How to Exclude IP Addresses in Google Ads

To exclude IP addresses in Google Ads, go to Campaigns → Settings → Additional settings → IP exclusions, enter the IP addresses you want to block, then save your changes. You can exclude up to 500 IP addresses per campaign. For exclusions across multiple campaigns, Google Ads also supports account-level IP exclusions. Manual IP exclusions work for known addresses, but the list needs ongoing maintenance as invalid traffic sources change.
Competitors clicking your ads, bot traffic and click farms are three of the most common ways click fraud quietly drains a Google Ads budget. Blocking that traffic protects your spend and pushes more of your budget towards people who might convert. The simplest manual lever is the IP exclusion list, which stops chosen IP addresses from seeing your ads. It works, but it has limits worth understanding before you rely on it. For coverage that keeps pace with fraud as it shifts, real-time fraud prevention closes the gaps a static list cannot.
What Are IP Exclusions in Google Ads?
IP exclusions let you name specific IP addresses that should not see your ads. Google allows up to 500 IP addresses per campaign, entered either individually or as blocks of addresses using an asterisk to wildcard the final part of the address. You can apply exclusions at account level, which covers every campaign, or at campaign level for more granular control.
One important caveat: campaign-level IP exclusions are not available for Performance Max, video, app, hotel or smart display campaigns. You can still exclude IPs from Performance Max at account level, which Google introduced in 2024, but only across every campaign at once, never for a single PMax campaign. For the detail, see how to exclude IP addresses in Performance Max.
How to Exclude or Block IP Addresses in Google Ads
Google makes it straightforward to apply IP exclusions at both account and campaign level.
Account level
This excludes the listed IP addresses from every campaign in your account.
- Log in to your Google Ads account and navigate to Settings.
- Click Account settings and find the IP exclusions section.
- Enter the IP addresses you want to block from seeing your ads, then click Save.
Campaign level
This gives you the flexibility to block invalid traffic on an individual campaign.
- Log in to your Google Ads account and click the Campaigns icon.
- Select the campaign you want to exclude IP addresses from.
- Click the settings icon, then on the settings page click Additional settings.
- Expand the IP exclusions section.
- Enter the IP addresses you want to exclude from the campaign and click Save.
To block a range rather than single addresses, replace the final part of the IP with an asterisk. This is useful when fraudulent clicks cluster within one network, but use it carefully, since broad ranges can catch genuine customers who share that block.
How to block a range of IP addresses
To block a range rather than single addresses, replace the final part of the IP with an asterisk. This is useful when fraudulent clicks cluster within one network, but use it carefully, since broad ranges can catch genuine customers who share that block.
How to Remove IP Addresses From the Exclusion List
Removing IPs matters as much as adding them. IP addresses are rarely fixed to a single user, so an exclusion that stops a bad actor today may block a real customer next month. Apply each exclusion only for as long as it is needed, then review it.
There is a practical reason too. With Google's 500-IP cap per campaign, you will eventually need to remove older entries to make room for new threats. To remove an exclusion, follow the same account or campaign steps above, delete the addresses you no longer want to block, and click Save.
How to Whitelist IP Addresses in Google Ads
Google Ads has no dedicated "whitelist" field, but you achieve the same outcome by keeping trusted IPs off your exclusion list and out of your reporting filters. The two addresses worth handling deliberately are your own.
Your team clicking your own ads to check they are live, or navigating to the site through a paid ad out of habit, inflates costs and pollutes conversion data. Exclude your office and VPN IP ranges at account level so internal traffic never triggers a paid click. Do the same for trusted agency or partner IPs. This is the mirror image of exclusion: instead of blocking bad actors, you are protecting the integrity of the traffic you already trust.
Which IP Addresses Should You Exclude?
Only exclude IP addresses when your click data shows clear evidence of invalid or unwanted activity. This could include IPs linked to repeated suspicious clicks, bot activity, click farms or known internal traffic that you do not want triggering your ads.
Avoid blocking an IP based on a single unusual click or assumption. Shared and dynamic IP addresses can represent multiple legitimate users, so an incorrect exclusion could prevent genuine prospects from seeing your ads.
The difficult part is knowing which IPs are genuinely invalid before adding them to your exclusion list. We cover the signals to look for and how to investigate your click data in our guide to identifying fraudulent IP addresses in Google Ads.
Working Around the 500-IP Exclusion Limit
Google Ads allows up to 500 IP exclusions per campaign. For advertisers dealing with a small number of known addresses, that may be enough. But if you are using IP exclusions to respond to sustained invalid traffic, the bigger problem is not simply running out of space. It is keeping the right IPs blocked as the traffic changes.
Google already filters traffic it identifies as invalid, including automated and repeated clicks. IP exclusions give advertisers an additional layer of control when they identify traffic they do not want their ads serving to. However, a static list has practical limits when the source of that traffic keeps changing.
