Detecting Bot Traffic on Adult Sites (Before It Fools You)
Adult sites attract more automated traffic than almost any other kind of site. Some of it is harmless, some of it inflates your ad impressions without paying, and some of it makes you believe a channel is working when it isn’t. These are the patterns we found on our own sites, and how to recognise them.
1. Fake search-engine referrers
One week our logs showed thousands of daily visits “from google.com” to one site, more than ever before. In reality real Google visitors had just dropped to almost zero. The “Google visitors” came from a single cloud provider’s IP range and walked through performer pages in alphabetical order, each with a https://www.google.com/ referrer.
How to spot it: group search-referred hits by the first two parts of the IP address. Real search visitors come from thousands of different consumer networks; a bot comes from a handful of ranges. Then compare with the search console: if the console shows no clicks but your logs show thousands, the logs are lying.
2. Headless browsers from one data centre
On one of our sites, 98% of traffic was a single headless browser operating from one country’s data centres. It loaded full pages, including ads, so ad impressions looked healthy. It never paid.
How to spot it: look for a very high share of traffic from one country or one hosting network, sessions of exactly the same length, and user agents that mention “Headless” or are identical across thousands of IPs. Check your revenue per real visitor, not per impression.
What to do: usually nothing dramatic. Blocking aggressive crawlers can also block legitimate search engines and AI crawlers you may want. We protect the server with caching and CPU limits and simply exclude this traffic from our decisions.
3. Leftovers from a domain’s previous owner
If you bought a used domain, expect old traffic-trade scripts and link exchanges to keep calling it. On one domain we saw a steady stream of requests carrying referrers like https://google.com, http://www.example.net/?x=3021... (two URLs in one header, which no real browser sends), hitting the favicon and old thumbnail paths.
What to do: return 410 Gone for the old script paths so link checkers eventually drop them, and filter these requests out of your traffic reports. If the old owner left spam backlinks, a disavow file in Google Search Console handles the worst.
4. Crawlers that look like people
Some crawlers (SEO tools, AI crawlers, price and content scrapers) send normal-looking browser user agents. Verified search engine crawlers publish their IP ranges; Google, Bing and others document how to confirm them. Anything claiming to be Googlebot from an unlisted IP is not Googlebot.
Useful habit: build a small list of verified crawler IP ranges from the published lists and refresh it daily. Then you can tell real Googlebot crawling apart from impostors, and also serve crawlers anything special you need to (for example, video sitemap details) without exposing it to scrapers.
5. Fake engagement
View counters that jump in round numbers, comments with links in them, and “likes” from accounts with no history are all common on upload platforms. Don’t use other platforms’ view counts alone to judge which content works; use your own tagged links and your own logs.
A simple weekly check
- Real search clicks per day from each search console.
- Search-referred hits per day from your logs, excluding the known bot ranges. The two lines should move together.
- Top 10 IP ranges by requests. Anything new and large deserves a look.
- Revenue per real visitor per site.
If the log line falls off a cliff while the search console still looks normal, the console is simply a few days behind. Logs are your early warning; consoles are your confirmation.