A valid click and a real lead are not the same thing. The whole problem of ad fraud in lead generation lives in the gap between them. Google spends enormous effort on one question: was this click real? It has to, because unfiltered click fraud would inflate its own reported costs. But it has no matching check for a different question: was this lead real? So a bot, a paid survey-filler, or a recycled phone number can produce a perfectly valid, billable click. Then it submits a form that is worth nothing. And by Google’s own admission, the platform will not remove that conversion. This guide is the operator’s version of the fix. We walk through where the fraud actually lives, channel by channel. We cover who is behind it and why the obvious defenses miss. Then we show how one-time-passcode (OTP) verification and bot detection catch what Google’s filtering is not built to catch. They work at the one point in the funnel where none of the upstream filtering operates: the conversion event.

- Google’s fraud filtering is scoped to clicks and impressions, not conversions. In its own words, a click can be “deemed invalid and removed, but the conversion occurring from that click may not necessarily be.” That gap is where lead fraud lives.
- The category that matters is SIVT (Sophisticated Invalid Traffic, the MRC’s term), engineered to pass the exact humanness and form checks a lead form relies on.
- Fraud concentrates in open-web Display and MFA arbitrage, opaque Search Partners, and Performance Max’s “spam loop.” Core Search is the cleanest tier.
- The actors are bots (documented at massive scale), human survey-fillers and co-reg farms (the FTC has hit these for $2.5M, $13.8M, and $145M), and recycled-lead farms.
- Easy defenses (call-duration rules, form validation, reCAPTCHA alone) each test something adjacent to intent. OTP tests reachability-for-genuine-purpose: a real person with real-time access to a real number who completed one more step.
- OTP is not magic. It proves the number is real, the person had access, and they cooperated. It says nothing about need or timeline. Verification and qualification are complementary layers.
Quick answers:
- Does Google refund you for fake leads?
- What is the difference between click fraud and lead fraud?
- Can bots really fill out my lead forms?
- What is a co-registration lead, and why is it low quality?
- Does OTP verification stop all fake leads?
- How do verified leads improve Google Ads bidding?
- What are GIVT and SIVT, and which one matters for lead gen?
- Should I opt out of Google Search Partners and be careful with Performance Max?
A note on how we source this. Ad fraud is a field full of confident numbers, most of them sold by companies that also sell fraud-detection tools. So we label every figure. Confirmed means a primary source with a direct incentive to be accurate or a legal record: the FTC, Google’s own documentation, the Media Rating Council. Vendor research means named primary research from a party with skin in the game but real data, like the ANA’s log-level study, Adalytics, or HUMAN Security, attributed by name. Estimate means a fraud-tool vendor’s modeled percentage, presented as a range, never as a single fact. Where sources conflict, we show the conflict rather than pick a winner. We write this as an operator. Elevarus buys clicks and runs verified-lead funnels, so the only question that matters here is whether a lead is a real, reachable person who wanted what you sell.
Why doesn’t Google just catch the fake leads for you?
Start with the structural answer, because it reframes everything that follows. Google’s invalid-traffic system is genuinely good at what it is built to do. And what it is built to do is filter invalid clicks and impressions. It constantly checks data points to decide whether an ad interaction is valid. It issues no charge in real time for what it catches. And it posts later credits for anything caught after invoicing, through a real feature called the Invalid Activity Credit Report. That is a yes-or-no, pre-conversion question. Google has both the infrastructure and the financial reason to answer it, because click fraud left unfiltered would inflate the CPCs it reports and damage trust in the auction.
Now read the limit in Google’s own words. Its help documentation states that “in rare cases, a click may be deemed invalid and removed, but the conversion occurring from that click may not necessarily be” (Google Ads Help, confirmed). Elsewhere it blames weak conversion performance on landing-page quality, vague keywords, or market conditions. It never blames invalid traffic at the conversion event. The filtering framework covers click and impression validity, full stop. Picture a real, human-clicked visit that lands on a real page and submits a real-looking form. By this framework it sits outside the invalid-click net, even when a fraud farm, a bot with a stolen identity, or a bored person chasing a gift card filled it out.
