What is signup abuse?

Signup abuse is the creation or operation of accounts in order to take a product benefit a genuine customer would pay for or earn. Fake signups, free trials claimed under fresh emails, bots filling the registration form, referral bounties paid to fictional friends, and duplicate accounts all belong here. The same cluster is often called account creation fraud or new account fraud. The damage starts at registration, before the account is a real customer. Account takeover is a different problem: someone stole a real customer's login. Credential stuffing is leaked passwords hammering the login page at scale.

What Dregs is built for

Dregs is built for the mess that shows up at signup: fake users in the registration form, freeloaders burning through free trials on a fresh email each time, bots filling the form, junk filling the user table, referral programs paying the same person twice, and one person running several duplicate accounts. Most of that damage is pre-account: it starts at registration, before anyone is a paying customer. Fake signup detection and fake account detection are the same job: score the identity at the moment of submission. Custom rules and lists then decide what happens, with less manual review than combing the user table by hand. Scores land moments after new activity, and every score opens into its observations so you can see exactly why an account was flagged. That's also how false positives get caught before a legitimate signup is punished.

Account takeover and credential stuffing are different problems. Someone stole a real customer's login, or leaked passwords are hammering the login page. Dregs still catches both from the events you already send. They are not the reason most teams pick Dregs. If the pain on your SaaS is junk in the user table, trials that never convert, or a referral program paying the same person twice, start with fake signups, trial abuse, bots, referrals, and duplicates rather than with stolen login detection.

How this differs from related problems

Three jobs get mixed together under "fraud detection," and only one of them is why most teams pick Dregs.

Signup abuse Fake signups, freeloaders burning free trials, bots filling the form, referral fraud, and duplicate accounts. The account itself is the problem.
Account takeover and credential stuffing Someone stole a real customer's login, or leaked passwords are hammering the login page. Dregs covers both. They are not why most teams start with Dregs.
Payment fraud and chargebacks Catching fake signups and bad behavior earlier in the funnel can also reduce downstream payment fraud and chargebacks. Dregs does not replace Stripe Radar or dispute tooling; it scores the accounts, and your processor still handles the transaction.

Where to start

If junk is landing in the user table, start here. Keep the account takeover and credential stuffing pages for when a real customer's login is the incident.

Frequently Asked Questions

Q: What is the difference between signup abuse and account takeover?

A: Signup abuse happens at and around registration: fake users, trial cycling, bots, duplicate accounts, and referral fraud. The account itself is the problem. Account takeover happens to a real customer after the account is already legitimate: someone stole that person's login. Dregs is built for the signup problem. Stolen logins are covered, but that is not why most teams pick Dregs.

Q: Does Dregs detect credential stuffing and account takeover?

A: Yes. Credential stuffing is leaked passwords hammering the login page; account takeover is the outcome when one of them works and someone else is inside a real customer's account. Both have dedicated pages and run on the events you already send. They are not the main reason to pick Dregs. If the traffic you care about is hitting registration rather than login, start with fake signups, signup bots, and free trial abuse.

Q: Does Dregs prevent payment fraud or chargebacks?

A: Dregs is built for signup abuse and account quality: fake signups, freeloaders, bots, and duplicates. Catching those earlier in the funnel can also reduce downstream payment fraud and chargebacks, because fewer bad accounts ever reach a card. Dregs does not replace Stripe Radar or dispute tooling. It does not decline cards, process payments, or manage chargebacks.

Q: Where should a SaaS operator start with Dregs?

A: If the pain is fake users, freeloaders burning free trials, or duplicate accounts, start with free trial abuse, fake signups, bot detection, referral fraud, and duplicate accounts. Keep the account takeover and credential stuffing pages for when a real customer's login is the incident.

Further Reading

Stop fake signups, trial cycling, and junk accounts.

Dregs helps you catch fake signups, freeloaders on the free trial, bots filling the form, referral abuse, and duplicate accounts. Account takeover and credential stuffing run on the same events, but they are not the reason most teams pick Dregs. Cutting that abuse earlier in the funnel can also reduce downstream payment fraud and chargebacks.

Schedule a Demo