How-to
Reading the Offenders Page
How to interpret the ASN table and drill into a suspicious network.
Jump to section
Summary strip
At the top of the page, a summary strip reads: "N ASNs · X requests (Y% of total) · Z open alerts" -- giving you an instant sense of scale for the current filter set.
Filter bar
Eight dropdown filters sit below the summary:
- ASN Country -- filter by the ASN's headquarters country (where the network is registered, not where its traffic originates)
- Bypass tier -- High (≥80%), Elevated (≥50%), or Normal (below 50%)
- Alerts -- filter to ASNs that have / don't have open alerts
- Type -- ISP, Cloud, VPN-Proxy, Transit, or Unknown
- Firewall -- filter by firewall action (see below)
- Channel -- re-rank by traffic attributed to one acquisition channel. "Worst networks on Google Paid" and "worst networks overall" are different lists, and this filter is the difference. Combined with the billed badge it answers "who is polluting the channels I pay for"
- Identity -- filter by declared identity: verified crawlers, AI agents, other declared bots, or nothing declared at all. "No declared identity" plus high volume is the actual offenders shortlist; a verified crawler at high volume is usually just a crawler
- Billed -- only networks whose addresses appear in your billed invalid ad clicks over the last 7 days (see the billed badge below)
Firewall filter pills
The Firewall dropdown surfaces what the edge actually did with each ASN's traffic. Five options:
| Pill | Matches |
|---|---|
| Any mitigation | ASNs where ≥1 request was blocked, challenged, or connection-closed |
| Blocked | ASNs with at least one block action |
| Challenged | ASNs hitting any of the challenge variants |
| Conn. closed | ASNs with a connection-close action (rare — anti-DDoS reset) |
| Monitor mode only | ASNs where log/allow rules fired but no mitigating action ever did |
The "Monitor mode only" pill is the inverse of "Any mitigation": rules fire but don't enforce. These are the ASNs worth auditing — either the rule should be promoted to a block/challenge, or it should be removed if it's noise. A residential ISP showing 100% log matches is usually a stale rule that hasn't been reviewed.
The pills only render when there are ASNs to populate them.
"Traffic from" chip
When you click a country on the Overview world map, or click through from a status code or cache status row, a "Traffic from" chip appears in the filter bar. This filters by the geographic origin of the requests, which is different from the ASN Country filter (based on the network's headquarters). For example, "Traffic from: Vietnam" shows all ASNs whose requests originate in Vietnam, even if those ASNs are headquartered elsewhere.
Search box
A search box lets you filter by AS number or organisation name. Type "45899" or "VNPT" to find a specific network. Organisation names are kept current from a live directory, so newer hosting and VPN networks resolve to real names rather than numbers.
Table columns
Each row in the Offenders table shows:
| Column | Description |
|---|---|
| ASN | AS number with organisation name, country flag, alert badge (if open alerts exist), and a bgp.tools link icon |
| Requests | Total request count with a proportional magnitude bar |
| % of total | This ASN's share of all traffic |
| Trend | A sparkline showing the traffic pattern over the selected window |
| Bytes | Total egress bytes |
| BPR | Bytes per request -- a low BPR (e.g. <1 KB) combined with high volume is a scraper signal |
| 499 rate | Percentage of requests where the client closed the connection |
| Hit rate | Cache hit ratio for this ASN. Renders "—" when cache outcomes are mostly unknown (typical of ASNs blocked at the edge before a cache decision), rather than a misleadingly healthy number |
| Bypass rate | Three-tier colouring: red at ≥80%, amber at ≥50%, normal below 50% |
| Origin bot load | Automated requests from this network that missed cache and reached your origin, with the network's bot share and how much of it reached origin underneath. Renders "—" when the source is not sending a bot score |
All columns are sortable -- click any column header to sort ascending/descending.
Ranking by what a network costs you
Sorting by Origin bot load is the fastest way to find what is actually costing you, and it will usually not agree with sorting by Requests.
Automated traffic your cache serves costs your origin nothing, however much of it there is. A crawler working steadily through your product images can be the single largest network on the page and still be free. A smaller network that misses cache on every request is the one your origin is paying for.
Sorting by Requests cannot tell those apart. Sorting by Origin bot load ranks them by the automation that actually reached you, so the expensive one rises to the top even when it is nowhere near the biggest by volume.
If the column shows "—" for every row, your source is not sending Cloudflare's bot score and automated traffic cannot be separated from human traffic. See Required Logpush fields.
The billed badge and the scanner chip
Two classifications appear next to a network's name when the data supports them:
- Billed badge (green) -- this network's addresses appear in your billed invalid ad clicks over the last 7 days: bot-scored landings that carried a real ad-platform click ID, meaning the platform charged you for them. The badge shows the click count, and an estimated spend once your channel rates are configured in Settings. It reads from the click-level evidence log over a fixed 7-day window, independent of the page's range picker, so it means the same thing on every page. Clicking the badge opens the channel that billed most of those clicks, with the evidence CSV and the paste-ready IP exclusion list right there. Volume and cost correlate poorly: a network can sit far down this table by requests and still be the one wasting your ad budget.
- Scanner infra chip (blue) -- this network's automation is email delivery-hour link scanning: mailbox security software opening links as messages arrive. The chip only appears while the Email channel itself classifies as delivery-time scanning, and only for networks whose bot landings are predominantly email. It exists so benign email security never tops your offenders list looking like an attack. Do not block or challenge these networks; that can break link scanning and hurt deliverability.
Pin and Ignore
- Pin an ASN to float it to the top of the table, regardless of sort order. Useful for watching a suspect network.
- Ignore an ASN to hide it from the table. Ignored ASNs are hidden behind a "Show N ignored" toggle at the bottom.
Pins and ignores are saved to your workspace and shared with your whole team: when you pin an ASN, your colleagues see it pinned too, on every device.
CSV export
Click the Export CSV button to download the current filtered view as a CSV file.
Drilling into an ASN
Click any row to open the ASN detail page: stat tiles, stacked timeseries with site-wide baseline overlay, cache breakdown, status codes, firewall actions, top paths, top IPs, UA families, alert history, and a Suggest rule button that drafts an eCDN rule for this network on demand.