Registration Bombing
One fine morning, your user table starts collecting registrations from people who don't exist.
Their names might resemble keyboard confetti (the likes of "wd4fQxyy0 GozwoWkV0M") but the email addresses are real, belonging to actual people who never came anywhere near your signup form. Despite the repeated registrations, nobody ever confirms the emails or logs in to your application, so clearly some kind of mischief is at play.
Why would anyone go to the trouble, you might wonder...
Your product was never the target.
Some lowlife has taken a list of real email addresses and is feeding them through every registration form on the internet, yours included, to flood each victim's inbox with confirmation emails. Your signup form has been conscripted as a mail cannon to spray shrapnel into the inboxes of people who never even heard of you: a distraction meant to stop the victim from seeing a notification of a fraud the attacker is conducting in the meantime.
Dregs recognizes this pattern and flags these repeated registrations as they arrive, so you can stop yourself from being an accomplice in the attack.
What Is Registration Bombing?
Registration bombing (also known as email bombing, subscription bombing, or list bombing) is an attack on an unsuspecting third party's email inbox, carried out through public signup forms. The attacker scripts sign-ups of a real victim's address across hundreds or even thousands of legitimate sites... sites like yours. Each site dutifully sends its "confirm your account" email, and the victim's inbox fills with hundreds of messages from services they've never even heard of.
The purpose is usually to create a smokescreen for a more serious crime. Buried somewhere in that flood of registration and welcome emails is the one email that really matters to the victim: a bank alert, a password-reset notice, or a receipt for a fraudulent purchase made with the victim's stolen card. The registration bombing runs while the real theft happens elsewhere, and by the time the victim has dug through the wreckage, the window for reacting to the theft has closed. This is why the registration bombing is worth taking seriously: it isn't just random vandalism or mischief, it's frequently the visible half of a genuine robbery in progress.
From your end, the signup traffic might look oddly calm. Fake registrations might even trickle in minutes or hours apart, staying well under your rate limits, because the botnet behind them is patiently working through a long list of target sites and a long list of victims. The name fields might just be random strings, since the operator of the scheme can't be bothered to fake plausibility for a form that only needs to trigger one email. That indifference is a tell: a specimen who won't even invent a proper fake name doesn't really want your product, only your confirmation emails.
Traditional abuse and fraud defenses are mostly aimed at attacks where you're the primary target, and registration bombing often slips past them.
| The Traditional Defense | Why It Often Fails |
|---|---|
| Rate limiting | The attack sometimes occurs at a snail's pace: one registration every twenty minutes or so, from a different residential IP each time. Each request looks harmless enough on its own, and your thresholds aren't reached. |
| Email verification | Verification emails aren't a defense here, they're the attack! The confirmation email is precisely what the attacker wants to exploit. Requiring email verification means your system faithfully delivering the ordnance with every submission. |
| CAPTCHAs | Solving farms clear them for fractions of a cent, and the attack's leisurely pace means there's no hurry. Meanwhile, your legitimate signups suffer extra friction. |
| Form validation | The email addresses are real and well-formed — more real, in a sense, than most junk signups, since they belong to actual people. The gibberish or made up names pass any length or character check. |
| Blocking disposable domains | These addresses are the opposite of disposable: aged personal inboxes at Gmail, Outlook, and regional providers, harvested from breach dumps. A disposable-domain list does nothing about them. |
What Registration Bombing Costs You
It's tempting to shrug off a bunch of unconfirmed accounts that never log in. But you're not a bystander in this attack; you're the delivery mechanism.
Sender reputation
Harvested lists might contain spam traps, and even real recipients will likely mark your unexpected email as spam. Bounces and complaints accumulate against your domain, and your provider throttles or suspends email sending.Complicity in fraud
Every confirmation email you send helps bury a fraud alert in some victim's inbox. Your brand name lands in the flood alongside the attacker's other accomplices, possibly remembered by the victim in a negative light.Polluted metrics
Hundreds of never-confirmed accounts settle into your user table and skew your metrics. Signup conversion craters for no visible reason, and those inaccurate numbers make it harder for your team to make good decisions.How Dregs Detects Registration Bombing
Individually, each bombing registration is meant to look forgettable. Chained together, they have a distinctive shape. Dregs evaluates both levels at once: every signup scored on its own plausibility the moment it lands, and the ongoing attack is exposed by the pattern across accounts. Every score is supported by observations, so you can see exactly why an account was flagged and confirm it isn't a false positive before anything gets blocked.
Example: Catching a Bombing Campaign
Here's how it might play out with Dregs keeping watch:
No manual review queue, no new friction for real users... just a quiet refusal to be ammunition in a fraudster's attack.
Stopping Registration Bombing
The attack only works if the confirmation email goes out, which means the fix sits entirely on your side of the wire. Dregs supplies the scores, along with custom rules and lists (badge rules and datasets, in Dregs terms), so you can automate whichever response fits.
Withhold the email
Accept the registration on the surface and simply decline to send the confirmation email when the scores say bombing. The attacker's script sees success; the victim's inbox sees nothing. This is the response that actually disarms the attack.
Delay and verify
Queue low-scoring registrations for a short delay before any email is sent. Bombing campaigns are exposed by their third or fourth account, so a brief hold lets the cross-identity picture form first — far less manual review than inspecting signups by hand.
Clean up the residue
Sweep flagged, never-confirmed accounts out of your database on a schedule, keeping your metrics honest and your user table free of accounts that were only ever ammunition. This is easy once Dregs has scored and tagged the identities as such.
Speed matters here more than in most abuse scenarios, because the confirmation email usually goes out within seconds of the signup. Dregs webhooks deliver scores to your application moments after the registration lands, in time to make the send-or-withhold decision while it still matters.
Registration bombing is just one type of attack, and it shares machinery with others: the accounts are created by bots, they pollute your database like fake signups, and the smokescreen frequently covers an account takeover happening somewhere else. Dregs combats all of these and more.
Take your signup form out of the attacker's arsenal.
Dregs scores every registration for authenticity and behavior the moment it's submitted, and links suspected bombing campaigns across accounts. Install the tracking script and stop being an accomplice.
Schedule a Demo