Reject, send back, or pass to the stitcher
Each row is something the document can show. The fraud rate is not in the table because the document does not contain it.
| What you see | Decision | Why | What you tell the buyer |
|---|---|---|---|
| No usable Impression, or a MediaFile the version cannot describe | Reject | The player will not record or select the ad | The export does not match the VAST version it declares |
| Media or trackers on http while the app is https | Reject | The runtime blocks mixed content and the beacons never land | Move every asset and tracker to https |
| VPAID on a CTV or SSAI line | Send back | The interactive runtime is not the television | Send a media file the player can decode, and SIMID only if you both support it |
| SSAI line and no mezzanine the stitcher can transcode | Send back | The stitch has nothing to work with | Add the mezzanine profile your spec asks for |
| Buyer required a verification vendor and the inline lacks it | Send back | Their report will not include this inventory | The node has to survive your wrappers too |
| A clean document on a direct IO | Pass the structure | You still have not measured invalid traffic | Direct is a path. It is not a fraud rate of zero |

Publisher ad ops on a direct or programmatic-guaranteed deal are the last people who can refuse a tag before a player or a stitcher has to eat it. The advertiser, or their agency, sends a URL or a file and a start date. Your player will request whatever you put in the ad server. If the file is wrong, the symptom later is a dark pod, a discrepancy, or a buyer who says verification did not fire. The symptom is a bad place to discover a missing Impression.
You are not the buyer's fraud vendor. DoubleVerify's May 2026 release described two direct CTV campaigns, one at 34 percent of impressions to bots and one at 25 percent. Those are examples from their log, not a property you can read off the advertiser's XML. Pixalate's 19 percent is an open-auction CTV share, and a direct buy is outside that sentence, which is also not a rate of zero. Rejecting a tag because of a headline rate rejects a population you did not measure. Accepting a tag because the IO says direct accepts a path, not a document.
The reject list that is actually in the file
Run the file or the URL before it is booked on the pod. A document that declares VAST and then omits an Impression the version requires will not produce the beacon your reconciliation expects. A MediaFile the declared version cannot carry, or a delivery type the player will not select, fails at creative choice rather than at the business deal. Insecure URLs on a secure app fail quietly: the player drops the request, the impression pixel never lands, and the buyer sees a short delivery against a signed goal.
VPAID is the interactive case that still arrives on CTV lines because the creative tool defaulted to it. The IAB deprecated it. A television and a stitcher are the wrong runtime. Send it back for a media file, and treat SIMID as a separate conversation you have already agreed, not as a synonym for VPAID. If your path is server-side insertion, also look for a mezzanine. A single web-weight progressive file can look valid and still give the stitcher nothing to transcode.
The buyer's verification node is their requirement, not yours, until you have agreed to carry it. If the IO says the campaign is measured by a named firm, look for that firm on the inline after your own wrappers. Publishers add hops. A node that exists in the advertiser's original file and disappears inside your ad server is your defect, and their report will describe it as unmeasured inventory. vastlint will show whether the node is in the document you test. It will not call the firm.
Get VAST spec updates, platform guides, and release notes in your inbox.
What you pass through, and what you automate
A clean structural pass means the player has a chance. It does not mean the encode will play on every device in your app, and it does not mean the campaign is free of invalid traffic. Say both of those in the acceptance note so the buyer's verification team does not treat your OK as a fraud sign-off. Point them at their own node, which you either carried or you did not.
One tag a week can live on the website: validate, test, inspect. A direct sales team that onboards tags every day will not keep the habit. That volume is a fixture in a repo, checked in CI, or a check inside the ad server before the response is committed. The website remains the place a person debugs the one tag CI rejected. The gate should not be a person remembering a tab.
If the tag is a wrapper into the advertiser's host, inspect it. Your player will. A wrapper that never resolves is a dark pod you could have seen without a regression on the device lab.
Acceptance note, in one pass
- Document or URL tested, and whether your own wrapper was included.
- Structural result: impressions, media, https, version consistency.
- CTV or SSAI extras you require: no VPAID, mezzanine present if the stitcher needs it.
- Verification vendor the IO names, present or absent on the inline.
- Explicitly out of scope: invalid-traffic rate, viewability, whether every device in the app will select the file.
Check the advertiser tag before it is booked
Paste the XML or the live URL. Nothing is stored. This does not classify invalid traffic.
Sources
Why a direct path is not a fraud rate of zero, and why the 34 percent figures are single campaigns.
Device failures that remain after the document is structurally clean.
When publisher volume should leave the website and enter CI or the ad server.
The agency-side pass on the same three artifacts.