Here are better ways to use your available exclusions.
Use account-level exclusions for IPs that affect multiple campaigns
Google Ads supports account-level IP exclusions, allowing you to block an address across campaigns without adding it individually to every campaign. This is particularly useful for known internal networks or IPs that consistently generate unwanted traffic across your account.
Campaign-level exclusions are better reserved for IPs relevant to a specific campaign.
Block IP ranges when the evidence supports it
Google allows an asterisk (*) to replace the final three digits of an IP address. If your data shows that multiple invalid clicks are consistently coming from the same IP range, excluding the range can cover more traffic without using hundreds of individual entries.
Use this carefully. A broader exclusion can also block legitimate users sharing that range, so the pattern should be well established before you apply it.
Use location exclusions for geographic problems
If the unwanted traffic is concentrated in a country or region you do not serve, use Google Ads location targeting rather than filling your IP exclusion list with addresses from that location.
Google itself recommends geographic exclusions when the problem is location-based rather than tied to individual networks.
Prioritise persistent sources of invalid traffic
Not every suspicious IP deserves one of your 500 campaign-level exclusions. Prioritise addresses where you have repeated evidence of unwanted activity and where blocking them is likely to have a meaningful impact on campaign spend or performance.
A single non-converting click is not enough evidence to block an IP.
Review exclusions as traffic patterns change
IP addresses are not permanent identities. Users can move between addresses, ISPs can rotate them, and multiple users can share the same address. Google also notes that excluded IPs can still appear in web logs in some circumstances.
That means an exclusion list should be reviewed rather than treated as a permanent blacklist.
Where Manual IP Exclusions Start to Break Down
This is where the 500-IP limit becomes less important than the underlying limitation of manual blocking.
TrafficGuard does not rely on an advertiser maintaining a longer static blacklist. Each click can be evaluated using multiple signals to determine whether the user and behaviour behind it are valid. When invalid or non-incremental activity is identified, protection can respond as that traffic changes rather than waiting for someone to find an IP, investigate it and update an exclusion list.
That distinction matters because the IP address is only one signal. Dynamic IPs, shared networks and changing traffic sources mean the same unwanted behaviour does not necessarily keep arriving from the same address.
Manual IP exclusions are useful when you know exactly what you want to block. For ongoing click fraud prevention, the challenge is identifying and responding to the next invalid click, not maintaining an ever-growing list of the last ones you found.
The Limitations of Manual IP Exclusion
Manual IP exclusions can stop known sources of unwanted traffic, but they are a reactive control. You have to identify the problem, find the IP address and add it to your exclusion list after the activity has already occurred.
That creates several limitations:
You are always reacting to past clicks. By the time an IP shows enough suspicious activity to investigate and block, you may have already paid for multiple invalid clicks.
IP addresses change. Bots, click farms and other sources of invalid traffic can rotate through different IP addresses. Blocking one address does not necessarily stop the same behaviour from returning through another.
One IP does not always mean one user. Shared networks can put many legitimate users behind the same public IP address. Blocking too broadly risks excluding genuine prospects along with the traffic you intended to stop.
Manual lists require constant maintenance. As traffic patterns change, advertisers have to investigate new IPs, review existing exclusions and keep campaign and account-level lists up to date.
Campaign-level exclusions are capped at 500 IPs. For accounts experiencing invalid traffic across a large or changing pool of addresses, a static exclusion list can quickly become difficult to manage.
This is why IP exclusion works best for known, persistent sources of unwanted traffic rather than as a complete click fraud prevention strategy. Effective prevention requires looking beyond the IP address to the signals and behaviour behind each click, then responding as that traffic changes.
How Automated IP Exclusion Works
Automated click fraud protection goes beyond maintaining a longer list of blocked IP addresses. Instead of waiting for an advertiser to identify suspicious activity manually, TrafficGuard analyses each advertising engagement using multiple signals to determine whether the traffic is valid, invalid or non-incremental.
TrafficGuard processes billions of advertising engagements every day and more than 3 trillion data points each month. This allows protection to respond as traffic patterns change, rather than relying on a static list of IP addresses identified days or weeks earlier.
The difference is important. An IP address alone does not tell you whether the person behind a click is genuine. Addresses can change, multiple users can share them, and sophisticated invalid traffic can rotate between networks and devices.
By evaluating the behaviour and signals behind the click, TrafficGuard can identify invalid traffic as it happens and automatically update prevention without requiring marketers to continually investigate, add, remove and rotate IP addresses themselves.
For advertisers, that turns IP exclusion from a manual clean-up exercise into part of a broader real-time prevention strategy.
See How Much Invalid Traffic Is Reaching Your Google Ads
Before adding more exclusions or automating prevention, find out how much invalid traffic is actually reaching your campaigns.
