Skip to content
Gurdx

Docs / Use-case guides

Fake account prevention

Block bots and throwaway registrations at the front door so your user base, email reputation and support queue stay clean.

The problem#

Fake accounts spam your forms, inflate your numbers, burn your email deliverability and set up later fraud. They typically use disposable emails, invalid phone numbers and cloud or anonymised networks.

Signals to combine#

Integration flow#

  1. Validate the email syntactically on the client for good UX.
  2. On submit, your server calls email scoring and, if you collect a phone, phone validation, in parallel.
  3. Call IP reputation for the request IP.
  4. Apply your policy: accept, accept with email confirmation required, or reject with a friendly message.
  5. Always confirm email ownership with a link or code. Scoring complements that step, never replaces it.
async function checkSignup({ email, ip }) {
  const headers = { Authorization: `Bearer ${process.env.GURDX_KEY}` };
  const [e, i] = await Promise.all([
    fetch(`https://gurdx.cretip.com/api/scoring/email?email=${encodeURIComponent(email)}`, { headers }).then(r => r.json()),
    fetch(`https://gurdx.cretip.com/api/lookup/ip/threats?ip=${ip}`, { headers }).then(r => r.json()),
  ]);

  if (e.status !== 'success' || i.status !== 'success') return 'review';
  if (e.data.score >= 3 || e.data.blacklisted || i.data.threats.isBot) return 'reject';
  if (e.data.score === 2 || i.data.threats.isTor) return 'verify';
  return 'accept';
}

Suggested thresholds#

Email score Action
0 Accept
1 Accept, with confirmation email
2 Require extra verification such as a phone OTP
3 Reject, or send to manual review

A bot flag or a blacklist hit overrides a good email score. Show a neutral message ("We couldn't create this account") so attackers learn little.

Note: Free providers like Gmail are common among genuine users. Do not penalise isFree by itself.

Add domains of abusive providers to an email_domain blacklist and watch the events page for spikes. Related: Multi-accounting.

Found a mistake? Tell us on the contact page. Contact