Every signup attempt, with its network
Shield records signup_view and signup_attempt events with a 0 to 100 risk score and reason codes such as vpn_detected, datacenter or asn_rotating. Never the form values, the password or the email.
Fake accounts arrive looking like real ones. FindIP Shield records every signup attempt on your site with a risk score and the network reasons behind it, so you can see which signups come from anonymizing or hosting networks and decide what to do about them.
Free Preview · 10,000 events per site per day · No credit card · Terms apply
A signup form only knows what the visitor typed. It cannot tell that the connection arrived through a datacenter in another country, that the IP changed twice during the session, or that the same network produced the last forty accounts.
Email checks catch disposable domains and miss plus-addressing. Rate limits catch bursts and miss a slow, patient script. By the time fake accounts show up as a payment problem or a distorted activation chart, they have been in your data for weeks.
The useful question is not whether an IP is bad. It is what happened, which signals explain the risk, and what the least disruptive response would be.
Shield records signup_view and signup_attempt events with a 0 to 100 risk score and reason codes such as vpn_detected, datacenter or asn_rotating. Never the form values, the password or the email.
Installing changes nothing. When you are ready, pick the signup form Shield discovered and choose monitor only, slow down, a Cloudflare Turnstile check, or stop. Every outcome is recorded next to the recommendation.
Before you create the account, verify the session from your server with your secret key. That is the one decision a browser cannot bypass.
For sites where you can edit the HTML or the application bundle. The same snippet works with React, Next.js, Vue, Vite or plain HTML.
Sign in, add the domain you control, and pick a privacy mode. You get a public site key; nothing connects until it is on a page.
Paste one script tag before the closing body tag, or run npm install @findip/shield and call init() with your site key. Auto page and form tracking is on by default.
Submit a test on your own form. The event, its risk score and the reasons behind it appear on the site dashboard moments later.
Prefer another route? Install through WordPress, Shopify, Google Tag Manager, or connect Cloudflare instead.
Create a free Shield site, install it, and look at the first real event before you decide on any response.
Try Shield on my siteFree Preview · Informational risk signals · You control enforcement