By Jimi Barkway · Published 1 September 2026 · Part of the honest manual
The short version
Affiliate fraud is real, rarer than the horror stories, and mostly visible in data you already have. Configure the boring defences on day one, know the signature of each abuse, and prepare the three awkward messages in advance, because the hard part of enforcement isn't detection. It's saying no to a human without burning the relationship.

Every founder's first question about affiliate fraud is "how bad is it?" The honest answer from the category's own data: in the largest published study (31.4 million referrals across 3,425 programs, July 2026; figures re-checked 1 September 2026), about 4% of referrals get flagged for review, and classic self-referral trips only around 0.15%. Fraud is a real cost, not an existential one. The bigger cost is usually something that isn't fraud at all, and we'll get to it.
Know each one by its signature
Self-referral. Someone buys your product through their own link, converting your program into a private discount. Signature: matching emails, addresses or payment details between partner and "customer". The one abuse software should catch entirely on its own; we block it by default on every plan.
Brand bidding. The partner runs search ads on your brand name and taxes traffic that was already yours. Signature: a sudden jump in referrals with search as the source, timed to nothing the partner published. Worth knowing: in that same study, 96% of all flagged referrals were paid-ad traffic, so when a program's numbers go strange without explanation, brand bidding is usually where the trail ends up.
Coupon-code leak. A partner's discount code escapes onto coupon sites, and every checkout that hunts for a code hands them credit. Signature: one code's usage suddenly dwarfing its partner's actual audience, minutes between click and purchase.
Cookie stuffing. Dropping your tracking cookie on people who never meaningfully clicked, then harvesting credit if any of them ever buy. Signature: clicks way up, conversion rate collapsing toward zero.
Incentivised traffic. The partner rewards people for signing up. Signature: a burst of conversions that churns to nothing inside a month or two, because none of them wanted the product.
And the boring one that costs the most: low-quality volume. Not fraud, no rule broken, an entirely sincere partner whose referred customers cancel in month one, every time. No terms clause catches it. Only module 6's habit of watching churn per affiliate does, and at most small programs this quietly outcosts all the actual fraud combined.
The boring defences, configured on day one
Most protection is settings, not vigilance: a hold period at least as long as your refund window (module 3), self-referral blocking on, your blocked traffic sources and brand keywords listed, and the terms from module 2 naming what's banned, in writing, before anyone joined. Those blocking safeguards ship on every plan of ours. On top of that sits monitoring, flags raised against referrals and payouts with the evidence attached (on our Scale plan), which matters for one specific reason: you want to act on evidence, not vibes, because every action below starts with being sure.
The part nobody publishes: the actual words
Detection is the easy half. The hard half is that enforcement means messaging a real person, often one with an audience, and telling them no. Founders postpone that conversation for weeks, and the delay costs more than the fraud. So here are the three messages, ready in advance.
Rejecting an application
Hi [name], thanks for applying. I'm going to say no for now: we're keeping the program small and focused on partners whose audience closely matches our buyers, and from what I can see that's not quite you yet. That can change, and if it does you'd be welcome to apply again. Good luck with [their actual thing].
Short, honest about the reason, and it leaves the door visibly open. What it never does is invent a fake capacity excuse; people compare notes.
First offence, assuming good faith
Hi [name], flagging something before it becomes a problem: we're seeing referrals from paid search ads on our brand name, which our terms don't allow (clause 1, agreed when you joined). I'm assuming this wasn't deliberate, and possibly it's an agency or a tool on your side. Commissions from those clicks will be reversed, and if the ads stop this week we're completely fine. Any questions, reply here.
The generous read is doing real work. Half the time it genuinely was an agency, and the partner keeps their dignity while the behaviour stops either way. Firm on the facts, warm to the person.
Ending it
Hi [name], we spoke on [date] about brand-bid traffic and it's continued, so I'm closing your account under our terms, effective today. Commissions on legitimate referrals to date will be paid out on the normal schedule; the flagged ones are voided. This isn't a conversation I enjoyed arriving at, and it's final.
Two things in that last message do the heavy lifting. Paying the legitimate balance signals the process was fair, which is what everyone watching will ask about. And "final" saves you the three follow-up emails asking for another chance.
When to eat the loss
Not every flag deserves the full process. A $9 commission with ambiguous evidence isn't worth an accusation that might be wrong; void it quietly or let it stand, and watch for a repeat. Save the confrontation for clear evidence and meaningful money. You're running a program, not a courtroom, and being known as fair is worth more than any single clawback.
One module left, and it's the strange one: module 8, when to stop paying attention to all of this.