Sweepstakes Fingerprinting: How Lottery Sites Detect Multi-Accounting
You submit an entry. Confirm your email. Fill out the bonus actions — follow on Twitter, share on Facebook, refer a friend. Do it again from a different email. And again.
Three days later, all three accounts get disqualified. No notification, no warning — you just vanish from the draw.
I watched this happen to someone testing a client's sweepstakes funnel last year. (They were QA testing, to be clear — checking whether their own platform's dedup actually worked.) The "different" entries used separate emails, separate browser profiles in Chrome, even separate phone verifications. Didn't matter. The backend linked them within 72 hours — using the same device fingerprinting techniques that ad platforms deploy.
The canvas fingerprint matched. The WebGL renderer string matched. The font enumeration list matched. Three "different" people were obviously the same laptop.
This is why sweepstakes platforms invest so heavily in device-level detection. It's not paranoia. It's math.
Why Sweepstakes Platforms Detect Multi-Account Entries
Here's the thing most people miss: giveaways aren't free marketing anymore. They're paid marketing.
When a brand runs a $50,000 car giveaway through Omaze, they're not being generous out of boredom. They're paying for email acquisition, social engagement, and brand awareness. The unit economics only work if entries represent real, unique humans who might become customers.
One person submitting 500 entries under 500 identities destroys that value proposition. The brand paid for 50,000 unique prospects. They got 49,500 real ones and 500 from some guy running a script in his garage. The sweepstakes company's entire business model depends on preventing this.
So they invest accordingly. And honestly? I expected sweepstakes detection to be weaker than ad platform detection. Figured it'd be amateur hour compared to Facebook. I was completely wrong. The fraud stack on serious giveaway platforms — PCH, Omaze, even mid-tier Rafflecopter campaigns with decent sponsors — rivals what you see on Facebook Business Manager. The same click fraud detection systems protecting ad campaigns now protect sweepstakes entries. Maybe that shouldn't have surprised me, but it did.
The sponsors demand it. No legitimate brand wants their $50K prize going to someone who gamed the system with fake entries.
The Obvious Fixes (That Don't Work)
When entries start getting disqualified, people try the predictable stuff.
Different emails. Useless as a fingerprint bypass. Email is an identifier, not a device signal. Platforms absolutely see that three Gmail accounts are all entering from the same machine with the same canvas hash.
Incognito mode. This one still surprises me — people genuinely believe private browsing changes their fingerprint. It doesn't. Incognito clears cookies and history. Your GPU, fonts, screen resolution, and timezone remain identical. To FingerprintJS, you're the same person you were 30 seconds ago.
Multiple browsers. Chrome vs Firefox does produce different fingerprints. Fair point. But sweepstakes platforms using serious detection (SEON, FingerprintJS Pro) cluster "same device, different browser" signals anyway. Your canvas hash differs slightly, sure — but your screen resolution, installed fonts, and timezone? Identical. That cluster still gets flagged. I spent an embarrassing amount of time testing this before accepting the obvious.
VPN. Datacenter IPs are red flags on sweepstakes platforms. Even if you don't get blocked outright, you're getting routed into manual review queues. And VPN IPs are shared by definition — if someone else on that exit node got flagged for fraud last month, you're inheriting their reputation.
Different phone numbers. Phone verification is an identity check, not a device check. You can verify ten numbers from the same laptop. The platform sees one device with ten phone numbers. That's worse, not better.
None of this works because none of it addresses the actual detection layer: hardware-level device fingerprinting.
What Sweepstakes Platforms Actually Detect
The detection stack on serious giveaway platforms looks more like SEON than regex. Here's what's actually being measured.
Canvas fingerprint. Your browser renders a hidden image. The exact pixel output depends on your GPU, graphics drivers, OS, and font rendering engine. The resulting hash is highly unique. Two entries, same hash, same device. Simple math. The audio/font/hardware fingerprinting mechanics apply identically here.
WebGL renderer. The GPU string exposed through WebGL ("ANGLE (NVIDIA, GeForce RTX 3080...)") identifies your graphics hardware. Combined with WebGL extension support and performance characteristics, it's another strong device signal.
Font enumeration. What fonts render correctly on your machine creates a signature. A Windows 11 laptop with Microsoft Office installed has a completely different font list than a stock Mac. This is high-entropy data.
Screen metrics. Resolution, color depth, device pixel ratio, available screen dimensions. Not unique alone, but combined with other signals, they narrow the pool fast.
Timezone and locale. If you claim to be entering from California but your browser timezone says you're in Germany, that's a red flag. Sweepstakes with geographic restrictions care deeply about this — the same timezone mismatch detection that catches fake ad clicks catches fake sweepstakes entries.
IP clustering and reputation. Even residential IPs get watched. Three entries from the same residential IP in 48 hours will get clustered. Platforms assume one IP = one household = one legitimate entry.
Behavioral patterns. How fast you complete entry forms. Whether you actually engage with bonus actions or just click through. Mouse movement patterns. Some platforms have implemented these; the trend is clearly toward more behavioral analysis. (Annoying, but understandable from their side.)
The scoring is composite. No single signal kills you. But canvas + WebGL + same residential IP + suspiciously fast form completion + three entries in 24 hours? That's a linked cluster. Gone. No appeals process. No "but I have three roommates" exception.
What Actually Prevents Detection
Real entry isolation requires the same stack that works for ad accounts and survey platforms — proper fingerprint separation at the device level.
Antidetect browser with hardware-consistent fingerprints. Canvas, WebGL, AudioContext, font values — all need to differ across profiles while staying internally coherent. A profile claiming Windows 11 with an NVIDIA GPU? Its font rendering, WebGL strings, and canvas hashes all need to match that config. Random values get nuked. Why? They don't correspond to any real device population SEON or FingerprintJS has ever observed. The detection models know what actual hardware looks like.
