How-to

The Channels Page

Every acquisition channel and campaign with Cloudflare's verdict per landing view, spend at risk in your currency, and evidence exports for invalid-traffic credit claims.

12 min readLast updated 22 August 2026
Jump to section

What the page is for

Your analytics tool tells you where visitors came from. It cannot tell you which of them were real, because it only sees visitors who run its JavaScript tag, and most automation never does. The Channels page (under Monitor) answers the question marketing actually needs answered: of the traffic each channel sends, how much is a person and how much is a machine?

Every landing view is classified twice, server-side at the edge. First by acquisition channel: ad platform click IDs are the strongest signal (the platform itself appended them), then UTM tags, then the referring site. Second by Cloudflare's bot verdict on that exact request. Nothing depends on a tag, so the numbers include the traffic tag analytics never sees, and same-site referrers are treated as internal navigation rather than fresh arrivals.

The counts come from a dedicated rollup that is exact by construction. When this page says a channel had 300 bot-scored landings, that is not an extrapolation.

Finding your way around

The page is organised by a section menu on the left: Channels, Campaigns, Landing pages, Geography, Timing, and Detection. The four headline tiles stay in view whichever section you are in. Each section loads its own data the first time you open it and keeps it cached afterwards, so the page opens quickly and switching between sections you have already visited is instant.

The Channels section

The Channels section opens with invalid arrivals over time: bars for bot-scored landing views per interval, a line for the invalid share of all arrivals. The two together separate the cases that matter. A volume spike with a steady share is simply more of everything, usually a campaign going out. A rising share on flat volume means automation is replacing shoppers, which is the replay signature the detector watches for.

Open channel and campaign spike alerts are drawn on the chart as dashed markers at the moment each opened, so the spike and its alert line up visually. Clicking a marker opens the alert.

Reading the table

Each channel row shows landing views split into human, suspicious, and bot-scored, an invalid rate bar, and a trend sparkline of the invalid share across the selected window. Channels where invalid views cost budget directly, meaning paid channels, email, and affiliates, carry a green money badge. Once two full weeks of history are banked, each row also shows its week-over-week change.

A high invalid rate is not automatically an emergency. Direct traffic runs a high rate everywhere, because fleets rarely send a referrer. The rates that deserve attention are the money channels: every invalid view there is a billed click, a wasted send, or a commission earned by automation.

If an open channel-invalid-spike alert exists for a channel, its row carries an alert badge that links straight to the alert.

Download History CSV, next to the table, exports the banked weekly history — one row per channel per week, kept indefinitely, long after the live analytics window has rolled off. It is the feed for your own reporting: a spreadsheet or BI tool can chart every channel's clean-versus-invalid trend from it directly.

The drill-down

Click any row to see who is behind that channel's invalid traffic:

  • Where it came from — the networks running it, each linked to its Offenders profile.
  • What it hit — the paths, with POST and error counts. Catalogue scraping is a cost problem; POSTs at cart and checkout are an attack.
  • What it claimed to be — browser identities. A tight version concentration is the headless-fleet fingerprint.
  • Markets it targets — which countries the invalid slice lands in.
  • Declared identities — named bots inside the slice. For Email this usually names the link scanners, which is most of that channel's invalid share explained.
  • Cloudflare's view of the addresses — the platform's independent IP classification (known bad host, Tor, monitoring service), corroborating the verdict.
  • Referring sites — for the Referral channel, which domains sent the traffic and each domain's own invalid share. Domains running almost entirely bot-scored at real volume carry an explicit fabricated flag: an invented referrer, not a partner.

The drill states plainly how much of the channel's invalid total its facets attribute, rather than pretending they sum exactly.

Email sends and the delivery-hour scan

The Email drill-down carries its own panel: every tagged send, with real clicks against machine clicks and a timeline of the send's first 24 hours, hour by hour.

