Criteo logoBanner / Display
Banner / Display channel · scored 0–100

Which Criteo placements send bots and invalid traffic?

Not all Criteo traffic is equal. ValidVisit scores every visit 0–100 and pins it to the exact placement that sent it — so you can tell real humans from bots and invalid clicks, worst placements first.

validvisit · criteo cut-list
Exclude the bad publisher domain in Criteo

The buyer pastes the bad domains/app-bundle IDs (one per line, no http/https) or uploads a .txt/.csv blocklist (up to 100,000 domains per upload, 255 chars/entry) and applies it to the ad set/line item; it takes effect within ~1 hour.

Where: Commerce Growth: ad set > Refine your targeting > Placement Targeting (allow/deny websites & apps, plus a Supply Vendors toggle). Commerce Max: Shared Library > Domain/App Lists to build the list, then line item > Targeting step > Domain Lists / App Bundle Lists section to apply it
Controls in Criteo’s campaign settings
IP lists OS OS version Browser Browser version Language Device Connection

ValidVisit reports the device, OS, browser — down to the version — plus the language and ISP behind every flagged visit, and Criteo supports OS, language and device type targeting. The segments we flag are segments you can exclude.

5
Criteo tokens mapped to attribution
2
sub-source dimensions scored
no-hop
one script, no funnel change
0–100
quality score on every visit
01 / SIGNAL

How invalid traffic slips in through Criteo placements.

Criteo is a commerce-media DSP built around dynamic retargeting: it follows shoppers who touched your product catalog and re-serves them personalized creative across an open-web publisher pool that runs from premium retail and news domains all the way down to long-tail inventory sourced through exchanges. That reach is the value and the exposure at once — your retargeting budget renders on thousands of publisher domains, and a meaningful slice of open-web supply is made-for-advertising (MFA) sites: pages built to carry ad slots rather than to be read, often stacking placements below the fold or refreshing them aggressively to manufacture views. Criteo passes a {{domain}} value identifying the publisher a visit rendered on, a {{width}} that maps to the slot, and {{adid}} plus {{creative_type}} for the unit served. The problem is that a session from a genuine returning shopper and one manufactured on an MFA page look identical inside Criteo’s own placement reporting. ValidVisit takes a different approach to telling them apart: every inbound visit is measured against 100+ independent data points spanning the network origin the visit came from, the device behind it, and how the visitor actually behaves on the page, and all of that collapses into one 0–100 quality score for that single visit, pinned to its {{domain}} and slot. Genuine shoppers clear the bar; automated and manufactured sessions surface as Suspect or Invalid. Because each visit carries its own score attributed to the publisher domain it rendered on, you can separate a domain that is merely low-converting from one with a structural IVT problem.

Retargeting traffic on Criteo carries IVT patterns shaped by how open-web supply actually operates, not by the banner format itself. The most persistent issue is made-for-advertising inflation: because a retargeting audience of known, high-intent shoppers is unusually valuable, MFA domains and low-quality placements are built specifically to intercept that spend — pages engineered to farm impressions and clicks, where a share of the resulting sessions come from visitors who never intended to engage, or from automated activity that exists only to generate rendered views and click revenue. These sessions arrive through a real browser on a real publisher URL, so crude IP-only filters rarely catch them. ValidVisit reads the network origin of each arriving visit as part of its scoring, which is where this shows its hand on Criteo’s open-web pool: manufactured traffic is frequently routed through residential proxy pools to mask a datacenter or server-farm source, and that routing leaves a mark across the wider set of signals long before any single filter would flag it.\n\nA second pattern is automation that doesn’t behave like a shopper: a meaningful slice of bot activity comes from tooling and stripped-down browser builds that behave nothing like a returning customer once the visit lands — the connection characteristics, the device profile, and the on-page activity simply don’t line up with a human on the OS and browser they claim to be. Retargeting makes this especially stark, because the audience is supposed to be a known human who already visited your store; a session that can’t reproduce ordinary human behavior against that expectation reads as invalid quickly.\n\nA third pattern is placement-level quality collapse: slots that auto-refresh, stack below the fold, or reload on scroll manufacture impression and click volume out of the same visitor, and the clicks they produce are reflexive or accidental rather than intentional. ValidVisit’s scoring separates this low-intent human traffic from outright automation — the session may look human across the network and device signals, but its depth and the texture of its engagement read as an involuntary or accidental interaction with a manufactured slot rather than genuine shopping interest. That distinction matters because the remedy differs: a bot-heavy {{domain}} warrants exclusion, while a low-intent but human slot may warrant a bid reduction instead of a full block.

