How to exclude IP addresses in Google Ads

Blue traffic funnel narrowing into an orange collection block on a dark background

Name an IP address in a Google Ads IP exclusion and Google stops serving your ads to it. Add the address at account level: Admin, then Account settings, then IP exclusions. The list takes 500 entries and applies to every campaign, Performance Max included. Campaign-level exclusions live under Additional settings. They skip Performance Max.

Typing the address is the simple bit. Choosing which addresses belong there, and spotting the moment a list is the wrong tool, is what decides whether any money comes back.

How do I exclude an IP from Google Ads?

There are two screens for this, and they do not do the same job. The steps and campaign types below come from Google's own help, retrieved 9 September 2026.

Account level, applies to every campaign

  • Sign in at ads.google.com.
  • Click Admin, then Account settings.
  • Open the IP exclusions section.
  • Enter the addresses you want to block, one per line.
  • Click Save. Nothing is stored until you do.

One account-level list covers Search, Shopping, Display, Demand Gen, Discover, YouTube and Performance Max. No other Google Ads IP exclusion reaches Performance Max.

Campaign level, applies to one campaign

  • Click the Campaigns icon and select the campaign.
  • Open Settings, then Additional settings.
  • Expand IP exclusions and enter the addresses.
  • Click Save.

Keep campaign level for a problem that lives in one campaign, such as a prospecting campaign in a market with a known scraper. Put everything else on the account list. Copying the same rows into fifteen campaigns is how the list goes stale.

When both lists have rows, Google merges them for that campaign. Account-level rows cannot be edited or removed from inside a campaign. Those stay under Account settings.

To drop an address later, open the same screen, delete the line, and save again.

Do IP exclusions work for Performance Max?

Campaign-level lists cannot do it. Google names Performance Max, video, hotel, App and Smart Display as unsupported for campaign-level IP exclusions. A campaign list never reaches Performance Max, even if that is where most of the spend sits.

Account-level IP exclusions do apply to Performance Max. Park the addresses that stay put there: your office, your agency, a competitor office you have already confirmed. New campaigns inherit the list, so the box is not something you have to remember on launch day.

What is the 500 IP exclusion limit in Google Ads?

Each campaign can hold 500 IP addresses. The account-level box is a second list built the same way. A wildcard such as 203.0.113.* uses one slot and covers 256 addresses, which is how ranges stretch the cap.

Once the box is full, people usually try three things: drop stale rows every month, move permanent offenders onto the account list so campaign slots stay free, and split spend across campaigns so each one gets its own 500. That buys time. Rotating residential proxies still outrun it.

What IP address formats does Google Ads accept?

Format Example Accepted
Single IPv4 203.0.113.45 Yes
IPv4 wildcard 203.0.113.* Yes, blocks .0 to .255
Single IPv6 Full standard notation Yes
CIDR range 203.0.113.0/24 No, convert to wildcard first

Google's help lets you paste specific addresses, or swap the last three digits for an asterisk. CIDR is rejected in that box. A block written as 203.0.113.0/24 needs to become 203.0.113.* before you paste it.

The same office often has two versions of an address. Exclude IPv4 and IPv6 when both exist. Tracking that only records IPv4 never sees the IPv6 traffic, and more mobile traffic is IPv6 only.

What are IP exclusions in Google Ads?

An IP exclusion tells Google not to show your ads to anyone on that address. No ad means no click, and no charge.

The situations where this is the right tool:

  • Your own office. For a small business, staff checking that the ad still runs are the most common source of self-inflicted invalid clicks.
  • A competitor's office address that shows up repeatedly in your logs and never converts.
  • A data centre range producing large click volumes from one subnet.
  • A cluster of addresses in one location inflating click-through rate with no conversions behind it.

Past clicks stay in the report. An exclusion does not credit them either. It only changes who can see the ad from that moment on. Credits for billed invalid activity live in Google Ads billing; the process is in Google Ads refunds.

Why does IP exclusion matter for campaign performance?

The wasted spend is the cost people notice. The larger hit is the data.

Smart Bidding learns from what happens after a click. A few hundred visits from people who were never going to buy teach it a customer who does not exist. It then bids up more traffic that looks the same. The campaign drifts in a way that reads as market conditions, not a data problem. The mechanism is in how invalid clicks break Smart Bidding.

