How to Detect Bot Signups and Fake Registrations
A rise in registrations does not always mean a rise in real customers. To investigate bot signups and fake registrations, examine how accounts are created, which details they share, and what they do next.
What you are looking for
Not all suspicious registrations are the same. Automated signups are created by scripts or bots that submit forms programmatically, sometimes imitating human timing and behavior to avoid detection. Fake registrations use invented or borrowed identities—including real people's details used without their knowledge—that do not correspond to genuine applicants. Duplicate accounts may be created by real users who want to claim a benefit more than once, often using slight variations of their details, though multiple accounts can also have legitimate uses such as separating personal and business activity.
Each type creates different downstream problems. Automated signups can exhaust promotional budgets and inflate engagement metrics. Fake registrations can distort customer data and create compliance exposure. Duplicate accounts can drain loyalty programs and referral schemes. Identifying which pattern you are dealing with shapes which controls are proportionate.
Business problems to investigate first
Before examining signals, establish what problem you are trying to solve. Common indicators that warrant investigation include:
- A promotional offer is being claimed at a rate that does not match expected conversion
- Registered accounts show little or no subsequent activity
- Customer support is receiving complaints about accounts they did not create
- Referral or loyalty credits are accumulating in accounts that never make a purchase
- Registration volume spikes sharply around a campaign launch and then drops
These patterns suggest investigation is warranted. They do not, on their own, confirm fraud—they identify where to look.
Signals that contribute to account screening
Several categories of signal can help distinguish genuine registrations from suspicious ones. None of these signals is conclusive on its own; they are most useful in combination.
Email signals include whether an address is associated with a known disposable-email provider, how recently the domain was registered, and whether the address has been seen in prior fraud activity. Depending on the service, email validation may assess syntax, domain configuration, and mailbox-level deliverability. Syntax and mail records alone do not establish whether a mailbox is active or available. A working inbox is not evidence of legitimacy—temporary addresses can receive messages.
Phone signals include carrier type (mobile, landline, fixed VoIP, or non-fixed VoIP), whether the number has been recently ported, and whether it is associated with high-risk patterns. Phone validation can assess formatting, number validity and—in supported cases—current activity. Available checks vary by provider, country and number type. Non-fixed VoIP numbers are easier to obtain in bulk and are worth noting alongside other signals, but line type alone is not proof of fraud or identity.
IP and network signals include whether the registration came from a data center, a known proxy or VPN, or a residential address. Residential proxies are harder to detect because they route traffic through real consumer devices. A single IP address submitting many registrations in a short window is a straightforward indicator; distributed automation is harder to identify.
Device signals include browser fingerprint consistency, whether automation tools are detectable, and whether the same device identifier appears across multiple accounts. Device fingerprinting has limitations—users can clear or spoof identifiers—but it remains a useful layer.
Why matching signals should prompt investigation, not automatic rejection
Shared signals between accounts are a reason to investigate, not a reason to reject automatically. Consider a hypothetical scenario: five accounts register within an hour, all using similar email patterns, the same IP address, and the same device fingerprint, and each claims an introductory discount. This pattern warrants investigation. It could represent coordinated abuse—or it could represent a household, a shared office network, or a device used by multiple family members.
Automatic rejection based on shared signals will block some legitimate users. The appropriate response depends on the value of the benefit being claimed, the cost of a false positive, and the confidence level of the signals involved. Proportionate controls—such as requiring additional verification rather than outright rejection—are often more appropriate than binary decisions.
Investigating signup fraud?
IFD helps teams understand the patterns and evaluate the right signals and controls.
A suggested review process
A structured approach to investigating suspicious registrations typically involves four steps:
- 1Establish a normal baseline. Understand what typical registration patterns look like for your product: average time to complete, geographic distribution, device mix, and post-registration behavior. Anomalies are only visible against a baseline.
- 2Inspect suspicious account groups. Identify accounts that share signals—email domains, IP addresses, device identifiers, referral codes—and examine their subsequent behavior. Accounts that never log in again, never complete a purchase, or immediately claim a benefit and go dormant are worth closer review.
- 3Choose proportionate controls. Options range from adding a verification step (email confirmation, phone verification, CAPTCHA) to rate-limiting registrations from specific sources, to holding accounts for manual review. The right control depends on the risk level and the cost of friction to legitimate users.
- 4Measure results. After implementing controls, monitor whether the pattern changes and whether legitimate registrations are being affected. Sampled review of flagged accounts, appeals data, and verified outcomes help calibrate accuracy. Where possible, shadow mode or controlled evaluation—flagging accounts without acting on them—allows you to assess impact before enforcing.
Evaluation questions to ask providers
When evaluating detection tools or data providers, the following questions help assess fit:
- What signals does the product use, and how are they combined into a score or decision?
- Can the product explain why a specific account was flagged?
- What is the typical response latency, and can it be used in real time at registration?
- How does the product handle false positives, and what is the correction process?
- How is the product priced—per lookup, per flagged account, or by volume tier?
Investigation checklist
- Identify which signup flows are affected and when the pattern started
- Compare account patterns: email domains, IP addresses, device identifiers, referral codes
- Review related signals: phone type, email reputation, network type
- Examine subsequent behavior: logins, purchases, benefit claims, dormancy
- Measure the impact of any controls on legitimate user registrations
Common questions
Can I detect bot signups without adding friction for real users?
Some detection can happen entirely in the background—IP reputation checks, email validation, and device fingerprinting do not require user interaction. Visible friction, such as CAPTCHA, is typically reserved for flows where background signals are insufficient or where the risk of abuse is high enough to justify the trade-off.
How do I know if my controls are blocking legitimate users?
Monitor the rate at which registrations are rejected or held for review, and track whether those accounts would have gone on to make purchases or engage with the product. A rising rejection rate without a corresponding drop in fraud indicators suggests over-blocking. Some providers offer a shadow mode that flags accounts without acting on them, which allows you to calibrate before enforcing.
Is a shared IP address enough to conclude that accounts are linked?
No. Shared IP addresses are common in households, offices, universities, and mobile networks. A shared IP is a signal worth noting alongside others—it is not sufficient on its own to conclude that accounts are fraudulent or that they belong to the same person.
Identity Flow Data helps teams understand fraud techniques, evaluate relevant signals, and compare solutions suited to their business.
Ready to investigate your signup flows?
Tell us about your challenge and we'll help you understand your exposure and identify the right signals and controls.
No advisory fee for buyers.
RELATED ARTICLES