Bot Traffic in Google Analytics: How to Identify It, Filter It, and Work Out What It Costs You
Table of contents
Bot traffic in Google Analytics is automated, non-human activity that gets recorded in your reports as if it were real visitors. It shows up as sessions with no engagement, traffic spikes from places you do not serve, and conversion rates that quietly sink for no obvious reason. If you have opened GA4, seen a jump in visitors, and felt suspicious rather than pleased, this guide is for you.
The suspicion is usually justified. According to the Imperva and Thales Bad Bot Report, automated traffic overtook human activity for the first time in 2024, reaching 51% of all web traffic, with malicious bots alone accounting for 37%. Google Analytics filters some of that automatically, but far from all of it. This guide walks through how to identify bot traffic in Google Analytics step by step, how to filter it out of your reporting, and, most importantly for anyone running Google Ads, how to work out whether those bots are costing you actual money rather than just messy charts.
Why bot traffic still shows up in Google Analytics
Google Analytics automatically excludes known bots, but unknown and sophisticated bots pass straight through into your reports. That single sentence explains most of the confusion around this topic, so it is worth unpacking.
GA4 properties automatically filter traffic from known bots and spiders, identified using a combination of Google’s own research and the International Spiders and Bots List maintained by the Interactive Advertising Bureau (IAB). This happens by default on every property. You cannot turn it off, and, frustratingly, you cannot see how much traffic was excluded either. There is no report showing what Google removed on your behalf.
The catch is the word “known”. The IAB list covers declared crawlers and well-documented automated tools: search engine spiders, monitoring services, the polite end of the bot spectrum. It does not cover a freshly built scraper, a headless browser running from a residential IP address, a click farm using real devices, or the newer wave of AI crawlers and agents hoovering up content for training and task automation. For Google Ads advertisers, this means the bots most likely to click an ad, fill in a junk form, or drain a budget are precisely the ones GA4’s automatic exclusion was never designed to catch. We covered that broader category in our plain-English guide to what invalid traffic actually means, and the sharp end of it in our piece on AI bots draining Google Ads budgets.
So when someone asks “does Google Analytics filter bot traffic?”, the honest answer is: partially, invisibly, and with a growing blind spot.
How to identify bot traffic in Google Analytics
You can identify bot traffic in Google Analytics by looking for sessions with near-zero engagement, sudden spikes from a single source or location, and technical fingerprints that do not match real customers. None of these signs is conclusive on its own. Two or three together usually are.
Here is the checklist we would run on any GA4 property, in order.
1. Sudden spikes in direct or unassigned traffic
Open Reports → Acquisition → Traffic acquisition and look at the “Direct” and “Unassigned” channel rows over the last 90 days. Bots frequently arrive with no referrer and no campaign tagging, so they pile up in these two buckets. A steady baseline that suddenly doubles for a few days, with no marketing activity to explain it, is the single most common signature of a bot wave.
2. Engagement time close to zero
Real people take time to read, scroll and click. In the same Traffic acquisition report, add the “Average engagement time per session” metric and compare your suspect segment against your normal traffic. Sessions averaging one or two seconds of engagement, at volume, are not customers deciding your service is not for them. They are scripts loading a page and leaving.
3. Engagement rate that collapses on one channel only
If your organic traffic engages at 60% but a specific paid campaign or referral source engages at 8%, the difference needs explaining. Build a GA4 Exploration with Session source/medium as the dimension and Sessions, Engagement rate and Average engagement time as metrics, then sort ascending. The rows at the top of that sorted list are your suspects.
4. Geography that makes no sense for your business
A plumber in Manchester does not need forty sessions a day from a single city in another hemisphere. Check Reports → User → User attributes → Demographic details and switch the dimension to City. Bot activity often concentrates absurdly in one or two locations, frequently data-centre cities. If you run location-targeted Google Ads and still see out-of-area clicks, that is a separate and more expensive problem we examine in our technical guide to detecting click fraud.
