Invalid traffic is advertising activity that does not represent a real person with real interest, and which should therefore be removed from the numbers advertisers pay against. The Media Rating Council, the New York body that audits and accredits media measurement in the United States, defines it as traffic or associated media activity that does not meet certain quality or completeness criteria, or otherwise does not represent legitimate traffic that should be included in measurement counts. The wording is deliberately wide. It covers a search crawler that fires an ad call, the second half of an accidental double-click, a botnet renting residential addresses to imitate households, and a competitor clicking a rival's ads to drain the budget. Only part of that is criminal. All of it corrupts the count.
Abbreviated to IVT, the category exists because digital advertising bills on events rather than audited circulation, and an event is cheap to manufacture. Without filtration a fake impression costs almost nothing and pays the full CPM.
The two tiers
The MRC standard splits invalid traffic in two, and the split governs what follows.
General Invalid Traffic, or GIVT, is activity identified through routine filtration using lists or standardized parameter checks. The standard names seven areas: known invalid data-center traffic; bots, spiders and crawlers; activity-based filtration on transaction-level campaign data; non-browser user-agent headers; pre-fetch traffic where the ad was never subsequently accessed; non-standard delivered ad sizes of 0x0 and 1x1; and sessions incapable of rendering images, such as headless browsers.
Sophisticated Invalid Traffic, or SIVT, covers cases requiring advanced analytics, multi-point corroboration and human intervention. Automated browsing runs from emulators and from hijacked consumer devices. Incentivized human invalid activity covers click farms, where non-robotic behavior is organized across users. Falsified measurement events span impression, viewability, click, location, referrer, consent string and conversion attribution. The list continues through app ID spoofing and domain laundering, crawlers masquerading as users, clickjacking, stacked ad serving, malware ad injection and cookie stuffing.
The consequence of the split is regulatory rather than technical. Every accredited measurement organization must apply GIVT detection, which is not separately accredited because it functions as a floor. SIVT detection is optional and separately accreditable. GIVT is meant to be consistent between vendors because it leans on shared resources: the IAB/ABC International Spiders and Bots List, maintained by the Alliance for Audited Media on behalf of IAB Tech Lab, and the data-center address list run by the Trustworthy Accountability Group. On data centers the MRC requires filtration of invalid traffic from the three largest hosting entities, naming Amazon AWS, Google and Microsoft. SIVT findings must instead be segregated and disclosed only at campaign total level, because transaction-level detail would let operators reverse-engineer the logic.
Where filtration sits in the transaction
Detection happens either before the ad serves or after. Up-front techniques block a bid or ad request in flight; back-end techniques review delivered traffic and strip it from reported counts. The MRC does not require up-front blocking and is openly cautious about it, warning that blocking telegraphs the method to the traffic source and invites A/B testing against the filter. Back-end detection is mandatory, and sophisticated adjustments made after a campaign closes must land within 14 days of completion.
Because filters only work on the signals they receive, vendors must also publish a decision rate: recorded impressions where enough information existed to reach a verdict, divided by total impressions intended for measurement. The MRC's worked example takes 100 rendered impressions, of which 85 yield enough information to decide, producing 15 unknown and a decision rate of 85 percent. Unknown traffic must not be assumed valid. The required telemetry maps onto the programmatic stack: IP address including X-Forwarded-For, unmodified user agent, device and app identifiers, referrer, consent string, publisher and placement IDs, ads.txt information, pre-fetch headers and OpenRTB attributes.
The buy side and the sell side
On the search buy side, Google's documentation lists six types of invalid activity: the second click of a double-click, manual clicks meant to raise a competitor's costs, manual clicks meant to raise a host publisher's earnings, activity from automated tools, known data-center traffic, and impressions designed to depress an advertiser's clickthrough rate. Timing then determines the remedy. Activity caught before an invoice generates is never billed. Activity caught afterwards produces credits, which Google states plainly are adjustments rather than refunds, appearing as negative values on later invoices. Automated reviews and the Click Quality Form investigation window both cover the previous 60 days.
Campaign-level visibility into those credits arrived late. Google published help documentation for the Invalid Activity Credit Report on June 1, 2026, breaking credits down by campaign and network alongside adjusted performance metrics. Whether the report was new or merely newly documented was never clarified, and coverage is limited to Search and Performance Max.
Sell-side exposure runs in reverse. Publishers receive no credits; they lose revenue and, inside Google's owned channels, serving capacity. AdSense ad serving limits, introduced in late 2020, cap how many ads an account can show while the system keeps evaluating traffic, with enforcement typically running around 30 days. YouTube published a creator FAQ on invalid traffic on April 20, 2026, acknowledging that channels accumulate it through third-party services selling views and subscribers, and that its list of causes is not exhaustive.
