Skip to main content
Open Fraud Control from the left sidebar of the dashboard, just below Settings.

What you get

Your attribution is never changed. A fraud rule never moves credit between networks and never turns an attributed install into an organic one. Your reports keep the same totals. Fraud Control only changes how a record is labelled and, at most, whether its postback is sent.
A postback is the conversion signal Linkrunner sends to an ad network or partner, for example “this install came from your campaign”. Networks use postbacks to optimise your campaigns.

Get started in five steps

1

Read the overview

The Linkrunner-managed rules already report a fraud rate. Look at it before changing anything.
2

Add one rule on Tag only

Start from a template where one fits. Tag only flags matches for reporting and changes nothing else.
3

Check the impact preview

Adjust the threshold until the share of flagged traffic looks plausible.
4

Let it run for a few days

Check its real flagged count in By rule and where the volume comes from in By channel.
5

Switch to Tag and suppress postbacks

Do this only once the flagged volume looks right, and one rule at a time. If you switch several rules at once, you cannot tell which one caused a drop in reported conversions.

Choose what happens when a rule matches

Every rule has one of two responses:
When a postback is suppressed, the ad network never hears about that conversion. A rule that is too broad can hurt the network’s optimisation without any visible error. Always run a new rule on Tag only first.
Click rules are always Tag only, because a click has no postback to suppress. They are still useful: a flagged click can be used to flag the install it leads to. See How a flag carries over.

Read the overview

The overview shows how much of your traffic is invalid and where it comes from. Fraud Control overview showing fraud rate, install postbacks withheld, clicks flagged, and flagged installs and in-app events The fraud rate only covers records the engine has already checked. A rule you saved an hour ago has not been applied to last week’s installs.

See where it comes from

By rule shows which rules flag the most traffic. By channel shows which ad network delivered the flagged traffic. By rule breakdown listing each rule with its flagged and withheld counts A rule with flagged records and 0 in Withheld is running on Tag only. That is expected while you are still measuring. Use By channel to tell bad traffic from a bad rule:
  • Flagged volume sits mostly in one network. That network’s traffic is likely the problem.
  • Flagged volume is spread evenly across all networks, including Organic / no network. The rule is likely too broad.

Create a rule

Select Create rule, then pick one of three ways to start:

Start from a template

Rule builder with the template gallery open, showing click injection, install hijacking, SDK spoofing, and install from a fraudulent click Templates are a starting point. Adjust the threshold and check the impact before saving.

Describe it in plain English

Select Describe and write a sentence, for example Tag installs that open less than 3 seconds after the click. Linkrunner drafts the conditions and the response. Always review the draft. Its thresholds are guesses until you check them against your own traffic.

Build it by hand

Rule builder editing a click injection rule, with conditions, response, and the impact preview showing 28,210 records checked and 2.1% flagged
  1. Rule name. Shown in reports and change history, so name it after what it catches.
  2. Check. What the rule runs on: Clicks, Installs, or In-app events. Each rule checks one type.
  3. Conditions. Each condition is a property, an operator, and usually a value. All must match for the rule to fire.
  4. What should happen when it matches. Tag only, or Tag and suppress postbacks.
Some properties need a second condition to work correctly, and the builder tells you when. The main one is click-to-install time. It only makes sense when a Play referrer click timestamp is present, and iOS installs do not have one. Without that extra condition, the rule flags real iOS installs.

Check the impact before you save

The Impact panel tests the rule against your traffic from the last 7, 14, or 30 days. Nothing is saved and no record changes. It shows how many records were checked and what share the rule would flag. Change the threshold and watch the percentage move until it looks right. What counts as plausible depends on the fraud type, but a rule that flags a large share of all traffic is almost always too broad. After saving, check By channel to confirm the flagged volume sits where you expect.
Rules that use IP lists, frequency caps, or percentiles cannot be previewed, because they depend on live or nightly-updated data. The panel says so instead of showing a number. This does not mean the rule is broken. Save it on Tag only and check its real count in By rule after a day.

Manage rules

Rules table listing each rule with its record type, response, and actions Each row shows what the rule checks and its response. From each row you can:
  • History: open the rule’s change log.
  • Toggle: turn the rule on or off. A disabled rule stops flagging right away and keeps its history.
  • Edit: reopen the builder, including the impact preview.
  • Delete: remove the rule. Records it already flagged stay flagged.
Changes take effect within about a minute.

Rules managed by Linkrunner

Rules marked Linkrunner are baseline protections that give every project fraud detection from day one. Linkrunner maintains them and updates them as fraud patterns change. You can view them and their history, but you cannot edit or delete them. Rules that apply to every project cannot be turned off.

How a flag carries over

Clicks, installs, and in-app events are checked separately, but a flag can carry forward:
  • Click to install. A flagged click is passed to the install it leads to, but the install is not flagged automatically. The Install from a fraudulent click rule decides that, so you stay in control.
  • Install to in-app event. Events from a flagged install are flagged too. They appear as Inherited from install in the overview.
This is why click rules are worth running even though they cannot suppress anything.

Affiliate partners

Affiliates pay their own publishers based on the postbacks they receive. If a postback simply never arrives, the affiliate cannot tell it from a delay and may keep paying for fraudulent traffic. So when a rule is set to Tag and suppress postbacks, affiliates are handled like this:
  • Each partner sets its own rejection URLs, one for installs and one for events, in its affiliate dashboard.
  • A rejection is only sent for a conversion the partner would otherwise have received, so its event mappings still apply.
  • The reasons are codes built from the rule type and the matched property, for example click_injection.ctit_seconds. They never include your rule’s name, threshold, or anything else you wrote.
  • The partner sees Rejected (fraud) and Withheld (fraud) in its postback logs. See Rejected conversions for what its endpoint receives.
Ad networks with a native integration, such as Meta, Google, and TikTok, and your own webhooks never receive a suppressed conversion.

Change history

Every rule change is recorded: who made it, what changed, and when. Open it from History on any rule. Rule history for a Linkrunner-managed rule, showing it was created and is managed by Linkrunner The log covers creation, turning a rule on or off, condition and scope changes, and response changes. Changes to managed rules are listed as Linkrunner. Rules created before change history existed show only their creation time.

Who can change rules

Troubleshooting

Check the rule is turned on, and wait a minute after saving. Confirm the rule checks the record type you meant (clicks, installs, or in-app events). Rules using an IP list, a frequency cap, or a percentile have no preview, so their first counts appear in By rule once traffic arrives.
Add the condition that requires a Play referrer click timestamp to be present. iOS installs have no Play referrer, so without it the rule compares two different measurements.
Open By channel. Volume concentrated in one network points to that network’s traffic. Volume spread evenly across all networks, including organic, points to a rule that is too broad. Open the rule and check its impact preview again.
Check Install postbacks withheld and By rule for rules set to Tag and suppress postbacks. Switch a rule back to Tag only to restore its postbacks while you adjust it.
Need help? Contact support@linkrunner.io.