Filter bot traffic before it reaches your landing page
Analytics tools can hide bots from your reports, but by then the page has already been served. Filtering at the link decides who reaches your landing page in the first place.
Updated
Where bot traffic on campaign links comes from
Any link you publish gets visited by software: search and social crawlers, link-preview bots, price and content scrapers, uptime monitors, mail security scanners, and automated click traffic on paid placements. Most of it is harmless, but none of it is a customer.
Why filtering on the page is too late
Bot filtering in an analytics tool removes known bots from reports after the visit. The page was still served, the offer was still seen, a form could still be submitted, and conversion counts based on landings are still off. Filtering at the link happens before the redirect, so a bot never reaches the page you care about.
The signals worth checking
Each signal catches a different kind of traffic. Most setups start with the first three.
- Bots and headless browsers: crawler names and automation tools in the user agent.
- Datacenter and server IPs: real people rarely browse from cloud providers or hosting companies.
- Tor exit nodes and visits with no identifiable ISP.
- Repeated clicks: many clicks from one IP in a short time.
- No referrer: useful for links that should always come from a known page.
- IPv6: only in special cases, since many real mobile users browse over IPv6.
Trade-offs to keep in mind
Every rule has false positives. Some company VPNs use datacenter IPs, privacy-minded people use Tor, and shared office networks produce repeat clicks. Turn on what matches your traffic, watch the results for a few days, and allowlist the IPs you know, such as your own team and QA.
What to show filtered traffic
Filtered visitors should still get a normal page: a neutral article or a generic page that loads fine. Crawlers and scanners see a working page, and your offer page, forms and conversion counts only see people.
Bot filtering in LumyFlow
Every LumyFlow campaign has a set of protections you switch on per campaign: block bots, datacenter and server traffic, Tor exit nodes, visitors with no ISP or no referrer, IPv6 visitors, and repeated clicks from one IP with a daily limit. Blocked clicks go to destination B, and allowlisted IPs and ranges always reach destination A.
Save a set of conditions once as a filter list and apply it to any campaign. The Traffic log shows each blocked click and the reason, so you can tune rules from real data.