Stop fake signups before they
fill your database
Every fake registration looks like growth until nobody activates, buys or renews. Bot-created accounts consume trials, bonuses, messages, storage and team time while filling your reports with users who were never genuine customers
ADPAL filters automated account creation before the registration reaches your application — without forcing every legitimate user through another puzzle or manual review step
.SCALE OF THE PROBLEM
Any public signup flow can become
an abuse endpoint
You do not need to be a large platform or a famous brand. You only need a registration that unlocks something valuable: a free trial, discount, referral payment, API token, storage quota, marketplace profile, messaging feature or access to gated content. Automation tests those opportunities continuously and moves towards the cheapest flow to exploit
A recognised automated threat
OWASP classifies bulk account creation as OAT-019. Fake accounts may later be used for spam, promotion abuse, reputation manipulation or misuse of platform features
53% of web traffic was automated
A global traffic analysis found that bots generated more than half of web traffic in 2025. This is broad context, not a fake-signup prevalence figure
27% of bot attacks targeted APIs
Signup abuse does not stop at the visible form. Bots can target mobile, headless and direct API registration endpoints
One signal is not enough
Disposable email, one IP address or one browser trait can be changed easily. Reliable detection needs account, device, behaviour and velocity context
There is no universal fake-signup rate. Your own activation, referral, promotion and account-usage data is the most useful baseline
.SNIPPET DEFINITION
What is fake signup prevention?
The important word is prevention. Email verification, database cleanup and fraud review can reduce damage later. Fake signup prevention aims to stop the automated registration itself, before the account receives value or enters business systems
Fake signup is not the same as account takeover. Fake signup creates a new account. Account takeover abuses an existing customer account. It is also not the same as form spam, which fills contact or lead forms with junk messages instead of creating user profiles
Fake signup prevention stops bots and coordinated users from creating accounts that are not tied to genuine customers. These accounts are used to abuse free trials, promos, referrals, messaging, reviews or APIs. Effective protection checks the registration journey before the account is created, without adding unnecessary friction for legitimate users.
.What it looks like
How fake signup abuse plays out
in a small SaaS business
The example below is illustrative. It explains the pattern without presenting invented
numbers as an ADPAL customer case study
A small SaaS company launches a 14-day trial with a modest pool of API credits. Signups rise sharply. The growth
dashboard looks excellent, and the cost per registration falls.
Activation does not follow. Many accounts verify an email, generate an API key and consume the free allowance
within minutes. They do not complete onboarding, invite a colleague, connect a real data source or return after the
credits are gone.
The same referral codes appear across clusters of accounts. IP addresses rotate, but browser, timing and request-
sequence patterns repeat. Some users return with a new email as soon as the previous trial expires.
Marketing paid to acquire phantoms. Product infrastructure served non-customers. The CRM filled with accounts
sales should never contact. The monthly report showed growth, but revenue and retention stayed flat.
The visible problem is not always a dramatic overnight spike. Sophisticated abuse can arrive slowly enough to blend
into normal acquisition. The giveaway is the gap between registrations and credible downstream behaviour
. Symptoms
Registration rises, but activation, first purchase, retention or product usage does not move with it
Large groups of accounts verify email but never complete meaningful onboarding
Many accounts are created from the same device or browser pattern while IP addresses keep changing
Disposable email domains, newly created domains or machine-like address patterns accumulate in the user table
The same promo, referral code, payment instrument, delivery detail or recovery method connects supposedly unrelated accounts
Trial credits, API quotas or welcome bonuses are consumed immediately after registration
Accounts create spam, fake reviews, marketplace listings or messages soon after signup
Signups arrive at machine-steady intervals, around the clock, with unusually similar form-completion sequences
Support repeatedly handles «new customer» bonus disputes, duplicate accounts or trial-reset behaviour
Mobile or API registration traffic grows even when the visible signup page looks normal
Recognise two or more? It is worth checking
The pattern to remember:
More registrations without more genuine activity is not automatically growth. Compare account creation with activation, value consumption and conversion
.Business impact
What fake signups really cost you
The direct cost of a fake account may look small. The combined cost across acquisition,
product, email, support and reporting is not. The most dangerous part is that several
losses appear as ordinary growth expenses
False growth and broken funnel metrics