5. Odd technical fingerprints
Under Reports → Tech → Tech details, look at browser and operating system combinations. Clusters of ancient browser versions, obscure screen resolutions like 800x600, or a sudden surge in a single Linux build are all classic automation tells. Real customer bases are messy and varied. Bot fleets are uniform.
6. Referral spam and hostname mismatches
Some bots exist purely to plant their website’s name in your reports so you visit them out of curiosity. Suspicious referral domains you have never heard of, often with spammy names, sending “traffic” that never engages, can be treated as spam on sight. Checking the Hostname dimension in an Exploration also catches events fired at your measurement ID from sites that are not yours.
7. A gap between Google Ads clicks and GA4 sessions
If you run paid campaigns, compare clicks in Google Ads against google/cpc sessions in GA4 for the same date range. Small discrepancies are normal. A large, consistent gap suggests a slice of the clicks you paid for never became real visits, which is a click fraud question rather than an analytics question. Our click fraud detection guide covers this cross-referencing method in depth, and the ClickGuardian glossary explains any unfamiliar terms you meet along the way.
How to filter bot traffic in Google Analytics
Filtering bot traffic in Google Analytics means excluding it from your reports so your data is readable again. GA4 gives you a handful of tools for this, and it is worth being clear about what each one can and cannot do.
Define internal traffic and IP filters. In Admin → Data streams → Configure tag settings → Define internal traffic, you can create rules that mark traffic from specific IP addresses, then activate a filter under Admin → Data settings → Data filters to exclude it. This works well for excluding your own office and any contractor who works on your site. It is much weaker against real bot networks, which rotate through thousands of residential IP addresses precisely so that IP-based rules cannot keep up.
List unwanted referrals. In the same tag settings area, “List unwanted referrals” lets you name spam domains so they stop appearing as referral sources. This tidies up the referral spam problem quickly and is worth ten minutes of anyone’s time.
Use comparisons and segments for the history you cannot clean. GA4 data filters only apply from the moment you create them. They never clean historical data, and a bot wave from last month is in your reports permanently. The practical workaround is to build comparisons or Exploration segments that exclude the suspect city, source or device profile, so your month-on-month reporting is not distorted by a spike you already understand.
Keep expectations honest. Filtering changes what you see, not what happens. A filtered bot still visited your site, still hit your server, and if it arrived through a paid ad, you were still charged for the click. This distinction matters enormously and it is the point most GA4 filtering guides stop short of. If your problem is messy reports, filters fix it. If your problem is bots interacting with things that cost money, filters merely hide it. Our guide to stopping fake and invalid traffic on your website covers the site-wide defences that go beyond reporting.
What Google Analytics cannot do about bot traffic
Google Analytics is a measurement tool, not a defence. GA4 cannot block a bot from visiting your site, cannot stop it clicking your ads, and cannot refund the money a fraudulent click cost you. It can only help you notice.
That limitation is not a criticism of GA4, which was never designed to be a firewall. But it leads to a trap we see small businesses fall into repeatedly: treating a clean-looking Analytics property as evidence that there is no bot problem. After an afternoon of filtering, the charts look healthy, the anomalies are hidden, and the invoices from Google Ads have not changed by a penny.
Google Ads does run its own, separate invalid click filtering, and advertisers are not charged for the clicks it catches. But Google’s own system is built to protect the auction ecosystem as a whole rather than your budget specifically, and the gap between what it catches and what gets through is exactly where sophisticated bots operate. We looked at that gap in detail in why Google’s invalid click protection is not enough. There is also a newer wrinkle: legitimate AI agents and agentic browsers now visit websites on behalf of real users, and their fingerprints in your analytics look nothing like the traditional bots the filters were trained on. We explored what that means for advertisers in our piece on AI agent traffic and Google Ads.
The honest summary: GA4 identification tells you that you have a bot problem. It cannot tell you which clicks you paid for were fake, and it cannot stop the next one.
When bot traffic in Google Analytics means your ad budget is at risk
Bot traffic becomes a financial problem the moment it overlaps with your paid campaigns. A scraper reading your blog for free is an annoyance. A bot clicking your £8 emergency call-out ad is a theft, repeated daily.