TrafficGuard offers a 30-day free detection period that analyses your Google Ads traffic without making changes to your campaigns. You can see which clicks are being identified as invalid, where that traffic is coming from and how much of your ad spend is affected.
That gives you real campaign data to work from rather than an estimate. If invalid traffic is limited to a handful of persistent IPs, manual exclusions may be enough. If the same behaviour is appearing across changing IPs, users or traffic patterns, you have the evidence to decide whether automated protection makes sense.
Start your 30-day free traffic analysis and see what is happening in your own Google Ads campaigns.
Why Google Ads IP Exclusions Are Not Enough to Stop Click Fraud
Excluding IP addresses in Google Ads is a useful way to stop known sources of unwanted traffic. But IPs change, networks are shared and campaign-level exclusions are capped at 500, making static lists difficult to rely on as invalid traffic evolves.
The bigger challenge is not maintaining a longer blacklist. It is identifying the behaviour behind each click quickly enough to prevent invalid traffic from continuing to consume your budget.
TrafficGuard goes beyond IP blocking by analysing multiple signals to identify and prevent invalid traffic in real time. See how TrafficGuard protects Google Search campaigns from invalid and non-incremental clicks without relying on manual IP lists.
Frequently Asked Questions
How many IP addresses can you exclude in Google Ads?
Google Ads lets you exclude up to 500 IP addresses per campaign. You can add them individually or as blocks using an asterisk to wildcard the final octet, and you can apply them at account level (across all campaigns) or campaign level. Because the 500-IP cap is per campaign, advertisers running large or fraud-heavy accounts quickly hit the ceiling, which is why many move to automated exclusion management with a tool like TrafficGuard.
Why does Google Ads cap IP exclusions at 500 per campaign?
Google caps the list at 500 because it treats IP exclusions as a supplementary control, not the primary defence, since its own systems already filter many invalid clicks. The limit also protects Google's infrastructure across millions of advertisers. The practical effect is that you must be selective about which 500 addresses earn a slot, and rotate them as fraud patterns shift.
How do I exclude a range or block of IP addresses in Google Ads?
Replace the final part of the IP address with an asterisk to block a whole range in a single entry, for example 203.0.113.*. This is efficient when fraudulent clicks come from one network, but use it carefully, because a broad range can also block genuine customers who share that block. Evidence-based blocking, informed by traffic-quality data, avoids cutting off real buyers.
How do I whitelist my own IP address in Google Ads?
Google Ads has no dedicated whitelist, so the practical approach is to exclude your own office and VPN IP ranges at account level. This stops internal traffic, such as staff clicking your ads to check they are live, from generating paid clicks and distorting your conversion data. Do the same for trusted agency or partner IPs.
What is the difference between account-level and campaign-level IP exclusions?
Account-level exclusions apply to every campaign in your account, which suits known internal IPs or persistent offenders, while campaign-level exclusions apply to one campaign and carry their own 500-IP allowance. Splitting spend across campaigns therefore multiplies your total exclusion coverage, a common workaround for the 500-IP limit.
Can you exclude IP addresses in Performance Max campaigns?
Only at account level. Since 2024, account-level IP exclusions apply to every campaign type, including Performance Max, but campaign-level exclusions are still not available for it, so you cannot exclude an IP from a single PMax campaign. Because that account-level list is blunt and manual, automated, real-time fraud prevention such as TrafficGuard is more effective for defending Performance Max spend.
How often should I update my Google Ads IP exclusion list?
You should review it on a regular cadence rather than setting it once, because IP addresses are rarely tied to one user and fraud sources move constantly. A stale list both misses new threats and risks blocking real customers on recycled addresses. TrafficGuard removes this burden by rotating thousands of IP exclusions automatically based on live threat analysis.
Will excluding IP addresses accidentally block real customers?
Yes, it can. Because IP addresses are often dynamic and shared, an address linked to fraud today may belong to a genuine customer next month, especially when you exclude broad ranges. This is why exclusions should be evidence-based, time-limited and reviewed often, and why behavioural detection that distinguishes bots from real users is more reliable than a static blocklist.
Is manually excluding IP addresses enough to stop click fraud, or do I need a tool?
Manual IP exclusion gives basic protection but is rarely enough on its own, because of the 500-IP cap, the lag between manual reviews, and gaps like Performance Max. TrafficGuard analyses more than 3 trillion data points monthly from billions of ad engagements to block invalid traffic in real time, which matters when TrafficGuard data shows up to 44% of tier-1 sports betting operators' ad spend is lost to invalid traffic.
Get started - it's free
You can set up a TrafficGuard account in minutes, so we’ll be protecting your campaigns before you can say ‘sky-high ROI’.
Subscribe
Subscribe now to get all the latest news and insights on digital advertising, machine learning and ad fraud.




