Skip to content
English
  • There are no suggestions because the search field is empty.

How to prevent bots from entering engagement campaigns

This guide covers the two protections available on engagement campaigns, how to choose between them, and how to read your protection results.

Tradable Bits offers two campaign protections: Spam Protection and Bot Protection. They are independent so you can turn on either, both or neither - whichever fits how fans are entering your campaign.

Both are found under Campaign Setup > Access Restrictions.

🔓 No Protection

This is the Default mode on campaigns. Most ideal for in-venue kiosks, staff-assisted entries or in-venue QR where traffic to the campaign is controlled, and the campaign URL is not publicly known.

 🛡️ Spam Protection

Spam Protection blocks entries when a certain threshold is met from the same IP address within 24 hours. Blocked fans see a clear error message, and then nothing else happens - the entry is simply not accepted.

Bot detection also runs in the background while Spam Protection is on. Nothing extra is blocked, but detections are logged on the Results page for Bot Protection to use later. 

Use it when: Your campaign link is public and fans are entering from their own devices and connections.

Don't use it when: Fans share a connection. In-venue kiosks, staff-assisted entry, and in-venue QR campaigns all route many legitimate entries through one IP address, and Spam Protection will start rejecting real fans partway through the night.

If you're running an in-venue campaign, either leave Spam Protection off or whitelist your venue's IP address in User Access Management. Whitelisted IPs are never blocked by either protection.


🤖 Bot Protection

Bot Protection blocks entries that don't behave like they came from a real person.

Rather than checking one entry in isolation, it looks at recent entry activity across your campaign and identifies patterns a real fan wouldn't produce:

  • How an IP address relates to the identities using it: A single IP address submitting under lots of different emails and phone numbers.
  • How an identity moves between locations: A single email or phone number submitting from lots of different IP addresses. 
  • Identity pairs that don't hold up. One phone number attached to many emails or one email attached to many phone numbers - a signature of generated identities rather than real people. 
  • Characteristics of the contact details themselves. i.e. Temporary domains.

These signals are weighed together, not acted on individually. 

On accuracy: Bot Protection is tuned for robustness and will err on the side of blocking or flagging entries. As a result, a small number of legitimate entries may be caught. Whitelist your known IP addresses - venues, staff, agencies - before turning this on.

Use bot protection when: your campaign link is public, prizes are meaningful or a large sponsor is attached. Anywhere there's a real incentive to farm entries. 

A note on how blocking looks: when Bot Protection rejects an entry, the entry screen still shows success. This is deliberate - a bot that gets an error message learns to try something else, while a bot that gets a success screen keeps burning effort on an attempt that isn't landing.

This is important to know when you're testing your own campaign. If you're submitting repeated test entries and they aren't appearing in your results, check the Bot Status report.

Start monitoring before you start blocking

Bot detection works from recent history, and we start cataloguing suspicious behaviour when Spam Protection is turned on. For longer-running campaigns with high rewards, you can first start to monitor, then enforce:

1. Turn on Spam Protection. Bot detection starts cataloguing in the background, but nothing aside from "spammers" are blocked.

2. Switch on Bot Protection. When switched on, it already has a history to act on and will automatically block suspicious attempts that meet the weighted threshold (pulling them out of your entries). 

    Reading your Bot Status Report

    Spot a bot, stop a bot. 

    Head to Results > Bot Status for a breakdown of what's getting through, flagged or blocked. Figures cover the past 7 days

    Status What it Means Is the entry in my campaign?
    Good Attempts Passed all active checks. Yes
    Questionable Attempts Entry went through but looks suspicious. Flagged for secondary review. Yes
    Rejected Attempts Blocked by Bot Protection. The entry screen showed success, but nothing was recorded No

    You can search the report by email, phone or partial match to look up a specific entry.

    If only Spam Protection is on: detections  are logged but not enforced.

    About Questionable Attempts: these entries are live in your campaign and count to your results. They're surfaced so you can spot a pattern if one develops - for example , a spike in questionable entries in a short window is worth a look before your draw a winner. 

    Choosing your setup

    Campaign type Recommended
    In-venue kiosk, staff-assisted, in-venue QR Neither protection, or whitelist your venue IP
    Public link, low-value prize Spam Protection
    Public link, meaningful prize Bot Protection, or both

    Whichever you choose, we also recommend using the Limit Entries section under Access Restrictions to set daily or lifetime entry limits per fan. Align these with your campaign's terms and conditions.

    Real-world example

    Let’s say you’re running a contest with a public link for a sponsor with major prizes. You want real fans entering from everywhere - not one IP farming your prize codes.

    Turn on Bot Protection, and:

    • Obvious abuse gets blocked
    • Questionable traffic gets logged
    • You keep control without breaking the fan experience

    It’s like turning on a firewall for your campaigns. 

    Frequently Asked 

    1. Can I run both protections at once? Yes.They're independent and check for different things. Spam Protection watches entry volume from a single IP. Bot Protection watches for patterns across identities. 
    2. Will Bot Protection block real fans? Not intentionally. The checks require combinations of suspicious signals, not any single one, but it is built to err on the side of security. If you believe a real fan was blocked, whitelist their IP or reach out to your Customer Success team.
    3. Do I need to set anything up? No. Both protections are toggles. Just turn them on.

     

     

     

     

    Still need assistance? Please reach out to your Customer Success Team or contact support@tradablebits.com