IP Address Analysis in Sweepstakes: Detecting Collusion and Multi-Accounting
How IP address intelligence detects organized fraud, multi-accounting, and collusion in sweepstakes — covering VPN detection, residential proxies, IP clustering, and best practices for building IP analysis into a multi-signal fraud model.
Individual sweepstakes entries look clean. A name, an email, a mailing address, a submission timestamp. Nothing suspicious. But pull back and examine the IP addresses behind those entries, and patterns emerge that are invisible at the individual level. Fifty entries from the same IP in an hour. A cluster of "different" entrants who all route through the same corporate VPN. A burst of activity from a datacenter in Virginia that has no residential users.
IP analysis is one of the strongest signals available for detecting organized fraud and multi-accounting in sweepstakes. It works because fraudsters can fake names, generate disposable email addresses, and fabricate mailing addresses — but they cannot easily hide the network infrastructure they use to submit entries. If you are not looking at IP data, you are ignoring the clearest trail fraudsters leave behind.
What an IP Address Reveals
An IP address is more than a number. When you look up an IP against intelligence databases, you get a layered profile that tells you a great deal about who (or what) submitted the entry.
Geographic location is the first layer. IP geolocation resolves to city, state, and country with varying accuracy. Residential IPs typically resolve to the correct city. Mobile IPs may resolve to the carrier's regional hub rather than the user's actual location. This data catches geographic anomalies — entries claiming a Texas mailing address but submitted from an IP geolocated to Romania, for example.
ISP type is one of the most valuable signals. ISPs fall into several categories: residential (Comcast, AT&T, Verizon Fios), mobile carrier (T-Mobile, Verizon Wireless), commercial/business (enterprise fiber providers), and datacenter/hosting (AWS, Google Cloud, DigitalOcean, OVH). A legitimate sweepstakes entry almost always comes from a residential or mobile IP. An entry from an AWS IP address is almost certainly automated.
VPN and proxy flags add more context. IP intelligence databases maintain lists of known VPN providers, open proxies, and anonymizing services. An entry submitted through NordVPN or ExpressVPN is not automatically fraudulent, but it warrants additional scrutiny — especially when combined with other signals. Tor usage is a stronger signal still: the number of people who happen to be Tor users and also happen to enter a sweepstakes for a chance to win a gift card is vanishingly small.
Beyond the broad "datacenter" classification, IP databases can identify the specific hosting provider. Entries from AWS EC2, Google Compute Engine, or Hetzner dedicated servers are almost certainly automated. Entries from smaller hosting providers or colocation facilities are equally suspect.
Detecting Multi-Accounting
Multi-accounting — one person submitting multiple entries under different identities — is the most common form of sweepstakes fraud. IP analysis is a natural starting point for detection, but it requires nuance. Multiple entries from the same IP are not automatically fraudulent.
A household with three family members who all enter a sweepstakes will generate three entries from the same residential IP. An office of 200 employees behind a corporate NAT gateway will generate dozens of entries from one IP. A university dorm can produce hundreds. These are legitimate entries that happen to share an IP address.
The key is combining IP data with other signals to distinguish shared networks from single actors using multiple identities. Same IP plus similar email patterns (john.smith.1@gmail.com, john.smith.2@gmail.com, john.smith.3@gmail.com) plus the same browser fingerprint is almost certainly one person with three accounts. Same IP plus different devices plus different email domains plus different form completion patterns is probably a shared household or office.
This is why IP address alone is a weak fraud signal. Treating IP as a standalone detection method is like judging a book by one page. IP address combined with device fingerprint, email pattern analysis, and behavioral data becomes a strong one. The scoring model should reflect this: an IP match alone might add 10 points to a fraud score, while an IP match plus a fingerprint match plus an email pattern match might add 70.
For a deeper look at how device-level signals complement IP analysis, see our device fingerprinting guide.
Detecting Collusion and Organized Fraud
While multi-accounting is one person pretending to be many, collusion is many people coordinating to game a promotion. IP analysis is particularly effective at detecting it because coordinated groups tend to share infrastructure.