Cost per signup improves while cost per activated or paying customer worsens. Channel comparisons, forecasts and product decisions are built on users who were never viable
Trial, API and infrastructure waste
Bots consume free credits, storage, compute, outbound messages and third-party API calls. Usage-based suppliers charge you even when the «user» has no commercial value
Promo and referral leakage
One person or bot operator creates many identities to claim welcome offers, coupons, referral rewards or free-shipping benefits repeatedly
Email-list and deliverability pressure
Invalid, disposable or disengaged contacts increase list costs and bounce volume. Gmail tells senders to monitor reputation and reduce volume when bounces or deferrals rise
Sales, support and moderation time
Teams qualify non-existent leads, review duplicate accounts, answer bonus disputes, remove spam and investigate suspicious activity after the cost has already landed
A launchpad for further abuse
A registered profile can post content, message users, scrape gated data, reserve inventory, test business rules or build reputation before a later fraud attempt
Measure the cost using downstream outcomes, not registration count alone. Compare cost per signup with cost per activated user, cost per first purchase and cost per retained customer. Then add the value of consumed trials, bonuses, messages, storage and staff time
Margin pressure
Never-activated accounts / total registrations
Accounts per device or session identifier
Promo claims / first purchases
Trial or API cost / activated customer
Verification messages / successful activations
Registration growth / revenue and retention growth
.Why bots create fake accounts
A new account is a reusable business asset
Bots do not create accounts for the sake of adding rows to your database. They create
them because registration unlocks value or trust. OWASP specifically flags signup
credits, free trials, referral bonuses and other value-dispensing features as abuse
magnets that need controls beyond ordinary authentication
Free-trial and API abuse
Create a new identity whenever the free allowance ends. The operator stays on the free tier while your infrastructure carries the cost
Promo and referral farming
Repeat «new customer» offers, self-refer through account chains or cash out rewards intended for separate people
Spam from trusted profiles
A registered account may reach inboxes, comments, communities or marketplace users that anonymous traffic cannot access
Fake reviews and reputation manipulation
Account farms post, vote, rate, report or brigade at a scale that changes what genuine users see
Ban and limit evasion
When one profile is suspended or reaches a quota, the operator switches to another account from the same farm
Gated scraping and inventory abuse
Accounts can unlock member-only data, book scarce slots, reserve stock, enter raffles or access higher request limits
Resale and later fraud
Aged or verified accounts can be sold, transferred or kept dormant until they have enough history to appear trustworthy
Metric manipulation
Some campaigns intentionally inflate users, votes, referrals or engagement. The result is a business decision based on manufactured demand
Fake signups vs form spam
Both attacks use forms, but the business damage is different. Fake signups create accounts. They pollute your user database, consume trials and abuse account-only features. Form spam submits junk through contact, lead or enquiry forms, burying genuine messages and wasting sales time
If the problem is junk enquiries rather than fake user profiles, see form spam protection →
Not every fake account is fully automated
Some abuse is hybrid: automation creates or manages accounts while a human completes difficult steps. Other multi-accounting is entirely human. Bot filtering is strongest against automated creation and coordinated machine-driven journeys. High-value promotions may still need payment, identity, eligibility and post-signup rules. The page should not promise that one traffic control solves every form of identity fraud
.How ADPAL prevents it
How ADPAL blocks automated fake signups
ADPAL evaluates registration traffic before the application creates the account. Instead of trusting one field such as IP address or email domain, it looks at the wider journey: browser characteristics, request sequence, timing, navigation behaviour, network context and repeated relationships across signup attempts
That matters because modern signup abuse is distributed. Attackers rotate proxy addresses, use real browsers and generate plausible emails. A single signal can be wrong. A coordinated set of signals can show that many «new users» are one automated operation
Suspicious automation can be stopped before it reaches the registration endpoint or handled according to the configured policy. Genuine users continue through the normal signup journey. Email verification, OTP, payment checks and product eligibility remain useful layers; ADPAL is designed to reduce the abusive traffic that reaches them, not replace every identity control
01
Observe the journey before submit
02
Connect repeated browser, network and behaviour signals
03
Apply the configured action before a fake account receives value
04
Keep downstream email, CRM, trial and promo systems cleaner
.DIY vs. perimeter
What you can try yourself — and
where it stops
Measure
Helps?
