How to exclude IP addresses in Google Ads for better campaign targeting

Traffic funnel graphic in blue dropping into an orange collection block (cover #90).

To exclude an IP address in Google Ads, open Settings, choose Account settings, then IP exclusions, and enter the addresses one per line. Campaign-level exclusions sit under the campaign's Settings in Additional settings. Each list holds up to 500 addresses and takes a few hours to apply.

The setup is the easy part. Finding the right addresses, and knowing when a list of addresses is the wrong tool entirely, is the work that decides whether this saves you any money.

How do I exclude an IP from Google Ads?

Google Ads has two places to do this, and they behave differently.

Account level, applies to every campaign

  • Sign in at ads.google.com.
  • Click Admin, then Account settings.
  • Open the IP exclusions section.
  • Enter the addresses you want to block, one per line.
  • Click Save. Nothing is stored until you do.

Account-level exclusions cover Search, Shopping, Display, Demand Gen, YouTube and Performance Max in one list, which is the only way to reach Performance Max at all.

Campaign level, applies to one campaign

  • Click the Campaigns icon and select the campaign.
  • Open Settings, then Additional settings.
  • Expand IP exclusions and enter the addresses.
  • Click Save.

Use campaign level when the problem is specific to one campaign, for example a prospecting campaign in a market where you have a known scraper. Use account level for everything else. Running the same list in fifteen campaigns is how exclusions get out of date.

To remove an address later, return to the same screen, delete the line and save again.

What IP address formats does Google Ads accept?

Format Example Accepted
Single IPv4 203.0.113.45 Yes
IPv4 wildcard 203.0.113.* Yes, blocks .0 to .255
Single IPv6 Full standard notation Yes
CIDR range 203.0.113.0/24 No, convert to wildcard first

Each list holds 500 entries. A wildcard counts as one entry and covers 256 addresses, so ranges are how you make the cap go further. If you are working from a block written in CIDR, a free converter will turn it into wildcard form in seconds.

One detail catches people out. If your tracking only records IPv4, you will never see the IPv6 traffic, and a growing share of mobile traffic is IPv6 only. Check that whatever you use to identify addresses reports both.

What are IP exclusions in Google Ads?

An IP exclusion tells Google not to serve your ads to anyone connecting from that address. They cannot see the ad, so they cannot click it, and you are not charged.

The situations where this is the right tool:

  • Your own office. Staff checking that the ad still runs are the single most common source of self-inflicted invalid clicks.
  • A competitor's office address that shows up repeatedly in your logs and never converts.
  • A data centre range producing large click volumes from one subnet.
  • A cluster of addresses in one location inflating click-through rate with no conversions behind it.

What an exclusion does not do is remove past clicks from your reporting or refund them. It only affects who sees the ad from that point forward.

Why does IP exclusion matter for campaign performance?

Wasted budget is the obvious cost and the smaller one. The expensive damage is to your data.

Smart Bidding learns from what happens after a click. Feed it a few hundred visits from people who were never going to buy, and it builds a picture of a customer who does not exist, then bids up more traffic that looks the same. The campaign gets slowly worse in a way that looks like market conditions rather than a data problem. That mechanism is broken down in how invalid clicks break Smart Bidding.

Clean traffic in means the algorithm optimises toward real buyers. That is the reason to bother with exclusions even when the wasted spend itself looks tolerable.

How can you identify which IP addresses to exclude?

Source What it shows Limitation
GA4 Repeat visits, zero engagement, session patterns No raw IP addresses at all
Server logs Full IP detail, timing, request patterns Needs technical access and manual work
Google Ads invalid clicks column Which campaigns are affected, and how much Never names the addresses
Click fraud detection tool Live IP-level detection and automatic exclusion Costs money, needs a tag on the site

Server logs are the honest starting point if you have access. Look for the same address hitting a paid landing page several times in a short window with no scroll and no form interaction, then cross-check the address against your conversion data before you block anything.

The cross-check matters more than it sounds. A loyal customer who visits often and converts once a quarter looks like a repeat clicker in a log file, and blocking them removes them from every campaign you run.

When should you block an IP address?

Repeated clicks with no conversions

A steady stream of clicks from one address that never converts, particularly from a location where a competitor is based. They bid on the same keywords, so they know exactly which searches trigger your ad.

Bots and click farms

Paid-to-click services and bot networks are sold openly. At volume they can exhaust a daily budget before lunch, which takes your ads out of the auction for the rest of the day. Those are the customers you never hear about. The same pattern shows up as invalid traffic in Google Ads reports.

Publisher fraud

On the Display network, a site owner inflating traffic to raise their own payout. It often hides in placements you never chose individually, and it uses rotating addresses behind VPNs.

People who dislike your brand

A former employee, an unhappy customer, or a rival's supporter. Small in volume, easy to identify, and exactly the case where a manual exclusion works well.

Why manual IP exclusion fails against click fraud

Manual lists work for fixed, known addresses. Your office. A competitor with a static connection. A single data centre.

They fail everywhere else, for three reasons.