Origin and evolution
Filtration predates the terminology: server-log auditing removed robots long before programmatic buying existed. What changed in the mid-2010s was scale and money. In December 2014 the Association of National Advertisers and White Ops published the first Bot Baseline report, measuring 5.5 billion impressions across 181 campaigns from 36 member companies and projecting $6.3 billion in global bot losses for 2015. The MRC issued Invalid Traffic Detection and Filtration Guidelines Version 1.0 as final on October 27, 2015, establishing the GIVT and SIVT structure the industry still uses.
Two prosecutions gave the category a criminal face. White Ops disclosed Methbot in December 2016, a data-center operation running since September 2014 that rented more than 1,900 servers and spoofed over 5,000 domains. The 3ve botnet that followed infected more than 1.7 million machines. On November 27, 2018, the US Attorney for the Eastern District of New York unsealed a 13-count indictment against eight defendants over both schemes.
The MRC issued IVT 2.0 as final on June 25, 2020, with a one-year grace period, adding data-center requirements, the decision rate, purchased-traffic disclosure and up-front filtration guidance. Interim updates on April 24, 2024 added three areas: privacy restrictions on IVT telemetry, bundle ID spoofing in connected TV, and property-level reporting aimed at made-for-advertising inventory.
Where the numbers disagree
Reported rates diverge by an order of magnitude depending on who measures what. Verification vendors report low single digits on protected inventory. Integral Ad Science measured global invalid traffic at 1.203 percent before the 2026 FIFA World Cup and 1.134 percent after kickoff, against an expected seasonal decline to 0.876 percent. DoubleVerify reported fraud and SIVT violation rates down 41 percent year over year in North America and 45 percent in EMEA on July 29, 2026, with North America still the highest tracked market at 0.6 percent.
Click-level vendors report far higher figures. Lunio recorded LinkedIn at a 17.62 percent invalid traffic rate in the first quarter of 2026, and found retail search campaigns running Google AI Max exposed to 72 percent more invalid trafficthan campaigns without it, at 5.28 percent against 3.07 percent in the second quarter of 2026.
Part of the gap is definitional: clicks and impressions are different denominators, and protected campaigns are not a random sample. A March 2025 investigation spanning more than a petabyte of traffic concluded that at least 40 percent of web traffic is non-human, and found cases where verification tools identified a visitor as a bot and served an ad anyway.
Reclassification moves the numbers too. Declared AI crawlers count as GIVT rather than fraud, and their volume is new: DoubleVerify recorded an 86 percent year-over-year rise in GIVT during the second half of 2024, 16 percent of it linked to AI tools. Changes to three MRC accredited metrics in Display and Video 360 on July 14, 2025 were expected to roughly double reported invalid and GIVT begin-to-render impressions, a detection improvement that reads on a dashboard as deterioration.
Underneath sits a harder problem. Filtration rests on user agents and addresses that are client-supplied and forgeable, a weakness visible in scanners forging AI crawler names from 824 addresses, and schemes that clear verification are never counted as violations at all.
Adjacent terms
Click fraud is a subset, describing deliberate manipulation of clicks for gain. Invalid traffic also covers accidental and benign non-human activity nobody intended as fraud.
Bot traffic is drawn differently rather than more narrowly. Invalid traffic includes organized human activity such as click farms, and much bot traffic never touches an ad.
Made-for-advertising inventory is a property-level quality judgment rather than a validity judgment, since traffic reaching an MFA site may be entirely human.
Recent developments
Detection and evasion have both automated. Google attributed a 40 percent reduction in deceptive practices to Gemini-based invalid traffic detection in August 2025. Against that, HUMAN Security disrupted NewsJunkie on July 11, 2026, a connected TV scheme routing through residential addresses at a peak of two billion bid requests daily.
Adoption of dedicated defenses remains thin. A Lunio survey of 131 senior marketing leaders fielded in May 2026 found 5.3 percent using dedicated invalid traffic tools, with 39.7 percent citing confidence in platform-side prevention as the reason not to, while 38.9 percent rated their trust in platform invalid click credits at 4 or below on a ten-point scale.
