before launch. Export the baselines from section two, pick the control pages, set data retention to 14 months, raise the engaged session timer if you plan to use that test, and agree the campaign tag.
  2. First hour. Reports, then Realtime, covering the last 30 minutes. Confirm sessions are arriving, the landing pages are the ones you submitted, and the source and medium look the way you agreed. A wrong landing page caught in hour one is the cheapest problem you will ever fix.
  3. Hour two, if you run ads. Pull the impression report, and if impressions are already climbing with delivery, pause and move the campaign off ad-bearing pages.
  4. Hour six. Traffic acquisition by Session source / medium: the referrer distribution against your list, and how much landed in Direct or Unassigned.
  5. Hour twenty-four. Country, city, language, device category and screen resolution against the spec. A day is enough volume for the distributions to be readable.
  6. Hour thirty-six. The hour of day exploration, views per session against the plan ratio, and engagement rate at whatever threshold you set.
  7. Hour forty-eight. Key events from the campaign segment (expect zero), organic conversion rate against baseline, control pages against baseline, and the Search Console versus GA4 organic delta if anything was sold to you as organic.

The decision at hour forty-eight. Raise a ticket if delivered volume is below the plan's stated daily range, if a dimension you paid to control does not match your setting, if views per session fall materially below the plan's own ratio, or if ad impressions moved. Stop outright if key events are arriving from the campaign, or if your organic segment changed. Everything else is a note for the next buy. And if every check passes while the campaign still does nothing useful for you, the problem sits upstream of measurement: when not to buy website traffic covers the cases where paid visits were the wrong instrument to begin with.

Frequently asked questions

FAQ

How can I tell if my website traffic is real or bot traffic?

No single metric proves it, so read the combination: screen resolution and browser version concentration, the hour of day curve against the target country's local time, the spread of engagement times rather than the average, and whether Search Console clicks moved for anything sold as organic. Real audiences are messy in all four at once.

Why did my direct traffic spike after buying visits?

Direct is GA4's fallback bucket for sessions arriving with no referrer header and no campaign parameters, so it fills when a referrer was never set, was stripped in transit, or was caught by your own unwanted referrals list under Admin, then Data streams, then Configure tag settings. Check that list first, because it is the cause people forget and the only one you can fix yourself.

Does GA4 automatically filter out purchased traffic?

GA4 excludes known bots and spiders using the IAB and MRC International Spiders and Bots List, on by default and impossible to turn off. That list catalogs declared crawlers, so automation driving an ordinary browser is not on it, and traffic surviving GA4 bot filtering proves nothing about its quality in either direction.

Should bought traffic ever produce conversions?

No, and finding conversions in your campaign segment is a reason to stop rather than to celebrate. Fake form fills waste sales time, corrupt lookalike and value-based audiences, and distort every optimization decision made downstream of that data.

How long should I wait before judging a traffic campaign?

Check delivery and landing pages inside the first hour, run the fidelity checks at twenty-four hours, and make the keep-or-stop call at forty-eight. Anything about search performance needs far longer, because Search Console data runs two to three days behind and a fortnight is the shortest window worth comparing.

Why does Search Console show fewer clicks than GA4 shows organic sessions?

Some gap is always structural: Search Console deduplicates clicks per query and session, covers one search engine, lags two to three days and defaults to Pacific Time, while GA4 loses sessions to consent and blockers. What matters is whether both moved together during your campaign, because organic sessions rising while clicks stay flat means the visits were labeled organic without passing through a results page.

About the Author

The SparkCliks Team builds and runs search click and website traffic services at sparkcliks.com, so much of our week goes on reconciling what a campaign delivered against what its spec promised, inside other people's analytics. The checks above are the ones we use, written so they work against any vendor including us. We do not promise rankings, positions or guaranteed outcomes: a service can honestly commit to delivering the visits and settings you configured, visible in your own reporting, and what a search engine concludes from that is its own decision. Questions can go to hello@sparkcliks.com.

Keep reading

Related articles