Speed. A click farm can deliver hundreds of clicks in the time it takes you to read a log file. By the time the address is in the box, the budget is gone.

Rotation. Mobile networks reassign addresses constantly, and VPNs and proxies cycle through pools of thousands. Blocking one address in a rotating pool blocks nothing.

The 500 cap. A serious bot operation has more addresses than your list has room for. You run out of space before they run out of connections.

This is the part of the job that does not scale by hand, which is why it gets automated.

How does automatic IP exclusion work?

Detection software sits between the click and your reporting, in three steps.

  • Monitoring. A tag on your landing pages and a link with your Google Ads account collect the signals behind each click: device, network, timing, behaviour on the page.
  • Scoring. Each click is judged against those signals rather than against a list. A data centre connection, an impossible click-to-load time or a browser fingerprint seen a thousand times that hour all count against it.
  • Blocking. Sources that fail are added to the Google Ads exclusion list automatically, within minutes, and removed again when the evidence expires so you do not accumulate a stale list.

The behavioural part is what catches rotating addresses. A network that changes IP every few minutes still produces the same fingerprint and the same on-page behaviour, and that is what gets matched. Across the 1,793+ businesses running ClickPatrol, the accounts that switch from manual lists to automated scoring find most of their invalid traffic was arriving from addresses that were never on any list.

Should you use IP exclusions alongside other tools?

Method Covers Limitations
Google Ads IP exclusions Known fixed addresses, internal traffic 500 per list, manual, useless against rotation
GA4 review Behaviour patterns, engagement gaps No IP data, slow to reveal a pattern
Server logs Complete IP-level visibility Technical access, time-intensive, after the fact
ClickPatrol Live scoring and automatic exclusion Subscription cost, tag installation

They are complementary rather than alternatives. Block your own office by hand, because that never changes, and let software handle anything that moves.

How do you know if your IP exclusions are working?

Watch the invalid clicks column. Give it two to four weeks. A drop means the exclusions caught the source. No drop usually means the traffic moved to addresses you have not listed.

Expect click-through rate to fall. That is the point. If CTR falls and conversions hold, you removed clicks that were never going to convert.

Compare cost per conversion, not cost per click. Pull the four weeks before and the four weeks after. Lower cost per conversion at the same conversion volume is the result you are looking for.

Give Smart Bidding a month. With cleaner conversion data the bidding model has less noise to learn from, and the change shows up later than the click metrics do.

Common mistakes with IP exclusions

  • Blocking before verifying. Check the address against your conversion history first. Blocking a customer removes them from every campaign, permanently, and nothing will tell you it happened.
  • Letting the list go stale. Office addresses change, bots rotate, employees move. Review monthly on a high-budget account, quarterly at minimum.
  • Adding exclusions to one campaign only. The same source simply spends your budget in the campaign next door. Use the account-level list unless there is a reason not to.
  • Ignoring IPv6. Tracking that only records IPv4 leaves a growing share of mobile traffic invisible.
  • Treating the list as the whole defence. Exclusions block addresses you already identified. They do nothing about the next one.

Putting it into practice

Start with the addresses you are certain about: your office, your agency, anyone internal who checks the ads. That alone removes a measurable share of invalid clicks in most accounts and carries no risk of blocking a customer.

Then work through server logs or GA4 for repeat visitors with no engagement, verify each candidate against conversion data, and add them at account level. Re-check the invalid clicks column after a month.

If the budget is large enough that a bad week costs real money, or the invalid share stays high after all of this, the manual route has reached its limit. Click fraud protection scores every click as it arrives and updates the exclusion list for you, which is the only version of this that keeps working against traffic that changes address faster than you can type.

Frequently Asked Questions

  • How many IP addresses can I exclude in Google Ads?

    Up to 500 entries. A single IPv4 address, an IPv6 address or an IPv4 wildcard such as 203.0.113.* each count as one entry, so a wildcard is the efficient way to cover a whole subnet.

  • Does Google Ads support CIDR notation for IP exclusions?

    No. Ranges written as 203.0.113.0/24 are rejected. Convert them to wildcard form, 203.0.113.*, before adding them. Free CIDR to wildcard converters do this instantly.

  • How long do IP exclusions take to work?

    Usually a few hours. Check the invalid click data after 48 hours to confirm the change took effect, and again after two to four weeks to see whether the traffic simply moved to different addresses.

  • Can I exclude IP addresses across the whole account?

    Yes. Account-level IP exclusions sit under Settings, then Account settings, and apply to every campaign including Performance Max. Campaign-level exclusions still exist but only cover the campaign you set them on.

  • Why does manual IP exclusion not stop click fraud?

    Speed and rotation. Fraudulent clicks arrive in bursts, so the budget is gone before you finish editing the list, and VPNs, proxies and mobile networks change addresses constantly, which makes any manual list out of date within days.

Abisola

Abisola

Abisola handles content and support at ClickPatrol. She helps customers get more value from cleaner traffic data and writes practical resources about ad fraud, fake traffic, and smarter PPC decisions.