NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Abstract ladder rung illustration representing CTR and User Signal Manipulation
Content & Platform AttackYour brand and its search results

CTR and User Signal Manipulation

Largely neutralized Search engines discount or ignore it; the fear exceeds the risk.

Click data is real, and that is not the same question as whether a stranger can make it lie about your page.

What CTR manipulation is, and the two questions inside it

CTR manipulation is the claim that a stranger can send engineered traffic to your listing in Google's results, make that traffic behave like a disappointed user, and get your page demoted for it. Click-through rate is clicks divided by impressions for one query and one URL, as reported in the Google Search Console Performance report. An impression is a single appearance of your link on a results page; a click, in Google's own definition, is a click that sends the user to a page outside Google Search, Discover or News.

Two versions circulate. The first is pogo-sticking: traffic that clicks your result, leaves within a second or two, then clicks a competitor's result for the same query, in the hope that the pattern reads as evidence your page does not satisfy the query. The second, quieter version is impression poisoning: driving your URL into the results for queries it has no business ranking for, so that a query-document pair accumulates impressions with almost no clicks and produces a terrible click-through rate on a query set you never targeted.

Both rest on a premise that is usually stated as one question when it is two. Is user click behavior an input to ranking? And can an outsider supply that behavior on your behalf? Almost every argument on this subject collapses the two, and the collapse is where the sales pitch lives. The first question is largely settled, and the answer since 2023 is yes. The second question decides whether you have anything to defend against at all, and it has never been publicly demonstrated in either direction.

That gap is the whole verdict. The evidence that click data exists is strong and recent. The evidence that a third party can turn it against you is absent. A page that treats the first as proof of the second is doing the arithmetic the sellers want done.

Three dated denials, and the one that actually answers the question

Google has addressed this on the record three times, and the three statements are not interchangeable.

  • Gary Illyes, early February 2019, in a Reddit AMA: "Dwell time, CTR, whatever Fishkin's new theory is, those are generally made up crap." Blunt, and — as the 2023 testimony below shows — overstated.
  • John Mueller, 4 November 2021, on Twitter/X: "If CTR were what drove search rankings, the results would be all click-bait. I don't see that happening." This is an argument about the naive model, not a description of the system.
  • John Mueller, 3 April 2021, asked directly whether third-party bot traffic affects rankings: "That has no effect on Google Search."

The third one is the only statement that answers the question this page is about. Read what it does and does not say. It is not a denial that click data exists in the ranking systems. It is a denial that externally generated traffic moves rankings — which is a narrower claim, a more defensible one, and the one an attacker's plan depends on being false.

Note the date. April 2021 predates both the antitrust disclosures and the 2024 documentation leak, and Google has not walked it back in the years since those landed. That matters, because the standard rebuttal to the 2019 and 2021 denials is "Google was caught out by the leak." On this specific denial, Google was not caught out; it simply has not been revisited.

What NavBoost and the 2024 leak actually established

The case on the other side is real and should not be waved away. It has two pillars, both dated.

Sworn testimony, autumn 2023. In the United States antitrust case against Google LLC in the District Court for the District of Columbia, Google's then head of search ranking, Pandu Nayak, testified about an internal system called NavBoost — a re-ranking mechanism that uses historical click data for a query. As reported by Danny Goodwin at Search Engine Land on 5 December 2023, Nayak described NavBoost as one of the important signals, trained on thirteen months of historical click and query data (down from eighteen months in 2017), segmentable by locale and device, and — this is the load-bearing detail — unable to rank documents that have no clicks at all. A sibling system, Glue, was described as the same thing extended to the non-click interactions on a results page.

The leak, March to May 2024. An automated commit exposed internal Google Content Warehouse API documentation on GitHub on 13 March 2024; analyzes were published on 27 and 28 May 2024, and on 29 May 2024 Google confirmed the documents were genuine, while cautioning against making inaccurate assumptions about Search based on out-of-context, outdated or incomplete information. The documentation contains attributes named goodClicks, badClicks and lastLongestClicks.

