[{"data":1,"prerenderedAt":107},["ShallowReactive",2],{"\u002Fglossary\u002Fban-evasion":3,"glossary-related-\u002Fglossary\u002Fban-evasion":100},{"id":4,"title":5,"body":6,"description":87,"extension":88,"meta":89,"navigation":90,"path":91,"relatedTerms":92,"seo":95,"sitemap":96,"stem":97,"term":98,"__hash__":99},"glossary\u002F6.glossary\u002Fban-evasion.md","What is ban evasion?",{"type":7,"value":8,"toc":80},"minimark",[9,13,17,22,25,28,37,41,49,52,55,63,67],[10,11,5],"h1",{"id":12},"what-is-ban-evasion",[14,15,16],"p",{},"Ban evasion is the practice of returning to a platform after being banned, usually by registering a new account, switching devices, or rotating IP addresses so the platform fails to recognize the returning user. The goal is to resume whatever behavior triggered the ban: harassment, spam, cheating, fraud, or repeated terms-of-service violations. A ban that only blocks an email address or username is trivial to evade, so durable enforcement has to recognize the person and their hardware rather than the account alone.",[18,19,21],"h2",{"id":20},"how-it-works","How it works",[14,23,24],{},"Most bans are applied at the account level, and account identifiers are cheap. A banned user signs up again with a fresh address from a free email provider, a plus-addressed alias, or a disposable domain, picks a new username, and is back inside in minutes. If the platform blocked their IP, they switch to a VPN, a datacenter proxy, or their phone's mobile connection, which assigns a new address on demand.",[14,26,27],{},"Determined evaders go further. They clear cookies and local storage, browse in incognito or anti-detect browsers, run virtual machines, or buy aged accounts from marketplaces so the replacement identity arrives with history attached. On mobile, they reinstall the app or factory reset the device to rotate app-scoped identifiers.",[14,29,30,31,36],{},"Ban evasion is a specific case of ",[32,33,35],"a",{"href":34},"\u002Fglossary\u002Fmultiaccounting","multiaccounting",": one person operates multiple identities, but the motive is escaping enforcement rather than farming incentives. The economics favor the evader as long as bans stay account-scoped, because creating a new account costs seconds while investigating and re-banning costs staff time.",[18,38,40],{"id":39},"how-to-detect-it","How to detect it",[14,42,43,44,48],{},"The strongest signal is device reuse. Cookies are easy to clear, but hardware and browser characteristics are not, so a ",[32,45,47],{"href":46},"\u002Fglossary\u002Fdevice-fingerprinting","device fingerprint"," that belonged to a banned account and reappears under a fresh signup is close to conclusive. This is the core of ban enforcement that actually holds: keep the fingerprints of banned devices and match every new session against that list.",[14,50,51],{},"Network signals come next. Watch for new accounts created from IP addresses, subnets, or ASNs already tied to banned accounts, and for signups on VPN or datacenter IPs shortly after a residential user was banned. Timing matters too. An account created minutes after a ban, from the same rough location, deserves scrutiny before it does anything at all.",[14,53,54],{},"Email and phone identifiers repeat in predictable ways: plus-addressed and dot-variant forms of a banned address, disposable email domains, sequential handles like \"mike_r2\" and \"mike_r3\", and VoIP verification numbers where the banned account used a real mobile line.",[14,56,57,58,62],{},"Behavior gives evaders away even when their technical footprint is clean. Returning users rejoin the same groups, message the same targets, keep the same timezone and language settings, and type and navigate the way they always did. Matching those traits against recently banned accounts catches the evaders who did everything else right. And because a replacement account is by definition not a genuine new user, ",[32,59,61],{"href":60},"\u002Fglossary\u002Ffake-account-detection","fake account detection"," at signup stops many evaders before their first action.",[18,64,66],{"id":65},"how-rupt-handles-it","How Rupt handles it",[14,68,69,70,74,75,79],{},"Rupt fingerprints every device it sees and links new signups back to previously banned devices and networks, so a ban follows the person instead of the account. The ",[32,71,73],{"href":72},"\u002Fdocs\u002Fv3\u002Fguides\u002Fban-enforcement","ban enforcement guide"," walks through wiring this into signup and login flows, and the ",[32,76,78],{"href":77},"\u002Fsolutions\u002Fmulti-accounting","multi-accounting solution"," covers the broader problem of one person running many accounts.",{"title":81,"searchDepth":82,"depth":82,"links":83},"",2,[84,85,86],{"id":20,"depth":82,"text":21},{"id":39,"depth":82,"text":40},{"id":65,"depth":82,"text":66},"Ban evasion is when a banned user returns to a platform under a new account, device, or IP address. Learn how to detect and stop repeat offenders.","md",{},true,"\u002Fglossary\u002Fban-evasion",[35,93,94],"device-fingerprinting","fake-account-detection",{"title":5,"description":87},{"loc":91},"6.glossary\u002Fban-evasion","Ban evasion","bJ5WBRtj-oVlIe7_Q9c_eHoB9nxJHdYagP92k3SdwWM",[101,103,105],{"path":46,"term":102},"Device fingerprinting",{"path":60,"term":104},"Fake account detection",{"path":34,"term":106},"Multiaccounting",1786669620255]