How the fraud actually works.
Signal research, teardowns of real abuse patterns, and the engineering behind the API. Written for the operators running the traffic, not for a search engine.
How to stop duplicate signups in a Go application
Build a Go signup flow that recognises a returning device and refuses a second free trial, using the kaidn-go client. Full working code and demo repo.
Read itHow old is this email address? The short answer is nobody knows
Every email age checker answers a different question from the one you asked. Here is what they actually tell you, and why it is useless on Gmail.
2 min readFingerprintJS alternatives, and the free one nobody mentions
The open-source library and the paid product get confused constantly. One of them survives ad blockers and one does not, and it is not the one you would guess.
3 min readIPinfo vs MaxMind: how to actually pick one
One question decides this before accuracy does, and most comparisons never ask it. A straight look at what separates the two and what neither can tell you.
4 min readMailinator: what it is for, and should you block it
Mailinator hands you an inbox in one second with no signup. Here is why it exists, why anyone can read your mail, and what blocking it really achieves.
3 min readCatching fake referrals: four queries and one fix that beats them all
Every farmed referral account looks normal on its own. The giveaway is in the shape of your referral tree, and you can find it with SQL you already know.
4 min readFingerprintJS Pro and Kaidn, side by side in 24 privacy browser sessions
We ran both engines in the same page loads across Tor, Mullvad, Brave and Camoufox. Every number, including the two rounds where our own detector was the one that was wrong.
11 min readBlocking disposable email domains is the easy half
A list of throwaway domains catches the lazy attempt. The one that costs you money uses a real Gmail address, six times, and every shortcut you would reach for first is wrong.
5 min readBuilding an MCP server for fraud investigation: why we expose evidence instead of risk scores
Most fraud APIs hand an AI agent a risk score and nothing else. We built one that hands over the evidence, and it changed how review queues actually get worked.
5 min readFraud playbooks
One page per abuse pattern: how the attack runs, what does not work, and the signals that do.
Account takeover
Why account takeover is caught by what changed rather than what looks wrong, how credential stuffing is actually run, and where detection stops and authentication takes over.
4 min readBonus abuse
How bonus abuse works, why per-account limits never hold it, and which signals separate a farmed signup from a real new user before the payout clears.
3 min readCard testing
Card testing costs you your payment processor, not stolen goods. How the attack works, and the signals that catch it in the first few minutes.
4 min readFake signups
Why most fake registrations are not after your money, how bulk signup gets automated, and the signals that separate a script from a slow human.
4 min readComparisons
Honest head-to-heads, each one with the case for choosing them instead.
AbuseIPDB alternatives
Five alternatives to AbuseIPDB for IP abuse data, and why a community reporting database answers a different question from a fraud decision.
3 min readCastle alternatives
Five alternatives to Castle for account security, and where the line sits between protecting logins and scoring the whole funnel.
3 min readFingerprint alternatives
Five alternatives to Fingerprint for device identification, and an honest account of when you want a specialist identifier versus a scoring layer that uses one.
4 min readIPinfo alternatives
Five alternatives to IPinfo for IP data, and the difference between knowing what an address is and deciding what to do about the person behind it.
3 min readBuilt for
Where the money leaves your particular kind of business, and which events are worth scoring.
Marketplaces
Why marketplaces have two user populations and one fraud budget, where seller-side loss actually happens, and which events to score on each side.
3 min readRewards & offerwalls
Why reward platforms lose money at the payout rather than the signup, which events carry the loss, and how partner reversals turn fraud into a second bill weeks later.
3 min readSaaS
Why SaaS abuse is a cost problem rather than a theft problem, which events are worth scoring when nothing gets withdrawn, and when to fix packaging instead.
3 min readFree tools
Run a check yourself, no signup. The same engine the API uses, one question at a time.
IP checker
Proxy, VPN, Tor and datacenter classification, with the ASN behind it.
No signupPhone number checker
Line type, carrier and country, plus VOIP and disposable detection.
No signupEmail checker
MX, SPF and DMARC, domain age, role accounts and the alias identity key.
No signupDisposable email checker
Is this address a throwaway? 160,000+ temp-mail domains, refreshed hourly.
No signupGlossary
Every term the product uses, defined in a paragraph, one anchor per term.