What SignupCops checks on every new signup
Keeping the click is the first half of SignupCops. The second half is deciding whether the signup deserves to be sent at all. Ad platforms learn from every conversion you report. If a third of your reported signups are throwaway emails, bots or the same person on five accounts, Meta and Google will go looking for more people like them. SignupCops checks each new account before it becomes a conversion.
Email intelligence
When your app calls identifyUser, the email is sent to the DataCops detection engine along with the visitor's IP. The engine looks at the email the way a fraud analyst would, but in a fraction of a second. It checks:
- Whether the domain is a disposable or temporary email service, or runs on the same mail infrastructure as one.
- Whether the domain has the usual email authentication records, such as SPF and DMARC, that real mail domains publish.
- How old the domain is. A domain registered last week is a very different signal from one that is ten years old.
- Whether the part before the @ looks random, like a string a script would generate.
- Patterns that point to accounts made in bulk, and plus-addressing tricks used to create many accounts from one inbox.
- Whether the email has any presence online at all.
The signals add up to a score. A score of 80 or more is critical, 50 or more is high and 30 or more is medium. Each signup in your dashboard shows its label and the reasons behind it, so you can see why an account was flagged, not just that it was.
IP and network checks
The visitor's IP is checked against DataCops' own IP intelligence, which covers 360+ billion addresses. It tells residential connections apart from datacenter, VPN, proxy and Tor traffic. A signup that comes from a hosting provider rather than a home or mobile connection is a strong sign of automation. The same browser check that runs on every DataCops session also flags automated browsers like Selenium, Puppeteer and Playwright, and signups from bot sessions are not enriched.
More than one account on the same device
Free trials and signup credits attract people who create a new account every time the old one runs out. SignupCops notices when a recent account already exists on the same device and shows the sibling accounts next to the new one. That signup is held back as a multi-account signup, so your ads are not paid out for the same person twice. It also gives your team a clear list to look at when trial or referral abuse is suspected.
Held, not blocked
SignupCops does not stop anyone signing up to your product. Your login, your onboarding and your product stay exactly as they are. What changes is what your ad platforms hear.
A signup is held back from your ad platforms when the risk action is block, when its label is high or critical, or when it uses a disposable email domain. It is also held when it looks like a second account on the same device. Held signups stay visible in Signup conversions with their reasons, so you never lose sight of them. Every other new signup is sent as CompleteRegistration with its click ID and hashed email.
This matters because the cost of a fake signup is not the signup. It is the next thousand clicks the ad platform buys, looking for more people who behave like it. Holding junk back keeps the learning clean.
Sending the signup to your ad platforms
Real signups go out server-side, from DataCops to each ad platform you connect. DataCops sends to 8 ad platforms: Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X. Meta, Google Ads, TikTok, LinkedIn and X connect with a one-click sign-in. Microsoft Ads, Reddit and Pinterest connect with an API key.
Each conversion carries the original click ID when the visitor had one, plus the email and any phone and name you passed, cleaned and SHA-256 hashed before they leave our servers. If the visitor clicked the ad on their phone and signed up later on a laptop, the hashed email still gives the platform a way to match. If the same person comes back on a new session and signs up with that email, DataCops can still link them to their first ad click.
Your own user ID travels with the signup too, so later events from your backend, such as a first payment you post to the DataCops conversions API, belong to the same person. The same sale is sent once per platform, even when more than one tool reports it.
Choose what each platform hears
Every connected platform has its own delivery settings. You can pause a platform, or switch on Real people only. With Real people only on, conversions from bots and datacenter traffic never reach that platform, and you can add VPN, proxy and Tor traffic too. It is off by default, so you decide per platform. B2B products often leave VPN off, because many real buyers work behind a company VPN.
See what reached each platform
The delivery report shows, per platform, how many signups were sent, skipped or failed, with a plain-English reason for each one that did not go. When someone asks why Google shows fewer signups than your database, you can answer in one screen.
From signup to paying customer
A signup is the start, not the sale. When a lead becomes a customer in your CRM, DataCops can send that sale back to your ad platforms too. HubSpot is checked every 5 minutes for the qualified field you chose, and any other system can release a held lead through the release API. Held leads expire after 14 days. Salesforce and Pipedrive connect through the DataCops webhook, directly or through Zapier, Make or n8n.
If paid clicks themselves look fake, the Organization plan adds two more tools: blocking bot IPs at the Cloudflare edge, and a refund evidence CSV for Google's Click Quality form covering the last 60 days. Google decides the refund.
Pricing: 500 free checks per site
Every site gets 500 SignupCops checks free, on every plan, including Free. That is enough to run SignupCops on a new product through its whole launch. On the Business plan ($59 a month, or $49 a month yearly) and the Organization plan ($359 a month, or $299 a month yearly), checks past the first 500 are billed at $9.50 per 500.
If you want the email check without the rest of SignupCops, for example inside your own backend or a support tool, it is also available as an API with your DataCops API key.
Consent and privacy
SignupCops sits inside the DataCops consent setup. The built-in cookie banner is shown in Europe by default, is built to the IAB TCF v2.2 standard, and has Google Consent Mode v2 on by default. For EU, UK and Swiss visitors, the server checks consent before any conversion is sent, and nothing goes to an ad platform until the visitor opts in. If your signup form asks for marketing consent, call identifyUser only after it is given. Users can ask for their data to be deleted through the DataCops deletion form, and their email, name and phone are wiped from DataCops.
Good to know before you start
- Pass accountCreatedAt with every identifyUser call, so returning logins are never sent as new signups.
- Put the DataCops script on every page and subdomain where a signup can finish, with the same key.
- Your first 500 checks per site are free, on every plan.
- Turn on Real people only for each platform you want to keep bot-free.