Security

Prevent cheating, duplicate votes, spam, and bot manipulation. Riddle offers multiple layers of security that you can combine depending on your use case – from simple browser-based limits to server-side IP restrictions and lead-ID verification.

Plays/votes per browser

Limit how many times someone can play or vote. This is the simplest form of duplicate prevention – it uses browser local storage, so it can be bypassed by clearing cookies or using a different browser.

If you have cookies disabled, the One vote per browser feature does not work as it requires the local storage. When cookies are disabled, use the IP limit instead, which is handled in our backend without cookies.

One vote per browser does not work in apps because they do not support local storage.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable One play/vote per browser to limit your audience to take a Riddle or vote once per browser.
    security one play per browser enabled
  3. Select a Refresh interval if people should be able to vote again later, e.g. once a day. Keep No refresh to allow only one vote in total. See Allow one vote per hour, day, week, or month.
    security refresh interval for one vote per browser

While One play/vote per browser is enabled, the "Play again" button is hidden.

What your audience sees:

  • Opening the Riddle does not count as a vote. A vote is counted as soon as someone submits their first answer.
  • If someone completed the Riddle and reloads the page, they see their result page.
  • If someone answered at least one question but did not finish and reloads the page, the Riddle appears as normal. As soon as they try to vote again, they see the message Only one vote allowed.
    only one vote allowed message

Allow one vote per hour, day, week, or month

With a Refresh interval, your audience can vote again in the next time window. This works for One play/vote per browser and One vote per Lead-ID, and brings people back to your Riddle regularly.

Refresh intervalYour audience can vote again
No refresh (default)Never – one vote in total
HourlyAt the start of every full hour
DailyEvery day at 00:00
WeeklyEvery Monday at 00:00
MonthlyOn the 1st of every month at 00:00

The windows are fixed calendar times, not rolling periods. They use your time zone in the Creator, the same one used for your Riddle's start and end dates. Example: with Daily, someone who votes at 23:50 can vote again ten minutes later at 00:00, not 24 hours later.

Use cases:

  • Daily poll or raffle: Enable One play/vote per browser and select Daily. Everyone can take part once per day, which gives your audience a reason to come back tomorrow.
  • Player of the month: Add a form with an email field, enable One vote per Lead-ID with email as the lead identifier, and select Monthly. Each email address can vote once per month, and on the 1st the same poll opens for the next vote.
  • Weekly quiz challenge: Select Weekly so returning players get one new attempt every Monday.

Play again

Show your audience a "Play again" button. Disable this for polls or competitions where retaking should not be allowed. Keep it enabled for educational quizzes or fun content where replaying is part of the experience.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable the "Play again" button. This lets your audience retake the Riddle as many times as they like.
    security play again button enabled

Enable IP limit

Limit how many votes can come from the same IP address. This is server-side and cannot be bypassed by clearing cookies. Use it as a stronger layer alongside or instead of browser-based limits.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable IP limit. This makes it harder for bots and scripts to affect your poll.
    security ip limit enabled
  3. Select a Refresh interval for your IP limit from the dropdown menu: Every Minute, Hourly, or Daily.
    security time interval
  4. Enter the # of tries per period that can come from a single IP address. We recommend 10 based on the use case that people in the same office who share the same IP address can all vote.
    security number of tries per period
    A single IP address can vote as often as this number within each period. After that, further votes from this IP address are blocked with an error message until the next period starts.
    This does NOT mean each poll taker can take your poll a set number of times (e.g. "4 times per user"). That is still capped at once per browser.
  5. Please note: We never store the actual IP addresses of your audience on our servers. Riddle is an EU-based, GDPR-compliant quiz maker so we don't store personal information like this. Find out more about Riddle.com's privacy policy here.

Enable one vote per lead-ID

Restricting votes by lead identifier adds another layer of security to your polls and quizzes. It prevents people from entering twice and cannot be bypassed in the same way one vote per browser can. Your Riddle needs a form block that collects the lead identifier, e.g. an email field. Without a form, the Status page in Publish shows a warning, because no lead can be collected.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable One vote per Lead-ID.
    security enable one vote per lead identifier
  3. Select a Refresh interval if the same lead identifier should be able to vote again later, e.g. once a month. Keep No refresh to allow only one vote in total. See Allow one vote per hour, day, week, or month.
    security refresh interval for one vote per lead-ID
  4. Go to the Publish section and click on Save and connect data.
    security go to save and connect data
  5. Select a data variable from the Lead identifier dropdown menu, such as phone or email. Someone reusing this lead identifier will be blocked at verification.
    security select lead identifier

What your audience sees: Someone who reuses a lead identifier sees an error message when they submit the form. If the lead identifier comes from the data layer, the error appears right away.

What this means for your stats

With One vote per Lead-ID, only complete, verified submissions are saved. Incomplete or duplicate attempts are not recorded in the statistics, guaranteeing clean, unmanipulated data. The only statistic that may increase is view count, but not starts or completions.

This is why Analyze shows a notice on the Overview, Breakdown, and Audience tabs: "This Riddle has “One vote per Lead-ID” enabled. Only data from users who have completed the Riddle are saved." The notice also appears if the option was enabled at any point in the past. It is not shown on Leads & CTA, because your lead data is not affected.

Analyze notice for one vote per lead-ID

Example: 500 people start your poll, 300 of them finish and submit the form. Analyze shows 300 starts and 300 completions, so the conversion from start to completion is 100%. The 200 people who dropped out are not counted, because their starts were never saved.

Enable spam filter for emails

Block disposable or temporary email addresses from being entered in forms. This requires your Riddle to have a form block with an email field.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable Spam filter for emails.
    enable spam filter
  3. Email addresses from GitHub's open source disposable email domains list will then be blocked. Your audience will then be asked to use a trusted email address instead.
    spam email blocked

Privacy opt-ins

Add consent boxes for your audience to click on before viewing the content on these sites.

  1. Go to the Settings section and click on Security: Multiple entries & bot protection.
    go to security
  2. Enable Privacy Opt-ins (YouTube, Vimeo, X). This is to add another step of consent because YouTube, Vimeo, and X add cookies to any of their content that is embedded in your Riddle.
    privacy opt-ins enabled
  3. Enter a message you want to appear in the Privacy text fields (optional).
    security privacy text
  4. Enter your preferred text into the Privacy text button field for what the button itself should say.
    security privacy text button

Tips

  • Casual polls or fun quizzes: Enable One play/vote per browser and keep the "Play again" button on. This prevents casual duplicate voting while keeping the experience light.
  • Competitions with prizes: Combine One vote per Lead-ID (email) with Spam filter for emails and disable the "Play again" button. This is the strongest combination against manipulation.
  • Recurring votes: Add a Refresh interval such as Daily or Monthly to One play/vote per browser or One vote per Lead-ID, so people can vote again in every new time window.
  • Corporate or office polls: Use IP limit with a generous number of tries (e.g. 10) to allow everyone in a shared office network to participate.
  • GDPR-sensitive content with embedded YouTube/Vimeo: Enable Privacy opt-ins to show a consent step before third-party cookies are loaded.