What those two things establish, jointly and beyond argument: Google's ranking systems have a memory of clicks, they have a concept of a bad click, and Google's public messaging for roughly a decade under-described this. Anyone still telling you clicks play no part in ranking is quoting 2019.

What they do not establish, and this is where careful reading earns its keep: nothing in the testimony or the leaked field names says the signal is per-session rather than aggregate, that it survives fraud filtering, or that it has a punitive direction an outsider can aim. The leak contained no source code, no weightings, and no indication of which attributes are live and which are deprecated. The existence of a field called badClicks proves that a bad click is a thing Google models. It proves nothing about who gets to manufacture one.

Google's own published description of this, in the How Search Works ranking documentation, is deliberately narrow: Google says it uses "aggregated and anonymized interaction data" to assess whether results are relevant, and transforms that data into signals. The two load-bearing words are aggregated and anonymized. The unit is a query-document pair across a population, not your session, and not the four hundred sessions somebody bought.

The two sides are answering different questions

Here is the argument this page exists to make, and it is the reason the verdict is what it is.

The denials and the disclosures are usually presented as a contradiction that one side must lose. They are not. Illyes in 2019 and Mueller in November 2021 were rebutting the practitioner model — raise your click-through rate, rank higher — which is the version sold in conference talks and the version the leak did in fact embarrass. Nayak in 2023 and the leaked schema in 2024 describe aggregate click memorization inside a re-ranking system. Those two things can both be true, and the most likely reconciliation is that Google's spokespeople were denying a claim nobody at Google recognized rather than denying the existence of NavBoost. That reconciliation is an inference, not a sourced fact, and it should be read as one.

But notice what neither side addresses. Every Google denial except the April 2021 one is about whether clicks are a ranking factor. Every disclosure is about whether Google keeps click data. An attack needs a third proposition that neither side has ever supplied: that an outsider's fabricated clicks reach the same store as a real user's, unfiltered, and push a competitor down.

For CTR manipulation to work as a negative SEO attack, three things must hold at once:

  1. Click data must be a live ranking input. Probable, after 2023. Grant it.
  2. The signal must have a punitive negative direction — an absolute demotion for bad clicks, not merely the absence of a boost. Unproven by any public source.
  3. Google's fraud filtering must fail to strip synthetic search traffic. Contradicted on the record by Mueller in April 2021, and implausible on its face: Google runs the largest click-fraud detection operation in the world because its advertising revenue depends on it.

Every commercial claim about this attack assumes all three silently. Grant the first and the other two are still doing the work, and neither has any public evidence behind it.

The two genuine unknowns, stated as unknowns

A reference page is worth more when it marks the edge of what is known than when it pretends the edge is not there. Two things on this subject are not known outside Google, and no amount of confident writing changes that.

Unknown one: the direction of the signal. Whether badClicks ever produces an absolute demotion, or only fails to produce a boost, is not established by any public source. This is the single most important open question on the topic. If the signal only withholds reward, then the worst an attacker can do with clicks is fail to help you, which is not an attack. If it punishes, the mechanism exists — and there is still no evidence anyone has driven it from outside.

Unknown two: filtering. Google has never published how synthetic search clicks are detected and stripped out of NavBoost, or whether they are stripped at all. Mueller's April 2021 statement is an assertion by an employer with an interest in the answer, not evidence. It is, however, the only on-record statement that addresses the question directly, and nothing has contradicted it in the four years since.

I have gone looking for the missing demonstration more than once, on the reasonable assumption that a decade of commercial interest would have produced one. It has not. What follows from admitting both unknowns is not "so it might work." It is narrower and more useful: no public, method-disclosed experiment has ever shown an outsider pushing somebody else's page down with clicks. Not one. The absence of a demonstration after a decade of people trying to sell the service is itself a finding.

