Home / Use case/

Fake Signup Prevention

Stop fake signups before they
fill your database

Every fake registration looks like growth until nobody activates, buys or renews. Bot-created accounts consume trials, bonuses, messages, storage and team time while filling your reports with users who were never genuine customers

ADPAL filters automated account creation before the registration reaches your application — without forcing every legitimate user through another puzzle or manual review step

.SCALE OF THE PROBLEM

Any public signup flow can become
an abuse endpoint

You do not need to be a large platform or a famous brand. You only need a registration that unlocks something valuable: a free trial, discount, referral payment, API token, storage quota, marketplace profile, messaging feature or access to gated content. Automation tests those opportunities continuously and moves towards the cheapest flow to exploit

A recognised automated threat

OWASP classifies bulk account creation as OAT-019. Fake accounts may later be used for spam, promotion abuse, reputation manipulation or misuse of platform features

53% of web traffic was automated

A global traffic analysis found that bots generated more than half of web traffic in 2025. This is broad context, not a fake-signup prevalence figure

27% of bot attacks targeted APIs

Signup abuse does not stop at the visible form. Bots can target mobile, headless and direct API registration endpoints

One signal is not enough

Disposable email, one IP address or one browser trait can be changed easily. Reliable detection needs account, device, behaviour and velocity context

There is no universal fake-signup rate. Your own activation, referral, promotion and account-usage data is the most useful baseline

.SNIPPET DEFINITION

What is fake signup prevention?

The important word is prevention. Email verification, database cleanup and fraud review can reduce damage later. Fake signup prevention aims to stop the automated registration itself, before the account receives value or enters business systems

Fake signup is not the same as account takeover. Fake signup creates a new account. Account takeover abuses an existing customer account. It is also not the same as form spam, which fills contact or lead forms with junk messages instead of creating user profiles

Fake signup prevention stops bots and coordinated users from creating accounts that are not tied to genuine customers. These accounts are used to abuse free trials, promos, referrals, messaging, reviews or APIs. Effective protection checks the registration journey before the account is created, without adding unnecessary friction for legitimate users.

.What it looks like

How fake signup abuse plays out
in a small SaaS business

The example below is illustrative. It explains the pattern without presenting invented
numbers as an ADPAL customer case study

A small SaaS company launches a 14-day trial with a modest pool of API credits. Signups rise sharply. The growth
dashboard looks excellent, and the cost per registration falls.

Activation does not follow. Many accounts verify an email, generate an API key and consume the free allowance
within minutes. They do not complete onboarding, invite a colleague, connect a real data source or return after the
credits are gone.

The same referral codes appear across clusters of accounts. IP addresses rotate, but browser, timing and request-
sequence patterns repeat. Some users return with a new email as soon as the previous trial expires.

Marketing paid to acquire phantoms. Product infrastructure served non-customers. The CRM filled with accounts
sales should never contact. The monthly report showed growth, but revenue and retention stayed flat.

The visible problem is not always a dramatic overnight spike. Sophisticated abuse can arrive slowly enough to blend
into normal acquisition. The giveaway is the gap between registrations and credible downstream behaviour

. Symptoms

Signs of a fake signup problem

You can spot many fake-account patterns without a security operations centre. Start with the business signals, then confirm them in registration and application logs

Registration rises, but activation, first purchase, retention or product usage does not move with it

Large groups of accounts verify email but never complete meaningful onboarding

Many accounts are created from the same device or browser pattern while IP addresses keep changing

Disposable email domains, newly created domains or machine-like address patterns accumulate in the user table

The same promo, referral code, payment instrument, delivery detail or recovery method connects supposedly unrelated accounts

Trial credits, API quotas or welcome bonuses are consumed immediately after registration

Accounts create spam, fake reviews, marketplace listings or messages soon after signup

Signups arrive at machine-steady intervals, around the clock, with unusually similar form-completion sequences

Support repeatedly handles «new customer» bonus disputes, duplicate accounts or trial-reset behaviour

Mobile or API registration traffic grows even when the visible signup page looks normal

Recognise two or more? It is worth checking

The pattern to remember:

More registrations without more genuine activity is not automatically growth. Compare account creation with activation, value consumption and conversion

.Business impact

What fake signups really cost you

The direct cost of a fake account may look small. The combined cost across acquisition,
product, email, support and reporting is not. The most dangerous part is that several
losses appear as ordinary growth expenses

False growth and broken funnel metrics

Cost per signup improves while cost per activated or paying customer worsens. Channel comparisons, forecasts and product decisions are built on users who were never viable

Trial, API and infrastructure waste

Bots consume free credits, storage, compute, outbound messages and third-party API calls. Usage-based suppliers charge you even when the «user» has no commercial value

Promo and referral leakage

One person or bot operator creates many identities to claim welcome offers, coupons, referral rewards or free-shipping benefits repeatedly

Email-list and deliverability pressure

Invalid, disposable or disengaged contacts increase list costs and bounce volume. Gmail tells senders to monitor reputation and reduce volume when bounces or deferrals rise

