Guide · Updated · 8 min read

Signup fraud detection that protects your ads too

Your CAPTCHA is not the weak spot. The fake account that gets past it, and then gets reported to Meta as a win, is.

The short answer

Signup fraud detection means checking every new account at three points: the form, the network it came from, and the device behind it. Then it means deciding what that account is allowed to touch, including the conversions you send to your ad platforms.

DataCops is a tool for the ad side of signup fraud: it gives every visit a bot verdict, checks each signup email, keeps flagged signups from reaching your ad platforms, sends the real sale back to the click, and lets you warm up new campaigns with your existing customers.

How DataCops does it:

  • Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default. Every form email is checked for disposable providers, domains with no mail server and an email risk score.
  • The sale after the form. HighLevel natively (lead, booked, showed, won with value, paid), any CRM by webhook, Shopify through the DataCops Shopify app, all matched to the click by click ID or hashed email and phone, and sent to Meta, Google Ads, TikTok and LinkedIn.
  • Ads Warmup. Upload your existing customers (up to 20,000 rows), see a 0 to 10 match score per person, and send them to Meta, Google Ads and TikTok so new campaigns start warm.
  • First-party collection, no extra tool. One script and one DNS record put collection on your own subdomain; with your DNS on Cloudflare, the free Worker reads the click at the edge before the page loads. Click IDs are kept on the server for up to 90 days.
  • Consent, memory and proof. A TCF 2.2 consent banner from your domain with Google Consent Mode v2 on by default, a server-set cookie up to 400 days where enabled, and a delivery log row for every send, counted once against the pixel.

Best for: ad-funded SaaS and lead gen teams, agencies, and anyone whose signups come from paid campaigns and whose fakes are polluting the ads.

  • At the form: an invisible challenge plus email verification.
  • At the network: VPN, proxy and datacenter IP checks.
  • At the device: many accounts from one machine is the loudest signal there is.
  • At the ads: risky signups held back from Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.

The trial that trained the wrong ad

Picture this. A SaaS team gives away 500 free API credits on signup and runs Meta ads to the trial page. One Monday, signups are up 40% on the week. Everyone is pleased for about a day.

Then support notices the pattern. Addresses like jn.k8471@ on domains nobody has heard of. Dozens of accounts from the same browser. Credits burned in the first ten minutes, then silence.

The credits are the small loss. The big one is in Ads Manager. Every one of those accounts fired CompleteRegistration through the Conversions API, and Meta did its job: it went and found more people like them.

The signup form is the door. The conversion you send to Meta is where the damage compounds.

The real cost of a cheap tool

Most signup-fraud tools are cheap, often free to start. That is the invoice, not the cost. Cheap tracking that is handled badly costs far more, because the bill arrives in what your ads learn.

  • Bots forwarded as buyers. A forwarder sends what reaches it. Junk conversions teach the platform to find more junk.
  • The sale that never gets sent. A booked call, a phone order or a won deal happens outside the store or the page. Most tools never see it.
  • The limit you hit on your busiest day. Hosts and apps cap requests, events or orders, and sending can pause or stop over the limit.
  • The build and the upkeep. Containers, plugins and automations need someone to build them and fix them when a platform changes.

The tracking is 0.17 percent of your spend. If one in five of the conversions your ads learn from is a bot or a fake lead, a fifth of the learning signal points at the wrong people, across the other 99.83 percent of the budget.

Cheap tracking is the cheapest line on the bill and the most expensive one to get wrong.

Signup fraud detection tools, by layer

These are not rivals. Most real setups use two or three.

Turnstile, reCAPTCHA, hCaptcha

Challenge layer

Turnstile and reCAPTCHA v3 run mostly invisible. reCAPTCHA v3 gives you a score from 0.0 to 1.0 and leaves the decision to you, so pick a threshold and log what it blocks. See our reCAPTCHA comparison.

Best for: cutting scripted volume with almost no friction.

Kickbox, ZeroBounce, NeverBounce

Email layer

Checks the address on submit: does the domain accept mail, is it a known throwaway, is the syntax real. A few lines of code and an API key.

Best for: newsletters and trials plagued by throwaway inboxes.

