Blog / Analytics & attribution

More than half of your “visitors” may be bots

On one site, 55% of the visits analytics reported were bots, and real engagement was 22.4%, not 8.9%. Why it matters for every decision you make, and how to separate people from bots.

Every decision about a website rests on its analytics: what to write next, which page to fix, which affiliate placement to keep, whether a redesign worked. On a site we worked on recently, 55% of the visits the analytics reported were not people.

Bot share

55%

Of reported visits were bots

Real engagement

22.4%

Not the 8.9% the dashboard showed

One bot

331,829

Requests a day, more than Google and three other major crawlers combined

Why it matters

  • You fix the wrong pages. With engagement reported at 8.9%, good pages look broken. Rewriting them wastes the budget and can hurt what already ranks.
  • You misjudge revenue. Bot clicks inflate affiliate and ad numbers, so placements that do not earn look like they do, and conversion rates look worse than they are.
  • You pay for it twice. One heavy bot was making more requests than Google’s crawler. That is server load and slower pages for real visitors — and for Google.
  • Experiments lie. Any test you run on polluted traffic measures the bots as much as the people.

How to separate people from bots

There is no single switch for this. It starts by comparing what the analytics records with what the server actually receives. From there, look for signals real visitors rarely produce together: no scrolling, no interaction, identical timing, traffic from data-centre networks, bursts at odd hours. Check any filter against traffic you know is real before applying it, so real readers are not filtered out.

On this site, we acted on it:

  • The heaviest bot was blocked: 100% of its requests stopped, 0% of Google’s.
  • Bots are now separated from real visitors before anyone reads a dashboard.
  • We also found the site’s own security policy was blocking its analytics and ad tracking. More on that in our post on security policies.

Five checks for your own site

  1. Compare the visits in your analytics with requests from real browsers in your server logs. A large gap deserves an explanation.
  2. Break engagement down by network, country and hour. Bots cluster; people spread out.
  3. Open your site with the browser console visible. Errors from your own security policy can silently block your own tracking.
  4. Before blocking any bot, confirm it is not Google. Verify the crawler by its network address, not by the name it gives itself.
  5. Treat a sudden jump in traffic with the same suspicion as a sudden drop.

The point

Clean data is not a reporting nicety. It is the ground every other decision stands on. On this project it is one of the first things we fixed, before any change to content or design.

This article is drawn from a real engagement. Client details withheld; every figure comes from the client’s own data.

Read the full case study →

Want us to look
at your site?

Tell us where traffic, revenue or your numbers stopped making sense. We will tell you what we would check first.

Prefer to write directly? enable JavaScript to see the address

Talk to an engineer

No sales theater. Tell us where your operation feels slow, repetitive, or difficult — an engineer reads every message.

Your message goes straight to our engineers at our address.