Fraud Analyzer
Fraud Analyzer is a basic overview of traffic and conversion patterns that OffZio has flagged. It groups possible issues such as duplicate clicks, bot-like user agents, targeting rejections, and GEO concentration so a Network Admin can see where to look next.
It is not an advanced fraud engine. It does not prove that a publisher is fraudulent, and it is not accurate enough to use as the only reason to pause traffic, cut payouts, or reject conversions.
Note: Do not trust this report 100%. Do not optimize campaigns, payouts, or publisher status from these numbers alone. Use Fraud Analyzer only to understand possible patterns. Then verify in the Conversion Report, Other Reports, campaign targeting, and the publisher’s actual traffic quality before you take action.
What Fraud Analyzer is for
Use this page as a starting point, not a verdict:
- See how many events were flagged in the selected period.
- See which rule types fired (for example, duplicate clicks vs targeting rejections).
- Notice GEO concentration or publishers that appear often in alerts.
- Open an alert and then check the real click and conversion data elsewhere.
Do not use it to:
- Automatically decide who to pay or who to ban.
- Scale or kill a campaign based on Risk Score or “Revenue at Risk.”
- Treat “100% fraud” on a small sample as proof of invalid traffic.
Tip: If Fraud Analyzer and the Conversion report disagree, trust the ledger and campaign settings more than this overview. Investigate first.
Who can use Fraud Analyzer
Only a Network Admin should review fraud alerts or change detection rule toggles. Confirm your role on the sidebar profile card if you are unsure. It should show a name and role such as OffZio Admin · Network Admin.
How to open Fraud Analyzer
- Sign in as a Network Admin.
- In the left sidebar, click Fraud Analyzer. It is a standalone menu item near Reports.
The page title is Fraud Analyzer. The subtitle reads Real-time fraud detection & prevention. Top-right actions are Export and Refresh. Totals follow the selected period (for example, July 13 to August 11).
KPI cards
Five cards summarize the selected period. They may also show a percentage versus the prior period. Read them as hints, not as billed or paid amounts.
- Fraud Events — How many times a detection rule flagged something. One click can contribute to a count; the number is not “confirmed fraud cases.”
- Bot Traffic — Clicks the bot rule treated as bot-like (user-agent or CDN signals). Shared browsers and unusual devices can look similar.
- Unique IPs — Distinct IP addresses seen in the flagged set. A low unique-IP count can mean concentration — or a small test.
- Revenue at Risk — Revenue associated with flagged activity. This is not money you should automatically withhold.
- Suspicious GEOs — How many countries appear as elevated invalid-traffic hotspots in this period.
Note: Do not trust these KPIs 100% for decisions or optimization. A high Fraud Events count or a large Revenue at Risk figure only means “look here.” Confirm in the Conversion report and campaign settings before you reject conversions, pause a publisher, or change payouts.
How to use these numbers
Work in this order:
- Read the cards and widgets to see what kind of flag is common (duplicate, bot, targeting, GEO).
- Open the related alert or publisher.
- Verify clicks and conversions in Other Reports and the Conversion Report.
- Check campaign targeting (device, OS, GEO, and similar limits) so a “rejection” is not just traffic outside the offer rules.
- Only then reject a conversion, mark it pending, or talk to the publisher.
Note: Again: do not optimize from this page alone. Risk Score, fraud %, and Critical labels are informational. They can be wrong on low volume, shared IPs, and legitimate retargeting.
Fraud by Type
This widget shows how flagged events break down by rule type. Examples you may see:
- Duplicate Clicks — Repeat clicks from the same IP on a campaign. Can show as most or all of the events in a small sample (for example, 100%).
- Bot Traffic — User-agent or CDN signals that look automated.
- Rejected Clicks — Clicks that did not pass campaign targeting or related filters.
- Rejected Conversions — Conversions rejected manually or by rules.
For illustration only, a period might show 22 events that are all Duplicate Clicks. That does not mean 22 confirmed fraud cases. It means the duplicate rule fired often — which is common when one person or one office IP tests a link.
GEO Hotspots
GEO Hotspots lists countries with elevated invalid or flagged traffic. A country can be labeled Critical with a high percentage. For illustration only, the US might appear as Critical with a very high share of flagged events.