What to watch on Criteo

Publisher {{domain}} IVT concentration

Segment your ValidVisit report by Criteo’s {{domain}} token. Domains driving a disproportionate share of your visit volume alongside low quality scores are the primary signal of made-for-advertising supply intercepting your retargeting budget. A single {{domain}} whose score profile sits well below your campaign baseline warrants adding to Criteo’s supply exclusion list before that domain’s volume distorts your retargeting bids — the decision stays yours, since a one-off IVT spike is different from a structural problem.

Slot {{width}} score profile within a domain

Look at how scores vary across {{width}} values on the same publisher. A domain that looks acceptable overall but has one slot size whose quality collapses usually points to an aggressive-refresh or below-fold placement rather than a bad publisher wholesale. That is a placement-level problem, and the appropriate action is often a bid reduction or slot-level exclusion rather than removing the whole domain.

Network-origin vs. on-page agreement by {{domain}}

For each publisher, check whether a visit’s poor score is driven mainly by where it came from on the network side or by how it behaved once it rendered. A {{domain}} whose low scores trace almost entirely to its traffic source points to a structural sourcing problem — the domain is acquiring sessions through proxy or datacenter routes. One where the weakness shows up mainly in on-page behavior suggests a smaller bot operation, which may be manageable with a lower bid rather than full exclusion.

Score trend by hour for top-volume domains

Automated activity on open-web supply often concentrates outside normal shopping hours, when real retargeting audiences are not browsing. If a high-volume {{domain}} shows quality scores well below your campaign baseline in low-traffic windows but looks valid during peak hours, that time pattern is itself a diagnostic signal worth including in your manual review before deciding on exclusion.

02 / SCORED

Pinpoint the bot publishers & placements in Criteo.

Criteo itself isn’t the problem — bots and invalid traffic concentrate in a handful of its sub-sources: the publisher, site or zone, and the placement or widget within it. So we roll the score up by those Criteo tokens, not by creative (which says nothing about whether a click was human).

Bought as one Criteo line, a buy reads as a single number. Scored per sub-source, a spread like this illustration runs from 91 down to 25 — the worst is nearly all bots. That’s the leak a blended average hides.

validvisit · console
0–49 invalid50–79 suspect80–100 valid
auto-surf.example25
zone 787072
market-daily.example91

Illustrative: Criteo traffic scored 0–100 per sub-source, worst first — down to the placement you buy.

Publisher / site / zone

Bot / invalid-traffic score broken down by:

  • Publisher Domain {{domain}}
Placement / widget

Bot / invalid-traffic score broken down by:

  • Slot Width {{width}}
Compare bot & invalid-traffic breakdown across every ad network →

See your own Criteo sub-sources scored this way.

03 / ATTRIBUTION

How ValidVisit attributes Criteo traffic

Each Criteo macro maps to a normalized parameter, so every scored click is pinned to the right campaign, creative and publisher.

validvisit · tracking url
A Criteo tracking URL ValidVisit can score
https://yoursite.com/landing?utm_source=criteo&utm_medium=banner&vv_campaign_id={{criteo_campaign_id}}&vv_publisher_id={{domain}}&vv_placement_id={{width}}&vv_ad_id={{adid}}&vv_creative_id={{creative_type}}
Campaign ID
Criteo macro
{{criteo_campaign_id}}
Maps to
campaign_id
Identifies
campaign
Publisher Domain
Criteo macro
{{domain}}
Maps to
publisher_id
Identifies
publisher
Slot Width
Criteo macro
{{width}}
Maps to
placement_id
Identifies
placement
Ad ID
Criteo macro
{{adid}}
Maps to
ad_id
Identifies
ad
Creative Type
Criteo macro
{{creative_type}}
Maps to
creative_id
Identifies
creative
04 / DETECTION

How the detection works.

