Reading the Signals: How to Identify Fraudulent Traffic in Pay-Per-Call and Lead Gen
Fraud in pay-per-call and lead gen rarely looks like fraud at first. It looks like a source that converts a little too well, calls that connect but never qualify, and leads that arrive in clean batches at odd hours. This is how to tell the difference between traffic worth paying for and traffic engineered to drain your budget.
The Fraud Types You Will Actually See
Different verticals attract different schemes. Here are the ones that show up in auto, health, home services, and CPL/CPS flows.
Bot and non-human traffic
Automated scripts fill forms or fire clicks at scale. Modern bots vary click timing, rotate IPs, and mimic scroll and typing behavior to pass basic filters. They produce volume with no downstream intent — leads that never answer, calls that never qualify.
Click spam and click injection
The affiliate fires large numbers of low-cost or fake clicks to claim attribution on conversions they did not drive. Click injection is the mobile variant: a click fired moments before an action so the fraudster steals credit from the real source.
Lead fraud — fabricated and duplicate
Fabricated leads use invented, synthetic, or stolen PII. Duplicate leads are old or already-sold records resubmitted with minor edits to collect a second payout from any buyer who skips deduplication. Both are common in CPL health and insurance.
Call fraud — IVR probing and repeat callers
On pay-per-call, fraud means calls engineered to bill without buying intent. A single bad actor can fire 20+ calls an hour, sometimes hundreds, from withheld or spoofed numbers. Repeat callers, IVR probing, and coached callers who hang up the moment the billable duration threshold is crossed are the usual patterns.
Domain spoofing and geo masking
Spoofing presents lookalike or misrepresented domains so traffic appears to come from a placement it does not. Geo masking uses proxies and VPNs to make out-of-area traffic look in-area — a problem when an advertiser only buys specific states.
Incentivized traffic
Users are paid, bribed, or tricked into submitting a lead or placing a call. Volume looks fine; contact and conversion rates collapse because the user never wanted the product.
Red Flags in the Data
You do not need to watch a fraudster work. The numbers expose them.
- Conversion rate anomalies. A source converting far above network baseline is suspicious, not impressive. Sudden surges from one source, site, or IP range are a standard fraud signature.
- Short call durations clustered at the billable threshold. Calls that consistently end seconds after they become payable are coached or fabricated.
- High duplicate rate. A source feeding repeated phone numbers, emails, or near-identical records is recycling leads.
- Mismatched geo and IP. A lead claiming a state while the IP resolves elsewhere — or to a known datacenter or VPN range — signals masking.
- Low contact and answer rate. Leads that never pick up and calls that never qualify point to bots or incentivized traffic.
- Suspicious time-of-day patterns. Steady overnight volume, perfectly even pacing, or bursts with no human rhythm indicate automation.
- Identical device fingerprints. Many conversions from the same device or IP in a short window means a device farm, not a market.
- Chargeback and refund spikes. On CPS, an affiliate with refund or chargeback rates well above the floor is sending low-quality or fraudulent buyers.
No single flag is proof. Two or three together on the same source is.
How to Detect It
Detection has to happen at the source level and per record — aggregate dashboards hide the bad sub-IDs inside good-looking totals.
Source-level tracking
Tag every click, call, and lead with the originating source and sub-ID. Measure conversion, duplicate, contact, and qualification rates per source, not just per campaign. Fraud concentrates; isolate it.
Call analytics
For pay-per-call, score calls on duration, repeat-caller frequency, withheld or spoofed caller ID, time between calls, and IVR behavior. Flag clusters of short calls and repeat numbers before the call routes to the advertiser.
Lead validation and verification
Validate phone and email at ingestion. Check geo against IP. Run records against your own database to catch duplicates and resubmissions. Use behavioral signals — typing cadence, mouse movement, headless-browser detection — to separate humans from bots.
TCPA consent trails
Require per-lead proof of consent, not assurances. Capture and store the consent record, IP, source URL, and timestamp. Tools like TrustedForm/ActiveProspect and Jornaya provide verifiable, tamper-resistant trails. Keep records for at least four years. Missing or reused consent is a fraud and liability flag at once.
IP and device fingerprinting
Score traffic against IP reputation, datacenter and proxy/VPN lists, and device fingerprints. Repeat fingerprints across "different" leads expose farms.
Third-party scrubbing
Scrub against the national DNC registry at least every 31 days, plus state lists, plus your internal suppression list. Use third-party fraud scoring as a second opinion on sources you cannot fully see.
How Namastey Handles It Operationally
Vetting tools matter less than when you apply them. Our process front-loads the checks.
- Source review before launch. Every publisher and traffic source is reviewed before it sends a single call or lead. We ask where the traffic comes from, how consent is captured, and for per-source transparency — not "trust us."
- Test caps. New sources start under volume caps. We measure contact rate, call duration, duplicate rate, and qualification against the offer's baseline before lifting limits. Bad sources get caught on a small sample, not a full spend.
- Duplicate windows. Leads and calls are deduplicated within defined time windows, so recycled and resubmitted records do not bill twice.
- Reporting by source. Advertisers and publishers see performance broken out by source and sub-ID. When quality drops, we trace it to the exact origin and pause it — instead of penalizing clean traffic in the same campaign.
Fraud detection is not a one-time filter. It is source review before launch, scored traffic during the run, and per-source reporting that makes the bad actor obvious. Catch it early, measure it per source, and you pay for traffic that performs.