Bot traffic is any visit, click or form submission made by automated software rather than a person. Some bots are useful, such as Googlebot fetching your pages for search; others scrape content, submit spam enquiries or click ads. Either way they are not customers, and when they reach your analytics or ad accounts they distort the figures you make decisions on.
How bot traffic works
Bots fall into a few broad kinds:
- Search engine and AI crawlers Which fetch pages to index them or feed AI tools. Many never run your analytics code, and GA4 excludes the well-known ones anyway, so they mostly appear only in server logs.
- Monitoring and SEO tools Such as uptime checkers and site auditors, some of which do run your tags.
- Spam and fraud bots Which fill in contact forms, create fake accounts or click ads.
- Headless browsers Automated copies of an ordinary browser that behave enough like a person to load your tags and appear in reports.
GA4 automatically excludes traffic from known bots and spiders, using Google’s own research and an industry list of identified bots. You cannot switch this off or see how much it removed. Anything not on those lists, particularly headless browsers, gets through and is counted as a real visit. The old problem of ghost spam, fake hits sent straight to analytics without visiting the site, is much rarer in GA4, because sending data that way now requires a secret key.
Why it matters
Bot visits inflate sessions and drag down engagement rate, which can make a healthy page look weak or a weak month look busy. Bot clicks on ads cost money: Google filters out the invalid clicks it detects so you are not charged for them, but no filter catches everything.
The most expensive kind for a UK lead-generation business is the bot that fills in your enquiry form. If that submission counts as a conversion, Smart Bidding learns to buy more of whatever traffic produced it, and the account drifts towards cheap placements that generate fake leads. The cost per lead looks better while real enquiries fall.
Common mistakes
- Assuming GA4’s built-in exclusion catches everything. It only covers bots already known.
- Counting every form submission as a key event, with no check that the lead was real.
- Trying to delete bot sessions from GA4. Processed data cannot be removed, and GA4’s data filters only cover internal and developer traffic, so you work around bot data in analysis rather than erase it.
- Blocking all bots in robots.txt or a firewall, including the search crawlers you need in order to be found.
- Mistaking your own team’s visits for bots, or the reverse. An internal traffic filter takes staff visits out of the picture.
How to act on it
Learn what bot traffic looks like on your site. Typical signs are a sudden jump in direct or referral visits, sessions from a city or country you do not serve, near-zero engagement time, one page receiving all of it, or many visits from the same screen size and browser. In GA4, build a comparison or an exploration segment to isolate that traffic, and exclude it from Looker Studio reports so decisions rest on human visits.
For ads, review placement and search terms reports regularly, exclude apps and sites that send clicks with no engagement, and keep an eye on the Invalid clicks column in Google Ads. Protect forms with a hidden honeypot field or a challenge such as Cloudflare Turnstile, validate submissions on the server, and only report a lead to Google Ads once it passes those checks. For crawlers, log file analysis shows which bots visit and how often. Keeping fake clicks and leads out of the data that bidding learns from is a routine part of PPC management.