This is where extension-based antidetect tools fail. They spoof the API responses but leave deeper signals intact — TLS fingerprints, navigator properties, plugin enumeration inconsistencies. Serious detection catches these mismatches within days.
Residential proxy per profile. Sweepstakes platforms cluster IPs aggressively. You need a sticky residential proxy ($3-8/GB from providers like IPRoyal or Smartproxy) geo-matched to your claimed entry location. If the sweepstakes is US-only, your IP should be US-based. One proxy per profile. No sharing.
Profile warm-up. A fresh browser profile with zero history submitting a sweepstakes entry looks suspicious. Before touching any giveaway platform, browse normally for a few days. Visit news sites, check social media, watch videos. Build realistic browsing history and cookies. Cold profiles trigger additional scrutiny.
Realistic entry behavior. Don't blast 50 entries in 10 minutes. Space entries across days. Actually complete bonus actions instead of just clicking submit. Read the terms. (Yes, read them. I know.) Behavioral analysis catches accounts that move too fast or too robotically — even when the fingerprint is clean. Patience isn't my strong suit either, but the detection systems don't care about my feelings.
Separate identity details. Different emails, different phone verifications, different social accounts for bonus actions. This doesn't bypass fingerprinting, but it prevents surface-level identity linking during manual reviews.
Testing Before You Burn Entries
Before submitting anything to a live sweepstakes, verify your profile separation actually works.
CreepJS — open-source fingerprinting demo that shows every signal your browser exposes. If CreepJS can link your "different" profiles to the same device, SEON can too.
FingerprintJS Pro demo — the same technology many sweepstakes platforms license. Their public demo generates a visitor ID. If two profiles produce the same visitor ID, they're linked.
BrowserLeaks — granular breakdown of canvas, WebGL, audio, fonts, screen, and timezone signals. Compare values across profiles manually.
Pixelscan — specifically built to test antidetect setups against modern detection stacks.
Run these checks before you submit entries, not after you've been disqualified. The detection happens at entry time, not draw time.
The Grey Area (Let's Be Honest)
Sweepstakes terms universally prohibit multiple entries per person. Every single one. I'm not going to pretend otherwise.
What we're describing here is the technical layer of detection. Legitimate use cases for understanding this include:
- QA testing for sweepstakes platform developers
- Fraud researchers studying fingerprinting implementations
- Brands auditing their own giveaway deduplication systems
- Academic research into device identification methods
If your goal is to submit fake entries and steal prizes from legitimate participants, this post won't help you long-term anyway. Detection updates constantly. SEON ships new signals quarterly. The arms race never ends. And — being honest here — the expected value of multi-entry gaming rarely exceeds the time investment once you account for detection rates and disqualification. I've seen the spreadsheets people build to justify this. The math almost never works. You'd make more money just... getting a job.
But if you're building sweepstakes technology, testing fraud prevention systems, or researching fingerprinting methods, the technical reality is: device fingerprinting is the primary detection vector, and addressing it requires real tooling.
The Stack That Works
For legitimate sweepstakes platform testing or fingerprinting research:
JustBrowser with native Chromium engine — canvas, WebGL, AudioContext, and font fingerprints modified at the C++ layer, not through a detectable extension. $9.99/month for unlimited profiles, or $99.99/year. Seven-day free trial, card required — cancel inside the week and you aren't charged.
Sticky residential proxies — one per profile, geo-matched to entry requirements. Budget $3-8/GB depending on provider and location targeting.
Manual warm-up — build browsing history before touching any platform. Minimum 3-5 days of realistic activity. Yes, this is tedious. Do it anyway.
Detection verification — CreepJS, FingerprintJS demo, BrowserLeaks. If profiles aren't distinct on these tools, they won't be distinct to SEON. Test first. Always.
For click fraud protection on ad campaigns (different problem), check ClickzProtect — they use the same fingerprinting signals in reverse, blocking bots instead of emulating them. For privacy-respecting analytics that won't leak fingerprint data to third parties, there's JustAnalytics. Different products, same portfolio.
Frequently Asked Questions
Why do sweepstakes sites limit entries to one per person?
Sweepstakes sponsors pay for genuine reach and engagement. When one person submits hundreds of entries under fake identities, the promotion loses its value — the brand isn't reaching new customers, and the statistical integrity of the draw collapses. Platforms enforce one-entry rules to protect both sponsors and legitimate participants.
Can VPNs help avoid sweepstakes duplicate detection?
VPNs change your IP but don't touch device fingerprints. Sweepstakes platforms using SEON or FingerprintJS can still link entries by canvas hash, WebGL output, and font enumeration. Datacenter VPN IPs are often flagged outright as suspicious. A VPN alone won't prevent detection.
What fingerprinting vendors do sweepstakes platforms actually use?
Mid-tier platforms often run SEON for fraud scoring, which includes device fingerprinting. Larger operations may license FingerprintJS Pro or build proprietary systems. Even Rafflecopter and Gleam integrations can pass fingerprint data to the sponsor's backend for deduplication.
Is submitting multiple sweepstakes entries illegal?
It depends on jurisdiction and intent. Violating sweepstakes terms is typically a civil matter, not criminal. However, using fake identities to claim prizes can cross into fraud territory. We're explaining the detection technology here — not endorsing circumvention. Legitimate uses for antidetect browsers include QA testing giveaway platforms and researching fingerprinting implementations.
Try JustBrowser
Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. $9.99/month or $99.99/year. 7-day free trial, card required — cancel any time in the seven days and you are not charged. Unlimited profiles.
Get started → · How it differs from Multilogin / GoLogin / AdsPower
Related Posts
Ready to manage multiple accounts?
Seven days free, then $9.99/month — one plan, everything included.