Tip: If most of your real traffic is supposed to be from that country, a “hotspot” may simply be where the campaign runs. Compare to Campaign performance grouped by Country (GEO) before you block a GEO.
Top Suspicious Publishers
This list ranks publishers that appear often in flags. Typical fields:
- Publisher name and id
- Event count
- Blocked count
- Risk Score
For illustration only, a row might show a team such as demoaff with a handful of events. Never pause a top publisher from this list alone. Top volume partners naturally produce more flags. Treat Risk Score as a hint, then verify their Conversion report and traffic quality.
Fraud Alerts
The alerts list is the event-level view of flags. Filters include All, Critical, High, Medium, and Low, plus search and additional filters.
Each alert typically shows:
- Alert ID — For example,
FRD-1-1. - Publisher
- Campaign
- Type — Which detection idea fired.
- Risk / Status — For example, Critical and Flagged.
- Click counts and a fraud %
- Associated revenue
- A view-details action
Note: Critical + Flagged means the basic rules scored the pattern highly. It is still not proof. Open details, then check the same publisher and campaign in reports.
Activity Log
The Activity Log shows recent moderation activity related to fraud review. If nobody has taken action yet, the page may show No recent moderation activity. That is normal.
Detection Rules
Further down, Detection Rules lists the basic checks. Each rule has a short description, a trigger count for the selected period, and an on/off toggle. Green status dots and trigger counts are informational only.
A Manage Rules link opens rule management. This article does not invent extra settings screens. Treat toggles as a basic way to turn a check on or off — not as a full custom rule builder.
- Bot Traffic Detection — Flags clicks identified as bots by user-agent or CDN signals.
- Duplicate Click Detection — Detects repeat clicks from the same IP on a campaign.
- Targeting Rejection Filter — Monitors clicks rejected because they did not meet campaign targeting (device, OS, interest, and similar limits).
- Conversion Rejection Monitor — Tracks conversions rejected manually or by rules.
- GEO Hotspot Monitor — Highlights countries with elevated invalid traffic.
Tip: If a rule is on and the trigger count is high, that only means the check ran often. Turning a rule off hides that pattern; it does not make traffic “clean.”
How to investigate a flag
- Open Fraud Analyzer and note the period.
- Open the alert (view details) or the publisher named in Top Suspicious Publishers.
- Write down the publisher, campaign, and rule type (duplicate, bot, targeting, conversion rejection, or GEO).
- Open Reports → Publisher or Campaign for the same dates. Compare Gross Clicks, Unique Clicks, and Clicks.
- Open the Conversion Report. Filter to that publisher and campaign. Check status, duplicate, click id, and whether conversions are already invoiced.
- Open the campaign and confirm targeting (GEO, device, OS). Targeting rejections are often “wrong traffic,” not “fraud.”
- Only after that, reject or mark pending specific conversions, ask the publisher for source details, or pause traffic if your process requires it.
Note: Do not skip to pausing the publisher from Fraud Analyzer. The Conversion report is where you change billing eligibility for a single event.
Common false positives
These patterns often look “fraudulent” on a basic IP or user-agent check and are still legitimate:
- Same office IP — Staff testing links, or a publisher’s team on one connection, creates duplicate-click flags.
- NAT / shared router — Many users behind one public IP look like repeat clicks.
- Shared mobile carrier IP — Carrier-grade NAT makes thousands of users appear as one IP.
- Retargeting and repeat visits — The same person can click an offer more than once.
- Low volume — 2 flagged clicks out of 2 is “100%” and is statistically meaningless.
- Targeting mismatch — Device or GEO filters reject clicks that are simply off-offer, not bots.
Best practices
- Treat Risk Score, Critical, and Revenue at Risk as hints only.
- Never pause a top publisher from this page alone.
- Never change payouts or invoice eligibility from Fraud Analyzer without checking the Conversion report.
- Compare Unique IPs and Gross vs Clicks on Other Reports before you call traffic invalid.
- Ask whether the campaign’s GEO and device rules explain the flag.
- Export if you need a snapshot for a teammate; still verify before acting.
Was this article helpful?