How Can I Prevent Bots or Spam Entries in My Contest?
Prevent bots and spam entries by turning on Gleam's Fraud Filter, Fraud Levels, and CAPTCHA, which flag suspicious entries automatically, and by using duplicate-IP and email checks to catch fake or repeated sign-ups. Every campaign runs these checks by default, at every plan level: Gleam confirms actions through the platform's own API, invalidates bounced email addresses, and blocks duplicate entries from the same IP before you ever pick a winner. Here's exactly how each layer works, and how it compares with SweepWidget and ViralSweep's published fraud tools.
Spam and bot entries can undermine fairness and damage trust, so entry validation is essential for serious contests. Gleam's built-in Fraud Filter automatically analyses 20+ entry attributes to detect suspicious behaviour, in real time, typically within about five minutes of the entry being submitted. When an entry is flagged, it's marked Invalid in the Actions tab, giving you visibility before winners are drawn.
Wherever a platform supports it, Gleam validates actions like following an account or joining a list through that platform's own API, so an entry only counts once the platform confirms the action is complete, not just because the entrant clicked a button. Where possible, Gleam also surfaces a proof link for the completed action so you can check it yourself before picking a winner. LinkedIn, YouTube, and Snapchat actions currently fall outside API verification, so entries flagged as invalid on those actions are worth a manual look.
Gleam's throwaway-account restriction adds another layer for account quality: when enabled, it rejects Twitter profiles that don't meet a minimum quality bar, filtering out obvious burner accounts before they can enter. See how Gleam handles users trying to cheat for more on this.
An entry with a bounced email address is automatically invalidated, so addresses that don't resolve to a real inbox are removed before winners are drawn. Combined with the fraud-level and CAPTCHA settings below, low-quality or fake sign-ups get filtered out at more than one point, not just at the moment of entry.
You can control how strict protection is using Fraud Levels. The default is High, balancing strong protection with legitimate participation. Options range from Off (minimal checks) to Very High (more aggressive challenges), with CAPTCHA, login verification, and VPN/data-centre protection increasing at higher levels.
CAPTCHA is applied intelligently to challenge risky traffic. You can leave it Automatic (recommended), set it to Always, or disable it if needed.
When multiple people try to enter from the same household or IP address, Gleam counts the first entry as valid and marks the rest Invalid by default; you can manually restore an entry if it turns out to be legitimate. Click the Globe icon next to any action to see every other action completed under that IP address, invalid or not, so you can judge a flagged entry for yourself. On paid plans, Block User removes a repeat offender from every Competition and Rewards campaign on your Site, not just the one where they were caught.
Clear rules also help deter abuse. Gleam automatically generates ready-to-publish Terms & Conditions based on your campaign setup (dates, prizes, locations), which you can edit to add usage rights, especially important for UGC. For guidance on permissions, see the UGC permission guide.
Finally, limit where entries can come from when appropriate. Allowed Locations let you include or exclude countries to reduce low-quality traffic from outside your target market.
SweepWidget and ViralSweep both publish their own fraud-prevention documentation. Here's what each one says is checked, and, importantly, whether that check is switched on by default, needs a manual setting change, or only unlocks behind a plan or traffic milestone, as of August 2026.
| Check | Gleam | SweepWidget | ViralSweep |
|---|---|---|---|
| On by default, any plan or campaign size | Fraud Filter, CAPTCHA (Automatic), and duplicate-IP checks run from your first entrant | The weakest manual security level has no email validation or fingerprinting at all; a separate volume-based system adds more checks once a campaign passes 5,000, 15,000, and 30,000 unique entrants, regardless of the manual setting | IP entry limit is on by default; email verification codes are a Business-plan-and-up add-on |
| Confirms the action actually happened | Yes, via the platform's own API where supported | Not described in SweepWidget's published docs | Not described in ViralSweep's published docs |
| Email checked for deliverability | Yes, bounced addresses are auto-invalidated | Only if you manually select "Standard" or higher, or once the volume-based system escalates it | Optional, via a paid verification-code add-on |
| Duplicate / same-IP entries | Auto-invalidated by default; Globe icon shows every action tied to that IP | Basic IP blocking at the "Weak" level; full device fingerprinting only at "Strong" or "Strict" | Configurable limit of 1–5 entries per IP, or unlimited |
| CAPTCHA | Automatic, Always, or Off | Available at every level | Not described in ViralSweep's published docs |
| Device fingerprinting | Not offered. Gleam instead combines 20+ entry-attribute scoring with API action verification | Yes, at "Strong" or "Strict" (SweepWidget's own pages cite both "100+" and "over 300" data points in different places) | Not offered |
| Cross-campaign abuse blocking | Yes, Block User applies Site-wide on paid plans | Not described in SweepWidget's published docs | Not described in ViralSweep's published docs |
SweepWidget's blog reports a self-reported "99.9%" bot-blocking rate; we haven't found an independent audit backing that figure. Their own docs also describe two separate protection systems: a manual security level you choose per campaign, from "Weak" to "Strict," and a volume-based system that adds checks automatically once a campaign passes certain entrant counts. So the actual protection on any given SweepWidget campaign depends on which level was picked and how many entrants it's had. Gleam doesn't publish an equivalent single number, because how many entries get flagged depends on your traffic sources, fraud level, and campaign settings, not on a fixed algorithm score. What's consistent is what's checked, and that it's active from your very first entrant, not gated behind a manual setting, a traffic milestone, or a plan upgrade.
Using these controls together helps you attract real participants, protect campaign integrity, and review anything suspicious before selecting winners.
See Next Article
Can I Use a Giveaway Picker With a 25 Words or Less Contest?
Yes, Gleam lets you randomly select or manually judge 25-word contest entries. Click to learn how to combine this with social media actions and other entry methods.