IP clustering. When a group of entries arrives from a narrow IP range (say, 192.168.1.x through 192.168.1.y on the same /24 subnet) and those entries share characteristics — similar timing, similar form completion speed, similar personal information patterns — that cluster is likely a coordinated operation. A bot farm running on a set of dedicated servers, a group of people in the same building systematically entering under manufactured identities, or a professional contest fraud ring using a shared VPN.
Geographic anomalies. A promotion for a regional grocery chain in the Pacific Northwest should generate entries concentrated in Oregon and Washington. If a burst of 200 entries arrives from IPs geolocated to Miami in a two-hour window, something is wrong. Geographic anomalies are especially telling for promotions tied to specific retail locations or regional products.
Time-of-day patterns. Legitimate entries follow predictable temporal patterns — they spike during commute hours, lunch breaks, and evenings, then drop off overnight. Bot operations and organized fraud rings operating across time zones produce flat or inverted distributions. A steady stream of entries at 3 AM local time, every night, for the duration of the campaign is not organic participation.
Velocity analysis. Beyond simple rate limiting ("no more than one entry per IP per hour"), velocity analysis looks at acceleration. A residential IP that generates one entry in week one, then three in week two, then twenty in week three shows a pattern consistent with someone discovering they can multi-account and escalating. Flagging the acceleration — not just the current rate — catches fraud earlier.
VPN and Proxy Detection
Fraudsters use VPNs and proxies for three reasons: to hide their true geographic location, to bypass geographic eligibility restrictions, and to rotate IP addresses so that rate limits and IP-based detection do not flag their activity.
Detection methods range from straightforward to sophisticated. Known VPN provider IP ranges are catalogued by IP intelligence services and updated regularly. Major providers like NordVPN, ExpressVPN, and Surfshark operate thousands of servers whose IP addresses are publicly discoverable. Datacenter IP ranges are similarly well-documented.
More advanced detection looks for DNS leaks (where a user's DNS requests reveal their true ISP despite VPN usage) and WebRTC leaks (where browser APIs expose the user's real IP address even through a VPN connection). These leaks are common and provide ground truth about the user's actual location and identity.
The challenge is that legitimate users also use VPNs. Corporate employees on mandatory VPNs, privacy-conscious consumers, users on public Wi-Fi who enable a VPN for security — none of these are fraudsters. Blanket VPN blocking creates false positives and alienates real participants. The better approach treats VPN usage as a risk signal that increases a fraud score rather than as a binary block. A VPN entry with no other suspicious signals should pass. A VPN entry with a datacenter IP, a suspicious email pattern, and a browser fingerprint that matches three other entries should be flagged.
The Residential Proxy Problem
Residential proxies are the hardest form of IP fraud to detect, and they are becoming more common. Unlike datacenter proxies that route traffic through servers in data centers (which are easy to identify), residential proxies route traffic through real residential IP addresses. The traffic appears to originate from a Comcast connection in suburban Chicago or a Verizon Fios line in Atlanta.
These residential IPs come from several sources: malware installed on consumer devices (the device owner has no idea their connection is being used as a proxy), SDK partnerships where app developers embed proxy functionality in exchange for revenue, and opt-in networks where users knowingly sell their bandwidth. The result is a pool of millions of genuine residential IPs that fraudsters can rotate through.
Because the IPs are genuinely residential, they pass ISP-type checks. They geolocate to real neighborhoods. They are not in any datacenter IP database.
Detection requires looking beyond the IP itself. Traffic volume from a single residential IP that exceeds what a normal household would produce is a signal — a residential connection generating 50 sweepstakes entries across different campaigns in a single day is not a family of enthusiastic participants. Known residential proxy provider IP ranges (Luminati/Bright Data, Oxylabs, Smartproxy) are tracked by some intelligence services, though coverage is incomplete. And behavioral signals that contradict the residential IP — such as entries with zero mouse movement, sub-second form completion, or identical submission patterns across supposedly different users — provide the evidence that IP data alone cannot.
IP Intelligence Services
No sweepstakes platform should build IP analysis from scratch. Third-party IP intelligence providers maintain continuously updated databases that classify IP addresses across multiple dimensions.
