Skip to content
Back to Journal
Google Ads

Google Ads Clicks From Countries You Don't Target: Why It Happens

12 min readBryan, Technical Analyst
Google Ads Clicks From Countries You Don't Target: Why It Happens

You targeted one country. You open the Locations report and there are clicks from two or three others — sometimes ones with no conceivable link to your business. The instinct is that Google is broken, or that you're being defrauded, and you reach for whichever fix matches your mood.

Both instincts can be right, and that's exactly the trap. "Clicks from another country" is not one problem with one cause. It's two problems that happen to look identical in a report, and the fix for one does nothing for the other. Switch settings when it's fraud and you'll still bleed budget; hunt for fraud when it's a setting and you'll waste a week finding nothing.

This guide separates them. First the setting almost everyone misreads, then the legitimate reasons real people click from abroad, then how to recognise when wrong-geo clicks are genuinely fraud — and why, in that case, your location settings are structurally the wrong tool.

The setting almost everyone has wrong

Google Ads gives every campaign a location option that quietly decides who counts as being "in" your targeted area. It sits under the campaign's location settings, most advertisers never open it, and it defaults to the broadest choice.

There are two options for your targeted locations:

  • Presence or interestPeople in, regularly in, or who've shown interest in your targeted locations. This is the default and Google's recommended setting.
  • PresencePeople in, or regularly in, your targeted locations.

Read the default again. It includes interest. That means someone sitting in another country, searching for something related to your targeted location, can qualify as "interested" and see your ad. Search "plumber in Austin" from London and you have shown interest in Austin — so an Austin-targeted campaign on the default setting is allowed to serve you, in London, and Google will count that as on-target.

For a huge share of advertisers — local services, regional lead-gen, anyone who can only actually serve customers in one country — that interest-based half is pure leakage. It's the single most common reason a campaign "targeted to one country" shows clicks from several.

The mirror image matters just as much and gets even less attention. When you exclude a location, the same two options apply:

  • Presence or interest — exclude people in, regularly in, or interested in the excluded location.
  • Presence — exclude only people in, or regularly in, it.

If you exclude a country but leave the exclusion on the narrower Presence setting, people merely interested in that country can still slip through. Plenty of advertisers add an exclusion, watch the clicks continue, and conclude Google is ignoring them — when in fact the exclusion is set to catch a smaller group than they assumed.

| Setting | Serves / excludes | Use it when | | --- | --- | --- | | Presence or interest (target) | People in, regularly in, or interested in the location | You genuinely want reach from anyone interested — travel, hospitality, national brands | | Presence (target) | Only people in, or regularly in, the location | You serve one area or country and want to pay only for people actually there | | Presence or interest (exclude) | Excludes people in, regularly in, or interested in the location | You want a country gone completely — the correct exclusion setting for most | | Presence (exclude) | Excludes only people in, or regularly in, the location | Rare; leaves interested users still eligible |

The two-minute fix: open Google's location settings options, switch your targeted locations to Presence, and set any excluded locations to Presence or interest. That one change removes most legitimate-but-unwanted foreign clicks — and, just as usefully, it makes the clicks that remain far more suspicious, because you've stripped away the innocent explanation.

The legitimate reasons real people click from abroad

Before you treat every remaining foreign click as an attack, rule out the honest causes. Real customers generate wrong-geo clicks all the time:

  • Travellers and expats. Someone from your country searching while abroad, or an expatriate looking for services back home. On the default setting these are on-target by design.
  • Privacy-conscious VPN users. A real, valuable customer sitting in your city, routing through a VPN whose exit node is in another country. Their IP says "elsewhere"; the human is local. (This one cuts both ways, as we'll see.)
  • Search Partners and Display spillover. Ads on the Search Partner network and Display can behave more loosely on geography than Search alone. If wrong-geo clicks concentrate there, the network — not fraud — may be the story.
  • Language and border effects. Bilingual regions, neighbouring countries, and shared languages produce genuine cross-border interest that can be worth having.

The point of listing these isn't to excuse the clicks — it's to set a baseline. A handful of low-volume foreign clicks that occasionally convert is normal. That is not what you're hunting. You're hunting the pattern that none of these explanations fit.

When wrong-geo clicks are actually fraud

Here's the reframe that makes the rest of this useful: the fraud signal is never the foreign click itself. It's the pattern around it. A single click from abroad tells you nothing. A cluster with the following fingerprints tells you plenty:

  • A country with no plausible link to your business, appearing repeatedly rather than once.
  • Hyper-local search terms — "emergency plumber near me," "[your city] dentist" — that a genuine foreign searcher would almost never type.
  • Near-zero engagement: sessions of a second or two, no scroll, no second page, bounce rates that dwarf your account average.
  • No conversions, ever, from that geography — high click volume producing exactly nothing.
  • Burst timing: clumps of clicks in tight windows, often off-hours for your market, rather than the smooth spread of real demand.
  • Clicks that persist after you've tightened the setting to Presence and excluded the country outright.