The panel exists because of a pattern that misleads at first sight. Mailbox security software opens every link in an email as the message is delivered, so a send's machine clicks pile into the delivery hour and then stop, while real recipients keep clicking for hours. Seen only as an invalid-rate number, that looks like an attack; seen on the timeline, it is unmistakably scanning. Each send therefore carries a verdict:

  • Delivery-hour scan — machine clicks concentrated in the delivery window, real clicks trailing on. This is benign email security software. The panel says so plainly, along with the response that actually helps: verify your email platform's machine-click filtering so opens and clicks are reported on human numbers. Do not block or challenge these networks; that can break link scanning and hurt deliverability.
  • Investigate — machine traffic that continues outside delivery windows, which does not match the scanner pattern. Worth checking list hygiene on your sign-up paths and the source networks in the drill-down facets.
  • Sends with too few machine views to classify, or first seen at the edge of the selected window, say so rather than guessing; widening the range resolves the latter.

Each send's real-click figure ("235 of 1.49k") is the number to report engagement on, and the machine slice is the traffic to keep out of browse-abandonment triggers and retargeting audiences. On the Email drill-down the paths facet is titled Links opened rather than "What it hit": spread across pages there usually reflects the links inside the send being opened once each, not browsing.

Send rows come from campaign-tagged landings, so untagged sends don't appear; the timeline needs the send's first hours inside the selected window to classify it.

Geography

The Geography section's world map shows landing views by the visitor's country, coloured by invalid volume, with each country's own invalid rate alongside. The read is straightforward: a market you do not sell to running a near-100% invalid rate is fleet infrastructure, not customers, and a high rate inside a core market means automation is riding your real demand.

A channel selector narrows the map to one channel's arrivals — "which markets is Google Paid's invalid traffic claiming to be from" is the question the evidence exports get asked alongside, and the map answers it directly.

Landing pages

The Landing pages section shows the pages automation actually enters on, ranked by bot-scored arrivals, each with its own invalid rate on the same exact basis as the rest of the page. A search or home page at near-100% is a scripted entry point, a deals page running hot during a campaign is that campaign being replayed, and platform controller URLs appearing here at all is automation using doors no shopper ever lands on.

Click any page to see which channels enter through it, each with Cloudflare's verdict. A page that looks healthy in total can be one channel's favourite scripted entry point — clean paid traffic and a Direct replay problem on the same door. The split records from 21 August 2026; earlier views appear as a labelled unattributed row so the drawer always reconciles with the page's exact total.

Detection

The Detection section groups each invalid arrival by Cloudflare's own account of how the verdict was reached: request heuristics, behavioural machine learning, JavaScript fingerprinting, anomaly detection. Tag-based tools infer threat types from whatever runs in the browser; this comes from the platform that saw every request, including the ones that never executed a script.

Below the totals, a per-channel method mix shows how each channel's invalid traffic was caught. The mix is a fingerprint the totals hide: a channel caught almost entirely by request heuristics is crude automation, easy to exclude; one caught mostly by behavioural machine learning is sophisticated, and worth the evidence log.

Campaigns

The Campaigns section shows the same verdicts at the level marketing plans at: landing views carrying one of your campaign codes (sourceCode, marketingCode, or utm_campaign). One campaign with a high invalid rate while its siblings stay clean means bots are re-requesting that campaign's tagged URLs. Each row carries a trend sparkline of its invalid share across the window, so a code that started climbing on Tuesday reads as exactly that.

Paid campaign rows also expand into their own drill-down: the networks, paths, claimed browser identities, and claimed countries behind that one campaign's invalid clicks, built from the same click log the Evidence CSV exports — so what you investigate and what you attach to a claim are the same population.

Each campaign is also watched by its own detector, the campaign-invalid-spike, which compares a code's invalid share against that code's own weekly baseline — across every channel at once. That last part matters: when fleets replay a campaign's tagged URLs they send no referrer and no click ID, so the bot-scored views arrive as Direct, not on the email or paid channel that owns the code, and the owning channel's numbers can look perfectly clean while the campaign is being replayed. When the detector opens an alert, the campaign's row carries a badge linking to it, and the alert itself names where the replayed views are landing.