100+
Scale

Data points → one score

Every visit is weighed against more than a hundred independent data points and reduced to a single, sortable 0–100 quality score.

1 verdict
Depth

Many angles, combined

Each data point is combined rather than checked in isolation, so a genuine human almost never trips enough of them to be flagged — and bots that beat one rarely beat the rest.

0–100
Model

Proprietary, not a black box

The detection model is ours and stays that way. What you get is a clear verdict on every visit — not a single brittle rule you can game, and not an unexplained number you can’t act on.

per source
Action

Pinned to the source

Every verdict maps to the campaign, publisher and placement that sent the click — so you know exactly which source to cut.

05 / THE CUT-LIST

How ValidVisit helps you cut fraud and bad publisher domains on Criteo.

Scoring and attribution are the means — the point is cutting the Criteo traffic that wastes your spend. Here’s how ValidVisit gets you a list you can act on.

  1. Score

    See what’s actually landing

    You buy Criteo clicks; what arrives are visits. ValidVisit scores each one 0–100 so real humans stand out from bots and invalid traffic — one script, no funnel hop, no fingerprinting.

  2. Attribute

    Pin the fraud to its source

    Every scored visit is tied to the exact Criteo publisher domain and zone via the network’s own tokens — so the bad traffic has an address, not just a headline percentage.

  3. Cut

    Take the publisher domains off your buy

    You get the worst offenders as a ready-to-use list plus postbacks to your tracker — so you can exclude them in Criteo and put your next dollar behind the traffic that converts.

FAQ

Criteo traffic quality, answered.

Does ValidVisit exclude bad domains in Criteo automatically, or is the process manual?

The process is manual. ValidVisit scores every visit and surfaces the {{domain}} values with weak quality scores in its reports and dashboard. You export those publisher domains and add them to Criteo’s supply exclusion list in Campaign Manager. There is no automated push from ValidVisit into Criteo’s platform — the workflow is: score in ValidVisit, identify the problem {{domain}} or {{width}} slot, exclude it in Criteo. Keeping you in control avoids removing a domain that had an isolated IVT spike rather than a structural problem.

Criteo already applies traffic-quality filtering — why score visits separately?

Criteo’s platform-level filtering removes some invalid activity for billing purposes, but it operates on Criteo’s own view of the traffic and you don’t get a per-visit, per-domain quality signal you can independently act on. ValidVisit sits outside that process: it gives you a 0–100 score for each visit, attributed to the {{domain}} it rendered on and the slot it occupied, that you own regardless of how Criteo classifies it. That independent view is what lets you find the made-for-advertising domains and low-quality slots draining your retargeting budget and exclude them yourself, rather than trusting that platform filtering already caught them.

Retargeting audiences are supposed to be real returning shoppers — how does invalid traffic get in at all?

The audience definition is real, but the supply it renders across is open. Criteo serves personalized creative through a wide publisher pool sourced partly through exchanges, and made-for-advertising domains are built specifically to intercept high-value retargeting spend by manufacturing impressions and clicks. Automated tooling and low-quality placements can generate sessions that carry your retargeting creative without belonging to a genuine returning shopper. ValidVisit scores each of those visits against how a real human on the claimed device and network would behave, so manufactured sessions surface as Suspect or Invalid against the domain that served them.

Which Criteo values give the most useful segmentation in ValidVisit?

The {{domain}} is the highest-leverage value because it maps directly to the publisher a visit rendered on and is the same dimension Criteo exposes for supply exclusion, so you can act on it without any translation step. The {{width}} adds slot-level resolution, letting you tell a bad publisher apart from a bad placement on an otherwise acceptable one. Adding {{adid}} and {{creative_type}} confirms whether a low-quality pattern is domain-wide or tied to how a particular unit is being served, and {{criteo_campaign_id}} ties each scored visit back to the campaign that generated it.

Detect fraud on other banner / display networks

Back to how it works
auto-surf.example25
zone 787072
market-daily.example91

Find the bots in your Criteo spend.

See which publishers and placements send real buyers vs bots — every visit scored 0–100, worst first.

Just your email · no card · unsubscribe anytime · privacy policy

Free trial at launch · just your email

One script · no cookies · no fingerprinting · raw IP never stored