That last one is the clincher. Once you've removed the interest-based explanation and explicitly excluded a country, legitimate interest-based serving from there should stop. Clicks that keep coming anyway aren't misconfigured targeting — they're traffic whose reported location doesn't match its real one. Which is the whole mechanism of geo-spoofing, and the reason your settings have run out of road.

Why your location settings can't stop it

Google decides where a click comes from largely by reading the visitor's IP address and mapping it to a place. That's a reasonable signal for honest traffic. It is also a signal that is trivial to fake.

Route through a VPN and your IP becomes the exit node's IP. Route through a proxy — especially a residential proxy borrowing a real household's connection — and you inherit that household's location. Come from a data center and you can present almost any geography you like. In every case, the location Google reads is the location the traffic chose to show it.

Follow what that does to targeting:

  1. A fraudulent or automated visitor in country A wants to hit your country-B campaign.
  2. They route through a VPN or residential proxy with an exit point inside country B.
  3. To Google, they are now a country-B user. They clear your Presence setting cleanly.
  4. Your location targeting — working exactly as designed — waves them straight through.

Targeting filters on the one signal fraud fakes first. That's not a bug you can configure away; it's the ceiling of what geo-targeting can do. Location settings are a preference, not a wall. They tell Google who you'd like to reach. They were never built to verify that a click's reported location is its real one — and against traffic that spoofs location on purpose, that's the only question that matters.

It's also not a fringe problem. Automated traffic now makes up more than half of all web traffic, per Imperva's bad-bot research, and the sophisticated end of it runs real browsers over residential IPs specifically to look like a local human. A bot wearing your city's IP address is indistinguishable, to your location settings, from a customer down the street. This is the same reason static IP blocking fails against residential-proxy fraud: both defences trust an address that the attacker controls.

How to diagnose what you actually have

Two reports and one cross-check will tell you which problem you're facing.

1. Read both halves of the Locations report. Inside the campaign, the Locations report can show two different views, and the difference between them is the entire point:

  • "What triggered your ad" (matched location) — the location Google associated with the search. This can be interest-based, and it's what makes an out-of-area click look on-target.
  • "Where your users were" (user location) — where people were physically located.

When matched location says "on target" but user location shows another country, you're looking at interest-based serving — a settings issue, fixable. When user location itself is full of countries you excluded, on local search terms, you're past settings and into spoofed or invalid traffic.

2. Cross-check GA4. Pull the geographic report in GA4 and line it up against Google Ads. If a region shows heavy sessions with rock-bottom engagement time and no key events, that agrees with the fraud read. (GA4 has its own blind spots here — many click bots never fire the analytics tag at all — which is why we treat detecting bot traffic in GA4 as one input, not the verdict.)

3. Weigh the signal cluster, not any single click. No report has a "this is fraud" column. You're combining geography, search term, engagement, conversion, and timing into a judgement. One weird click is noise. The full pattern, surviving a tightened setting, is a diagnosis.

What actually works — in order

Do the cheap, certain fixes first, then escalate only as far as your traffic forces you.

1. Fix the setting. Switch targeted locations to Presence; set excluded locations to Presence or interest. This alone clears most legitimate-but-unwanted foreign clicks and sharpens every click that remains.

2. Exclude explicitly. Don't rely on targeting one country to exclude every other. Name the countries and regions you never serve and exclude them outright, on the correct Presence or interest setting. Related tactics live in Google Ads exclusion lists and the mechanics of IP exclusions.

3. Know where IP exclusions stop. You can add offending IPs to Google Ads exclusions, but the ceiling is real — Google caps you at 500 IP exclusions per campaign, there's no bulk import of ranges, and, critically, spoofed traffic rotates addresses. Block one residential-proxy IP and the next click arrives on a fresh one. Manual IP blocking is a bucket against a tide when the tide changes address every click. This is precisely where VPN and proxy traffic outruns the tool.

4. Move to click-level protection. When wrong-geo clicks survive a tightened setting and explicit exclusions, the problem isn't where Google thinks the click is from — it's that the click is invalid and dressed in a local IP. Real-time protection scores each visitor on signals a spoofed location can't launder — data-center and proxy fingerprints, behavioural tells, velocity — and keeps the invalid ones out of the campaign instead of chasing their addresses after the fact.