Paid campaigns carry their own Evidence and IPs downloads on the row — the same evidence CSV and paste-ready IP exclusion list as the channel drill-down, scoped to that one campaign. Claims and IP exclusions are filed per campaign in the ad platform, so the artifact scopes the same way. Owner-only, like every evidence export.

Privacy is by allowlist: only those three parameters are ever read, values must look like campaign codes, and nothing user-typed is stored.

Spend at risk

Add cost-per-view estimates in Settings, under Channel spend estimates: average cost per click for paid channels, cost per delivered email, average commission per referred visit for affiliates. The page then turns invalid views into currency figures on the money tile, on each money-channel row, and on each campaign. Estimates are display-only and never affect detection.

Evidence and exclusions for the ad platforms

Paid channel drill-downs include two downloads, both owner-only, both built from a thirty-day log of bot-scored clicks that carried an ad platform click ID.

Evidence CSV lists those clicks with timestamps, campaign codes, click IDs, source addresses, paths, networks, and bot scores. This is the attachment an invalid-traffic credit claim needs.

IP exclusions is the fix rather than the refund: a paste-ready list of the source addresses behind those billed clicks, ranked by click count and capped at the five hundred entries Google Ads accepts per campaign. Add it under your campaign's IP exclusion settings. As everywhere in Edge, applying it is your decision and your click; Edge only prepares the list.

The same evidence surfaces on the ranking pages: networks behind billed clicks carry a green billed badge on Offenders (clicking it lands back here with the billing channel's drill-down open), and the IPs page shows per-address billed-click counts with a matching filter.

Timing

The Timing section's hour-of-day strip shows each channel's invalid share across the day, over the last week. Real shoppers follow waking hours, so human-heavy channels cool overnight. Fleets run flat around the clock: an unbroken hot strip is the machine signature, and a channel that only heats up in the small hours tells you exactly when the replay runs.

Alerts and the weekly report

Two detectors watch this page's numbers. The channel-invalid-spike watches the money channels and opens an alert when a channel's invalid share jumps against its own weekly baseline, with an absolute floor so a wobble on a handful of views never pages anyone. It deliberately ignores organic and referral channels, which carry a permanent bot background. The campaign-invalid-spike is its campaign-grain twin, described in the Campaigns section: it watches each code across all channels, because a single replayed campaign can hide inside a flat channel aggregate. Neither detector ever suggests blocking a channel or pausing a campaign — real customers arrive through both.

The weekly bot report includes a Marketing channels section built from banked weekly history, so channel trends survive beyond the live analytics window and week-over-week comparisons come from full, comparable weeks only. The section opens with a short generated summary, clearly labelled as such: a few sentences composed strictly from the week's own numbers, never anything invented, and the section reads identically without it if generation is unavailable.

Requirements

Channel classification reads three Logpush fields: ClientRequestURI (click IDs, UTM tags, campaign codes), ClientRequestReferer (the referring site), and ClientRequestHost (the hostname the visitor asked for). The last one is what lets Edge tell navigation within your own site apart from a real referral arrival — without it, every internal page-to-page move counts as a Referral landing and the Referral numbers inflate badly. If your traffic isn't shipping ClientRequestHost, the page says so in a banner rather than presenting inflated numbers unqualified; add the field to the CDN Zones Logpush job and classification corrects itself from the next batch. See HTTP Methods and Required Logpush Fields.

Data start dates

Channel classification began on 21 August 2026, with campaign codes, referring sites, the evidence log, country geography, landing pages, detection methods, and the email send panel all following the same day. Windows that reach further back undercount until they roll past those dates, and week-over-week comparisons begin once two full weeks are banked.

Still stuck? Email support or open the support widget in the bottom-right.