This is also why the same fraud that barely dents a brand-awareness display campaign is a direct financial wound in lead generation. In lead gen you are not paying for eyeballs. You are paying for a person you intend to call, quote, and close. If that person is a bot or an uninterested incentivized clicker, the cost does not stop there. You carry it forward into your sales time, your CRM data, and, as we will see, into how you train your own bidding.
GIVT vs SIVT: the two words that explain the whole problem
To defend against fraud you have to be precise about which fraud. The Media Rating Council, the body that sets measurement standards for the industry, splits invalid traffic into two tiers, and the distinction is the most useful mental model an operator can carry.
GIVT, General Invalid Traffic, is the traffic caught by routine, list-based means: known bots, spiders and crawlers, data-center IP ranges, non-browser user agents, pre-fetch activity. It is cheap to catch because it announces itself. Most platforms filter the bulk of GIVT automatically.
SIVT, Sophisticated Invalid Traffic, is the hard tier. The MRC describes it as the cases that need advanced analytics, multi-point corroboration, and significant human review: bots that mimic human behavior, hijacked devices and sessions, domain spoofing, ad stacking, adware, and human fraud farms. SIVT is the category that matters for lead generation, for one reason. It is engineered to look legitimate. A lead form’s defenses are humanness checks and data-shape checks, and SIVT is built to pass exactly those. When people say “our form validation is fine and we still get junk,” they are describing SIVT and human fraud farms walking through the front door.
On top of the measurement standard sits a separate certification layer, run by the Trustworthy Accountability Group (TAG). Its “follow-the-money” transparency specs are the supply-chain hygiene of the ad ecosystem: ads.txt, where publishers declare who is authorized to sell their inventory, and sellers.json, where exchanges declare who they transact with. A frequently cited 2017 industry study found TAG-certified distribution channels carried 83% less fraud than broader industry averages (614 Group, vendor research, and the closest thing to an audited before-and-after in this space). The operator takeaway is concrete. A valid ads.txt on a publisher domain is a real, checkable signal, and made-for-advertising sites frequently skip or misconfigure it.
Where does ad fraud actually live? A channel-by-channel map
Fraud exposure is not evenly distributed. It concentrates in the channels with the most intermediaries, the least placement transparency, and the weakest quality signal. Here is the map an operator should carry into a media plan.
| Channel | Dominant fraud vector | Placement opacity | How auditable |
|---|---|---|---|
| Display / GDN | Made-for-Advertising (MFA) arbitrage, plus domain spoofing and ad stacking (SIVT). ANA: only 36 cents of every $1 into a DSP reaches the consumer. | Medium | Highest of the four. URL-level placement reports, exclusion lists, ads.txt / sellers.json checks. |
| Search Partners (SPN) | Brand-safety and placement gaps (Adalytics found ~36,612 sites serving Google search ads). Not an IVT-rate finding. | High | Low. Google states it does not tell you the site your ad ran on. Opt-out, not a placement list. |
| Performance Max | The spam loop: optimize to raw form-fills with no quality signal and the algorithm buys the cheapest submissions, then scales budget toward them. | Very high | Low. Even after 2026 channel reporting, you still cannot see which Display or Discover placements produced a form. |
| Native (Taboola / Outbrain) | Low-intent arbitrage supply. The funnel that feeds MFA: bought near $0.20 CPM, resold at $2 to $5 CPM once ad-stacked. | Medium | Medium. Often a lead-quality problem, not strictly IVT-classifiable fraud. |
Display and the Google Display Network. Historically the most fraud-prone paid channel, because it is an open marketplace with layers of resellers between you and the publisher. The dominant vector here is not classic bot fraud. It is Made-for-Advertising (MFA): real sites, often with real but low-value or incentivized human traffic, built purely to arbitrage ad revenue. They buy cheap traffic and stack ad units to resell impressions at a markup. The single most defensible number in this space comes from the ANA’s Programmatic Media Supply Chain Transparency Study, which used advertiser log-level data rather than a vendor’s own panel. Only about 36 cents of every dollar entering a demand-side platform actually reached the consumer, with roughly 35% of spend going to non-viewable, invalid, non-measurable, or MFA traffic (ANA, vendor research, limited sample of 21 advertisers). MFA specifically was pegged near 15% of programmatic spend in that 2023 wave.
