Finding fake event registrations before they reach your headline number
Fake event registrations are found by scoring each record against several weak tests at once: disposable email domains, repeated phone and address strings, sub second form completion, and arrival bursts with no campaign send behind them. Act on the records failing two or more tests, and quarantine them instead of deleting.
Registration jumps by 2,800 over a weekend. No campaign was sending, no partner was promoting, and the show is fourteen weeks out with nothing in the calendar that would explain it. On Monday somebody puts the new cumulative total in the pacing report, because that is what the report does.
Fake event registrations do not announce themselves, and whatever created those records, they are now in the denominator of your pacing index, in the audience number the sales team quotes, and in the file that will eventually be handed to an auditor. Removing them in March is a conversation about why the number went down. Removing them on the Monday is housekeeping.
Which tests actually catch a fabricated registration?
The mistake is looking for the one test that identifies a fake registration. There is not one. Every individual signal has a legitimate explanation, and a screen built on any single test will delete real people.
Domain class. Disposable and throwaway inbox providers exist to create accounts that will never be read again. Castle published an open source list in May 2026 of the top thousand disposable domains it observed in real abuse activity, refreshed daily, and made a point of excluding privacy forwarding services such as SimpleLogin and Addy on the grounds that their purpose is privacy. Castle's own framing is the part worth borrowing: it says disposable email usage alone is not enough to identify malicious activity, and recommends correlating it with device fingerprinting, proxy detection and velocity analysis. Domain class is also the input to the weekly corporate domain share, which is a quality read on a file that is already real.
Repeated strings. The same phone number on eleven records. The same street address on forty. The same company name typed identically, character for character, on records with unrelated surnames. Repetition at that scale is generated rather than typed.
Completion speed. The elapsed time between the form loading and the form submitting. A human filling in eleven fields including a company name and a job title takes tens of seconds at minimum. A submission at 1.4 seconds was not typed.
Arrival pattern. Registrations arriving in a dense burst with no campaign behind it, at an hour that makes no sense for the country on the record, spaced with a regularity human traffic never has.
Every one of these has an innocent version. A shared corporate switchboard number legitimately appears on dozens of records from the same firm. A browser autofill can complete a form in under two seconds for a real person who has typed those details a hundred times before. A partner association can email its members at midnight without telling you. That is why the screen has to be scored rather than applied as a filter.
Score the record on how many tests it fails
Run all four tests over the whole file, keep the result as four flags, and count them per record.
Work it on a file of 14,000 registrations. The domain test flags 780 records. The repeated string test, set to flag any phone or address string appearing on three or more records, flags 1,240. The completion time test, set at under eight seconds, flags 1,610. The arrival pattern test, flagging any record inside a burst of more than 200 registrations per hour with no campaign send in the preceding 48 hours, flags 2,050.
Add them up naively and you get 5,680 flags. The count of distinct records carrying at least one flag is 3,800, which is 27.1 per cent of the file, and that is the number that will terrify whoever sees it first. It should not be acted on, because a single flag is mostly noise.
The count of records failing two or more tests is 1,900, which is 13.6 per cent. The count failing three or more is 610, which is 4.4 per cent.
Now the decision is legible. The 610 are as close to certain as this method gets, and they can be quarantined without further discussion. The 1,900 are the population worth a person's attention, and they are the number to report, because they are the difference between telling exhibitors 14,000 and telling them 12,100. The gap between 3,800 and 1,900 is the cost of pretending any one test is decisive.
Two of the four tests need instrumentation you may not have. Completion time requires the registration platform to record two timestamps, the moment the form was served and the moment it was submitted, and a lot of platforms expose only the second. Arrival pattern requires the created timestamp at second resolution and a record of your own campaign sends in the same timeline. Both are worth asking for, and both are much easier to add before a campaign than during one.
The burst signature is the strongest of the four
If you can only build one test, build the timing one, because generated traffic has a shape that human traffic does not.
Plot registrations per hour across the campaign and mark your own sends. Real registration traffic tracks the sends with a decaying tail over a day or two, shows a working hours pattern in the countries you sell to, and dies overnight. Generated traffic sits at a near constant rate for hours, ignores the send calendar entirely, and does not care what time it is anywhere.
The arithmetic is simple enough to do in a spreadsheet. Take the median registrations per hour over the previous 14 days, excluding the 48 hours after each send. If that median is 6 and you are seeing 240 an hour for nine hours straight, that is 40 times the baseline with no cause, and the 2,160 records created in that window are one population that arrived together and should be examined as one.