Sales, support and moderation time

Teams qualify non-existent leads, review duplicate accounts, answer bonus disputes, remove spam and investigate suspicious activity after the cost has already landed

A launchpad for further abuse

A registered profile can post content, message users, scrape gated data, reserve inventory, test business rules or build reputation before a later fraud attempt

Measure the cost using downstream outcomes, not registration count alone. Compare cost per signup with cost per activated user, cost per first purchase and cost per retained customer. Then add the value of consumed trials, bonuses, messages, storage and staff time

Margin pressure

Never-activated accounts / total registrations

Accounts per device or session identifier

Promo claims / first purchases

Trial or API cost / activated customer

Verification messages / successful activations

Registration growth / revenue and retention growth

.Why bots create fake accounts

A new account is a reusable business asset

Bots do not create accounts for the sake of adding rows to your database. They create
them because registration unlocks value or trust. OWASP specifically flags signup
credits, free trials, referral bonuses and other value-dispensing features as abuse
magnets that need controls beyond ordinary authentication

Free-trial and API abuse

Create a new identity whenever the free allowance ends. The operator stays on the free tier while your infrastructure carries the cost

Promo and referral farming

Repeat «new customer» offers, self-refer through account chains or cash out rewards intended for separate people

Spam from trusted profiles

A registered account may reach inboxes, comments, communities or marketplace users that anonymous traffic cannot access

Fake reviews and reputation manipulation

Account farms post, vote, rate, report or brigade at a scale that changes what genuine users see

Ban and limit evasion

When one profile is suspended or reaches a quota, the operator switches to another account from the same farm

Gated scraping and inventory abuse

Accounts can unlock member-only data, book scarce slots, reserve stock, enter raffles or access higher request limits

Resale and later fraud

Aged or verified accounts can be sold, transferred or kept dormant until they have enough history to appear trustworthy

Metric manipulation

Some campaigns intentionally inflate users, votes, referrals or engagement. The result is a business decision based on manufactured demand

Fake signups vs form spam

Both attacks use forms, but the business damage is different. Fake signups create accounts. They pollute your user database, consume trials and abuse account-only features. Form spam submits junk through contact, lead or enquiry forms, burying genuine messages and wasting sales time

If the problem is junk enquiries rather than fake user profiles, see form spam protection →

Not every fake account is fully automated

Some abuse is hybrid: automation creates or manages accounts while a human completes difficult steps. Other multi-accounting is entirely human. Bot filtering is strongest against automated creation and coordinated machine-driven journeys. High-value promotions may still need payment, identity, eligibility and post-signup rules. The page should not promise that one traffic control solves every form of identity fraud

.How ADPAL prevents it

How ADPAL blocks automated fake signups

ADPAL evaluates registration traffic before the application creates the account. Instead of trusting one field such as IP address or email domain, it looks at the wider journey: browser characteristics, request sequence, timing, navigation behaviour, network context and repeated relationships across signup attempts

That matters because modern signup abuse is distributed. Attackers rotate proxy addresses, use real browsers and generate plausible emails. A single signal can be wrong. A coordinated set of signals can show that many «new users» are one automated operation

Suspicious automation can be stopped before it reaches the registration endpoint or handled according to the configured policy. Genuine users continue through the normal signup journey. Email verification, OTP, payment checks and product eligibility remain useful layers; ADPAL is designed to reduce the abusive traffic that reaches them, not replace every identity control

01

Observe the journey before submit

02

Connect repeated browser, network and behaviour signals

03

Apply the configured action before a fake account receives value

04

Keep downstream email, CRM, trial and promo systems cleaner

.DIY vs. perimeter

What you can try yourself — and
where it stops

Measure

Helps?

The practical limit

Email verification

Partly

Proves control of an inbox, not that one real customer owns one account. Bots and disposable inboxes can automate the confirmation flow

Phone or OTP verification

Partly

Raises attacker cost, but creates messaging fees and user friction. SIM farms, virtual numbers and human-assisted abuse still exist

Block disposable email domains

Partly

Useful as a risk signal. Lists age quickly, new domains appear and legitimate privacy-conscious users can be caught

CAPTCHA or challenge

Partly

Stops some simple automation, but adds accessibility and conversion cost. Solver services, real-browser bots and human-in-the-loop workflows reduce its value

Rate limit by IP

Barely

Proxy pools distribute signups across many addresses. Aggressive limits can also block offices, mobile carriers and shared networks

Honeypot fields

Barely

Catches basic scripts. Modern automation renders the page, executes JavaScript and avoids obvious hidden fields

Email-domain or account-age rules

Partly

Helpful for scoring, but not proof. Attackers can use established providers and age accounts before abuse

Invite-only or manual approval

Yes, with cost

Strong for small closed communities, but slows growth and creates permanent operational work

Manual database cleanup

After the fact

Removes some junk later. Trial value, email sends, CRM syncs and reporting damage have already occurred