Resist the tidy headline here. A later, smaller ANA wave (11 brands) put MFA nearer 4% of programmatic dollars. The ANA tied that to those specific advertisers actively excluding MFA after press attention, not to a market-wide decline. In the same period, DoubleVerify reported MFA impressions actually rising 19% year over year. So the honest read is a range: 4% to 15%-plus, depending on who is measuring and whether they had already acted. It is not “MFA dropped to 4%.” Display fraud is also the most auditable of the four channels. URL-level placement reports, account-level exclusion lists, third-party MFA blocklists, and ads.txt checks all reach it.
Google Search Partners (SPN). This is the most concretely documented controversy in the set, and it deserves both sides. A November 2023 investigation by Adalytics, an independent ad-tech research firm, identified roughly 36,612 websites serving Google search ads through Search Partners. It alleged serious brand-safety and placement-visibility gaps, including ads appearing on a domain a Fortune 500 brand had explicitly blocklisted years earlier. Google itself confirms the underlying opacity. Its documentation states it does not tell you the website where your ad showed on the Search Network. Google’s on-record response called the claims “wildly exaggerated.” It said Adalytics had “intentionally triggered” many flagged placements. And it countered that more than 90% of Search Partner impressions come from top-100 sites and apps, and that policy-violating sites represent 0.002% of impressions (Google, on record). Treat this as a documented dispute, not a settled fraud rate: Adalytics measured brand safety and transparency, not an IVT rate. The practical operator move is unchanged. Search Partners is lower-intent and hard to audit, so most lead-gen accounts review whether to opt out, using the campaign-level Search Partners exclusion.
Performance Max. This is the channel most relevant to the lead-gen fraud thesis, and the one where you have the least visibility. PMax serves across Search, Display, YouTube, Gmail, Discover, and Maps as a single automated box. Google added channel-level reporting in early 2026. Even so, you still cannot see which specific Display or Discover placements produced a given form submission. So the exclusion tooling that works on standard Display largely does not reach PMax’s inventory. On top of that opacity sits the mechanism that should worry every lead-gen operator: the spam loop, which we break down step by step in how Performance Max spam leads happen and how to stop them. Say a PMax campaign optimizes to a raw “form submission” goal with no quality signal fed back. The algorithm maximizes a reward and is not intent-aware, so it finds the cheapest submissions available. Junk registers as conversions. The model sees high conversion volume and scales budget toward the sources producing the junk. That is not a bug you can exclude your way out of. It is a signal problem, and it is the direct bridge to the bidding section later in this guide.
Native (Taboola, Outbrain, and similar). The lowest-friction, cheapest channel to abuse. Structurally it is not a separate problem; it is the supply source that feeds MFA on Display. MFA operators buy their initial cheap traffic from content-recommendation widgets and social feeds, often around $0.20 CPM. Then they resell it at $2 to $5 CPM once it has run through their own ad-stacked pages. Native is the funnel; Display is where the arbitrage margin is captured. One honest nuance to keep: much of this inventory is not technically IVT-classifiable fraud. It can pass viewability and brand-safety minimums. The problem is content quality and click intent. These are low-intent, curiosity-driven, sometimes incentivized clicks, which is a lead-quality problem more than a strict invalid-traffic problem. For an operator the effect on your form is the same. But the label matters when you are deciding whether to dispute a charge or simply verify harder.
Who is actually behind the fake leads?
Channels are where fraud is delivered. Actors are who is delivering it. There are three families, and they fail your defenses in different ways.
Bot networks. The scale here is genuinely hard to picture. HUMAN Security reported the BADBOX 2.0 operation across more than a million compromised connected-TV devices, with related activity peaking near 10 billion fraudulent ad requests a day (HUMAN Security, reported; the primary disclosure page was access-blocked to our fetch, so this is attributed and corroborated through secondary coverage). Residential-proxy networks make it worse by routing fraudulent traffic through real consumer IP addresses. One network reportedly ran across roughly 2 million hijacked devices before a Google, FBI, and IRS-CI disruption. And Bitsight reports that about 20% of residential-proxy exit nodes talk to malware sinkholes, meaning much “residential” traffic rides on infected machines. The evasion toolkit is mature: headless browsers with rotating canvas and TLS fingerprints, commercial CAPTCHA-solving farms that clear challenges for cents using humans plus machine learning, residential-IP laundering that defeats geo-blocking, and the newest twist, agentic bots that fill forms with synthetic or stolen PII to manufacture fake conversions. Practitioners call that last one “lead poisoning,” and it ties directly to the bidding section.
