Launch protection

Turn protection on for the first time and pick a sensitivity and action mode that lets you observe before blocking.

After the wizard, protection is set up but not enforcing. This page walks through turning it on. The recommended week-one configuration: Recommended sensitivity + Warn action mode — strong enough to catch fraud, gentle enough that you can watch what it does before blocking real ad spend.

Open the protection page

In the sidebar, click Protection. The page is titled Threat & Fraud Protection and is organized into four cards: Protection Status, Detection Strategy, Detection Sensitivity, and Protective Action.

Turn protection on

In the Protection Status card, toggle Active on.
Leave Detection Strategy on Automatic — ClickFortify's AI handles the decisions. You can switch to Manual later if you want to tune individual checks.
Set Detection Sensitivity to Recommended (level 3, the default).
Set Protective Action to Warn.
Click Save.

Pick a sensitivity level

The sensitivity slider has 5 levels:

LevelNameWhat it does
1Low ProtectionAllows most traffic
2BalancedFilters obvious threats
3RecommendedBest for most accounts
4StrictBlocks aggressive patterns
5Very StrictMaximum fraud prevention

Start at Recommended. If you see legitimate clicks getting flagged, drop one level. If fraud is still getting through after a week, go up one. Don't jump levels — small changes give you signal.

Pick an action mode

The Protective Action card has three options. Pick one based on how confident you want to be before clicks are blocked from your ads:

ModeWhat it doesWhen to use
ObserveLog only, no blockingFirst few days — see what protection would flag without affecting your ads
WarnAdd bad IPs to exclusion listsRecommended for week one. Protects future clicks without retroactively blocking flagged ones
StrictBlock all threats immediatelyAfter you've watched a week and trust the calls

Why "Warn" for week one

Warn is the safe middle ground. It builds your IP-exclusion lists from flagged clicks (so future visits from the same fraudster don't reach your ads) while leaving today's clicks alone. You get the data — false positives are visible in the dashboard — without risking real conversions on day one.

After 5-7 days, if the flags look right, switch to Strict.

What happens next

Have more questions?