Clean traffic in means the algorithm optimises toward real buyers. That is why exclusions still matter when the wasted spend itself looks small.

How can you identify which IP addresses to exclude?

Source What it shows Limitation
GA4 Repeat visits, zero engagement, session patterns No raw IP addresses at all
Server logs Full IP detail, timing, request patterns Needs technical access and manual work
Google Ads invalid clicks column Which campaigns are affected, and how much Never names the addresses
CRM records and form submissions Leads that are fake, repeated contact details, multiple signups from the same range Only reveals sources after they submit a form
Click fraud detection tool Live IP-level detection and automatic exclusion Costs money, needs a tag on the site

Read the CRM too. Dead leads, forms with almost the same details, or several accounts opened from one range are all reasons to look that address up in the logs.

If you can open server logs, start there. The same address hitting a paid landing page several times in a short window, with no scroll and no form interaction, is the pattern. Match it against conversion data before you block it.

Skip that match and you can lock out a real buyer. A customer who visits often and converts once a quarter looks like a repeat clicker in a log file. Blocking them takes them off every campaign you run.

When should you block an IP address?

Only block an address when you can say why it is on the list. A one-off spike is usually a shared network. That is a poor use of a slot on a 500-cap list.

Repeated clicks with no conversions

A steady stream of clicks from one address that never converts, particularly from a location where a competitor is based. They bid on the same keywords, so they know exactly which searches trigger your ad.

Bots and click farms

Paid-to-click services and bot networks are sold in the open. At volume they can empty a daily budget before lunch, which pulls your ads out of the auction for the rest of the day. Those are the customers nobody calls about. The same pattern shows up as invalid traffic in Google Ads reports.

Publisher fraud

On the Display network, a site owner inflating traffic to raise their own payout. It often hides in placements you never chose individually, and it uses rotating addresses behind VPNs.

People who dislike your brand

A former employee, an unhappy customer, or a rival's supporter. Small in volume, easy to identify, and exactly the case where a manual exclusion works well.

Why manual IP exclusion fails against click fraud

A typed list is fine for fixed, known addresses: your office, a competitor on a static connection, one data centre.

Everywhere else it breaks, for three reasons.

Speed. A click farm can land hundreds of clicks while you are still reading a log file. The budget is gone before the address is in the box.

Rotation. Mobile networks hand out new addresses all the time. VPNs and proxies cycle through pools of thousands. Blocking one address in a rotating pool blocks nothing.

The 500 cap. A serious bot operation has more addresses than the list can hold. You run out of space first.

That part of the job does not scale by hand, so it gets automated.

How does automatic IP exclusion work?

Detection software sits between the click and the report. It does three things.

  • Monitoring. A tag on your landing pages and a link with your Google Ads account collect the signals behind each click: device, network, timing, behaviour on the page.
  • Scoring. Each click is judged against those signals rather than against a list. A data centre connection, an impossible click-to-load time or a browser fingerprint seen a thousand times that hour all count against it.
  • Blocking. Sources that fail are added to the Google Ads exclusion list automatically, within minutes, and removed again when the evidence expires so you do not accumulate a stale list.

Behaviour is what catches rotating addresses. A network that changes IP every few minutes still leaves the same fingerprint and the same on-page behaviour, and that is what gets matched. Across the 1,793+ businesses running ClickPatrol, accounts that leave a typed list for automated scoring find most of their invalid traffic came from addresses that were never on any list.

ClickPatrol connects to the Google Ads account, updates the tracking template, and excludes invalid IP addresses. Google shows that permission on the consent screen. The product write-up for that Google Ads path is Google Ads click fraud protection.

Should you use IP exclusions alongside other tools?

Method Covers Limitations
Google Ads IP exclusions Known fixed addresses, internal traffic 500 per list, manual, useless against rotation
GA4 review Behaviour patterns, engagement gaps No IP data, slow to reveal a pattern
Server logs Complete IP-level visibility Technical access, time-intensive, after the fact
ClickPatrol Live scoring and automatic exclusion Subscription cost, tag installation

Use them together. Block your own office by hand, because that never changes, and let software handle anything that moves.

How do you know if your IP exclusions are working?

