Network and ASN fraud
Every visit arrives from a specific internet network, and AdPix labels it: data center, proxy, VPN, home ISP or mobile carrier. The Networks tab tells you which networks your paid budget is burning in. It is a premium feature.
Why the network needs its own layer#
A visitor can clear cookies, rotate their IP and spoof their device. What is hard to change is the network they connect from: the data center renting them a virtual server, the mobile carrier that issued the SIM, the residential-proxy company that sold their address. That is why AdPix scores a separate layer at network level.
It answers a question no other report answers: which networks is my ad budget burning in.
Fraud protection and the Networks tab are not open on the free plan. If your active property is on the free plan you get an upgrade card instead of the page. See plans and entitlements.
How the network is attached to an event#
This happens at collection time. AdPix resolves the IP to an ASN number, the name of the organisation that owns the network, and a network type. The type comes from a list of known ASNs first, and falls back to a guess from the organisation name:
| Network type | Label on the page | Meaning |
|---|---|---|
datacenter_hosting |
Data center / hosting | virtual servers and cloud — nobody browses from there |
vpn |
VPN | tunnelling service |
proxy |
Proxy | public proxy |
tor |
Tor | the Tor network |
residential_proxy |
Residential proxy | a real home address rented out to bots |
residential_isp |
Residential ISP | fixed home broadband |
mobile_carrier |
Mobile carrier | mobile data |
business |
Business | corporate networks and backbone |
unknown |
Unknown | network resolved, class not determined |
The first five are inherently high-risk for paid traffic. The next three carry real people, and the page colours them neutrally.
The network number is never used as a key for identifying a user and never overwrites a deterministic identity edge such as email or phone. It is a fraud-detection input only.
The scoring grain: network × channel#
At network level, each scored row is one network within one channel. The reason is that the same network can be entirely normal in organic traffic and clearly suspect on one paid channel — and it is only the second one you want to exclude.
Two entry conditions apply: the network must have been resolved, and it must have at least five sessions in the range. Below that volume, nothing is scored.
After the base score — the same detector ensemble and the same severity tiers as the overview — four network overlays are applied:
| Overlay | When it fires | How much it does |
|---|---|---|
| Known-fraud denylist | the ASN is on the list and the network does not convert | raises the score and lifts the tier to at least potential; only reaches confirmed with zero conversions and at least twenty sessions |
| Network-type prior | the type is one of the five high-risk classes and the network does not convert | nudges the score only — never a verdict on its own |
| Sanctioned origin | at least half the sessions come from a sanctioned country that is not your own market | review at most |
| Geo mismatch | at least seventy percent of sessions fall outside the property's declared target countries | review at most |
The geo-mismatch overlay is active only when an advertising geo target has been declared for the property; if none is declared the rate stays at zero and no verdict comes out of it. That default is deliberate, so no false positive is manufactured on this path before you have stated a target.
The precision shields#
This is the most important section on the page, particularly if your audience is domestic.
- A network that converts is never flagged. The bar is 2%, and it is applied ahead of every overlay: the denylist, the network-type prior, sanctioned origin and geo mismatch all skip a converting network.
- Mobile carriers, residential ISPs and business networks are never flagged on model opinion. For those three classes the ceiling is review unless a hard structural signal also fires: a known-fraud denylist match, a high share of data-center and proxy traffic, or a dwell-variance collapse (every session lasting almost exactly the same time).
- Sanctioned origin is not a hard signal. It is deliberately kept out of the hard set so that it can never break the shield above. Genuine cross-border fraud is confirmed by the structural signal that comes with it, not by the country it came from.
- Your own market is never sanctioned origin. AdPix derives each property's home market from its own data: the country supplying at least half the sessions. No configuration is needed and nothing about any one country is special — the same rule works for every market.
- The absence of conversions is never on its own a reason to flag.
The practical consequence for a business serving a domestic audience: the country's major fixed and mobile operators are recognised as residential or mobile at collection time, they are absent from the built-in known-fraud denylist, and real customer traffic from them is not flagged for its network class or a low conversion rate. What gets flagged is behaviour, not nationality.
The page says the same thing itself: "This is about the networks — not the people or any country."
What the Networks tab shows#
Top to bottom:
The hero card also prints a benchmark: typical invalid traffic runs 10–20% of paid spend, and anything well above that is worth investigating. If your spend spans several currencies the page warns that the totals may mix rates.
The network detail drawer#
Clicking any network opens Network detail. This is what to read before you block anything or open a dispute:
- Why this network was flagged — the list of signals that actually fired. If none did, the page says plainly that no specific signals were recorded.
- The network's numbers — distinct IPs, distinct fingerprints, GIVT rate, sanctioned-geo rate, network reputation and fraud score.
- Behavior — average dwell, dwell uniformity (CV) and bounce rate. A low dwell uniformity means every session lasted about the same time; humans do not behave that way.
- Recent sessions — a sample of up to a hundred recent sessions with time, source, device, country, dwell, page count, conversion and the IP
/24block. The page's own hint is explicit: a burst of many short, non-converting sessions from few IPs is the click-fraud shape. - Download evidence (CSV) — the evidence packet for that network, for a dispute file.
If the network columns are empty#
Network enrichment needs an ASN database on the server, and it is deliberately optional and non-fatal: if it is missing, collection works exactly as before and only the network columns stay empty. In that state the Networks tab has nothing to show while the rest of Fraud Protection works normally. On a self-hosted installation, check this with whoever operates the platform.
Two other empty states are fine: a network with fewer than five sessions in the range is not scored at all, and the message "No flagged networks for this range — your paid traffic looks clean." means exactly what it says.
Where to go next#
Once you have identified a network, two things remain: excluding it from ad targeting, and claiming the money back. Both are in blocklist and refund evidence. To understand how the waste figure is built, read wasted spend.
Frequently asked questions#
Does traffic from mobile carriers and home ISPs get flagged?
Not on network type or on the absence of conversions. Those networks are recognised as residential or mobile at collection time, they are absent from the known-fraud denylist, and in scoring they never go past review unless a hard structural signal also fires — a denylist match, a high share of data-center traffic, or a collapse in dwell-time variance.
Why isn't traffic from my own country counted as sanctioned origin?
Because that overlay is cross-border only. AdPix infers each property's home market from its own data — the country supplying at least half the sessions — and excludes it. For a business selling domestically, the sanctioned-origin rate is zero.
The Networks tab is empty. What is wrong?
Three common causes. First, network enrichment needs an ASN database on the server; without it the network columns are never populated. Second, a network with fewer than five sessions in the range is not scored at all. Third, wasted spend needs imported ad cost; with no cost the hero number stays at zero.
Does the ASN affect user identification?
No. The ASN is a fraud feature only. It is never an identity key and it never overwrites a deterministic identity edge such as email or phone.
Thanks — your feedback helps us improve the docs.