Fake signups

Detect fake signups before they distort your numbers

Fake accounts arrive looking like real ones. FindIP Shield records every signup attempt on your site with a risk score and the network reasons behind it, so you can see which signups come from anonymizing or hosting networks and decide what to do about them.

Free Preview · 10,000 events per site per day · No credit card · Terms apply

Proxy VPN Tor Hosting network Malicious IP IP rotation in session
The problem

Rate limits see bursts. They do not see where a signup came from.

A signup form only knows what the visitor typed. It cannot tell that the connection arrived through a datacenter in another country, that the IP changed twice during the session, or that the same network produced the last forty accounts.

Email checks catch disposable domains and miss plus-addressing. Rate limits catch bursts and miss a slow, patient script. By the time fake accounts show up as a payment problem or a distorted activation chart, they have been in your data for weeks.

The useful question is not whether an IP is bad. It is what happened, which signals explain the risk, and what the least disruptive response would be.

What Shield shows you

The evidence, then the response you choose

Every signup attempt, with its network

Shield records signup_view and signup_attempt events with a 0 to 100 risk score and reason codes such as vpn_detected, datacenter or asn_rotating. Never the form values, the password or the email.

A response per form, chosen by you

Installing changes nothing. When you are ready, pick the signup form Shield discovered and choose monitor only, slow down, a Cloudflare Turnstile check, or stop. Every outcome is recorded next to the recommendation.

A server-side check for the decision that matters

Before you create the account, verify the session from your server with your secret key. That is the one decision a browser cannot bypass.

Setup

Install on any website in three steps

For sites where you can edit the HTML or the application bundle. The same snippet works with React, Next.js, Vue, Vite or plain HTML.

Create a Shield site

Sign in, add the domain you control, and pick a privacy mode. You get a public site key; nothing connects until it is on a page.

Add the snippet

Paste one script tag before the closing body tag, or run npm install @findip/shield and call init() with your site key. Auto page and form tracking is on by default.

Watch the first real event

Submit a test on your own form. The event, its risk score and the reasons behind it appear on the site dashboard moments later.

Prefer another route? Install through WordPress, Shopify, Google Tag Manager, or connect Cloudflare instead.

Boundaries

What a risk score is, and what it is not

An assessment, not proof. A VPN, a hosting network or a changing IP is common for privacy-conscious and corporate users too. Shield explains the reasons so you can decide; it does not pass judgement on a person.
Friction, not a security boundary. Anything decided in the browser can be bypassed by someone who controls it. For decisions that matter, verify the session from your server with your secret key.
Unknown is never safe. Where no intelligence was available the status is unknown. Shield fails open: if a decision does not arrive, the form submits as normal.
Questions

Frequently asked

No. Privacy-conscious people and corporate networks use VPNs every day. Shield reports the signal and the reason so you can decide; a risk score is an assessment, not proof of abuse. Most teams start by watching and only add a challenge for the highest scores.

Not unless you configure a response for a form. Installing the snippet is monitor only. When you do enable a response, you choose it per form, from slow down to a Turnstile check to stop, and Shield fails open: if a decision does not arrive, the form submits as normal.

Form attributes and the submit event, never the values. Passwords, emails, phone numbers and payment fields are never sent. How much browser and session context is collected depends on the privacy mode you choose.

Yes. Pass a hashed user ID to the SDK or the dataLayer once the account exists. Shield hashes identifiers in the browser, so a risky session can be traced to an account in your system without Shield holding the raw email.

Shield is in Free Preview: 10,000 events per site per day, no credit card. Beyond the quota events are not recorded; they are never silently dropped as safe.

Start by watching one real flow.

Create a free Shield site, install it, and look at the first real event before you decide on any response.

Try Shield on my site

Free Preview · Informational risk signals · You control enforcement