What is signup abuse?
Signup abuse is the creation or operation of accounts in order to take a product benefit a genuine customer would pay for or earn. Fake signups, free trials claimed under fresh emails, bots filling the registration form, referral bounties paid to fictional friends, and duplicate accounts all belong here. The same cluster is often called account creation fraud or new account fraud. The damage starts at registration, before the account is a real customer. Account takeover is a different problem: someone stole a real customer's login. Credential stuffing is leaked passwords hammering the login page at scale.
What Dregs is built for
Dregs is built for the mess that shows up at signup: fake users in the registration form, freeloaders burning through free trials on a fresh email each time, bots filling the form, junk filling the user table, referral programs paying the same person twice, and one person running several duplicate accounts. Most of that damage is pre-account: it starts at registration, before anyone is a paying customer. Fake signup detection and fake account detection are the same job: score the identity at the moment of submission. Custom rules and lists then decide what happens, with less manual review than combing the user table by hand. Scores land moments after new activity, and every score opens into its observations so you can see exactly why an account was flagged. That's also how false positives get caught before a legitimate signup is punished.
Account takeover and credential stuffing are different problems. Someone stole a real customer's login, or leaked passwords are hammering the login page. Dregs still catches both from the events you already send. They are not the reason most teams pick Dregs. If the pain on your SaaS is junk in the user table, trials that never convert, or a referral program paying the same person twice, start with fake signups, trial abuse, bots, referrals, and duplicates rather than with stolen login detection.
How this differs from related problems
Three jobs get mixed together under "fraud detection," and only one of them is why most teams pick Dregs.
Where to start
If junk is landing in the user table, start here. Keep the account takeover and credential stuffing pages for when a real customer's login is the incident.
Free Trial Abuse
The same person claiming the trial under a fresh email, linked back to the trials that came before.
Fake Signups
Junk registrations with thin profiles and disposable inboxes, scored at submission.
Bot Detection
Signup bots creating accounts at scale from rotating IPs and inboxes.
Referral Fraud
Self-referral and fictional friends collected for a bounty on both sides.
Duplicate Accounts
One operator behind several accounts, connected through shared devices and behavior.
Frequently Asked Questions
Q: What is the difference between signup abuse and account takeover?
A: Signup abuse happens at and around registration: fake users, trial cycling, bots, duplicate accounts, and referral fraud. The account itself is the problem. Account takeover happens to a real customer after the account is already legitimate: someone stole that person's login. Dregs is built for the signup problem. Stolen logins are covered, but that is not why most teams pick Dregs.
Q: Does Dregs detect credential stuffing and account takeover?
A: Yes. Credential stuffing is leaked passwords hammering the login page; account takeover is the outcome when one of them works and someone else is inside a real customer's account. Both have dedicated pages and run on the events you already send. They are not the main reason to pick Dregs. If the traffic you care about is hitting registration rather than login, start with fake signups, signup bots, and free trial abuse.
Q: Does Dregs prevent payment fraud or chargebacks?
A: Dregs is built for signup abuse and account quality: fake signups, freeloaders, bots, and duplicates. Catching those earlier in the funnel can also reduce downstream payment fraud and chargebacks, because fewer bad accounts ever reach a card. Dregs does not replace Stripe Radar or dispute tooling. It does not decline cards, process payments, or manage chargebacks.
Q: Where should a SaaS operator start with Dregs?
A: If the pain is fake users, freeloaders burning free trials, or duplicate accounts, start with free trial abuse, fake signups, bot detection, referral fraud, and duplicate accounts. Keep the account takeover and credential stuffing pages for when a real customer's login is the incident.
Further Reading
Stop fake signups, trial cycling, and junk accounts.
Dregs helps you catch fake signups, freeloaders on the free trial, bots filling the form, referral abuse, and duplicate accounts. Account takeover and credential stuffing run on the same events, but they are not the reason most teams pick Dregs. Cutting that abuse earlier in the funnel can also reduce downstream payment fraud and chargebacks.
Schedule a Demo