HomeBlogQR Code Bot Traffic: How to Tell If Your Scan Numbers Are Fake

QR Code Bot Traffic: How to Tell If Your Scan Numbers Are Fake

A qr code bot traffic guide — what actually counts as fake scans, the real signals SMLLR scores every scan against automatically, the Bots On/Off dashboard toggle, and how to manually sanity-check your numbers on any platform.

By Aakash Verma, Founder

Why "Fake Scans" Are a Real Concern, Not Paranoia

A sudden spike in scans that doesn't match any campaign activity, or a code that seems to get scanned constantly overnight when nobody should be near it, is a legitimate thing to be suspicious of — not every scan a QR code records came from a human being who intended to open it. Some of this is completely benign (explained below); some of it is automated scanning that has nothing to do with your actual audience. Either way, if you're making budget or campaign decisions off scan counts, it's worth knowing which is which.

What Actually Counts as Bot Traffic

Not every non-human scan is malicious, and lumping them together leads to the wrong conclusions:

  • **Link-preview bots** — when someone shares your QR's destination link in WhatsApp, Slack, or Facebook Messenger, those platforms auto-fetch the URL once to generate a preview card. This is completely normal and expected, not an attack.
  • **Security and monitoring scanners** — corporate email/link-safety tools and some antivirus products automatically visit URLs to check them, which can register as a scan with no human involved.
  • **Scripted or automated traffic** — a script, a scraper, or a monitoring tool hitting the link directly (via `curl`, a headless browser, or a similar tool) rather than a phone camera.
  • **Genuinely malicious or inflated traffic** — automated repeated hits designed to run up a scan count or exhaust a scan-limit redirect, which is the case actually worth worrying about.

How SMLLR Scores Every Scan Automatically

Every scan on SMLLR runs through a fraud-detection engine that checks six independent signals and combines them into a single score: a bot-like user agent (patterns matching known scripts, scrapers, and headless browser tools), a rapid repeat scan from the same IP address against the same QR code within 30–60 seconds, a high-volume IP sending an unusually large number of scans in a short window, missing or inconsistent location data, missing standard browser headers that a real phone browser always sends, and an IP address originating from a known datacenter or cloud provider range rather than a residential or mobile network. A scan scoring 40 or above is flagged suspicious; 60 or above is flagged fraudulent. This runs automatically on every scan, with no setup required.

The "Bots: On/Off" Toggle in Your Reporting Dashboard

SMLLR's reporting dashboard has a "Bots: On/Off" toggle, and it defaults to Off — meaning scans flagged as suspicious or fraudulent are already excluded from your headline numbers unless you explicitly turn bot data on. Flipping it on shows you the full, unfiltered picture (all traffic, including what the fraud engine flagged), which is useful specifically when you want to see how much automated activity a code is attracting, or to sanity-check the filter itself, rather than for day-to-day reporting.

Manually Spotting Bot Patterns Even Without a Built-In Detector

If you're evaluating scan data on a platform without this kind of automatic scoring, the same underlying signals are worth checking by hand: scans clustered in the exact same second or minute (a human audience doesn't scan in perfect unison), a scan log with no device or browser information at all (real phones always report this), and geographic locations wildly inconsistent with where a physical placement actually is — a poster in a single Mumbai store generating scans spread evenly across a dozen countries is not a marketing win, it's a signal worth investigating.

What to Do If You Suspect Inflated Numbers

Cross-reference the suspicious spike against something bots can't fake: actual conversion. If a code shows a large jump in scans but Lead Hub captures, Play & Win claims, or landing-page form fills stay completely flat, that mismatch is itself the evidence — a real audience converts at some rate, however small; a bot flood generally converts at zero. Don't overreact to a single unexplained spike either; check the pattern over a few days before concluding something is wrong, since real campaigns (a social post going unexpectedly viral, a TV mention) can also produce a legitimate, sudden jump.

Why This Matters for Billing and Budget Decisions

This isn't just a curiosity — it has a real practical stake. SMLLR's scan-limit redirect rules (Basic plan, ₹1,999/month, and up) can switch a code's destination automatically once it hits a set number of scans, which exists to handle things like limited-stock promotions. A burst of bot traffic against a code with a scan-limit rule active could exhaust that limit and flip the destination prematurely, before a single real customer got the intended offer — one more reason the bot-detection layer running by default matters beyond just cleaner reporting.

Create your QR code on SMLLR, and trust that your reported scan numbers already reflect real human traffic by default.

Frequently Asked Questions

Are all non-human QR code scans malicious?

No. Link-preview bots (WhatsApp, Slack, Facebook auto-fetching a shared URL) and corporate link-safety scanners are common, benign sources of non-human scans. The concern is specifically automated or scripted traffic designed to inflate counts or exhaust a scan limit.

How does SMLLR detect bot traffic automatically?

Every scan is scored against six signals: a bot-like user agent, a rapid repeat scan from the same IP within 30–60 seconds, a high-volume IP in a short window, missing or inconsistent location data, missing standard browser headers, and a known datacenter/cloud IP range. A score of 40+ is flagged suspicious, 60+ fraudulent.

Does SMLLR exclude bot scans from my reports automatically?

By default, yes — the dashboard's "Bots: On/Off" toggle defaults to Off, meaning suspicious and fraudulent scans are already excluded from your headline numbers unless you explicitly switch it on to see the full, unfiltered traffic.

How can I manually check if my scan numbers are inflated on any platform?

Look for scans clustered in the exact same second or minute, scan records with no device or browser information at all, and geographic locations that don't match where the physical QR code is actually placed.

What's the best way to confirm a scan spike is real and not bot traffic?

Check whether the spike is matched by actual conversions — Lead Hub captures, Play & Win claims, or landing-page form fills. Real traffic converts at some rate; a bot flood typically converts at zero, which is itself the evidence.

Can bot traffic affect my scan-limit redirect rules?

Yes — a burst of automated traffic against a code with a scan-limit redirect rule (Basic plan, ₹1,999/month, and up) could exhaust the limit and flip the destination early, before real customers reach the intended offer.

Should I always keep the Bots toggle turned off?

For day-to-day reporting, yes — it gives you the cleaner, human-traffic-only picture by default. Turning it on occasionally is useful if you specifically want to see how much automated activity a particular code is attracting.

Related Resources