Bot Detection & Traffic Quality
Sealmetrics uses multiple layers of protection — from IP and User-Agent blocklists to HMAC token validation and domain authorization — so that your analytics data reflects real human visitors, not bots or spam traffic. Detected bot traffic is blocked immediately, never stored, and never appears in reports.
How does Sealmetrics detect bots?
1. IP blocklist
The IP of each request is checked in flight against blocklists, and is not stored either way:
- Global list — a public list of IPs known to send automated traffic
- Per-account blocklist — IPs or CIDR ranges you choose to exclude
2. User-Agent filtering
Bot signatures in the User-Agent string are detected:
- Known bot identifiers (Googlebot, Bingbot, etc.)
- Automated tool signatures (curl, wget, python-requests)
- Headless browser patterns (HeadlessChrome, PhantomJS)
3. Burst detection
A session that sends too many pageviews within a few seconds is blocked for a period. This check applies to traffic whose country cannot be determined.
4. HMAC token validation
Each request includes a cryptographic token:
- Validates that the request comes from the tracker served for your account
- Time-bound token expiration
5. Domain authorization
Only authorized domains can send data:
- Configure allowed domains in Settings
- Prevents data injection from unauthorized sources
- Subdomain wildcard support
What happens when bot traffic is detected?
When bot traffic is detected:
- Blocked immediately — No data stored
- Logged for analysis — Helps improve detection
- Not counted — Never appears in reports
What gets filtered?
| Traffic Type | Filtered | Notes |
|---|---|---|
| Search engine crawlers | Yes | Googlebot, Bingbot, etc. |
| SEO tools | Yes | Ahrefs, Semrush, Moz |
| Uptime monitors | Yes | Pingdom, UptimeRobot |
| Security scanners | Yes | Vulnerability scanners |
| Automated testing | Yes | Selenium, Puppeteer |
| Known automated-traffic IPs | Yes | Public list of automated-traffic IPs |
| Your own test traffic | Configurable | Optional filtering |
What Passes Through
| Traffic Type | Tracked | Notes |
|---|---|---|
| Real browsers | Yes | Chrome, Firefox, Safari, etc. |
| Mobile apps | Yes | In-app browsers |
| VPN users | Yes | Legitimate users with VPNs |
| Tor exit nodes | Configurable | Can be filtered if needed |
Agent Detection (not available)
Advanced agent detection — also referred to as Agent Analytics — is designed but not live, and cannot be enabled on any account, including on request. Nothing described in this section runs today, and no account collects behavioral signals. The layers above are the whole of what filters bot traffic.
If it ships, it would work like this:
- Initial classification — first hit analyzed
- Behavioral signals — mouse movements, scroll patterns, timing
- Final classification — human vs. suspected agent
Planned classification results:
| Classification | Meaning |
|---|---|
human | Confirmed human behavior |
agent_suspected | Automated behavior detected |
Classification would happen at session level: the entrance is classified and its pageviews inherit the result.
Custom Blocklists
Adding IPs to Blocklist
You can exclude specific IPs via the dashboard:
- Go to Settings → Security
- Select IP Blocklist
- Add IPs or CIDR ranges
192.168.1.100 # Single IP
10.0.0.0/8 # CIDR range
Common Use Cases
- Exclude your office IP
- Block competitor scrapers
- Filter internal testing traffic
User-Agent Blocklist
Block traffic by User-Agent patterns:
- Go to Settings → Security
- Select UA Blocklist
- Add patterns (supports regex)
curl/* # Block curl requests
python-requests/* # Block Python scripts
custom-bot/* # Block specific bot
Data Quality Indicators
In your reports, look for:
- Bounce rate — Extremely high rates may indicate bot traffic
- Session duration — 0-second sessions could be bots
- Geographic distribution — Unusual concentrations warrant investigation
Best Practices
- Review traffic periodically — Check for anomalies
- Use content grouping — Helps identify targeted bot traffic
- Monitor conversion rates — Bots don't convert
- Check referrer sources — Unknown referrers may be spam
Comparison with Other Tools
| Feature | Sealmetrics | Google Analytics |
|---|---|---|
| Bot filtering | Blocklists, burst detection, token and domain checks | Single checkbox |
| Custom blocklists | Yes | Limited |
| Real-time blocking | Yes | Delayed |
| Transparent filtering | Yes | Black box |
- Bot traffic is filtered by IP blocklists (the IP is checked in flight and not stored), User-Agent signatures, a burst detector, HMAC token validation and domain authorization; blocked hits are never counted.
- Search engine crawlers, SEO tools, uptime monitors, security scanners, automated testing and IPs on the public automated-traffic list are filtered; real browsers, in-app browsers and VPN users pass through.
- Custom IP/CIDR and User-Agent blocklists are configurable per account; Agent Analytics (behavioral human-vs-agent classification) is designed but not live and cannot be enabled.
Related Documentation
- Domain Authorization
- First-Party Tracking
- Security & Privacy overview
- Bot Stats — query filtered bot traffic through the API
- Frequently Asked Questions — common privacy and traffic-quality questions