All articles Industry

Self-Exclusion Evasion: Detecting Returning Players Who Signed Up Again

Self-exclusion only works if an operator can recognize an excluded person when they come back. The problem is that they rarely come back as themselves — they come back with a new email, a new card, and a name spelled just differently enough to slide past an identity check.

Self-exclusion is a cornerstone of responsible gambling, and in many jurisdictions honoring it is a hard license condition. Yet the mechanics of enforcement are weak wherever they lean only on the data a player controls. This post covers how evasion actually happens and which signals expose a returning excluded player.

How players evade self-exclusion

Evasion is almost always a re-registration story. The excluded account is closed, so the player opens a new one and changes the fields that identity matching depends on:

  • A fresh email and phone number, which are trivial to obtain
  • A minor name variation — “Jon” for “John”, a dropped middle name, a transposed accent
  • A different payment instrument — a second card, a partner’s card, an e-wallet, or crypto
  • A new address, sometimes a relative’s or a mail-drop

Every one of those is a field the player supplies. An identity-only exclusion list is being asked to catch someone precisely where they have full control of the input. Meanwhile the things the player does not easily change — the laptop, the phone, the home network — carry straight over from the closed account to the new one.

Signals that survive re-registration

The durable signals sit below the registration form, in the device and network layer:

  • A stable visitorId. A persistent device identifier that holds across cleared cookies and incognito sessions links the new signup back to the excluded device, even when every typed field is different.
  • Household and network correlation. A new account operating from the same home IP range and the same device cluster as a recently excluded player is a strong review trigger.
  • Payment-to-device links. When a “new” card first appears on the exact device that belonged to an excluded account, the connection is hard to explain innocently.
  • Behavioral continuity. Session timing, staking patterns, and game preferences often mirror the prior account because the underlying person has not changed.

Cross-referencing these against your exclusion population turns a name-matching problem into a device-and-behavior matching problem — one the evader cannot solve by editing a form. Prynt issues a stable visitorId from a single client call and links it to server-side signals, so a returning excluded device surfaces at registration rather than months into a complaint.

Where geography and proxies complicate things

Some evaders add a VPN or proxy to break the network link, hoping a new IP hides the connection to the excluded account. That move is itself a signal. A registration arriving from a datacenter IP, a known VPN exit, or a residential proxy — especially when the stated address is domestic — deserves elevated scrutiny. Our VPN and proxy detection classifies connection type server-side, so an anonymized re-registration reads as higher risk instead of blending in with clean traffic.

The goal is not to block every VPN user. It is to notice when anonymization coincides with other exclusion signals, because that combination is far more suspicious than either alone.

Turning signals into an enforcement workflow

Detection is only useful if it feeds a defensible process. A workable approach:

  1. Fingerprint at registration and login. Capture a visitorId before the account is fully created, so a device match can block the signup rather than unwind it later.
  2. Score against the exclusion population. Flag new accounts whose device, network, or payment links intersect recently excluded players.
  3. Route matches to human review. Device evidence is strong but not infallible — shared family devices and public terminals exist. A person confirms before an account is closed.
  4. Document the decision. Keep the signals and the reasoning, both for the player’s protection and for your regulator.

Handled this way, exclusion enforcement stops being a spelling contest and becomes a question of whether the same device and household keep reappearing.

Self-exclusion is a promise to vulnerable people, and a promise you cannot keep with identity fields alone. Device intelligence gives you the persistent thread evaders assume they have cut. Explore the signals in our playground or see plans on our pricing page to start building enforcement that survives a re-registration.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading