Attribution and blacklist exports

How to find which source sent the bot traffic, and how to turn that into a list you can paste into an ad network.

Last updated

A percentage is not actionable

Knowing that 38 percent of your traffic was bots tells you nothing you can act on. Knowing that zone 4471 on one network was 91 percent bots, across 12,000 visits, is a decision you can make this afternoon.

Every classification carries its attribution: source, medium, campaign, sub IDs, placement, zone, creative, click ID, country, device, and hour. Those columns have been in the schema since the first migration.

How an identifier is judged

An identifier is rolled up across everything it sent in the range before it is judged, never on its worst row. Blocking a zone blocks every campaign running on it, so a zone that ran 95 percent bots under one campaign and clean under nine others is not recommended for blocking.

  • An identifier needs at least 10 events in the range before its bot share is treated as evidence rather than noise.
  • It appears on the block list at 50 percent bot traffic or above.
  • Untagged traffic is never listed. An empty identifier is not a source you can block.

Two export formats, for two different jobs

  • A plain list per field, one identifier per line. This is what you paste into an ad network block field, which is why zones, placements, and sub IDs are kept as separate lists rather than one mixed block.
  • A CSV carrying events, bot events, and bot share for each identifier. This is what you attach when you ask a network for a refund, because the verdict alone will not persuade anyone.

There is no IP blacklist, and there never will be

TrueVisit discards the raw IP address after the geographic and range lookups and never writes it to storage. There is therefore no visitor IP to export, by design rather than by omission. What you get instead are the identifiers an ad network can actually block.