What the experiments show, and what they were testing

The famous result is Rand Fishkin's, published on 1 May 2014: a page ranking seventh for a niche query, roughly 175 to 250 real people clicking it from a Twitter request within a few hours, and the page reaching the top position in US results inside three hours. It is cited constantly. It is almost never cited with its author's own caveats, which were that this was not enough evidence to say for certain that Google uses query and click volume, and that coincidental links, a temporary effect and geographic variance were all live alternatives.

Two features of that experiment matter more than the outcome. It used real people, recruited publicly, not automated traffic. And it tested a positive push on the tester's own page. Later attempts to repeat the format produced mixed and frequently null results, and where an effect appeared it decayed quickly.

Every credible public version of this experiment shares that second property. There is no comparable published test, with a disclosed method, in which an outsider drove a third party's page down. The experimental record on the offensive use of clicks is empty, and a marketing sector has been selling into that emptiness for ten years.

Reading the traffic without misreading the ranking

The traffic is visible even when the ranking effect is not, which is exactly why this panics people. Work in this order.

Check whether rank moved at all. Pull position history, not click-through-rate history. If your positions are flat and your CTR fell, the cause is nearly always the results page itself — an AI Overview or a new feature block pushing organic results down, a title Google rewrote, a competitor's rich result — and not your page. This single check ends most investigations, and skipping it is how a SERP layout change becomes a six-week hunt for an attacker.

Search Console, Performance, Search results. Filter to the affected query and page and turn on date comparison. Bot activity does reach this report: Mueller said on 6 August 2021 that Google does not necessarily filter all of it out of Search Console. Google's own Performance report documentation is silent on filtering invalid or automated activity, which corroborates that. It does note that clicking a result, returning, and clicking the same link again counts as one click — so crude repeat-clicking records fewer clicks than the person paying for it expects.

The Queries tab. A sudden bloom of queries you never targeted, often in another language or another industry, carrying impressions and near-zero clicks, is the impression-poisoning signature.

Server logs, not analytics. Most engineered traffic never executes analytics JavaScript, so GA4 can show nothing while the logs show everything. In the logs, look at variance rather than volume: single-page sessions, sub-two-second durations, one referrer, a narrow user-agent range, a narrow network range, no scroll, no second event. Real disappointed humans are not that uniform.

What it gets mistaken for. Almost everything: a core update the same week, seasonality, a Search Console reporting change, rank-tracking tools and scrapers inflating impressions — that last one is extremely common and entirely benign.

The response, when the correct response is mostly nothing

  1. Do nothing, first. This is genuinely the correct answer in most cases. There is no remediation to perform against a signal Google says it does not take from third parties, and purchased traffic decays on its own when whoever is paying stops.
  2. Establish whether ranking moved. If it did not, there is no attack to remediate.
  3. Separate the ranking question from the hosting question. High-volume engineered traffic can genuinely hurt you — exhausted server resources, inflated hosting bills, wrecked Core Web Vitals field data, polluted conversion analytics. Those are real harms with real fixes: rate limiting, an edge or CDN bot rule, filtering the traffic out of your reporting views. None of them is an SEO fix, and describing them as one is how a hosting problem gets billed as a recovery engagement.
  4. Annotate your analytics so the spike is not read as a real audience change a year from now.
  5. Do not disavow anything. The disavow tool operates on links. It has no bearing on traffic or clicks whatsoever, and a careless disavow file is one of the few ways to damage yourself for real.
  6. Do not file a reconsideration request. That process exists only to answer a manual action — a penalty applied by a human reviewer at Google and shown to you in Search Console under Security and Manual Actions. There is no manual action for being clicked on.
  7. If the volume is an availability problem, block it at the edge by network characteristics. Never by tightening robots.txt or blocking by user-agent patterns that can catch Googlebot, which converts a non-problem into a real deindexing problem.

And do not buy protection from this. There is no product that stops a stranger from clicking a search result, there is no evidence the clicking does anything, and a monitoring service for the threat is a subscription to watching a graph you can already see in Search Console for nothing. Anyone selling you CTR protection is selling you protection from something that has never been publicly shown to work, and I would rather lose the engagement than take money for it.