MaxMind (GeoIP2, minFraud) provides geolocation, ISP identification, and fraud scoring. Their minFraud service combines IP intelligence with email, device, and transaction data for a composite risk score. It is the industry standard for e-commerce fraud detection and adapts well to sweepstakes use cases.
IPinfo offers detailed IP metadata including geolocation, ASN (Autonomous System Number), company identification, and privacy detection (VPN, proxy, Tor, relay). Their privacy detection API is particularly relevant for sweepstakes fraud.
IP2Location provides similar geolocation and proxy detection capabilities, with a strong database of known proxy and VPN IP ranges.
These services have limitations. No database is 100% accurate — geolocation can be wrong, especially for mobile IPs. Residential proxies evade most detection. Mobile carrier IPs are shared by thousands of users simultaneously through Carrier-Grade NAT, making them unreliable for individual attribution. IP intelligence is a powerful input to fraud detection, but it is not a standalone solution.
Best Practices for IP-Based Fraud Detection
The most important rule: use IP as one signal in a multi-signal model. IP analysis alone produces too many false positives (shared networks, VPN users) and too many false negatives (residential proxies, mobile IPs). Combine it with device fingerprinting, email analysis, behavioral signals, and cross-submission pattern detection. Our complete fraud prevention guide covers all seven major attack types and how to layer defenses against them.
Never block solely on IP. Blocking an IP blocks everyone behind that IP — including legitimate users on shared networks. Use IP signals to adjust fraud scores, not to issue hard blocks. The only exception is datacenter and known bot hosting IPs, which can be blocked outright since they have no legitimate sweepstakes participants.
Track IP patterns over time, not just per-entry. A single entry from an IP tells you little. The same IP appearing across dozens of entries over a campaign's duration tells a story. Build IP histories that track cumulative behavior.
Security thresholds should match the stakes. A campaign with a $10 coupon prize can afford lighter screening — the cost of a false positive (losing a legitimate entrant) outweighs the cost of a false negative (awarding a $10 coupon to a fraudster). A $100,000 grand prize sweepstakes warrants aggressive screening where the calculus inverts.
Two other considerations matter. Mobile carriers use Carrier-Grade NAT, meaning thousands of users share the same public IP at any given time — treat mobile carrier IPs with lighter scoring than residential IPs. And always log and retain IP data for investigation. Even if IP analysis does not flag an entry in real time, retained IP data is invaluable for post-hoc investigation when a suspicious winner is drawn.
How Comprizant Handles IP Analysis
Comprizant integrates IP intelligence into every stage of the entry processing pipeline. At entry time, each submission is enriched with IP metadata — geolocation, ISP classification, VPN/proxy detection, and threat scoring. This data feeds into the real-time fraud scoring model alongside device fingerprint, email analysis, and behavioral signals.
Cross-submission analysis runs in batch, examining IP patterns across all entries within a campaign and across campaigns for the same organization. The batch fraud detector identifies IP clusters — groups of entries from related IPs that share suspicious characteristics — and retroactively flags entries for human review.
Fraud thresholds are configurable per campaign across three tiers (standard, enhanced, and enterprise), so brands can match their security posture to their risk tolerance. IP is one of 13+ signals in the scoring model, weighted appropriately against the other signals to minimize false positives while catching organized fraud.
Key Takeaways
- IP addresses reveal geographic location, ISP type, VPN/proxy usage, and hosting provider — each signal tells a different story about the entry's legitimacy.
- Multi-accounting detection requires combining IP data with device fingerprints, email patterns, and behavioral signals. IP alone is too weak to act on.
- IP clustering and velocity analysis are the most effective techniques for detecting organized fraud and collusion rings.
- VPN detection should adjust fraud scores, not issue blanket blocks. Legitimate users also use VPNs.
- Residential proxies are the hardest IP fraud to detect because they use genuine residential IP addresses. Behavioral analysis is the primary countermeasure.
- Different campaign types warrant different IP-based thresholds. Match security intensity to prize value and risk tolerance.
Build Fraud Detection Into Every Campaign
Comprizant's entry pipeline integrates IP intelligence, device fingerprinting, behavioral analysis, and cross-submission detection into a unified fraud scoring model — configurable per campaign, with no additional friction for legitimate participants.