Your link can rack up a dozen clicks before a single human sees it. Share it in Slack and the count jumps by three; post it on X and it climbs again. None of those were people — they were bots fetching your URL automatically. If your analytics count them, your numbers are inflated, and every decision you make from those numbers is a little bit wrong.
This is the biggest reason two analytics tools show wildly different click counts for the same link, and it is the honest core of a topic that usually gets scaremongered: most click inflation is not malicious fraud — it is infrastructure. Crawlers, scanners, and preview bots are just doing their jobs. Here is how to tell the machines from the people.
Click fraud vs bot traffic vs invalid clicks
Three terms get used interchangeably and mean different things. Getting them straight is the whole game:
- Bot traffic — any automated request, and mostly benign: link-preview crawlers, security scanners, search engines, uptime monitors. It inflates counts, but nobody is trying to hurt you.
- Invalid clicks — an ad-platform term for clicks Google or Meta decides not to bill you for, whether from bots, accidental double-taps, or suspicious patterns. It is about billing, not intent.
- Click fraud — the deliberate, malicious version: someone clicking to drain a competitor's ad budget, or to inflate their own affiliate or publisher payouts. It is real, but it is the smallest slice of what inflates a normal link's numbers.
Most people searching for "click fraud" are really looking at the first two. If your Monday-morning report shows more clicks than you expected, the culprit is almost always benign bots — not an attacker.
Where the fake clicks come from
When you post a link almost anywhere, machines reach it before humans do. Here is the full cast, why each one hits your link, and whether a good analytics tool can filter it out:
| Source | Why it hits your link | Filterable? |
|---|---|---|
| Link-preview crawlers (Slack, iMessage, WhatsApp, Discord, X) | Rendering the preview card | Yes — known user agents |
| Email security scanners (Proofpoint, Mimecast, Microsoft Defender) | Pre-clicking every link to check for malware | Mostly |
| Search & SEO crawlers (Googlebot, Bingbot, Ahrefs) | Indexing the web | Yes |
| AI crawlers (GPTBot, ClaudeBot, PerplexityBot) | Training and retrieval | Yes |
| Uptime monitors | Someone's health check pinging the URL | Yes |
| Scrapers & competitive intel | Harvesting links and data | Partly |
| Actual click fraud | Ad-budget drain, affiliate fraud | Hard — needs behavioural analysis |
The one almost nobody explains is the email scanner. A single B2B email send can generate a click on every link from the recipient's corporate security appliance before any human opens the message. Proofpoint, Mimecast, and Microsoft Defender all "detonate" links in a sandbox to check for malware. That is why B2B email click-through rates look implausibly good — a chunk of every send is a security robot, not a prospect.
Why inflated numbers cost you
It feels good to see a big number, but bot-padded stats make you worse at your job:
- You misjudge which channel works. If one platform's preview bot hits your link five times and another's hits once, the first looks like the better channel when it is not.
- You misread timing. A spike that is really the preview crawler looks like an audience that is not there.
- You cannot compare campaigns when the bot "tax" is different for each one — which also quietly corrupts your UTM attribution, since the tagged link's count includes machines the campaign never reached.
Honest analytics means smaller numbers and better decisions. A tool that proudly shows more clicks than a competitor may simply be counting more bots.
How to tell if your clicks are real
You do not need special tools to catch obvious inflation. Run these six checks:
- Time-clustering. Dozens of clicks in the same second is machine behaviour — humans do not arrive in a synchronised burst.
- Zero dwell time. A click with no time spent on the destination is usually a fetch-and-leave bot.
- Datacenter networks. Clicks from cloud providers (AWS, Google Cloud, Azure) rather than residential ISPs are automated; residential connections are probably human.
- Device or OS mismatch. Desktop clicks on a print-QR campaign, or a wave of identical user agents, do not match how real people would reach that link.
- Clicks before you published. If the count moved before you shared the link anywhere, that is scanners or crawlers, full stop.
- Geography that does not fit. A burst from a country you do not market to, with no referrer, is almost always automated.
If your shortener cannot show you these breakdowns at all, that is its own answer — you cannot trust a number you cannot inspect. We tested which shorteners even let you see this data in our URL shortener comparison. The same problem applies to scans, not just clicks: a printed QR code is fetched by the very same crawlers, which is why tracking QR-code scans needs the same filtering.
What we filter, and what we do not
Honesty about the limits is more persuasive than a claim of perfect detection, so here is exactly where INBIO draws the line.
What we exclude from your click counts: known link-preview crawlers, the major email security scanners, search and AI crawlers, and uptime monitors — identified by their user agents and network signatures. These never count against your plan and never appear in your primary stats, though you can toggle them into view, because hiding data is not the same as filtering it.
What we cannot reliably catch: a bot that perfectly imitates a human browser from a residential connection, and deliberate click fraud spread across many IPs to look organic. Detecting those needs behavioural fingerprinting we deliberately do not do — because we never store a visitor's raw IP address. We truncate and hash it, so you see "someone in Berlin, on mobile, via LinkedIn," never a person's identity. Filtering without fingerprinting means we miss the cleverest bots; we think that is the right trade.
Click fraud in paid advertising
If you run ads, "invalid clicks" is the version of this you will meet most. Google and Meta run their own filters and retroactively credit you for clicks they judge invalid — which is why your ad dashboard, your analytics, and your shortener will never show exactly the same number. That is expected, not a bug: each measures a slightly different thing at a different point in the funnel.
Use the ad platform's numbers for billing and bid decisions, and your own bot-filtered click and attribution data to judge whether the traffic actually did anything once it landed. When the two disagree wildly, that gap is usually bots the platform did not bill you for — useful signal, not a reason to panic.
The takeaway
Bots are a normal, unavoidable part of sharing links — the goal is not to eliminate them, it is to not count them as people. Separate click fraud (rare, malicious) from bot traffic (common, benign) from invalid clicks (an ad-billing term), pick analytics that filter the bots by default and show humans and machines separately, and run the six checks above when a number looks too good. Smaller, honest numbers beat big, flattering ones every time. Preview bots are worst on social, so if that is where you share, short links for Instagram come with the filtering built in.
Want click data you can trust? Shorten a link with INBIO — free, with bot-filtered analytics on every link. New to short links? Start with our step-by-step guide to shortening a URL.