Where the law reaches, and where it stops

Thin, and it is better to say so than to imply otherwise. There is no Google reporting channel for "somebody is clicking my search result." The spam report form covers spam appearing in the results, not traffic sent to you.

Where an engineered traffic flood is sustained and volumetric, it can be characterized as unauthorized access or damage under the Computer Fraud and Abuse Act, 18 U.S.C. §1030, and under state computer-crime statutes. In practice the CFAA's damage-or-loss thresholds and the difficulty of attributing distributed traffic to a person make it an expensive and rarely-run theory. Where the source is a competitor and intent is provable, tortious interference with prospective economic advantage is the more usual state-law framing. Neither is fast, and neither restores a ranking.

One useful distinction: if the traffic is aimed at your ads rather than your organic listing, you are in a completely different and much better-served system. Google Ads operates invalid-traffic detection with automatic credits, it is documented, and it has a support path. That is click fraud, an advertising problem with an advertising remedy — and it is not the same thing as the organic attack this page is about, however often the two get filed under one name.

Frequently asked questions

Can a competitor send bot traffic to my site and hurt my Google rankings?

There is no public evidence that they can, and one direct denial that they cannot. Asked on 3 April 2021 whether third-party bot traffic affects rankings, John Mueller of Google said: "That has no effect on Google Search." That statement has not been retracted, including after the 2023 antitrust testimony and the 2024 documentation leak. What is true is that click data exists inside Google's ranking systems. What has never been demonstrated is that an outsider's fabricated clicks reach that data unfiltered, or that the data has a punitive direction someone can aim at you.

Doesn't the 2024 Google leak prove CTR is a ranking factor?

It proves less than it is usually said to prove, and more than Google previously admitted. Google confirmed on 29 May 2024 that the leaked documentation was authentic, and it contains fields named goodClicks, badClicks and lastLongestClicks. So Google's systems model clicks, and the 2019 denials were too broad. But the leak contained no source code, no weightings, and no indication of which fields are live. A field name proves a concept exists. It does not tell you the concept can be driven from outside, and it says nothing at all about negative direction.

My click-through rate collapsed but my rankings did not move. What happened?

Almost certainly the results page changed above you, not your page. An AI Overview, a new feature block, a larger set of ads, a competitor gaining a rich result, or Google rewriting your title will all cut clicks at an unchanged position. Compare position history against click history over the same window before treating it as an attack. If position is flat, there is nothing here that a link, a disavow file or a reconsideration request could fix.

Should I block the bot traffic I can see in my server logs?

Only if the volume is a hosting or availability problem, and then for that reason rather than an SEO one. Blocking at the edge by network characteristics is safe. Blocking by broad user-agent rules or by tightening robots.txt is not, because it is very easy to catch Googlebot or Google's rendering fetches in the same rule and convert a harmless traffic spike into a genuine deindexing incident. Weigh that trade honestly: an unmeasured risk of a fake attack is not worth a measured risk of a real one.

Is it worth buying CTR protection or a bot-traffic monitoring service?

No. There is no mechanism a service could interpose between a stranger and a search result, the underlying threat has never been publicly demonstrated, and the observation such a service sells you is already in Search Console at no cost. If a vendor's pitch relies on the 2024 leak, ask them for the disclosed-method experiment in which an outsider pushed a third party's page down. There isn't one.

Google denied click signals in 2019 and testified about NavBoost in 2023. Which is true?

Both statements are accurately reported, and they answer different questions. The 2019 and November 2021 denials were aimed at the practitioner claim that raising your click-through rate raises your rank. The 2023 testimony describes NavBoost, a re-ranking system trained on aggregated historical click data for a query. Reading the denials as directed at the naive model rather than at the existence of click memorization reconciles them, though that reconciliation is an inference rather than something Google has said.

Top