Watch the invalid clicks column. Give it two to four weeks. A drop means the exclusions caught the source. No drop usually means the traffic moved to addresses you have not listed.

Expect click-through rate to fall. That is the point. If CTR falls and conversions hold, you removed clicks that were never going to convert.

Compare cost per conversion, not cost per click. Pull the four weeks before and the four weeks after. Lower cost per conversion at the same conversion volume is the result you are looking for.

Give Smart Bidding a month. With cleaner conversion data the bidding model has less noise to learn from, and the change shows up later than the click metrics do.

Common mistakes with IP exclusions

  • Blocking before verifying. Check the address against your conversion history first. Blocking a customer removes them from every campaign, permanently, and nothing will tell you it happened.
  • Letting the list go stale. Office addresses change, bots rotate, employees move. Review monthly on a high-budget account, quarterly at minimum.
  • Adding exclusions to one campaign only. The same source simply spends your budget in the campaign next door. Use the account-level list unless there is a reason not to.
  • Ignoring IPv6. Tracking that only records IPv4 leaves a growing share of mobile traffic invisible.
  • Treating the list as the whole defence. Exclusions block addresses you already identified. They do nothing about the next one.
  • Leaving out the reason for an address. After six months, nobody can recall whether 203.0.113.45 belonged to a competitor or the old office. Note the date and reason on one line per entry, or each monthly review becomes guesswork.

Putting it into practice

Begin with the addresses you are sure about: your office, your agency, anyone internal who checks the ads. In most accounts that already cuts a measurable share of invalid clicks, and it will not lock out a customer.

Then work through server logs or GA4 for repeat visitors with no engagement. Check each candidate against conversion data, and add the keepers at account level. Look at the invalid clicks column again after a month.

If a bad week already costs real money, or the invalid share stays high after all of this, the typed list has gone as far as it can. Google Ads click fraud protection scores every click as it arrives and updates the exclusion list for you. That is the version that still works when traffic changes address faster than you can type.

Frequently Asked Questions

  • How many IP addresses can I exclude in Google Ads?

    Google Ads allows up to 500 IP addresses per campaign. The account-level list is a second box with the same shape. A single IPv4 address, an IPv6 address, or an IPv4 wildcard such as 203.0.113.* each count as one entry, so a wildcard is the efficient way to cover a whole subnet.

  • Does Google Ads support CIDR notation for IP exclusions?

    No. Google Ads rejects ranges written as 203.0.113.0/24 in the IP exclusions box. Convert them to wildcard form, 203.0.113.*, before adding them. Google's help, retrieved 9 September 2026, accepts specific addresses or an asterisk in place of the last three digits.

  • Do IP exclusions work for Performance Max?

    Campaign-level IP exclusions do not. Google lists Performance Max, video, hotel, App and Smart Display as unsupported at campaign level. Account-level IP exclusions under Admin, then Account settings, do apply to Performance Max. Put office and other permanent addresses on that account list if Performance Max carries any of your spend.

  • Can I exclude IP addresses across the whole account?

    Yes. Account-level IP exclusions sit under Admin, then Account settings, and apply to every campaign, including Performance Max, Search, Shopping, Display, Demand Gen, Discover and YouTube. Campaign-level exclusions still exist but only cover the campaign you set them on. Google merges both lists when both have rows.

  • How do you block an IP address in Google Ads?

    Go to Admin, select Account settings, and open IP exclusions. Add addresses one per line. A wildcard such as 203.0.113.* blocks a range in one slot. Click Save. The block applies to every campaign in the account, including Performance Max. Campaign-level exclusions sit under Additional settings and skip Performance Max.

  • Why does manual IP exclusion not stop click fraud?

    Speed and rotation. Invalid clicks arrive in bursts, so the budget is gone before you finish editing the list. VPNs, proxies and mobile networks change addresses constantly, which makes any typed list out of date within days. The 500-address cap fills before a rotating operation runs out of connections.

Abisola Tanzako, Content Manager at ClickPatrol

Written & reviewed by

Abisola Tanzako

Content Manager, ClickPatrol (click fraud & invalid-traffic specialist)

Abisola covers bot traffic, ad fraud and PPC protection, drawing on ClickPatrol platform data from 1,793+ businesses.

Last updated: 14 September 2026