The dregs of internet society are a resourceful lot. Scammers, spammers, freeloaders, bad bots, and assorted other pests employ a whole arsenal of dirty tricks to exploit your free trials, wreck your metrics, harm your legitimate users, ratchet up your costs, and generally cause trouble on your site.
Here are the tricks you're most likely to find behind the fake signups and duplicate accounts in your user table, plus the defenses that hold up. Each entry explains the term, why it matters when you run an online product or community, and how to detect and stop it.
An attacker gains control of a legitimate user's account. How Dregs spots the change in device, location, credentials, and behavior.
A browser that gives every profile a different, convincing device fingerprint, and the clues it still leaves behind.
The user you removed, back under a new account. Why email and IP bans don't hold, and how to recognize the same person on the next signup.
Reading patterns across an account's activity rather than judging one event in isolation. How Dregs finds suspicious changes and repeated behavior.
Separating useful automation from bots that create accounts, scrape content, test credentials, or abuse your product.
A pool of automated accounts run as one resource. How it differs from a botnet, and what gives the coordination away.
Identifying automation without forcing every legitimate user to solve a puzzle. Why CAPTCHAs fail accessibility, and what to use instead of a challenge wall.
A service that answers CAPTCHAs by the thousand for a few dollars, and why that makes CAPTCHA a toll rather than a barrier.
Attackers test stolen username and password pairs against your login page at scale. How Dregs catches the campaign and the accounts it compromises.
Recognizing a browser and device from the characteristics they reveal. How Dregs uses fingerprints alongside network, identity, and behavior.
A temporary inbox that lasts just long enough to receive a confirmation link, and what it means for your signup form.
One person operating several accounts to multiply a benefit or evade a restriction. How Dregs connects accounts that are trying to look unrelated.
Fabricated profiles and junk registrations that pollute your user table and distort growth metrics. How Dregs scores each signup.
Finding suspicious accounts and activity before abuse becomes expensive. How Dregs combines identity, device, network, and behavioral evidence.
Scoring the account rather than one visit or IP. How Dregs keeps Humanity, Authenticity, Uniqueness, and Behavior as separate fraud scores.
The same person repeatedly claiming a trial under fresh accounts. How Dregs links the new signup to the trials that came before it.
A browser controlled through code rather than by a person clicking through a visible interface. How Dregs detects the automation it leaves behind.
A map of accounts and the evidence connecting them. How Dregs exposes duplicate accounts, fraud rings, and other coordinated activity.
Connecting fragments that belong to one operator, even when the accounts are trying to look unrelated. How Dregs finds the evidence between them.
One account, two places, and not enough time to get between them. What the signal catches and why VPNs make it noisy.
Operating several accounts at once to stack rewards, trials, votes, or other benefits. How Dregs detects the shared operator behind them.
A new account that isn't a genuine customer. Banks mean a stolen or synthetic identity, while on a SaaS product it usually means fake signups.
A rack of real handsets operated together, so one party's activity looks like the activity of a great many people.
One inbox, unlimited addresses. Why blocking the feature backfires, and how to handle the duplicates instead.
Fraudsters refer their own fake accounts to collect rewards from both sides. How Dregs connects the referrer to the fictional friends being referred.
Launch credits and signup coupons collected more than once. How Dregs links the reused device to the redemptions that never become a paid plan.
Fake signups, trial freeloaders, bots, and junk in the user table, and how that differs from a stolen login or leaked passwords hammering the login page.
Verification texts requested and never completed. How scores on the account differ from an SMS firewall, and how to stop the next send.
A second or third identity posing as a different person, so one voice can sound like a consensus or give itself false credibility.
Never letting a free trial end. How the same freeloader keeps signing up again, and how SaaS teams can stop it.
Using behavior to find activity that doesn't fit an account's history or its peers. How Dregs applies the approach to your external users.
Measuring the risk attached to each user rather than one transaction or IP address. How Dregs produces four scores with the evidence behind them.
Counting how often something happens, and why a threshold on its own isn't enough to keep repeat abuse in check.
Dregs helps you catch fake signups, trial abuse, ban evasion, and bots. Each account gets Humanity, Authenticity, Uniqueness, and Behavior scores that open into their observations, so you can see exactly why.
Start Free Trial