Brand Safety and Ad Fraud in Programmatic Advertising: What Brands Need to Know

Ad fraud and brand safety are the two objections that stop more programmatic budgets than any others. Both concerns are legitimate. The open programmatic ecosystem does contain fraudulent inventory, and ads do sometimes appear next to content brands would never choose deliberately.

What is less commonly discussed is that both problems are largely solvable with controls that have existed for years. The brands losing money to fraud are usually the ones who never implemented verification, never reviewed placement reports, and never asked their agency what protections were in place.

This guide explains how ad fraud actually works, what brand safety failures look like in practice, which controls genuinely protect campaigns, what verification costs and delivers, and the specific questions to put to any partner managing your programmatic spend.

Want a brand safety review of your current campaigns? Talk to BUO Programmatic.

 

Ad Fraud and Brand Safety Are Different Problems

These two issues get discussed together but they are distinct, and conflating them leads to solutions that address one while leaving the other exposed.

Ad fraud is theft. Someone is taking your budget and delivering impressions that no human being ever saw, or that were seen by a person who was never a legitimate audience member. The harm is direct financial loss.

Brand safety is context. Your ad was seen by a real person, but it appeared next to content that damages your brand by association. The harm is reputational rather than financial, though the reputational cost can far exceed the media cost.

A third related concept, brand suitability, sits alongside brand safety. Safety concerns content that is universally unacceptable. Suitability concerns content that is fine for some advertisers but wrong for a specific brand. A news article about an airline incident is not unsafe, but it is unsuitable for an airline advertiser.

Both issues are managed within campaign setup and ongoing optimization. See how this fits into full-service programmatic advertising.

How Ad Fraud Actually Works

Understanding the mechanics helps clarify why certain controls work and others do not.

Bot traffic and non-human traffic

Automated scripts simulate human browsing behavior, loading pages and triggering ad impressions. Sophisticated bot networks mimic mouse movement, scroll behavior, and session patterns well enough to evade basic detection. The advertiser pays for impressions that no person ever saw.

Domain spoofing

A low-quality site misrepresents itself in the bid request as a premium publisher. The advertiser believes they purchased inventory on a well-known news site and pays a premium CPM, but the ad actually served on an unknown site with no audience value.

Ad stacking and pixel stuffing

Multiple ads are layered on top of each other in a single ad slot, with only the top one visible. Every advertiser in the stack is charged for an impression while only one had any chance of being seen. Pixel stuffing shrinks an ad to a single pixel, technically served but impossible to view.

Click farms and click injection

Human or automated networks generate clicks on ads to inflate engagement metrics and drive performance-based payouts. In mobile environments, click injection intercepts install events to claim attribution credit for conversions the fraudster did not drive.

Made-for-advertising sites

These sites exist solely to serve ads rather than to provide content anyone wants. They are typically stuffed with ad slots, produce low-quality auto-generated or scraped content, and buy cheap traffic to inflate impression volume. Technically the impressions are real, but the audience value is close to zero.

What Brand Safety Failures Look Like

Brand safety incidents range from mildly embarrassing to genuinely damaging. Common failure categories include ads appearing next to violent or graphic news coverage, placement alongside hate speech or extremist content, adjacency to misinformation or conspiracy content, appearance on piracy sites, and placement next to content that contradicts the brand message.

The reputational risk is not evenly distributed. A consumer packaged goods brand appearing next to a breaking news tragedy faces a different level of exposure than a B2B software company. Financial services, healthcare, and children’s products typically require the most conservative settings because the regulatory and reputational stakes are highest.

The Controls That Actually Protect Campaigns

Effective protection layers multiple controls rather than relying on any single mechanism.

Pre-bid verification

Pre-bid filtering evaluates each impression opportunity before a bid is submitted, blocking bids on inventory that fails fraud or safety criteria. This is the most effective control because it prevents spend rather than reporting on it after the fact. Pre-bid segments from verification vendors integrate directly into the demand-side platform.

