Skip to content
AdPixDocsSearch the docsEnglishOpen console

Network and ASN fraud

Every visit arrives from a specific internet network, and AdPix labels it: data center, proxy, VPN, home ISP or mobile carrier. The Networks tab tells you which networks your paid budget is burning in. It is a premium feature.

Why the network needs its own layer#

A visitor can clear cookies, rotate their IP and spoof their device. What is hard to change is the network they connect from: the data center renting them a virtual server, the mobile carrier that issued the SIM, the residential-proxy company that sold their address. That is why AdPix scores a separate layer at network level.

It answers a question no other report answers: which networks is my ad budget burning in.

Premium feature

Fraud protection and the Networks tab are not open on the free plan. If your active property is on the free plan you get an upgrade card instead of the page. See plans and entitlements.

How the network is attached to an event#

This happens at collection time. AdPix resolves the IP to an ASN number, the name of the organisation that owns the network, and a network type. The type comes from a list of known ASNs first, and falls back to a guess from the organisation name:

Network type Label on the page Meaning
datacenter_hosting Data center / hosting virtual servers and cloud — nobody browses from there
vpn VPN tunnelling service
proxy Proxy public proxy
tor Tor the Tor network
residential_proxy Residential proxy a real home address rented out to bots
residential_isp Residential ISP fixed home broadband
mobile_carrier Mobile carrier mobile data
business Business corporate networks and backbone
unknown Unknown network resolved, class not determined

The first five are inherently high-risk for paid traffic. The next three carry real people, and the page colours them neutrally.

ASN is a feature, not an identity

The network number is never used as a key for identifying a user and never overwrites a deterministic identity edge such as email or phone. It is a fraud-detection input only.

The scoring grain: network × channel#

At network level, each scored row is one network within one channel. The reason is that the same network can be entirely normal in organic traffic and clearly suspect on one paid channel — and it is only the second one you want to exclude.

Two entry conditions apply: the network must have been resolved, and it must have at least five sessions in the range. Below that volume, nothing is scored.

After the base score — the same detector ensemble and the same severity tiers as the overview — four network overlays are applied:

Overlay When it fires How much it does
Known-fraud denylist the ASN is on the list and the network does not convert raises the score and lifts the tier to at least potential; only reaches confirmed with zero conversions and at least twenty sessions
Network-type prior the type is one of the five high-risk classes and the network does not convert nudges the score only — never a verdict on its own
Sanctioned origin at least half the sessions come from a sanctioned country that is not your own market review at most
Geo mismatch at least seventy percent of sessions fall outside the property's declared target countries review at most

The geo-mismatch overlay is active only when an advertising geo target has been declared for the property; if none is declared the rate stays at zero and no verdict comes out of it. That default is deliberate, so no false positive is manufactured on this path before you have stated a target.

The precision shields#

This is the most important section on the page, particularly if your audience is domestic.

  • A network that converts is never flagged. The bar is 2%, and it is applied ahead of every overlay: the denylist, the network-type prior, sanctioned origin and geo mismatch all skip a converting network.
  • Mobile carriers, residential ISPs and business networks are never flagged on model opinion. For those three classes the ceiling is review unless a hard structural signal also fires: a known-fraud denylist match, a high share of data-center and proxy traffic, or a dwell-variance collapse (every session lasting almost exactly the same time).
  • Sanctioned origin is not a hard signal. It is deliberately kept out of the hard set so that it can never break the shield above. Genuine cross-border fraud is confirmed by the structural signal that comes with it, not by the country it came from.
  • Your own market is never sanctioned origin. AdPix derives each property's home market from its own data: the country supplying at least half the sessions. No configuration is needed and nothing about any one country is special — the same rule works for every market.
  • The absence of conversions is never on its own a reason to flag.

The practical consequence for a business serving a domestic audience: the country's major fixed and mobile operators are recognised as residential or mobile at collection time, they are absent from the built-in known-fraud denylist, and real customer traffic from them is not flagged for its network class or a low conversion rate. What gets flagged is behaviour, not nationality.

The page says the same thing itself: "This is about the networks — not the people or any country."

What the Networks tab shows#

Top to bottom:

1
Ad spend likely wasted — the hero number, with its share of the range's total paid spend. It is built by joining flagged sessions to the ad cost you imported; with no cost imported it stays at zero. The calculation is covered in wasted spend.
2
High-risk networks — up to eight networks, ranked by waste. A network appears here when it is on the denylist, its type is inherently high-risk, it carries a high share of sanctioned-origin traffic, or — for residential ISPs and mobile carriers — it actually reached potential or confirmed.
3
Channel × network breakdown — the full table, with network, network type, channel, conversion rate and wasted spend.
4
Where spend leaks, by channel — the same money rolled up per channel, so you know which channel leaks most.
5
Block these networks — the exclusion-list export for Google Ads and Meta. This section is shown only when those exports are enabled on your installation.

The hero card also prints a benchmark: typical invalid traffic runs 10–20% of paid spend, and anything well above that is worth investigating. If your spend spans several currencies the page warns that the totals may mix rates.

The network detail drawer#

Clicking any network opens Network detail. This is what to read before you block anything or open a dispute:

  • Why this network was flagged — the list of signals that actually fired. If none did, the page says plainly that no specific signals were recorded.
  • The network's numbers — distinct IPs, distinct fingerprints, GIVT rate, sanctioned-geo rate, network reputation and fraud score.
  • Behavior — average dwell, dwell uniformity (CV) and bounce rate. A low dwell uniformity means every session lasted about the same time; humans do not behave that way.
  • Recent sessions — a sample of up to a hundred recent sessions with time, source, device, country, dwell, page count, conversion and the IP /24 block. The page's own hint is explicit: a burst of many short, non-converting sessions from few IPs is the click-fraud shape.
  • Download evidence (CSV) — the evidence packet for that network, for a dispute file.

If the network columns are empty#

Network enrichment needs an ASN database on the server, and it is deliberately optional and non-fatal: if it is missing, collection works exactly as before and only the network columns stay empty. In that state the Networks tab has nothing to show while the rest of Fraud Protection works normally. On a self-hosted installation, check this with whoever operates the platform.

Two other empty states are fine: a network with fewer than five sessions in the range is not scored at all, and the message "No flagged networks for this range — your paid traffic looks clean." means exactly what it says.

Where to go next#

Once you have identified a network, two things remain: excluding it from ad targeting, and claiming the money back. Both are in blocklist and refund evidence. To understand how the waste figure is built, read wasted spend.

Frequently asked questions#

Does traffic from mobile carriers and home ISPs get flagged?

Not on network type or on the absence of conversions. Those networks are recognised as residential or mobile at collection time, they are absent from the known-fraud denylist, and in scoring they never go past review unless a hard structural signal also fires — a denylist match, a high share of data-center traffic, or a collapse in dwell-time variance.

Why isn't traffic from my own country counted as sanctioned origin?

Because that overlay is cross-border only. AdPix infers each property's home market from its own data — the country supplying at least half the sessions — and excludes it. For a business selling domestically, the sanctioned-origin rate is zero.

The Networks tab is empty. What is wrong?

Three common causes. First, network enrichment needs an ASN database on the server; without it the network columns are never populated. Second, a network with fewer than five sessions in the range is not scored at all. Third, wasted spend needs imported ad cost; with no cost the hero number stays at zero.

Does the ASN affect user identification?

No. The ASN is a fraud feature only. It is never an identity key and it never overwrites a deterministic identity edge such as email or phone.

Build with the APIUnderstand where revenue comes from.
Was this page helpful?