SEON, IPQualityScore

Risk scoring API

Email, phone and IP signals rolled into one score per check. Deep data, and strong for payment and fintech risk. See SEON and IPQualityScore.

Best for: fintech and marketplaces that also need payment fraud checks.

Castle, Sift, Verisoul

Account risk platforms

Signup plus login protection, account takeover, rules and manual review queues. More than most growth teams need, exactly what a trust team wants. See our Castle comparison.

Best for: products with a trust and safety team and account takeover risk.

DataCops SignupCops

Conversion layer

Checks each signup for email risk, VPN, proxy and datacenter IPs, and other accounts on the same device. Risky and disposable-email signups are saved for you to see and held back from your ad platforms. It also keeps the ad click ID through Sign in with Google. See SignupCops.

Best for: SaaS, AI apps and trials that buy signups with Meta, Google Ads or TikTok.

When not to use DataCops

  • You need device-level intelligence with your own rules. Dedicated fraud tools give you raw signals and a rules engine. DataCops is switches, not code.
  • You need payment fraud or account takeover tools. DataCops does not cover those.

Ads Warmup: tell the ads who pays

Signup fraud detection scores accounts and visitors inside your product. It does not tell the ad platforms which people are real customers, so new campaigns learn from scratch. The customers you already have are the best description of who to find.

Ads Warmup, DataCops' flagship feature, sends them to your ad platforms before a campaign spends:

  1. Upload a customer list. A CSV of past buyers, old leads or booked calls. DataCops reads your columns; only email is required.
  2. See a match score for every person. An estimate from 0 to 10 from email, phone, name, location, click ID and customer ID, before anything is sent.
  3. Pick the event. Purchase, Lead, Complete registration, Add to cart or Schedule.
  4. Send server-side. Up to 20,000 people per upload to Meta, Google Ads and TikTok, with a sent, skipped or failed result per person. Google Ads credits only people who clicked a Google ad.

Each row is dated when you press send, not with the old sale date, so it gives a new campaign real customers to learn from on day one. Preview is free; sending needs a paid plan.

What else a fraud API never does

  • Capture at the edge. With DNS on Cloudflare, the free, optional DataCops Cloudflare Worker reads click IDs and UTMs off the first request, before the page or any script runs. It captures; it does not block.
  • Keep the click on the server. gclid, wbraid, gbraid, fbclid, ttclid and li_fat_id are stored for up to 90 days, so a deal that closes weeks later still finds its click. A signed server-set cookie lasts up to 400 days where enabled.
  • Check the lead's email. Fixed rules, not guesses: disposable providers, domains with no mail server and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
  • Install on Shopify. The DataCops Shopify app adds a web pixel and a theme app embed, so every paid order reaches your ads, express checkouts included. See Shopify Conversions API.
  • Hand evidence to Google. On the Organization plan, the fraud refund report exports bot-flagged Google Ads clicks in the format Google's Click Quality form asks for. You attach it; Google decides.

What is signup fraud?

Signup fraud is any account created by someone who will never be a real user: a script, a trial farmer, a promo abuser, or a person paid to fill forms. It comes in two flavours.

The cheap kind

Scripts hammering your form, throwaway inboxes, made-up domains. Loud, high volume, easy to catch with a challenge and an email check.

The expensive kind

Real email addresses, residential proxies, a real browser, a human or an AI agent at the keyboard. Passes the form. Looks clean in your CRM. Gets counted as a conversion.

Where do fake signups get through?

Every layer catches something and misses something. Know which is which before you buy anything.

LayerCatchesMisses
Challenge (CAPTCHA)Basic scriptsSolver services, agents, paid humans
Email verificationDisposable inboxes, dead domains, typosReal addresses in the wrong hands
IP checksVPNs, datacenters, known proxiesClean residential IPs
Device and account linksMany accounts from one machineFarms that rotate devices
Conversion layerStops risky signups reaching your adsNothing gets refunded; it prevents, not reports

Stack the first four and you catch most of it. Most teams stop there. The fifth row is the one that decides whether the misses cost you a database row or next month's ad budget.

Do fake signups hurt Meta and Google Ads?

