Keep Bots Out of Your Prebid Auctions
Every page view on a publisher site triggers a header bidding auction. For most publishers that means every crawler, headless browser, scraper and automation script triggers one too. Those requests look like inventory to your demand partners, but nobody will ever see the ad. This article looks at what invalid traffic does to a Prebid setup, why the usual defences miss most of it, and how the new IVT filter in BiddingStack, powered by Transfon Security, keeps it out of the auction.
Invalid traffic (IVT) is any ad request that does not originate from a real person. Some of it is harmless and declared, such as search engine crawlers. A growing share is not: headless Chrome sessions, scraping tools, AI agents, ad verification bots, and click farms running on residential proxies. On a typical publisher site, non-human sessions account for anywhere from a few percent to well over a third of page views, depending on the content and how attractive it is to scrape.
Header bidding does not distinguish between them. When Prebid runs, it sends a bid request to every configured bidder for every page view. A bot that loads the page ten thousand times a day generates ten thousand auctions, each fanning out to ten or more SSPs.
The damage is easy to miss because it does not show up as a single line in any report.
Lower CPMs. Buyers price inventory on measured outcomes: viewability, engagement, conversions. Impressions served to bots score zero on all of them. Those impressions are blended into the same placement stats as your real traffic, and the algorithm prices the whole placement lower to compensate.
Bidder trust. SSPs and DSPs run their own IVT detection. When a large share of a publisher's bid requests is flagged after the fact, the response is rarely a phone call. It is a quiet reduction in bid rate, a lower priority in the buyer's supply path, or in the worst case a place on a blocklist that is hard to get off.
Wasted infrastructure. Every bot auction consumes bidder timeout budget, browser CPU, and outbound requests. It adds latency for the requests that matter without producing revenue.
Polluted reporting. Fill rate, win rate and revenue per thousand page views are all diluted. Optimisation decisions based on those numbers are made against a picture that includes traffic that can never convert.
Most publishers already have something in place, but it tends to work at the wrong layer.
What is missing is a decision at the moment the page loads, before Prebid asks anyone for a bid.
BiddingStack now includes an IVT filter that makes exactly that decision. It is a single switch at the project level, and when it is on, every visit is checked before the header bidding auction starts.
The check is powered by Transfon Security, the same traffic intelligence that protects websites and ad campaigns across the Transfon platform. It combines signals observed in the visitor's browser with server-side classification from Transfon's network, covering datacenter and proxy detection, browser integrity, automation fingerprints and behavioural analysis. The result is a verdict for that session.
Two design choices matter for publishers considering it.
It fails open. If the verdict cannot be reached in time, for example during a network problem, the visitor is treated as genuine and the auction runs. The filter will never cost you a real impression because a lookup was slow.
It runs in parallel. The check happens alongside the normal page load and consent flow, not before it. Real visitors do not wait.
The first thing that changes is bid request volume, which drops by roughly the share of traffic that was invalid. That is expected and is the point.
On the requests that remain, the metrics buyers care about move in the right direction. Viewability and engagement rates rise because the denominator no longer includes sessions that could never be viewed. Bid rates and CPMs on the affected placements typically follow over the next few weeks as buyer algorithms re-learn the inventory.
Reporting also becomes usable again. Fill rate and revenue per thousand reflect people, so placement and bidder decisions are made on real numbers.
Ad server page view counts are unchanged. The filter changes what enters the Prebid auction, not what the ad server or analytics see.
The filter is available to all BiddingStack publishers. Open the project in your dashboard, switch on Enable IVT filter for Prebid in the Demand section, save and publish the configuration. No changes to placements, bidders or ad server setup are needed. The step by step guide is in the BiddingStack documentation.
For publishers already using Transfon Security on their site, the filter reuses the same verdict, so there is no second lookup and no additional tag.
Data Privacy and Security, Performance and User Experience, Regulation Compliance, User and Revenue Growth