Understanding Bot Traffic

Bot traffic refers to any non-human visitors clicking your links. While this might sound concerning, most bot traffic is legitimate and serves important functions on the internet.

Bots click links for several legitimate reasons:

  • Link previews — Social platforms like Facebook, X, and LinkedIn fetch your links to generate preview cards
  • Spam detection — Email providers and social networks check links to protect users from malicious content
  • Search indexing — Search engines like Google crawl links to index content
  • Security scanning — Anti-virus and firewall services verify link destinations

How Linkly identifies bots

Linkly weighs three signals to detect bot traffic:

1. User agent detection

Many bots identify themselves through their user agent string. For example, Googlebot, Facebookbot and Twitterbot all announce themselves. See our full list of detected bots.

2. Verified bots

Major crawlers are confirmed against the networks they genuinely operate from, so a visit claiming to be Facebook's link preview crawler is verified as the real thing rather than taken at its word.

3. Network and request signals

Some automation doesn't identify itself at all. For these we look at where the request came from — a cloud hosting provider like AWS, Google Cloud or DigitalOcean — together with how the request behaves. Real browsers send a distinctive set of headers that most automated tools don't.

Both parts matter, because plenty of real people reach your links through hosting networks: Facebook and Instagram in-app browsers, mobile carrier proxies and iCloud Private Relay all route traffic that way. A visit from one of those networks that otherwise looks like a genuine browser is counted as a person, and its network appears in your analytics as, for example, Amazon.com (cloud) — so it's clear why a hosting provider shows up among your human visitors.

Social media crawler handling

Linkly can optionally exclude social media crawlers from Facebook, X, LinkedIn, Google, and YouTube from your analytics. When enabled:

  • They aren't recorded in your analytics
  • They don't count against your click limits
  • They're always allowed through, even when bot blocking is enabled
  • They can still generate custom social previews

This keeps your analytics focused on human visitors while social sharing continues to work seamlessly.

Automatically ignored user agents

Linkly automatically ignores traffic from certain known bot user agents. These requests are redirected normally but not recorded in analytics or counted against your click limits:

  • Bytespider — ByteDance's web crawler
  • python-requests — Python HTTP library commonly used for automated scripts
  • curl — Command-line HTTP tool

This filtering happens automatically for all links and requires no configuration.

Is bot traffic bad?

In most cases, no. The majority of bots are "good bots" performing useful functions.

However, bot traffic can be problematic when it:

  • Inflates click counts — Making it harder to measure real engagement
  • Skews conversion rates — Bots never convert, so high bot traffic makes conversion rates appear lower
  • Consumes click limits — Though social media crawlers can be excluded from limits

For information about invalid traffic from advertising platforms, see our article on TikTok invalid traffic.

Human clicks by default

Your traffic reports show human clicks by default. Bot traffic is automatically excluded from your headline click count, so your numbers reflect real visitors without any setup.

Next to your click total you'll see how many bots were filtered — for example, "1,240 clicks · 380 bots filtered" — so nothing is hidden.

To see all traffic, use the Include bot traffic toggle at the top of your reports. This counts bots in your totals and adds a Robots tab that breaks the bot traffic down by name.

Note: This affects reporting only. Bot clicks still count toward your plan's click limit, and the API returns all traffic by default — pass bots=false to exclude bots from an API request.

Blocking bot traffic

You can optionally block bots from accessing your links entirely. However, we generally don't recommend this because:

  • Good bots that check for spam may flag your link as suspicious if blocked
  • Custom social previews won't work on most platforms
  • Search engines won't be able to index your links

To block other bots while still allowing social media previews, enable both "Block bots" and "Skip social crawler tracking" on your link.

How to block bots

1
2

Under Block bots, enable Block known bots

Under **Block bots**, enable **Block known bots**
Under Block bots, enable Block known bots
3

Blocked bots will see an Access Blocked page

The HTTP status code returned is 403 Forbidden.

Blocked bots will see an **Access Blocked** page
Blocked bots will see an Access Blocked page

Frequently asked questions

Bots visit links to generate previews, check for spam, and index content for search engines. This is normal and usually beneficial.

Should I block robots?

In general, no. Blocking robots can cause your links to be flagged as spam by social networks and email providers.

Only block bots if you have a specific reason, such as private internal links.

Why is most of my traffic from bots?

Links shared via social media, email, or SMS often generate significant bot traffic because these platforms actively scan links for spam and security threats.

As your human traffic grows, bots will represent a smaller percentage of total clicks.

Do bots count against my click limit?

Most bots do count against your limit, as it costs the same to process any request.

However, you can enable Skip social crawler tracking to exclude social media crawlers from Facebook, X, LinkedIn, Google, and YouTube from limits and analytics.

Blocked requests also don't count toward your limits.

Why don't I see these bots in Google Analytics?

Google Analytics relies on browser JavaScript to track visitors. Bots typically don't execute JavaScript, so they don't appear in GA reports.

Linkly records all traffic server-side, giving you complete visibility into both human and bot traffic.

How does Linkly know if a visitor is a bot?

Most legitimate bots identify themselves via their user agent string, and major crawlers are verified against the networks they genuinely operate from. See our list of detected bots.

For automation that doesn't identify itself, we combine where the request came from — such as a cloud hosting provider — with how it behaves, since real browsers send a distinctive set of headers that most automated tools don't.

Yes. VPN services route traffic through data centers, but a real browser is recognised as a visitor and passes through normally — including on links with bot blocking enabled.

If a link does appear blocked, check whether you're testing with a command-line tool or script rather than a browser, since those are treated as automation.

What about fake clicks from ad platforms?

Invalid traffic from advertising platforms like TikTok is a different issue from bot traffic. These clicks come from real mobile devices but may not represent genuine interest.

See our article on TikTok invalid traffic for more information.

Plan availability

Included on every plan

Compare plans →

Get 100 short links and track 500 monthly clicks for free.