Skip to content

Affiliate click fraud and compliance: a guide for publishers

What affiliate click fraud is, how it is detected on the publisher side, what the FTC and the EU require, and why a cookie-free tag simplifies everything.

By convli teamPublished 5 min read
Cover illustration: Affiliate click fraud and compliance: a guide for publishersconvli

Affiliate click fraud is any click or conversion manufactured to collect a commission that was not earned: bots that click, extensions that rewrite links at the last second, stolen coupons, bought traffic that never buys. Affiliate marketing pays for results, and where results are paid for there are incentives to manufacture them. An honest publisher can be dragged into these problems without looking for them: a campaign rejected for “suspicious traffic”, a network holding payments, a reader complaining about a misleading link.

This article covers the two faces of compliance a publisher controls: keeping traffic clean and keeping to disclosure and privacy rules. It is not legal advice; it is a practical guide to what to ask and what to demand from the platform you use.

What kinds of fraud affect a publisher?

Non-human clicks: crawlers, bots and monitoring tools that follow links. They never buy, but they inflate CTR and can trip alarms at the network. Forced clicks: hidden iframes or automatic redirects that record a click without the reader’s intent — banned in every program. Cookie hijacking: extensions or scripts that replace another affiliate’s identifier with their own just before purchase. And incentivized or bought traffic: visits that arrive for a reward rather than interest, with conversion close to zero.

The publisher rarely originates these practices, but usually bears the consequences if its platform does not filter them.

How is click fraud detected on the publisher side?

The first defense is counting only what a human could have seen: an impression exists when half of the module was on screen for at least one second, not when the code executed. The second is signing every click: the link carries a server-issued token that expires and cannot be forged, so a click without a valid token does not count. That is how the publisher tag from convli works.

The third is de-duplication: several clicks from the same browser on the same link within minutes count as one. The fourth is flagging rather than blocking: a click with a bot signature is recorded with a reason (“known user agent”, “no prior impression”, “ineligible country”) and excluded from payments, but remains visible in reports so the publisher understands what happened. Those filtered clicks also stay out of the rotation that learns from results, so a bot cannot skew which campaign gets shown.

And the fifth, on the conversion side, is idempotency: the network may resend the same postback several times; the system must recognize it and count the sale once.

Clean traffic is not declared: it is demonstrated with viewable impressions, signed clicks and conversions counted exactly once.

What do the FTC, the European Union and Latin America require on disclosure?

In the United States, the FTC’s endorsement guides require any commercial relationship to be disclosed clearly and conspicuously, close to the content, without relying on the reader hovering or opening a drop-down. In the European Union, the Unfair Commercial Practices Directive and national rules (Spain, Germany, France) require advertising to be identified as such; regulators have fined brands and creators alike. Argentina, Mexico, Chile and Colombia apply equivalent criteria through their consumer-protection and fair-trading laws.

For a publisher, the right practice is simple: every commercial module carries a visible “Sponsored” word, every affiliate link is marked rel=“sponsored” (as Google’s guidance on outbound links asks) and buying guides open with a note that the publication may earn a commission. The same rules apply to anyone posting on social media; the influencer guide goes into detail. None of this lowers conversion; its absence lowers trust.

Why does a cookie-free tag simplify consent?

The GDPR and the ePrivacy directive in Europe, and laws such as California’s in the United States, require consent for cookies and equivalent technologies that are not strictly necessary. An affiliate module that stores an identifier in the reader’s browser to follow them across pages falls squarely into that category: it needs the banner, consent management and everything that entails.

The alternative is to design the tag so it needs none of that: no cookies, no device fingerprint, no persistent identifiers. The click carries its identifier in the URL to the network; the impression is recorded with a hash of the IP address that changes daily, enough to de-duplicate and nothing more. With that design, every widget format runs without creating new consent obligations for the publisher and without touching the trust relationship with the reader. The network and the merchant will set their own cookies when the reader reaches their site, and that falls under their policies.

Content compliance

Networks and programs have their own rules: no bidding on the brand name in search engines, no unauthorized coupons, excluded categories (gambling, alcohol, unlicensed financial products), excluded markets. A publisher should be able to see those restrictions on the campaign sheet before using it and trust that the platform will not show campaigns its site cannot run.

It also pays to review your own contracts: some programs forbid links in newsletters or on social media; others require the displayed price to be refreshed frequently. When a platform normalizes these rules and applies them before serving, the publisher stops reading fine print.

A checklist

Impressions counted only when viewable. Clicks signed with an expiring token. De-duplication and bot reasons visible in reports. Idempotent postbacks. A “Sponsored” label on every module and rel=“sponsored” on every link. An affiliate note in buying guides. No cookies or persistent identifiers in the tag. Program rules applied before serving. Properties reviewed before activation. And a clear channel to report abuse.

Nothing on that list is exotic. All of it can be verified by asking the platform how it does it and checking in the browser. A publisher who can answer those ten questions sleeps well, gets paid on time and keeps its readers.

Frequently asked questions

Is the publisher liable when a bot clicks its affiliate links?

It almost never causes the problem, but the network can hold payments or reject the campaign if that traffic is not filtered. That is why it pays to use a platform that flags suspicious clicks with a reason and excludes them from payouts before they reach the network.

Is an “affiliate link” note at the end of the article enough?

No. The FTC and European regulators expect the disclosure to sit close to the content and be visible without scrolling or opening a drop-down. The usual practice is a note at the top of the guide plus a “Sponsored” label on every commercial module.

Does a cookie-free affiliate tag need a consent banner?

If it stores no identifiers in the browser and takes no device fingerprint, it creates no new consent obligation for the publisher. The cookies the network and the merchant set on their own sites fall under their policies.

convli team · convli

Ready to earn from what you already publish?

Create an account and add your first property in minutes.