Inclusion lists over exclusion lists

Exclusion lists block known bad domains. The problem is that fraudulent domains multiply faster than any list can track. Inclusion lists invert the logic by permitting only approved domains. This reduces reach substantially but produces dramatically cleaner delivery. Most sophisticated programs run inclusion lists for premium campaigns and carefully monitored exclusion lists for scale campaigns.

Private marketplace deals

PMP deals purchase inventory directly from vetted publishers through a private auction. The inventory is verified, the publisher relationship is known, and domain spoofing is effectively eliminated. CPMs are higher than open exchange but the quality difference usually justifies it for brand-sensitive campaigns.

Ads.txt and sellers.json

These industry standards let publishers declare which sellers are authorized to sell their inventory, making domain spoofing far more difficult. Any DSP or agency running your campaigns should be enforcing ads.txt compliance as a baseline. The IAB Tech Lab maintains the specification and adoption is now widespread across legitimate publishers.

Keyword and category blocking

Contextual analysis blocks placement on pages containing specified keywords or falling into defined content categories. This is effective but requires calibration. Overly aggressive keyword blocking eliminates enormous amounts of legitimate news inventory and drives up costs by shrinking available supply.

Viewability thresholds

Setting minimum viewability requirements ensures you pay for impressions that had a genuine chance of being seen. The Media Rating Council standard defines a viewable display impression as 50 percent of pixels in view for at least one continuous second, and a viewable video impression as 50 percent in view for two continuous seconds.

The Media Rating Council publishes the full measurement standards that verification vendors are accredited against.

Not sure what protections are running on your campaigns? Request a verification audit from BUO.

 

Verification Vendors and What They Cost

Third-party verification is the standard mechanism for measuring and enforcing brand safety and fraud protection. The major vendors provide pre-bid filtering, post-bid measurement, viewability tracking, and detailed placement reporting.

Verification typically costs between 0.10 and 0.50 dollars CPM depending on the services included and campaign volume. On a 20 dollar CPM video campaign, that represents roughly one to two percent of media cost. Against fraud rates that can reach double digits on unprotected open exchange inventory, the return is straightforward.

What matters is that verification is actually enabled and enforced rather than simply reported. Some agencies purchase verification, receive reports showing fraud, and never act on them. Reporting without pre-bid enforcement means you learn about wasted spend after it has already happened.

Verification capabilities vary across demand-side platforms. Our comparison of the leading programmatic advertising platforms covers how each handles inventory quality controls.

Reading Your Placement Reports

Placement reports are the single most useful transparency document in programmatic advertising, and most brands never request them. The report lists every domain and app where your ads served, with impression volume and performance for each.

Reviewing this report monthly surfaces problems that aggregate metrics hide. Warning signs include large impression volumes on domains you do not recognize, sites with generic names and no discernible content focus, unusually high click-through rates paired with zero conversions, extremely low viewability on specific domains, and heavy concentration of spend on a small number of unknown sites.

  • Request a full domain-level placement report at least monthly
  • Manually review the top 50 domains by spend every reporting cycle
  • Investigate any domain you cannot identify by visiting it directly
  • Compare viewability rates across domains and exclude persistent underperformers
  • Watch for made-for-advertising characteristics: excessive ad density, thin content, no clear editorial purpose
  • Track what percentage of spend goes to your top 100 domains versus the long tail

If your agency cannot or will not provide a domain-level placement report, that is a significant transparency concern. There is no legitimate reason to withhold it.

Balancing Protection Against Reach and Cost

Every protective control reduces available inventory. Aggressive settings improve quality but shrink scale and increase CPMs as the eligible impression pool narrows.

The most common overcorrection is blanket news blocking. Many brands exclude all news content to avoid adjacency to negative stories. This eliminates some of the highest-quality, most-viewed inventory on the open web, drives budget toward lower-quality alternatives, and defunds legitimate journalism. Category-level and keyword-level controls within news environments generally serve brands better than wholesale exclusion.