Survey-fillers, incentivized traffic, and co-registration farms. This is the family most lead-gen buyers underestimate, because the traffic is human and therefore passes every humanness test. A co-registration lead is captured as a byproduct of a survey, sweepstakes, or gift-card offer, where the person checked a side box consenting to third-party contact. The PII is real; the intent is a reward, not your product. This is where the confirmed FTC record does the heavy lifting, and these are court outcomes, not vendor estimates. The FTC penalized Fluent, LLC $2.5 million over an alleged consent farm that used dark patterns to harvest consent, and permanently banned it from robocalls. It fined Solar Xchange, operating as Vision Solar, $13.8 million over millions of calls to numbers on the National Do Not Call registry, an on-vertical solar precedent. And in August 2025 it reached a $145 million settlement with Assurance IQ and MediaAlpha ($100 million and $45 million). In that case MediaAlpha reportedly sold roughly 119 million leads in 2024 through misleading domains and a fabricated “Health Insurance Give Back Program,” directly on-vertical for the U65 and ACA lanes. These sit inside Operation Stop Scam Calls, a multi-agency sweep the FTC has tied to more than $2 billion in judgments (reported).
Recycled, aged, and resold lead farms. The quietest family. Real contact data that was real once, then went stale, got reassigned, or was simply sold and re-sold across buyers. You can pay for the same dead number twice. There is no dramatic botnet here, just a business model built on the fact that most buyers never verify a number is still held by the person who once owned it.
Why the easy defenses fail
Before the fix, be clear about why the common defenses do not solve this. Each one tests something adjacent to intent, not intent itself, which is why sophisticated and human fraud walk through them.
Call-duration thresholds are a billing trigger, not a quality guarantee. A minimum call length filters misdials, but a real human with no intent, or a paid caller, simply talks past the mark. Duration measures persistence, not interest.
Basic form validation confirms a field is well-formed, that an email has an @ and a phone has ten digits. Well-formed fake data passes trivially, and a real incentivized human enters real, valid, useless data.
reCAPTCHA and similar challenges, used alone, are defeated three ways: headless automation that solves them, tokens purchased in bulk from solving farms, or a literal human click-farm worker who clicks through. A CAPTCHA proves “probably not a naive bot.” It does not prove “a person who wants what you sell.”
The unifying principle is worth stating plainly, because it is the setup for the entire OTP argument. Every one of these tests something near the edge of intent, humanness, data shape, persistence, but none of them tests the thing you actually care about: reachability for a genuine purpose. That is the specific gap OTP is built to close.
How OTP and real-time verification defeat each vector
Here is the payoff. A one-time-passcode step at the moment of capture converts a weak fact, “a number was typed into a box,” into a strong one, “a person with real-time access to that number was present and cooperative.” That single upgrade defeats the major fraud families in different ways, and the reason it works is that it tests possession and motivation rather than appearance.
| Fraud vector | Why the easy defense misses it | Why OTP catches it |
|---|---|---|
| Bots / headless automation | reCAPTCHA alone falls to headless solving, purchased tokens, or a real click-farm worker. Fingerprints can be rotated. | No phone in possession. A bot can type a well-formed number but cannot receive and relay the SMS code inside the 2 to 5 minute window. Spoofing fakes the browser, not the handset. |
| Fake / dead / recycled numbers | Basic form validation accepts any well-formed number. A recycled or reassigned number looks perfectly valid. | The code never comes back. This directly targets resold-lead and aged-data fraud, which trade on numbers no one is holding. |
| Survey-fillers / incentivized | Call-duration thresholds are a billing trigger, not intent. A real no-intent human talks past the mark and fills any form. | Friction plus motivation. They already collected their reward; a live step tied to YOUR specific offer is disproportionately abandoned by people with no interest in it. |
| Renter posing as homeowner (solar) | Nothing upstream checks property ownership. The lead reads as a homeowner because they typed that they are one. | OTP paired with a property-record cross-check flags the mismatch between the verified person and the claimed ownership. Anchor the risk on the confirmed Solar Xchange case, not on a vendor percentage. |
Bots fail on possession. A bot can generate a flawless phone number, but it cannot take physical possession of the handset and relay a code that arrives on it within a two-to-five-minute window. Fingerprint spoofing fakes the browser; it does not conjure a phone. This is precisely the vector that headless automation and CAPTCHA-farm workarounds cannot cross, because it is not a challenge to solve, it is an object to hold.
