Thank you! We’ve received your message and will contact you soon.

The $1,000-a-Day Leak: How to Stop Paying Top Tier CPMs for Spoofed Traffic

Aug 4, 20265 min read
Author Photo
Andriy Liulko Head of Sales
hero image

TL;DR:

  • 30% of internet users now use VPNs, breaking legacy IP-based geographic targeting.
  • Media buyers routinely pay Tier-1 CPMs for Tier-3 traffic when users mask their location.
  • High-payout CPA campaigns fail when restricted offers serve to spoofed users who cannot convert.
  • Ad servers must cross-reference IP addresses against native browser timezones and language settings to catch mismatched geographic data before the budget is spent.

A publisher approaches your agency with a direct deal. Their SimilarWeb metrics show the United States as their second-largest traffic source, followed closely by the Netherlands. You sign the insertion order, connect the tags, and start paying $1,000 a day for Tier-1 European and North American inventory.

Then you turn on advanced tracking and review the server logs. Over 50% of the US users and 80% of the Dutch users are connecting from Bangladesh, Pakistan, and Vietnam. They are routing their connections through commercial VPNs. You are paying Tier-1 CPMs for Tier-3 traffic.

(This is not a fantasy - our AdOps team recently untangled this exact scenario for a client.)

Global VPN usage has fundamentally broken IP-based targeting, creating a leak that drains agency margins.

Don't let spoofed traffic drain your budget. Epom Ad Server’s native mismatch detection automatically flags VPN traffic before you pay for it. [Start your 14-day free trial] to audit your publisher supply today.

The Problem with IP-Based Targeting

Legacy ad servers rely on IP addresses to determine geography. If a user connects through an Amsterdam server, the ad server logs a Netherlands impression and charges the European rate.

According to GlobalWebIndex, nearly a third of all internet users now operate through VPNs or proxy servers daily. The IP address no longer indicates a user’s physical location or purchasing power. Buyers pay for geographic data that does not reflect reality.

Emerging markets in Asia Pacific lead in VPN Usage

It’s not just about casual users employing VPN - there has been a rise in geo-masking schemes where fraudsters buy ad inventory in emerging markets, route the traffic through proxy networks or commercial VPNs, and then sell those impressions to Western advertisers at a steep markup. The financial yield justifies the cost of maintaining proxy networks.

Buyers relying solely on top-level network reporting remain blind to this arbitrage. They see a dashboard showing consistent delivery in their target countries and continue funding the fraudulent supply chain.

Consider a CPA campaign for a US-only streaming service or iGaming operator with a target acquisition cost of $50. The ad server reads a US IP address and serves the restricted offer. The user is actually in Vietnam. They click the ad and browse the landing page. Because the offer is geographically locked, they cannot convert. Your ad spend buys zero acquisitions.

Over a few days, the campaign data warps. The CPA spikes from $50 to $300. You absorb the loss to maintain the client relationship and erode your agency margins. Alternatively, the advertiser notices the discrepancy, demands an explanation for the $300 acquisition cost, and pulls the budget entirely.

At this point, catching VPN traffic is a matter of operational survival, not technical optimization.

The Solution: Triangulating the Mismatch

If IP addresses are compromised, how do you catch the spoofers? You stop relying on a single data point.

At Epom, we operate a geo-mismatch filter to cross-check the IP against the browser timezone and the browser language settings.

When an Epom Ad Server tag fires on a publisher's site, we cross-reference the IP against two native browser signals:

  1. Browser timezone
  2. Browser language settings

The IP address can be faked with a $5/month VPN. But very few casual users bother to dig into their operating system to permanently alter their machine's native timezone (e.g., UTC+6 Dhaka) or their core browser language.

Epom uses L.E.S. IP (Last External Source IP) to identify the last reliable public IP address in the connection chain, which often exposes the real location behind a VPN. Besides, we use a server-side fingerprinting model (combining IP and User Agent) to maintain a level of precision in tracking and frequency capping.

When a user's IP registers as Netherlands, but their browser is operating in a South Asian timezone and language, our server flags a mismatch. The system immediately identifies the user as VPN-masked.

You now know definitively whether you are dealing with a local user, or a VPN-masked user.

💡 Pro Tip: Don't rely on cookie-based capping, which is easily exploited by VPN users. Epom Advanced Capping uses server-side tracking and fingerprinting to count impressions and actions even when cookies are disabled or spoofed.

Verifying Publisher Supply

The 2023 Association of National Advertisers (ANA) study revealed that advertisers waste $22 billion annually on inefficient programmatic buys. A large portion of that waste happens because of misattributed and unverified traffic.

Operators buying direct publisher traffic require infrastructure to filter spoofed impressions before the budget clears.

Epom Ad Server provides a Traffic Quality Report and native mismatch detection. Media buyers use these tools to identify the true origin of a publisher's traffic, renegotiate payouts based on verified geographies, and ensure high-payout offers reach valid users.

Regulated industries and high-payout CPA campaigns face compounded risks when purchasing masked traffic. If an operator bids on US-only traffic for a restricted offer (like adult content or regional sports betting), serving that ad to a spoofed user guarantees a zero percent conversion rate.

Head of Sales, Epom
Andriy Liulko

Tips & Tricks for VPN-proof Targeting on Epom Ad Server

All the targeting information in Epom Ad Server is verified with the help of IP2Location© database. Alternatively, it is possible to switch Country and Location targeting in your network to MaxMind© database if your partners use it, for example.

  1. Different targeting types (Geo + Language + Time) work according to the AND rule, meaning user must match the Geo-IP, Browser Language, and Client Local Time simultaneously to receive a Tier-1 ad. This effectively blocks users who have a US IP but a Bangladeshi browser language and timezone.
  2. When Targeting is set both on Campaign and Banner levels, both Targetings will be applied by the AND rule.
  3. Exclude Targeting type has a higher priority than Include. In case of a collision, the Exclude rule will be selected by the system.
  4. Client local time checkbox on Day and Time and Time Range targetings allows applying client's timezone instead of GMT+0.

Stop Funding Illusions

When you base your media buying on raw IP addresses, you fund geographic illusions. Protecting your margins requires infrastructure that verifies the human behind the IP. By triangulating network data with native browser signals and enforcing strict exclusion rules, media buyers eliminate the spoofed traffic that drains CPA budgets.

The traffic may exist, and the clicks may register, but if the location is masked, the conversion is impossible. Verify your supply chain, demand placement-level transparency, and stop paying a premium for data that lies to you.

[Start your 14-day free trial] with Epom today to audit your supply chain and protect your margins.

Rate this article

0 ratings
Average: 0 of 5

Share this article

thank you image

Thank you!

Your guide is on its way to your inbox,
you'll get it in a second

Get Your Free Copy
cooldown image

A registration has already been submitted from this page. Please try again in 10 minutes.