Timeline
- December 9, 2014 - ANA and White Ops publish the first Bot Baseline report, projecting $6.3 billion in global bot losses for 2015
- October 27, 2015 - MRC issues Invalid Traffic Detection and Filtration Guidelines Version 1.0 as final, establishing the GIVT and SIVT categories
- December 2016 - White Ops discloses Methbot; the operation shuts down
- November 27, 2018 - US Department of Justice unseals a 13-count indictment against eight defendants over Methbot and 3ve
- June 25, 2020 - MRC issues IVT 2.0 as final, adding the decision rate, data-center requirements and purchased-traffic disclosure
- Late 2020 - Google introduces AdSense ad serving limits
- June 25, 2021 - The one-year IVT 2.0 compliance grace period ends
- April 24, 2024 - MRC publishes interim IVT updates covering privacy, CTV bundle ID spoofing and property-level reporting
- July 14, 2025 - Google implements changes to three MRC accredited metrics in Display and Video 360
- August 12, 2025 - Google reports a 40 percent reduction in deceptive practices from Gemini-based detection
- April 20, 2026 - YouTube publishes a creator FAQ on invalid traffic
- June 1, 2026 - Google publishes help documentation for the Invalid Activity Credit Report
- July 10, 2026 - IAS reports invalid traffic running roughly 30 percent above the seasonal forecast during the 2026 FIFA World Cup
- July 29, 2026 - DoubleVerify reports fraud and invalid traffic violation rates down 41 percent in North America and 45 percent in EMEA
- August 12, 2026 - Lunio publishes retail findings on AI Max invalid traffic exposure
Related PPC Land coverage
- MRC updates the Invalid Traffic (IVT) Detection and Filtration Standards - The IVT 2.0 update and the additions it introduced, including the decision rate and purchased-traffic requirements.
- Google announces changes to MRC accredited metrics in July 2025 - The Display and Video 360 counting changes and Google's GIVT and SIVT detection methods.
- Google Ads documents Invalid Activity Credit Report for the first time - Campaign-level and network-level credit reporting for Search and Performance Max.
- Retailers on AI Max face 72% more invalid traffic, Lunio finds - The retail edition of Lunio's vertical studies, covering more than 414 million clicks.
- LinkedIn drives the most bot clicks per ad dollar, new report finds - Platform-level invalid traffic rates across four channels, with LinkedIn highest.
- Only 5.3% of marketers use IVT tools as 75.6% lose ad budget to bots, Lunio - Survey evidence on the gap between concern about invalid traffic and spending against it.
- Invalid traffic stays 30% above forecast as World Cup surge hits, IAS finds - Seasonal invalid traffic and made-for-advertising measurement around the 2026 tournament.
- DoubleVerify: ad fraud drops 41% in North America, 45% in EMEA - Regional violation rates on protected campaigns, plus AI bot click findings on unprotected media.
- Bot traffic costing advertisers billions as fraud detection fails, investigation reveals - The petabyte-scale investigation reporting at least 40 percent non-human web traffic and verification failures.
- DoubleVerify reveals North America's ad quality improvements amid rising bot fraud - The 86 percent GIVT rise in the second half of 2024 and its link to AI crawlers.
- Google deploys Gemini AI to combat ad fraud with 40% reduction - Google's application of large language models to invalid traffic classification.
- YouTube's hidden invalid traffic problem: what creators aren't told - The April 2026 creator FAQ and the mechanisms through which channels accumulate invalid traffic.
- Understanding AdSense Ad Serving Limits - How publisher-side enforcement works, including duration and the categories Google applies.
- HUMAN Security kills NewsJunkie CTV fraud scheme hitting 2 billion bids daily - A connected TV device and app spoofing operation routed through residential addresses.
- IAS blocks 800 Papyrus domains faking $1 million a month in ad traffic - Hidden browser windows inside mobile applications generating self-clicking activity.
- AdSense gets full IP address sharing - and it's off by default - How address truncation affects invalid traffic detection resolution in bid requests.
- Scanners posing as ClaudeBot hunt credential files from 824 addresses - Crawler name forgery and its consequences for name-based traffic filtering.
- AutoBait exposed: inside the AI slop factory draining ad budgets - A 200-domain made-for-advertising network and the property-level quality problem it illustrates.
- Google just made invoice tracking bearable with new billing report - The billing summary treatment of invalid traffic credits before campaign-level reporting existed.
- CTV fraud schemes up 140% as AI arms both sides of the fight - Connected TV fraud growth, protected versus unprotected violation rates, and TV-off impressions.
Summary
Who: The Media Rating Council writes and audits the standard; IAB Tech Lab and the Trustworthy Accountability Group maintain the shared lists; verification vendors including DoubleVerify, Integral Ad Science, HUMAN Security, Pixalate and Lunio perform detection; platforms including Google, Microsoft and Meta filter internally; advertisers and publishers absorb the consequences.
What: Traffic or media activity that fails quality or completeness criteria and should be excluded from measurement counts, divided into General Invalid Traffic identified through lists and parameter checks, and Sophisticated Invalid Traffic requiring advanced analytics and human review.
When: Formalized by the MRC on October 27, 2015, comprehensively updated on June 25, 2020, and extended by interim updates on April 24, 2024 covering privacy, connected TV spoofing and property-level reporting.
Where: Across every digital environment the standard reaches, including desktop and mobile web, mobile in-app, connected TV and over-the-top, audio, and cross-media measurement that incorporates linear television components.
Why: Because digital advertising bills on manufacturable events. Without filtration, advertisers pay for activity no person performed, publishers compete against inventory that costs nothing to fabricate, and the performance data feeding automated bidding is trained on signals that never came from a customer.
Discussion