Fake, dead, and recycled numbers fail on delivery. If the number is not real and in service and in the submitter’s hand, the code never comes back. This is the direct counter to recycled and resold-lead fraud, which trades on numbers nobody is holding anymore.
Survey-fillers fail on friction plus motivation. They already collected their reward from the survey that captured them. A live verification step tied specifically to your offer is disproportionately abandoned by someone with no interest in that offer. The mechanism is sound and consistent across the field, though there is no audited public drop-off figure, so treat it as a mechanism rather than a measured rate. What you are doing is raising the effort required to fake interest above the value the fraudster placed on it.
Renters posing as homeowners fail on cross-reference, in verticals where it matters. In solar especially, pairing OTP with a property-record or homeownership cross-check flags the mismatch between the verified person and the claimed ownership. Anchor the risk on the confirmed Solar Xchange enforcement rather than on the circulating vendor percentages for solar fraud, which are unverified estimates; the point stands without them.
A useful byproduct falls out of doing this at all: a clean provenance record. OTP completion naturally yields a consent timestamp, an IP, and a record of the form version and consent language shown, which is exactly the documentation a compliant lead operation wants to keep anyway.
The verified-lead to bidding loop: the compounding advantage
Everything above is defense. This is where verification turns into an offensive advantage, and it is the part most fraud discussions miss. Smart Bidding is an auction-time loop that chases more of whatever conversion signal you send it. That is its entire nature. So the signal you feed it decides what it optimizes toward.
Feed it raw form-fills and you have handed the algorithm a reward it can maximize by finding more form-fillers, including the cheap fraudulent ones. It will faithfully scale budget toward the sources producing them. That is lead poisoning at the account level: your own bidding, trained on unverified conversions, becomes a fraud amplifier. Now invert it. Import only OTP-verified or otherwise qualified leads as the conversion, or assign them higher value, through offline conversion imports or enhanced conversions for leads. Bidding then retrains toward real, reachable people and starves the fraud channels of the budget they were feeding on. This is the same offline-conversion lever we cover in depth in the Google Ads bid strategies for lead gen guide and the pay-per-call offline conversion tracking guide. Here the point is narrower and sharper: verification is what makes the imported signal honest, and an honest signal is the only kind worth optimizing on.
Two honest caveats keep this from becoming vendor hype. First, treat the benefit as a documented mechanism, not a proven Google case study. No Google-published study directly links verified-lead-only imports to a measured quality gain, and we will not pretend one exists. The mechanism, that bidding chases the signal you feed it, is well established. The size of the gain in your account is yours to measure. Second, there is a logistics deadline attached. Reporting indicates the legacy offline-upload path migrates to Google’s Data Manager API by mid-2026. So any custom CRM-to-Google pipeline should confirm it has migrated, or the highest-leverage signal in the account can quietly stop flowing. (We flag the exact date as reported rather than independently re-verified here; confirm it against Google’s current developer documentation before you rely on it.)
The honest limits of OTP verification
The fastest way to lose an operator’s trust is to oversell, so here is the boundary, stated plainly. OTP proves exactly three things: the number is real and in service, the submitter had real-time access to it, and they were engaged enough to complete a step. That is a lot. It is decisively more than any humanness check gives you. But notice what it does not prove. It says nothing about need, fit, or buying timeline. A real, reachable homeowner who is “just looking” and has no budget sails straight through, verified and useless to your close rate. Verification removes the fake; it does not manufacture intent.