Yes, and more than they hurt your database. Ad platforms optimise toward whoever converts. Send them a fake signup and you have told them what a good customer looks like.

Server-side tracking does not save you here. It moves the event off the browser so ad blockers cannot eat it. That is useful. But a bot that completes your form fires a server event just as reliably as a buyer does. Better delivery of bad data is still bad data.

Every fraud API scores the signup. Almost none decide whether Meta hears about it.

This is the gap we built for. DataCops is the tracking solution for ad-funded businesses: it keeps bots out of what your ads learn from and sends the sale that happens after the form to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X.

One signup, on its way to Meta
EmailDisposable domain
IPDatacenter
Accounts on this device6
CompleteRegistration to MetaHeld back

The account still exists, so you decide what to do with it. The ad platform just never learns from it. For lead forms rather than app signups, LeadCops does the same job in two lines of code and can hold the ad conversion until your CRM confirms the lead.

Stop fake signups, step by step

  1. Measure first. Count signups by email domain, IP type and device for the last 30 days. Find where the junk clusters before you pick a tool.
  2. Add an invisible challenge to the signup form. Log its scores for a week before you block on them.
  3. Verify the email on submit. Reject dead domains. Flag disposable ones instead of silently accepting them.
  4. Check the network and the device. Datacenter IPs and one machine opening many accounts are your strongest signals.
  5. Gate the free thing, not the signup. Hand out trial credits after email confirmation, or after a phone check if the credits are worth real money.
  6. Hold risky signups back from your ads. Only send CompleteRegistration for accounts that passed. See Conversions API setup.
  7. Send the later stage too. A paid plan or an activated account tells Meta far more than a signup ever will.

Fake accounts are a support problem. Fake conversions are a budget problem.

FAQ

Can I warm up a new campaign with my existing customers?

Yes, with DataCops Ads Warmup. Upload a CSV of customers (only email is required, up to 20,000 rows), see a 0 to 10 match score for each person, and send them to Meta, Google Ads and TikTok, dated when you send. Google Ads credits only people who clicked a Google ad.

What is signup fraud detection?

It is checking each new account for signs it was made by a bot, a throwaway inbox or someone farming free trials. The check looks at the email, the IP, the device and how the form was filled. The good setups also decide what happens to a risky account next.

Does CAPTCHA stop fake signups?

It stops the cheap scripts. Solver services and AI agents get through many challenges, and people paid to sign up pass them by definition. Treat CAPTCHA as the first filter, not the whole answer.

Is email verification enough?

No. It catches typos, dead domains and disposable inboxes. It does not catch a real Gmail address used by a bot on a residential proxy. You need IP and device signals as well.

Should I block risky signups or just flag them?

Block only what you are sure of, like disposable domains on a paid trial. Flag the grey zone and review it. A false block loses a real customer; a flag costs you a minute.

Do fake signups hurt my Meta and Google Ads results?

Yes. If a fake signup fires CompleteRegistration, the ad platform treats it as a win and looks for more people like it. Server-side tracking does not fix this on its own: it sends the bot signup just as reliably as a real one.

When should I use phone verification?

When the free thing you give away is worth real money: trial credits, payouts, free API usage. It stops most scripted abuse but adds friction, so test it on your own funnel before making it mandatory.

How does SignupCops handle a risky signup?

Your app calls identifyUser after the signup. DataCops checks the email, VPN, proxy and datacenter IPs, and other accounts on the same device. High-risk and disposable-email signups are saved for you to see but held back from your ad platforms.

Which ad platforms does DataCops send signups to?

Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X. Not Microsoft Ads, Pinterest, Reddit or X.

Sources

Let your ads learn from real users

Every signup gets checked. Risky ones stay out of Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X, and the real ones keep the click that earned them.

Setup in 5 minutes. No credit card.

Live traffic quality

Updated just now

Visits · last 24h

487
Real users
35873.5%
Bots · auto-filtered
12926.5%

Without filtering, 26.5% of your reported traffic is bot noise inflating dashboards and draining ad spend.

Don't trust your analytics!

Make confident, data-driven decisions withactionable ad spend insights.

Setup in 2 minutes
No credit card