The right calibration depends on category sensitivity. A children’s brand should run conservative settings and accept reduced reach. A B2B software company can typically run moderate settings and gain meaningful scale. Setting maximum protection by default without considering the tradeoff often costs more in lost efficiency than it saves in avoided risk.

Questions to Ask Your Programmatic Partner

These questions surface whether protections are genuinely in place or merely claimed.

  1. Which verification vendor are we using, and is it running pre-bid or post-bid only?
  2. Can you send me a full domain-level placement report for last month?
  3. What percentage of our spend went to inventory flagged as invalid traffic?
  4. Are we enforcing ads.txt compliance on all inventory purchases?
  5. Are we running inclusion lists, exclusion lists, or neither?
  6. What viewability threshold are we enforcing, and what is our actual measured viewability?
  7. What share of our budget goes to private marketplace deals versus open exchange?
  8. How do you handle made-for-advertising sites specifically?

Clear, specific answers indicate a partner with real controls in place. Vague reassurance that everything is handled usually indicates the opposite.

Evaluating agency capability extends beyond brand safety. See our full framework for choosing a programmatic advertising agency.

Channel-Specific Considerations

Connected TV

CTV fraud has grown as budgets have shifted into the channel, primarily through spoofed device identifiers and falsified app inventory. Verification specifically accredited for CTV environments is essential. Our overview of CTV advertising covers how the inventory ecosystem works.

Digital out-of-home

DOOH carries lower fraud risk than digital channels because screens are physical assets in verified locations. Brand safety concerns center on placement context rather than fraudulent impressions. See what DOOH advertising is for how inventory is verified.

Programmatic audio

Audio fraud typically involves falsified listening sessions or misrepresented inventory. Podcast environments carry additional brand suitability considerations given the range of content available. See programmatic audio advertising for how targeting and inventory selection work.

Frequently Asked Questions

How much programmatic spend is lost to ad fraud?

Industry estimates vary widely depending on methodology and whether campaigns run verification. Unprotected open exchange campaigns consistently show materially higher invalid traffic rates than campaigns running pre-bid verification and inventory quality controls. The gap between protected and unprotected campaigns is the more useful comparison than any single industry-wide figure.

Does verification eliminate fraud completely?

No. Fraud techniques evolve continuously and verification vendors respond reactively. Verification substantially reduces exposure but cannot eliminate it. Layering verification with private marketplace deals, inclusion lists, and regular placement review produces meaningfully better protection than any single control.

Is private marketplace inventory always safer than open exchange?

Generally yes, because the publisher relationship is known and inventory is vetted. PMP deals largely eliminate domain spoofing. They do not automatically guarantee brand suitability, since a verified premium publisher can still run content unsuitable for a specific advertiser.

Should I block all news inventory?

Usually not. Blanket news blocking removes high-quality, high-attention inventory and pushes budget toward weaker alternatives. Keyword-level and category-level controls within news environments typically deliver better outcomes than wholesale exclusion for most advertisers.

Who is responsible if my ads appear somewhere inappropriate?

Responsibility is shared across the agency, the DSP, the exchange, and the verification vendor. Practically, your agency owns campaign setup and is accountable for whether appropriate controls were configured and enforced. Contracts should specify what protections are in place and what happens when they fail.

Protect Your Budget and Your Brand

Ad fraud and brand safety are real risks in programmatic advertising, and they are also manageable ones. The controls work. Pre-bid verification, inventory quality standards, ads.txt enforcement, private marketplace deals, and disciplined placement review together eliminate the large majority of exposure.

What separates protected campaigns from vulnerable ones is rarely budget or sophistication. It is whether anyone configured the controls, whether anyone reviews the reports, and whether the partner running the campaign treats inventory quality as a standing responsibility rather than an afterthought.

BUO Programmatic builds campaigns with verification, inventory quality controls, and transparent placement reporting as standard practice rather than optional add-ons. Get in touch to review what protections are running on your current campaigns.

Ready to protect your programmatic investment? Request a strategy call with BUO Programmatic.