Skip to main content

Bot Detection & Traffic Quality

Sealmetrics uses multiple layers of protection — from IP and User-Agent blocklists to HMAC token validation and domain authorization — so that your analytics data reflects real human visitors, not bots or spam traffic. Detected bot traffic is blocked immediately, never stored, and never appears in reports.


How does Sealmetrics detect bots?​

1. IP blocklist​

The IP of each request is checked in flight against blocklists, and is not stored either way:

  • Global list — a public list of IPs known to send automated traffic
  • Per-account blocklist — IPs or CIDR ranges you choose to exclude

2. User-Agent filtering​

Bot signatures in the User-Agent string are detected:

  • Known bot identifiers (Googlebot, Bingbot, etc.)
  • Automated tool signatures (curl, wget, python-requests)
  • Headless browser patterns (HeadlessChrome, PhantomJS)

3. Burst detection​

A session that sends too many pageviews within a few seconds is blocked for a period. This check applies to traffic whose country cannot be determined.

4. HMAC token validation​

Each request includes a cryptographic token:

  • Validates that the request comes from the tracker served for your account
  • Time-bound token expiration

5. Domain authorization​

Only authorized domains can send data:

  • Configure allowed domains in Settings
  • Prevents data injection from unauthorized sources
  • Subdomain wildcard support

What happens when bot traffic is detected?​

When bot traffic is detected:

  1. Blocked immediately — No data stored
  2. Logged for analysis — Helps improve detection
  3. Not counted — Never appears in reports

What gets filtered?​

Traffic TypeFilteredNotes
Search engine crawlersYesGooglebot, Bingbot, etc.
SEO toolsYesAhrefs, Semrush, Moz
Uptime monitorsYesPingdom, UptimeRobot
Security scannersYesVulnerability scanners
Automated testingYesSelenium, Puppeteer
Known automated-traffic IPsYesPublic list of automated-traffic IPs
Your own test trafficConfigurableOptional filtering

What Passes Through​

Traffic TypeTrackedNotes
Real browsersYesChrome, Firefox, Safari, etc.
Mobile appsYesIn-app browsers
VPN usersYesLegitimate users with VPNs
Tor exit nodesConfigurableCan be filtered if needed

Agent Detection (not available)​

Not live

Advanced agent detection — also referred to as Agent Analytics — is designed but not live, and cannot be enabled on any account, including on request. Nothing described in this section runs today, and no account collects behavioral signals. The layers above are the whole of what filters bot traffic.

If it ships, it would work like this:

  1. Initial classification — first hit analyzed
  2. Behavioral signals — mouse movements, scroll patterns, timing
  3. Final classification — human vs. suspected agent

Planned classification results:

ClassificationMeaning
humanConfirmed human behavior
agent_suspectedAutomated behavior detected

Classification would happen at session level: the entrance is classified and its pageviews inherit the result.


Custom Blocklists​

Adding IPs to Blocklist​

You can exclude specific IPs via the dashboard:

  1. Go to Settings → Security
  2. Select IP Blocklist
  3. Add IPs or CIDR ranges
192.168.1.100        # Single IP
10.0.0.0/8 # CIDR range

Common Use Cases​

  • Exclude your office IP
  • Block competitor scrapers
  • Filter internal testing traffic

User-Agent Blocklist​

Block traffic by User-Agent patterns:

  1. Go to Settings → Security
  2. Select UA Blocklist
  3. Add patterns (supports regex)
curl/*               # Block curl requests
python-requests/* # Block Python scripts
custom-bot/* # Block specific bot

Data Quality Indicators​

In your reports, look for:

  • Bounce rate — Extremely high rates may indicate bot traffic
  • Session duration — 0-second sessions could be bots
  • Geographic distribution — Unusual concentrations warrant investigation

Best Practices​

  1. Review traffic periodically — Check for anomalies
  2. Use content grouping — Helps identify targeted bot traffic
  3. Monitor conversion rates — Bots don't convert
  4. Check referrer sources — Unknown referrers may be spam

Comparison with Other Tools​

FeatureSealmetricsGoogle Analytics
Bot filteringBlocklists, burst detection, token and domain checksSingle checkbox
Custom blocklistsYesLimited
Real-time blockingYesDelayed
Transparent filteringYesBlack box
In short
  • Bot traffic is filtered by IP blocklists (the IP is checked in flight and not stored), User-Agent signatures, a burst detector, HMAC token validation and domain authorization; blocked hits are never counted.
  • Search engine crawlers, SEO tools, uptime monitors, security scanners, automated testing and IPs on the public automated-traffic list are filtered; real browsers, in-app browsers and VPN users pass through.
  • Custom IP/CIDR and User-Agent blocklists are configurable per account; Agent Analytics (behavioral human-vs-agent classification) is designed but not live and cannot be enabled.

Written and maintained by the Sealmetrics Team