What you get
Your attribution is never changed. A fraud rule never moves credit between networks and never turns an attributed install into an organic one. Your reports keep the same totals. Fraud Control only changes how a record is labelled and, at most, whether its postback is sent.
Get started in five steps
1
Read the overview
The Linkrunner-managed rules already report a fraud rate. Look at it before changing anything.
2
Add one rule on Tag only
Start from a template where one fits. Tag only flags matches for reporting and changes nothing else.
3
Check the impact preview
Adjust the threshold until the share of flagged traffic looks plausible.
4
Let it run for a few days
Check its real flagged count in By rule and where the volume comes from in By channel.
5
Switch to Tag and suppress postbacks
Do this only once the flagged volume looks right, and one rule at a time. If you switch several rules at once, you cannot tell which one caused a drop in reported conversions.
Choose what happens when a rule matches
Every rule has one of two responses:
Click rules are always Tag only, because a click has no postback to suppress. They are still useful: a flagged click can be used to flag the install it leads to. See How a flag carries over.
Read the overview
The overview shows how much of your traffic is invalid and where it comes from.
The fraud rate only covers records the engine has already checked. A rule you saved an hour ago has not been applied to last week’s installs.
See where it comes from
By rule shows which rules flag the most traffic. By channel shows which ad network delivered the flagged traffic.
0 in Withheld is running on Tag only. That is expected while you are still measuring.
Use By channel to tell bad traffic from a bad rule:
- Flagged volume sits mostly in one network. That network’s traffic is likely the problem.
- Flagged volume is spread evenly across all networks, including Organic / no network. The rule is likely too broad.
Create a rule
Select Create rule, then pick one of three ways to start:Start from a template

Templates are a starting point. Adjust the threshold and check the impact before saving.
Describe it in plain English
Select Describe and write a sentence, for exampleTag installs that open less than 3 seconds after the click. Linkrunner drafts the conditions and the response.
Always review the draft. Its thresholds are guesses until you check them against your own traffic.
Build it by hand

- Rule name. Shown in reports and change history, so name it after what it catches.
- Check. What the rule runs on: Clicks, Installs, or In-app events. Each rule checks one type.
- Conditions. Each condition is a property, an operator, and usually a value. All must match for the rule to fire.
- What should happen when it matches. Tag only, or Tag and suppress postbacks.
Check the impact before you save
The Impact panel tests the rule against your traffic from the last 7, 14, or 30 days. Nothing is saved and no record changes. It shows how many records were checked and what share the rule would flag. Change the threshold and watch the percentage move until it looks right. What counts as plausible depends on the fraud type, but a rule that flags a large share of all traffic is almost always too broad. After saving, check By channel to confirm the flagged volume sits where you expect.Rules that use IP lists, frequency caps, or percentiles cannot be previewed, because they depend on live or nightly-updated data. The panel says so instead of showing a number. This does not mean the rule is broken. Save it on Tag only and check its real count in By rule after a day.
Manage rules

- History: open the rule’s change log.
- Toggle: turn the rule on or off. A disabled rule stops flagging right away and keeps its history.
- Edit: reopen the builder, including the impact preview.
- Delete: remove the rule. Records it already flagged stay flagged.
Rules managed by Linkrunner
Rules marked Linkrunner are baseline protections that give every project fraud detection from day one. Linkrunner maintains them and updates them as fraud patterns change. You can view them and their history, but you cannot edit or delete them. Rules that apply to every project cannot be turned off.How a flag carries over
Clicks, installs, and in-app events are checked separately, but a flag can carry forward:- Click to install. A flagged click is passed to the install it leads to, but the install is not flagged automatically. The Install from a fraudulent click rule decides that, so you stay in control.
- Install to in-app event. Events from a flagged install are flagged too. They appear as Inherited from install in the overview.
Affiliate partners
Affiliates pay their own publishers based on the postbacks they receive. If a postback simply never arrives, the affiliate cannot tell it from a delay and may keep paying for fraudulent traffic. So when a rule is set to Tag and suppress postbacks, affiliates are handled like this:- Each partner sets its own rejection URLs, one for installs and one for events, in its affiliate dashboard.
- A rejection is only sent for a conversion the partner would otherwise have received, so its event mappings still apply.
- The reasons are codes built from the rule type and the matched property, for example
click_injection.ctit_seconds. They never include your rule’s name, threshold, or anything else you wrote. - The partner sees Rejected (fraud) and Withheld (fraud) in its postback logs. See Rejected conversions for what its endpoint receives.
Change history
Every rule change is recorded: who made it, what changed, and when. Open it from History on any rule.
Who can change rules
Troubleshooting
A rule I saved is flagging nothing
A rule I saved is flagging nothing
Check the rule is turned on, and wait a minute after saving. Confirm the rule checks the record type you meant (clicks, installs, or in-app events). Rules using an IP list, a frequency cap, or a percentile have no preview, so their first counts appear in By rule once traffic arrives.
A click-to-install rule is flagging iOS installs
A click-to-install rule is flagging iOS installs
Add the condition that requires a Play referrer click timestamp to be present. iOS installs have no Play referrer, so without it the rule compares two different measurements.
My fraud rate looks too high
My fraud rate looks too high
Open By channel. Volume concentrated in one network points to that network’s traffic. Volume spread evenly across all networks, including organic, points to a rule that is too broad. Open the rule and check its impact preview again.
An ad network reports fewer conversions than before
An ad network reports fewer conversions than before
Check Install postbacks withheld and By rule for rules set to Tag and suppress postbacks. Switch a rule back to Tag only to restore its postbacks while you adjust it.