The overlap is bigger than most advertisers assume. Integral Ad Science measured a 10.9% fraud rate on campaigns running without anti-fraud technology, roughly fifteen times the rate on protected campaigns, and the wider benchmarks collected on the ClickGuardian click fraud statistics page point the same direction year after year. For home services businesses, the exposure is amplified by high costs per click and tight local targeting: a modest number of fake clicks on a plumbing campaign does disproportionate damage to a £1,000 monthly budget.
So once your GA4 checklist has confirmed suspicious traffic, the practical question is not “how do I filter this?” but “how much of this am I paying for?”. A reasonable first step is to put your own spend, cost per click and industry into the ClickGuardian ROI calculator and see what your likely exposure looks like in pounds rather than sessions.
If the number justifies acting, this is the point where a dedicated layer earns its keep. ClickGuardian’s bot traffic detection analyses the behavioural, network and repetition signals of every visitor to your ads in real time, scores each one, and blocks the sources that keep coming back, which is exactly the work GA4 reports cannot do for you. Identification in Google Analytics and protection on your paid traffic are not competing approaches. The first tells you there is a problem, the second stops it costing you money.
Frequently Asked Questions
Does Google Analytics filter out bot traffic automatically?
Google Analytics automatically excludes traffic from known bots and spiders in all GA4 properties, using Google’s own research combined with the IAB International Spiders and Bots List. This filtering cannot be disabled and Google does not report how much traffic it removed. However, it only covers known, declared bots. New bots, sophisticated scrapers, headless browsers and click farm traffic routinely pass through and appear in your reports as ordinary sessions.
How do I know if my website traffic is bots?
The most reliable signs of bot traffic in Google Analytics are sessions with average engagement time close to zero, sudden spikes in direct or unassigned traffic, visitors concentrated in cities or countries you do not serve, uniform technical fingerprints such as identical outdated browsers, and referral sources you do not recognise. No single sign is proof by itself. Several appearing together across the same date range gives you a confident diagnosis.
Can Google Analytics block bot traffic?
No. Google Analytics is a reporting tool and cannot block any visitor from reaching your website or clicking your ads. GA4 filters only change what appears in your reports. Blocking bots requires action at other layers: server or firewall rules for site traffic, and a click fraud protection service such as ClickGuardian for paid traffic, which can exclude fraudulent sources from seeing your Google Ads at all.
Why did my direct traffic suddenly spike in GA4?
A sudden spike in direct traffic in GA4 with no matching marketing activity is most commonly caused by bot traffic, because bots typically arrive with no referrer information and get bucketed as direct. Check the spike’s average engagement time, geography and device profile. If engagement is near zero and the traffic clusters in one location or one technical configuration, treat it as automated rather than as a mysterious surge in brand interest.
Does bot traffic in Google Analytics mean I am paying for fake ad clicks?
Not automatically, but it is the right question to ask. Bot traffic on organic or direct channels costs you nothing directly. The moment bot sessions appear under paid channels such as google/cpc, every one of them represents budget you spent on a visitor who was never a customer. Google Ads filters some invalid clicks, but its protection has well-documented gaps, so compare your Google Ads click counts against GA4 paid sessions and use a traffic quality tool if the gap is significant.
Last updated: August 2026. For the cross-referencing method that ties paid clicks to analytics sessions, see the technical guide to detecting click fraud. For the wider category this traffic belongs to, see what is invalid traffic? and how to stop fake and invalid traffic on your website, and for the newest threat, how AI bots drain Google Ads budgets. For the sourced numbers behind this article, see the click fraud statistics page. To estimate what invalid traffic is costing your own campaigns, use the ClickGuardian ROI calculator.
Written by ClickGuardian
Click Fraud Protection Experts
ClickGuardian helps businesses protect their ad spend from click fraud using AI-powered detection and real-time blocking. Founded by advertisers who experienced click fraud first-hand, we now protect over 2,000 businesses globally.