So verification and intent-qualification are complementary layers, not substitutes. OTP raises the floor by removing bots, dead numbers, and farmed incentivized noise. That way your screening, scoring, and sales triage operate on real humans instead of wasting time on ghosts. It does not replace that screening. An operator who treats a verified lead as a qualified lead has simply moved the mistake one step down the funnel.
OTP is also not absolute. SIM-swap and social-engineering attacks against one-time passcodes are a real, if small, failure mode. Hold this in a calibrated way, not an absolute one. OTP is a very high bar against bulk, cheap, automated fraud and against farmed incentivized traffic, which is the overwhelming majority of what hits a lead form. It is not an unbreakable guarantee against a determined attacker targeting one specific individual. In lead generation the threat is volume fraud, not a targeted operation against your single most valuable prospect. So that trade is heavily in your favor. Being honest about the edge case is exactly what separates an operator’s guidance from a vendor’s pitch.
What this means for you as an operator
Put the pieces together and the strategy is simple to state and hard to fake. Google will filter your invalid clicks; it will not filter your invalid leads. The fraud that reaches your form is disproportionately SIVT and human, engineered to pass the checks most buyers rely on. It comes through the least transparent channels: open-web Display and MFA, Search Partners, and Performance Max’s spam loop. The actors are documented and, in the survey-filler and co-reg lane, federally prosecuted. The easy defenses fail because they test appearance, not reachable intent. Real-time OTP verification, paired with bot and spam detection and identity checks, tests reachable intent at the one point in the funnel the platform does not touch. And importing only those verified outcomes turns your own bidding from a fraud amplifier into a fraud filter.
That verification layer, the part of the funnel most guides ignore, is exactly what Elevarus runs. We are the operator, not a widget: we buy the clicks, verify the leads at the conversion event, and feed only the honest signal back into the account. See how our lead generation model works for the full picture. If you run the verticals where this bites hardest, the fraud economics are laid out on the solar lead generation page (the Solar Xchange vertical), the U65 private health page and ACA page (where the MediaAlpha case landed), and the HVAC and Medicare pages.
This pillar sits alongside our four Google Ads guides for lead gen. For the auction lever that decides what you pay, read the Quality Score guide; for keeping an account serving through policy enforcement, the Limited Ad Serving policy guide; for writing the ads themselves, the ad copy, RSA, DKI, and pinning guide; and for the bidding that all of this feeds, the bid strategies guide. Fraud defense is not a separate discipline from Google Ads; it is the quality control that makes every other lever honest.
Frequently Asked Questions
Does Google refund you for fake leads?
No. Google’s invalid-traffic system credits invalid clicks and impressions, not conversions. In its own words, a click can be deemed invalid and removed while the conversion from that click is not. Google attributes low conversion quality to your landing page, keywords, or the market, never to invalid traffic at the conversion event. So a bot or a paid survey-filler who produces a valid, credited click and then submits a junk form still costs you the media and the lead, with nothing refunded. That gap is exactly where lead verification has to operate.
What is the difference between click fraud and lead fraud?
Click fraud happens before the conversion: invalid clicks or impressions that inflate spend. Google has strong infrastructure and a direct financial incentive to filter it, because unfiltered click fraud would inflate its own reported CPCs. Lead fraud happens at the conversion event: a real-looking form submission from a bot, a fraud-farm worker, a recycled number, or a no-intent incentivized clicker. Google’s filtering is not designed to catch it, and by its own admission does not remove the conversion. Click fraud is Google’s problem to filter; lead fraud is yours.
Can bots really fill out my lead forms?
Yes, routinely, and increasingly with agentic automation that fills forms with synthetic or stolen PII specifically to look like real conversions. Security researchers have documented bot operations at enormous scale: HUMAN Security reported the BADBOX 2.0 botnet across more than a million compromised devices, and residential-proxy networks route this traffic through real consumer IP addresses to defeat IP and geo blocking. Headless browsers rotate fingerprints and CAPTCHA-solving farms clear challenges for cents. What a bot cannot do is take physical possession of a real phone and relay a one-time passcode in real time.
What is a co-registration lead, and why is it low quality?