5. Protect the conversion, not just the click. The deeper cost of wrong-geo fraud isn't the wasted click — it's what a fake conversion does to automated bidding. Feed junk conversions into Smart Bidding and it learns to chase that traffic, so a geo-spoofing problem quietly becomes a Smart Bidding trained on fraud problem. On Meta the stakes are higher still: Meta offers no IP exclusions at all and optimises almost entirely on the conversion signal, so filtering fraud out of the conversion stream — before it reaches the platform — is the only real defence.

The honest summary

Clicks from countries you don't target are two problems wearing one disguise. Most of the volume is a setting: the default "Presence or interest" option serving anyone merely interested in your area, fixable in two minutes by switching to "Presence" and excluding unwanted regions properly. The rest — the clicks that survive that fix, land on hyper-local terms, engage with nothing, and convert never — is geo-spoofed traffic, and no location setting can stop it, because targeting trusts the one signal fraud fakes first.

Diagnose before you act: read matched location against user location, cross-check GA4, and judge the pattern, not the click. Fix the setting, exclude explicitly, and when foreign clicks outlive both, stop treating a fraud problem like a targeting one.

ClickFortify blocks invalid clicks in real time across Google Ads and Meta Ads from $8/mo — scoring each visitor on signals a spoofed location can't fake, so the traffic your geo-targeting waves through doesn't reach your budget or your bid strategy.

Frequently Asked Questions

Why is Google Ads getting clicks from countries I didn't target?

There are two separate causes and it's worth knowing which one you have. The first is your location setting: Google Ads defaults to 'Presence or interest,' which shows ads not only to people physically in your targeted location but also to people anywhere who show interest in it — someone abroad searching for services in your city, for example. That is working as designed, and switching to 'Presence' narrows it. The second cause is geo-spoofing: traffic routed through a VPN, proxy, or data-center IP that reports a false location. Google reads location largely from IP address, so spoofed traffic can appear to be in your country when it isn't, or hit you from outside it. The first is a settings fix. The second is a fraud problem your settings cannot solve.

What is the difference between Presence and Presence or interest in Google Ads?

They define who counts as being in your targeted location. 'Presence or interest' — the default — shows ads to people in, regularly in, OR who have shown interest in your targeted locations. 'Presence' shows ads only to people in, or regularly in, those locations. The interest half of the default is what produces most 'clicks from another country' surprises: someone searching from abroad for a business in your area qualifies as interested and can see your ad. For most lead-gen and local businesses that only serve one country, 'Presence' is the safer choice. The same distinction applies to excluded locations, and getting the exclusion setting wrong is a common reason unwanted regions keep slipping through.

How do I stop Google Ads from showing in other countries?

Do it in this order. First, in each campaign's location settings, switch location options from 'Presence or interest' to 'Presence' so you only serve people actually in your targeted area. Second, explicitly exclude the countries you never want to serve, and set the exclusion to 'Presence or interest' so you exclude people merely interested in those places too. Third, check the User locations report to see where clicks physically came from, not just what you targeted. If wrong-country clicks continue after all three — especially on terms only a local would search — you are likely looking at geo-spoofed or automated traffic that targeting cannot filter, and you need click-level protection.

Are clicks from other countries always click fraud?

No, and assuming so will send you chasing the wrong fix. Plenty of foreign clicks are legitimate: real customers travelling or using a VPN for privacy, expatriates searching for services back home, and the interest-based serving built into the default location setting. The fraud signal isn't the mere presence of foreign clicks — it's the pattern. Repeated clicks from a country with no plausible connection to your business, on hyper-local search terms, with near-zero engagement and no conversions, arriving in bursts, is not a curious traveller. It's the shape of automated or competitor traffic hiding behind a spoofed location.

Can VPN and proxy users bypass my Google Ads location targeting?

Yes, because location targeting is built on IP geolocation and a VPN or proxy changes the IP. Someone in another country connecting through a VPN exit node inside your target region looks, to Google, like a local user — so they clear a 'Presence' setting cleanly. The reverse also happens: your own settings can't see that a 'local' visitor is really foreign traffic wearing a local IP. This is the structural limit of geo-targeting — it filters on a location signal that is trivial to fake — and it's why VPN, proxy, and data-center traffic is a fraud-detection problem rather than a targeting one.

How can I tell where my Google Ads clicks are really coming from?

Use the Locations report inside the campaign and read two different views. 'What triggered your ad' (matched location) shows the location Google associated with the search — which can be interest-based and misleading. 'Where your users were' (user location) shows where people were physically located. The gap between them is exactly the interest-based serving the default setting allows. Cross-check against GA4's geographic report, and watch for the tell that no report labels: clicks from a region with sky-high volume and zero engagement or conversions. That combination points past targeting mistakes to invalid traffic.