The reason this test is the strongest is that it is the hardest for the other side to avoid without giving up the thing they came for, which is volume.
Should you delete the records you flag?
Move flagged records to a held state with the flags attached and the original row intact. Do not delete, and do not merge them into a general junk bucket.
Three reasons. The first is that you will be wrong about some of them, and a held record can be released while a deleted one has to be re-created by an annoyed registrant. The second is that the flags are evidence, and if this ends up in front of an auditor or a partner dispute, the working matters more than the conclusion. The third is that quarantined records are the training data for doing this better next edition, and every one you delete is a row you cannot learn from.
Report them as their own line in the weekly pack: registrations received, registrations held, registrations released after review, and net live registrations. The pacing index runs on the net figure. The gross figure stays visible so nobody thinks a number was hidden.
Where a show already runs a human vetting queue, the held population feeds it as its own reason code, and the automated screen becomes the first pass of one process instead of a second one running alongside.
The version of this that hits your exhibitors
The same machinery that generates registrations also generates the emails your exhibitors receive offering to sell them your attendee list.
Trade Show Executive reported in April 2024 on the Federal Trade Commission's rule covering government and business impersonation, which lets the agency file federal court cases and impose civil penalties over spoofed business emails, misused logos and false claims of affiliation. In that piece Marsha Flanagan, president and chief executive of the International Association of Exhibitions and Events, said her team receives no less than 75 attempts each year for IAEE's own annual show, against a US market of more than 10,000 shows a year. An earlier Trade Show Executive piece in February 2022 quoted Consumer Technology Association chief executive Gary Shapiro saying the association had received at least 60 reports of fraudulent email solicitations using its name and logo since January 2021.
That is worth keeping in the same conversation for one practical reason. The list being sold is fabricated, and part of what makes it saleable is a plausible headline attendance figure taken from your own marketing. A registration number you have not screened is the raw material for somebody else's fraud, and it is the number your exhibitor will compare the fake list against when deciding whether it looks real.
Where the screen is wrong
The four tests are biased against exactly one legitimate population, which is registrants arriving through a channel you do not control.
An association emails 8,000 members at once with a pre-filled link. The records arrive in a burst, complete in three seconds because the link carried the details, and share a handful of domains. Three of the four tests fire. Those are real people and they are probably your best audience, and a screen run without a list of partner sends will quarantine them on a Monday morning.
The fix is boring and it is the only fix: maintain a calendar of every send by anyone, including partners, exhibitors and media, at the same resolution as your own. Any burst test without that calendar is guessing.
The screen also has nothing to say about a record that is real, unique and worthless. A person who exists, typed their own details at a normal speed from a corporate domain, and had no intention of attending will pass all four tests. The same goes for a real registrant working a promotional code they were never entitled to, which is a policy problem with a person behind it. This method finds fabricated records. It does not find uninterested ones, and confusing the two will make you overconfident about a file that is clean and still not what your exhibitors were sold. Any attendee analytics reporting on file quality has to carry both readings.
This week, pull the created timestamps for one completed edition at second resolution, plot registrations per hour, and lay your own send calendar on top. Circle every hour where volume ran more than ten times the fortnightly median with no send behind it. Whatever is inside those circles is the population to look at first, and you will know within an afternoon whether you have this problem at all.
Questions people ask about fake event registrations
- How do you detect fake event registrations?
- Run four tests over the whole file and count the flags per record. Disposable domain lists catch throwaway inboxes, repeated phone or address strings catch generated identities, completion time under a few seconds catches automation, and registration bursts with no campaign send behind them catch bulk creation. No single test is decisive, so score them together.
- What percentage of event registrations are fake?
- There is no general figure, and a screen that reports one is usually reporting its own sensitivity. On a worked file of 14,000 registrations, 3,800 records carried at least one flag while 1,900 failed two or more and 610 failed three or more. The middle number is the one worth reporting.
- Should you delete suspected fake registrations?
- Quarantine them instead. Move flagged records to a held state with the flags attached and the original row intact. Some judgements will be wrong and a held record can be released, the flags are evidence if an auditor or a partner disputes the count, and quarantined records are the training data for doing this better next edition.
Related reading
- Corporate email domain share as an early read on audience quality
- Spotting registration promo code abuse before it dents the paid mix