How blocking works
Why we never block a shared IP
Most click-fraud tools decide an IP address is fraudulent and block it outright. On Indian mobile networks that address can belong to thousands of unrelated people at once. This page explains why, and what we do instead.
What carrier-grade NAT actually does
India has roughly 48 million routable IPv4 addresses for well over a billion internet connections. To make that work, Jio, Airtel, Vi, and BSNL route mobile data through carrier-grade NAT (CGNAT) — thousands of subscribers sharing one public IP address at a time. It’s standard architecture, not a misconfiguration, and it isn’t unique to India, but India’s mobile-first ad traffic makes it the dominant case here.
These pools aren’t drawn tightly around a neighbourhood or a pincode. Carrier gateways operate at a regional or circle level — a subscriber’s public IP commonly traces back to a gateway in Mumbai or Delhi regardless of which city they’re actually in. A pool can span an entire metro area or state.
What this means for IP-based blocking. If a click-fraud tool blocks an IP after seeing a couple of suspicious clicks from it, and that IP is a CGNAT gateway, every other subscriber behind that same gateway is blocked too — including real customers who never clicked anything fraudulent. Because the ad simply stops showing to them, nobody sees this happen. No error, no complaint, just a customer who was never reached.
Why we don’t do it this way
We use IP as one signal among several, never as the sole basis for a block. Two rules are built into the scoring engine specifically for this:
Never blocked, whatever the score
- Known CGNAT ranges, including
100.64.0.0/10, used heavily by Jio and Airtel - Private, loopback, link-local, and multicast address ranges
- Any IP with 12 or more distinct devices behind it
What we weight instead
- Device-level repetition — the same browser or device fingerprint clicking repeatedly
- Behavioural signals — mouse, touch, scroll, and keyboard activity, or the lack of it
- Automation tells — headless browser flags, implausible device characteristics
- Sustained daily patterns — a device that returns and re-clicks a paid ad every day
The 12-devices-per-IP guard exists because office NAT and carrier CGNAT produce the same shape of data as a genuine burst of repeat clicking — many clicks, one address. There is no way to tell them apart from IP volume alone. So volume alone never triggers a block; it only raises a device’s score if that same device is independently showing automation or behavioural signals too.
The deliberate trade-off. This means GhostClicks will sometimes under-block — a fraudulent click from a busy CGNAT range may go unblocked because we can’t isolate it from the legitimate traffic sharing that address. We accept that. Wrongly excluding a shared IP silently suppresses real buyers who never appear in any report to tell you they were turned away. Missing a fraudulent click costs you the click’s price. Blocking a real customer by mistake costs you the sale, and you’d never know it happened.
What this looks like in practice
| Scenario | An IP-only tool | GhostClicks |
|---|---|---|
| One device clicks the same ad 8 times in a week | Blocks the IP if volume crosses a threshold | Flags the device fingerprint, not the IP; blocks only if the device is also excludable |
| A CGNAT gateway serving 10,000 subscribers sends a fraudulent click | May block the gateway IP, cutting off every subscriber behind it | Never blocks the range; relies on device and behavioural signals to isolate the click |
| A ten-person office clicks an ad from one NAT address | Reads as high-volume repeat clicking from one IP | Guarded by the 12-devices-per-IP rule — distinct devices, not blocked as one actor |
Where this still has limits
This approach reduces the risk of silently losing real customers; it doesn’t eliminate every edge case. A small, tightly-targeted campaign concentrated on a local wired ISP with a narrower allocation could still see genuine collisions between a fraudster and a real customer sharing an address — we don’t yet have confirmed data on how granularly every regional wired provider allocates its pools, and we say so rather than claim more precision than we have.
What we can say with confidence, because it’s enforced in code rather than asserted in a brochure: no exclusion this product writes to a Google Ads account will ever contain a known CGNAT range, a private address range, or an address with a dozen or more distinct devices behind it.
See also: what we can and can’t see in your account and on your website. Questions? support@ghostclicks.in