How-to

Reading the Offenders Page

How to interpret the ASN table and drill into a suspicious network.

6 min readLast updated 22 August 2026
Jump to section

Summary strip

At the top of the page, a summary strip reads: "N ASNs · X requests (Y% of total) · Z open alerts" -- giving you an instant sense of scale for the current filter set.

Filter bar

Eight dropdown filters sit below the summary:

  • ASN Country -- filter by the ASN's headquarters country (where the network is registered, not where its traffic originates)
  • Bypass tier -- High (≥80%), Elevated (≥50%), or Normal (below 50%)
  • Alerts -- filter to ASNs that have / don't have open alerts
  • Type -- ISP, Cloud, VPN-Proxy, Transit, or Unknown
  • Firewall -- filter by firewall action (see below)
  • Channel -- re-rank by traffic attributed to one acquisition channel. "Worst networks on Google Paid" and "worst networks overall" are different lists, and this filter is the difference. Combined with the billed badge it answers "who is polluting the channels I pay for"
  • Identity -- filter by declared identity: verified crawlers, AI agents, other declared bots, or nothing declared at all. "No declared identity" plus high volume is the actual offenders shortlist; a verified crawler at high volume is usually just a crawler
  • Billed -- only networks whose addresses appear in your billed invalid ad clicks over the last 7 days (see the billed badge below)

Firewall filter pills

The Firewall dropdown surfaces what the edge actually did with each ASN's traffic. Five options:

PillMatches
Any mitigationASNs where ≥1 request was blocked, challenged, or connection-closed
BlockedASNs with at least one block action
ChallengedASNs hitting any of the challenge variants
Conn. closedASNs with a connection-close action (rare — anti-DDoS reset)
Monitor mode onlyASNs where log/allow rules fired but no mitigating action ever did

The "Monitor mode only" pill is the inverse of "Any mitigation": rules fire but don't enforce. These are the ASNs worth auditing — either the rule should be promoted to a block/challenge, or it should be removed if it's noise. A residential ISP showing 100% log matches is usually a stale rule that hasn't been reviewed.

The pills only render when there are ASNs to populate them.

"Traffic from" chip

When you click a country on the Overview world map, or click through from a status code or cache status row, a "Traffic from" chip appears in the filter bar. This filters by the geographic origin of the requests, which is different from the ASN Country filter (based on the network's headquarters). For example, "Traffic from: Vietnam" shows all ASNs whose requests originate in Vietnam, even if those ASNs are headquartered elsewhere.

A search box lets you filter by AS number or organisation name. Type "45899" or "VNPT" to find a specific network. Organisation names are kept current from a live directory, so newer hosting and VPN networks resolve to real names rather than numbers.

Table columns

Each row in the Offenders table shows:

ColumnDescription
ASNAS number with organisation name, country flag, alert badge (if open alerts exist), and a bgp.tools link icon
RequestsTotal request count with a proportional magnitude bar
% of totalThis ASN's share of all traffic
TrendA sparkline showing the traffic pattern over the selected window
BytesTotal egress bytes
BPRBytes per request -- a low BPR (e.g. <1 KB) combined with high volume is a scraper signal
499 ratePercentage of requests where the client closed the connection
Hit rateCache hit ratio for this ASN. Renders "—" when cache outcomes are mostly unknown (typical of ASNs blocked at the edge before a cache decision), rather than a misleadingly healthy number
Bypass rateThree-tier colouring: red at ≥80%, amber at ≥50%, normal below 50%
Origin bot loadAutomated requests from this network that missed cache and reached your origin, with the network's bot share and how much of it reached origin underneath. Renders "—" when the source is not sending a bot score

All columns are sortable -- click any column header to sort ascending/descending.

Ranking by what a network costs you

Sorting by Origin bot load is the fastest way to find what is actually costing you, and it will usually not agree with sorting by Requests.

Automated traffic your cache serves costs your origin nothing, however much of it there is. A crawler working steadily through your product images can be the single largest network on the page and still be free. A smaller network that misses cache on every request is the one your origin is paying for.

Sorting by Requests cannot tell those apart. Sorting by Origin bot load ranks them by the automation that actually reached you, so the expensive one rises to the top even when it is nowhere near the biggest by volume.

If the column shows "—" for every row, your source is not sending Cloudflare's bot score and automated traffic cannot be separated from human traffic. See Required Logpush fields.

The billed badge and the scanner chip

Two classifications appear next to a network's name when the data supports them:

  • Billed badge (green) -- this network's addresses appear in your billed invalid ad clicks over the last 7 days: bot-scored landings that carried a real ad-platform click ID, meaning the platform charged you for them. The badge shows the click count, and an estimated spend once your channel rates are configured in Settings. It reads from the click-level evidence log over a fixed 7-day window, independent of the page's range picker, so it means the same thing on every page. Clicking the badge opens the channel that billed most of those clicks, with the evidence CSV and the paste-ready IP exclusion list right there. Volume and cost correlate poorly: a network can sit far down this table by requests and still be the one wasting your ad budget.
  • Scanner infra chip (blue) -- this network's automation is email delivery-hour link scanning: mailbox security software opening links as messages arrive. The chip only appears while the Email channel itself classifies as delivery-time scanning, and only for networks whose bot landings are predominantly email. It exists so benign email security never tops your offenders list looking like an attack. Do not block or challenge these networks; that can break link scanning and hurt deliverability.

Pin and Ignore

  • Pin an ASN to float it to the top of the table, regardless of sort order. Useful for watching a suspect network.
  • Ignore an ASN to hide it from the table. Ignored ASNs are hidden behind a "Show N ignored" toggle at the bottom.

Pins and ignores are saved to your workspace and shared with your whole team: when you pin an ASN, your colleagues see it pinned too, on every device.

CSV export

Click the Export CSV button to download the current filtered view as a CSV file.

Drilling into an ASN

Click any row to open the ASN detail page: stat tiles, stacked timeseries with site-wide baseline overlay, cache breakdown, status codes, firewall actions, top paths, top IPs, UA families, alert history, and a Suggest rule button that drafts an eCDN rule for this network on demand.

Still stuck? Email support or open the support widget in the bottom-right.