Perimeter filtering plus business rules

Best layered option

Stops automated registration early, while eligibility, payment and account rules cover value abuse that may continue after signup

Built for growth teams

Built for growth teams, not security
departments

ADPAL Bot Protection places one control layer in front of the signup journey. The
business objective is simple: stop automated account creation before it becomes a
CRM, email, trial or support problem

Explore ADPAL Bot Protection 

Low-friction signup protection

No routine CAPTCHA for normal customers; adaptive challenges only for uncertain requests

Web and API coverage

Protect the visible form and the registration endpoints used by mobile apps, single-page applications and direct API clients

Rules for high-risk flows

Apply tighter policy to free trials, referrals, promos, marketplace registration or other signup paths that unlock immediate value

Clearer traffic evidence

Use dashboard and event data to see why registration traffic was allowed, logged, challenged or blocked, subject to confirmed product capabilities

Privacy-conscious operation

Cookieless and EU-residency claims should be published only after Security and Legal confirm the exact data flow and retention model

Works with existing controls

Keep email verification, OTP, CRM deduplication and eligibility rules. Perimeter filtering reduces the volume they must process

Practical deployment choices

Point your DNS at the managed reverse proxy — live in hours, then a short monitoring period before enforcing. CMS-integrated deployment is available through hosting partners

One product across bot use cases

The same product layer can address other automated abuse covered by ADPAL, without buying a separate point tool for every signup-related symptom

Compare the experience with a CAPTCHA-first approach

What credible proof should
show

.Learn more

Learn more about fake accounts
and signup abuse

See Content Theft protection

Guide

How bad bots ruin business logic

Guide

Bad bot vs real user: how to tell the difference

.FAQ

Questions about fake signup prevention

What is fake signup prevention?

Fake signup prevention is the process of stopping automated or coordinated account registrations that do not represent genuine customers. The objective is to identify abusive registration journeys before the account is created and before it receives a trial, promo, referral reward, messaging access or API quota

Why do bots create fake accounts?

Because an account unlocks value. Bots use accounts to repeat free trials, farm bonuses, self-refer, post spam or reviews, bypass bans, scrape gated content, reserve inventory or prepare for later fraud. Wherever one account receives something valuable, attackers test whether many accounts can receive it too

Are fake signups the same as form spam?

No. Fake signups create user accounts and damage your database, trials, promos and product metrics. Form spam sends junk through contact or lead forms and hides genuine enquiries. The attacks may use similar automation, but the business impact and page intent are different

Will email verification stop fake registrations?

It helps, but it proves only that the registrant can access an inbox. Disposable inboxes, aliases and automated email workflows can confirm accounts at scale. Keep verification for account quality and recovery, but do not treat it as proof of one genuine customer

Should I block every disposable email address?

No single email characteristic should be an automatic verdict for every business. Disposable addresses are a useful risk signal, especially around promotions, but some legitimate users choose them for privacy. Combine email risk with device, behaviour, velocity and downstream account relationships

Does CAPTCHA stop fake signups?

CAPTCHA can reduce simple automation and may be useful as a selective challenge. It is not a complete fake-account strategy. Real-browser automation, solver services and human-assisted workflows can pass challenges, while every genuine user sees extra friction and accessibility cost

Is phone verification stronger than email verification?

Usually, because acquiring phone numbers has a cost. It is still not a guarantee of one person per account. Virtual numbers, SIM farms and recycled numbers exist, and OTP messages create direct cost. Use phone checks where the value at risk justifies the friction

How do I know whether registrations are fake?

Compare registration with downstream behaviour. Look for accounts that never activate, many accounts linked by device or referral signals, immediate trial consumption, rotating IPs with repeated browser patterns, promo claims without purchases and mobile/API signups that bypass the normal journey

Will genuine customers be blocked?

Any automated decision system can make mistakes, so avoid absolute zero-false-positive claims. Use multiple signals, sensible thresholds, logging, review paths and gradual rollout. The goal is to reduce broad friction while preserving a recovery route for unusual but legitimate users

Does protection work with my signup form and CRM?

Perimeter protection is intended to sit before the registration endpoint, which can reduce the need to rebuild the form itself. Exact compatibility depends on your web, API, mobile, identity-provider and CRM architecture. Confirm the supported integration path before publishing a universal claim

Can ADPAL remove fake accounts already in my database?

Traffic protection is primarily preventive. Existing accounts still need a cleanup plan based on activation, device relationships, usage, payment, referral and risk data. Export and review in stages rather than deleting every inactive user, because legitimate dormant accounts may exist

Can bot protection stop human multi-accounting too?

Not completely. Some multi-account abuse is manual or hybrid. Bot protection can identify automated creation and coordinated machine-driven activity, but high-value trials and promotions may also need identity, payment, eligibility, velocity and post-signup controls. Treat it as layered business-logic protection

Every signup should be a real
customer

Growth you cannot activate, retain or monetise is not growth. It is
infrastructure, marketing and operational cost wearing a user ID. Find out
how much automated account creation is reaching your signup journey

No credit card

GDPR-ready