Most traffic-quality writing is built for Google Ads and enterprise display. This one is built for the person buying pop and push inventory, where the formats behave differently, the standard metrics mislead, and the tooling assumes a budget you do not have.
It is assembled from measured production traffic — 975,000+ events across multiple networks, 21,000+ zones scored, and a 924-visit delivery study joined visit by visit — not from theory.
1. The four populations, and why mixing them costs money
Almost every bad decision in this niche comes from treating four different populations as one. They need different responses:
| Population | What it is | Correct response |
|---|---|---|
| GIVT | Declared bots, datacenter IPs, crawlers | Block on sight |
| SIVT | Residential proxies, farms, human-like automation | Corroborated, zone-level detection |
| Unrendered delivery | Real users whose browser never loaded the page | Fix delivery — never block |
| Valid rendered | Reached and displayed your page | The only traffic worth optimising |
The third row is the one standard taxonomies miss, and it is large. Full breakdown: invalid traffic explained for media buyers.
2. Ghost traffic: clicks that never load the page
We joined 924 accepted clicks end to end over 24 hours. 305 never issued a request to the destination at all. Not slow, not bounced — no HTTP request was ever made.
The cause was not the traffic source. It was an interstitial page in our own chain that required the browser to act. Popunders open in background tabs, which browsers throttle and discard, so any JavaScript hop, meta-refresh or click-to-continue step silently kills a share of visits. Replacing it with a server-committed redirect moved arrival from 52% to 67% and confirmed renders from 29% to 42% on identical spend.
Deep dives: ghost traffic explained and the full 924-click teardown.
3. Render is a measurement, not a verdict
Low render rate feels like proof of bots. On pop traffic it can be inverted: a real human on a suspended tab produces the same silence as a bot, while a headless browser executes JavaScript flawlessly. Block on render alone and you remove humans while keeping the sophisticated automation.
Full render evidence requires DOM/paint and visibility on the same visit — never the union of separate beacon streams. Why the obvious inference fails: no render is not a bot signal.
4. Residential proxies: the hardest category
A residential proxy exits through a real home connection, so geolocation, ASN classification and IP reputation all return clean results — correctly. The IP is not the fraud; it is a borrowed exit door. List-based filtering cannot solve this.
What works is asking whether a population behaves like real households, measured against each network's own baseline rather than a global list. What does not work — and we will say it plainly — is per-visit certainty on a freshly rotated exit used once. That is not detectable from server-side evidence by anyone, at any price. Detail: residential proxy bot traffic.
5. Zone intelligence: where evidence actually accumulates
Individual visits are noisy; zones are not. A single visit rarely proves anything, but a zone producing hundreds of visits reveals its character through repetition, concentration and consistency. This is why judgement belongs at zone level, and why a zone quality score outperforms per-visit scoring on pop inventory.
Across 21,389 analysed zones, a large share proved to be confirmed bot sources — but the important discipline is the reverse one: never loosen detection to recover volume. Volume is recovered only by removing false positives on real humans. See the 21,389-zone analysis and why zone intelligence beats bot scores.
6. Diagnosing your own campaign
If you have traffic and no conversions, get three numbers before theorising: clicks billed (A), requests that reached your server (B), and sessions in analytics (C). The A→B gap is a delivery problem. The B→C gap is a measurement problem. They are not the same and do not share a fix.
Step-by-step: traffic but zero conversions, a 20-minute diagnosis.
7. What good looks like
- Server-committed delivery. One redirect, no browser-dependent hop.
- Corroborated detection. Never kill on a single weak signal.
- Zone-level judgement with per-source baselines.
- Honest measurement: unmeasurable stages reported as not available, never as zero.
- False positives treated as the primary risk, because blocking a buyer costs more than leaking a bot.
That is the model PureGuard is built on, and every figure above came from running it against live traffic rather than from a specification.