The practical limit
Email verification
Partly
Proves control of an inbox, not that one real customer owns one account. Bots and disposable inboxes can automate the confirmation flow
Phone or OTP verification
Partly
Raises attacker cost, but creates messaging fees and user friction. SIM farms, virtual numbers and human-assisted abuse still exist
Block disposable email domains
Partly
Useful as a risk signal. Lists age quickly, new domains appear and legitimate privacy-conscious users can be caught
CAPTCHA or challenge
Partly
Stops some simple automation, but adds accessibility and conversion cost. Solver services, real-browser bots and human-in-the-loop workflows reduce its value
Rate limit by IP
Barely
Proxy pools distribute signups across many addresses. Aggressive limits can also block offices, mobile carriers and shared networks
Honeypot fields
Barely
Catches basic scripts. Modern automation renders the page, executes JavaScript and avoids obvious hidden fields
Email-domain or account-age rules
Partly
Helpful for scoring, but not proof. Attackers can use established providers and age accounts before abuse
Invite-only or manual approval
Yes, with cost
Strong for small closed communities, but slows growth and creates permanent operational work
Manual database cleanup
After the fact
Removes some junk later. Trial value, email sends, CRM syncs and reporting damage have already occurred
Perimeter filtering plus business rules
Best layered option
Stops automated registration early, while eligibility, payment and account rules cover value abuse that may continue after signup
Built for growth teams
Built for growth teams, not security
departments
ADPAL Bot Protection places one control layer in front of the signup journey. The
business objective is simple: stop automated account creation before it becomes a
CRM, email, trial or support problem
Low-friction signup protection
No routine CAPTCHA for normal customers; adaptive challenges only for uncertain requests
Protect the visible form and the registration endpoints used by mobile apps, single-page applications and direct API clients
Apply tighter policy to free trials, referrals, promos, marketplace registration or other signup paths that unlock immediate value
Use dashboard and event data to see why registration traffic was allowed, logged, challenged or blocked, subject to confirmed product capabilities
Cookieless and EU-residency claims should be published only after Security and Legal confirm the exact data flow and retention model
Keep email verification, OTP, CRM deduplication and eligibility rules. Perimeter filtering reduces the volume they must process
Point your DNS at the managed reverse proxy — live in hours, then a short monitoring period before enforcing. CMS-integrated deployment is available through hosting partners
One product across bot use cases
The same product layer can address other automated abuse covered by ADPAL, without buying a separate point tool for every signup-related symptom
.Proof
What credible proof should
show
.Learn more
Learn more about fake accounts
and signup abuse
Guide
How bad bots ruin business logic
Guide
Bad bot vs real user: how to tell the difference
.FAQ
Questions about fake signup prevention
What is fake signup prevention?
Fake signup prevention is the process of stopping automated or coordinated account registrations that do not represent genuine customers. The objective is to identify abusive registration journeys before the account is created and before it receives a trial, promo, referral reward, messaging access or API quota
Why do bots create fake accounts?
Because an account unlocks value. Bots use accounts to repeat free trials, farm bonuses, self-refer, post spam or reviews, bypass bans, scrape gated content, reserve inventory or prepare for later fraud. Wherever one account receives something valuable, attackers test whether many accounts can receive it too
Are fake signups the same as form spam?
No. Fake signups create user accounts and damage your database, trials, promos and product metrics. Form spam sends junk through contact or lead forms and hides genuine enquiries. The attacks may use similar automation, but the business impact and page intent are different
Will email verification stop fake registrations?
It helps, but it proves only that the registrant can access an inbox. Disposable inboxes, aliases and automated email workflows can confirm accounts at scale. Keep verification for account quality and recovery, but do not treat it as proof of one genuine customer
Should I block every disposable email address?
No single email characteristic should be an automatic verdict for every business. Disposable addresses are a useful risk signal, especially around promotions, but some legitimate users choose them for privacy. Combine email risk with device, behaviour, velocity and downstream account relationships
Does CAPTCHA stop fake signups?
CAPTCHA can reduce simple automation and may be useful as a selective challenge. It is not a complete fake-account strategy. Real-browser automation, solver services and human-assisted workflows can pass challenges, while every genuine user sees extra friction and accessibility cost
Is phone verification stronger than email verification?
Usually, because acquiring phone numbers has a cost. It is still not a guarantee of one person per account. Virtual numbers, SIM farms and recycled numbers exist, and OTP messages create direct cost. Use phone checks where the value at risk justifies the friction
How do I know whether registrations are fake?
Compare registration with downstream behaviour. Look for accounts that never activate, many accounts linked by device or referral signals, immediate trial consumption, rotating IPs with repeated browser patterns, promo claims without purchases and mobile/API signups that bypass the normal journey
Will genuine customers be blocked?
Any automated decision system can make mistakes, so avoid absolute zero-false-positive claims. Use multiple signals, sensible thresholds, logging, review paths and gradual rollout. The goal is to reduce broad friction while preserving a recovery route for unusual but legitimate users
Does protection work with my signup form and CRM?
Perimeter protection is intended to sit before the registration endpoint, which can reduce the need to rebuild the form itself. Exact compatibility depends on your web, API, mobile, identity-provider and CRM architecture. Confirm the supported integration path before publishing a universal claim
Can ADPAL remove fake accounts already in my database?
Traffic protection is primarily preventive. Existing accounts still need a cleanup plan based on activation, device relationships, usage, payment, referral and risk data. Export and review in stages rather than deleting every inactive user, because legitimate dormant accounts may exist
Can bot protection stop human multi-accounting too?
Not completely. Some multi-account abuse is manual or hybrid. Bot protection can identify automated creation and coordinated machine-driven activity, but high-value trials and promotions may also need identity, payment, eligibility, velocity and post-signup controls. Treat it as layered business-logic protection
Every signup should be a real
customer
Growth you cannot activate, retain or monetise is not growth. It is
infrastructure, marketing and operational cost wearing a user ID. Find out
how much automated account creation is reaching your signup journey
No credit card
GDPR-ready