A co-registration or co-reg lead is a contact captured as a byproduct of some other action, usually a survey, sweepstakes, or gift-card offer, where the person checked a side box consenting to be contacted by third parties. The PII is real, but the intent is not: they wanted the reward, not your product. Because they are real humans, they pass humanness checks, form validation, and even a short phone call. The FTC has pursued the deceptive machinery behind these leads as independently illegal, including a $2.5 million penalty and permanent robocall ban against one alleged consent farm.
Does OTP verification stop all fake leads?
No, and any vendor claiming it does is overselling. OTP proves exactly three things: the number is real and in service, the submitter had real-time access to it, and they were motivated enough to complete a step. It says nothing about need, fit, or timeline, so a real but just-looking homeowner sails through. It is also not absolute against a determined, individually targeted attacker using SIM-swap or social engineering. What it does is set a very high bar against bulk, cheap, automated fraud and against farmed incentivized noise. Verification and intent-qualification are complementary layers, not substitutes.
How do verified leads improve Google Ads bidding?
Smart Bidding chases whatever conversion signal you feed it. Send it raw form-fills and it learns to find more form-fillers, including the cheap fraudulent ones, and scales budget toward them. This is lead poisoning. If instead you import only verified or qualified leads as the conversion, through offline conversion imports or enhanced conversions for leads, bidding retrains toward real, reachable people and starves the fraud channels. Treat this as a sound, documented mechanism rather than a published Google case study. Note the offline-upload path is reported to migrate to Google’s Data Manager API in mid-2026, so confirm your pipeline is current.
What are GIVT and SIVT, and which one matters for lead gen?
They are the Media Rating Council’s two tiers of invalid traffic. GIVT, General Invalid Traffic, is caught by routine list-based checks: known bots, crawlers, data-center IPs. SIVT, Sophisticated Invalid Traffic, is the hard tier: bots that mimic humans, hijacked devices, human fraud farms, and other traffic engineered to look legitimate. SIVT is the category that matters for lead generation, because it is designed to pass the exact humanness and validation checks a lead form relies on. Verification at the conversion event is aimed squarely at the SIVT-grade and human-fraud-farm fills that upstream filtering is not built to catch.
Should I opt out of Google Search Partners and be careful with Performance Max?
For most lead-gen accounts, yes to reviewing both. Search Partners inventory is lower-intent and hard to audit; Google states it does not tell you which site your ad ran on, and a 2023 Adalytics investigation raised brand-safety concerns that Google disputes. Performance Max is the higher risk for junk leads because of the spam loop: optimize to raw form-fills and the algorithm buys the cheapest submissions, then scales budget toward them. The fix is not just exclusions, it is feeding the system a real quality signal, which brings you back to verification and outcome import.
Sources
- Google Ads Help: About invalid traffic (Confirmed, primary; invalid-click vs conversion quote verified verbatim)
- Google Ads Help: Invalid Activity Credit Report (Confirmed, primary)
- Google Ads Help: About offline conversion imports (Confirmed, primary; the verified-lead bidding lever)
- Google Ads Help: Enhanced conversions for leads (Confirmed, primary)
- MRC Invalid Traffic Detection and Filtration Guidelines Addendum (Confirmed, standard; GIVT and SIVT definitions)
- FTC: Assurance IQ and MediaAlpha to pay $145 million (Confirmed, primary; corroborated via secondary coverage, direct fetch blocked)
- FTC: Fluent, LLC case timeline (Confirmed, primary; $2.5M penalty and robocall ban)
- FTC: Solar Xchange, LLC case (Confirmed, primary; $13.8M, on-vertical solar)
- ANA Programmatic Media Supply Chain Transparency Study (Vendor research, log-level, limited sample; the 36-cents and MFA figures)
- Adalytics: Search Partners transparency investigation (Vendor research; disputed by Google)
- AdExchanger: coverage of the Adalytics Search Partners report and Google’s response (Trade; both sides of the dispute)
- HUMAN Security: BADBOX 2.0 disruption (Vendor research, reported; direct fetch blocked, attributed and corroborated via secondary coverage)
- Bitsight: residential proxy services and malware ecosystems (Vendor research; the ~20% sinkhole figure)
- Search Engine Land: why Performance Max lead generation fails (Trade; the spam-loop mechanism)
- TAG Certified Against Fraud program overview (Confirmed program; ads.txt and sellers.json supply-chain layer)





