Security
Prevent cheating, duplicate votes, spam, and bot manipulation. Riddle offers multiple layers of security that you can combine depending on your use case – from simple browser-based limits to server-side IP restrictions and lead-ID verification.
Plays/votes per browser
Limit how many times someone can play or vote. This is the simplest form of duplicate prevention – it uses browser local storage, so it can be bypassed by clearing cookies or using a different browser.
If you have cookies disabled, the One vote per browser feature does not work as it requires the local storage. When cookies are disabled, use the IP limit instead, which is handled in our backend without cookies.
One vote per browser does not work in apps because they do not support local storage.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable One play/vote per browser to limit your audience to take a Riddle or vote once per browser.

- Select a Refresh interval if people should be able to vote again later, e.g. once a day. Keep No refresh to allow only one vote in total. See Allow one vote per hour, day, week, or month.

While One play/vote per browser is enabled, the "Play again" button is hidden.
What your audience sees:
- Opening the Riddle does not count as a vote. A vote is counted as soon as someone submits their first answer.
- If someone completed the Riddle and reloads the page, they see their result page.
- If someone answered at least one question but did not finish and reloads the page, the Riddle appears as normal. As soon as they try to vote again, they see the message Only one vote allowed.

Allow one vote per hour, day, week, or month
With a Refresh interval, your audience can vote again in the next time window. This works for One play/vote per browser and One vote per Lead-ID, and brings people back to your Riddle regularly.
| Refresh interval | Your audience can vote again |
|---|---|
| No refresh (default) | Never – one vote in total |
| Hourly | At the start of every full hour |
| Daily | Every day at 00:00 |
| Weekly | Every Monday at 00:00 |
| Monthly | On the 1st of every month at 00:00 |
The windows are fixed calendar times, not rolling periods. They use your time zone in the Creator, the same one used for your Riddle's start and end dates. Example: with Daily, someone who votes at 23:50 can vote again ten minutes later at 00:00, not 24 hours later.
Use cases:
- Daily poll or raffle: Enable One play/vote per browser and select Daily. Everyone can take part once per day, which gives your audience a reason to come back tomorrow.
- Player of the month: Add a form with an email field, enable One vote per Lead-ID with email as the lead identifier, and select Monthly. Each email address can vote once per month, and on the 1st the same poll opens for the next vote.
- Weekly quiz challenge: Select Weekly so returning players get one new attempt every Monday.
Play again
Show your audience a "Play again" button. Disable this for polls or competitions where retaking should not be allowed. Keep it enabled for educational quizzes or fun content where replaying is part of the experience.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable the "Play again" button. This lets your audience retake the Riddle as many times as they like.

Enable IP limit
Limit how many votes can come from the same IP address. This is server-side and cannot be bypassed by clearing cookies. Use it as a stronger layer alongside or instead of browser-based limits.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable IP limit. This makes it harder for bots and scripts to affect your poll.

- Select a Refresh interval for your IP limit from the dropdown menu: Every Minute, Hourly, or Daily.

- Enter the # of tries per period that can come from a single IP address. We recommend 10 based on the use case that people in the same office who share the same IP address can all vote.

A single IP address can vote as often as this number within each period. After that, further votes from this IP address are blocked with an error message until the next period starts.
This does NOT mean each poll taker can take your poll a set number of times (e.g. "4 times per user"). That is still capped at once per browser. - Please note: We never store the actual IP addresses of your audience on our servers. Riddle is an EU-based, GDPR-compliant quiz maker so we don't store personal information like this. Find out more about Riddle.com's privacy policy here.
Enable one vote per lead-ID
Restricting votes by lead identifier adds another layer of security to your polls and quizzes. It prevents people from entering twice and cannot be bypassed in the same way one vote per browser can. Your Riddle needs a form block that collects the lead identifier, e.g. an email field. Without a form, the Status page in Publish shows a warning, because no lead can be collected.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable One vote per Lead-ID.

- Select a Refresh interval if the same lead identifier should be able to vote again later, e.g. once a month. Keep No refresh to allow only one vote in total. See Allow one vote per hour, day, week, or month.

- Go to the Publish section and click on Save and connect data.

- Select a data variable from the Lead identifier dropdown menu, such as phone or email. Someone reusing this lead identifier will be blocked at verification.

What your audience sees: Someone who reuses a lead identifier sees an error message when they submit the form. If the lead identifier comes from the data layer, the error appears right away.
What this means for your stats
With One vote per Lead-ID, only complete, verified submissions are saved. Incomplete or duplicate attempts are not recorded in the statistics, guaranteeing clean, unmanipulated data. The only statistic that may increase is view count, but not starts or completions.
This is why Analyze shows a notice on the Overview, Breakdown, and Audience tabs: "This Riddle has “One vote per Lead-ID” enabled. Only data from users who have completed the Riddle are saved." The notice also appears if the option was enabled at any point in the past. It is not shown on Leads & CTA, because your lead data is not affected.

Example: 500 people start your poll, 300 of them finish and submit the form. Analyze shows 300 starts and 300 completions, so the conversion from start to completion is 100%. The 200 people who dropped out are not counted, because their starts were never saved.
Enable spam filter for emails
Block disposable or temporary email addresses from being entered in forms. This requires your Riddle to have a form block with an email field.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable Spam filter for emails.

- Email addresses from GitHub's open source disposable email domains list will then be blocked. Your audience will then be asked to use a trusted email address instead.

Privacy opt-ins
Add consent boxes for your audience to click on before viewing the content on these sites.
- Go to the Settings section and click on Security: Multiple entries & bot protection.

- Enable Privacy Opt-ins (YouTube, Vimeo, X). This is to add another step of consent because YouTube, Vimeo, and X add cookies to any of their content that is embedded in your Riddle.

- Enter a message you want to appear in the Privacy text fields (optional).

- Enter your preferred text into the Privacy text button field for what the button itself should say.

Tips
- Casual polls or fun quizzes: Enable One play/vote per browser and keep the "Play again" button on. This prevents casual duplicate voting while keeping the experience light.
- Competitions with prizes: Combine One vote per Lead-ID (email) with Spam filter for emails and disable the "Play again" button. This is the strongest combination against manipulation.
- Recurring votes: Add a Refresh interval such as Daily or Monthly to One play/vote per browser or One vote per Lead-ID, so people can vote again in every new time window.
- Corporate or office polls: Use IP limit with a generous number of tries (e.g. 10) to allow everyone in a shared office network to participate.
- GDPR-sensitive content with embedded YouTube/Vimeo: Enable Privacy opt-ins to show a consent step before third-party cookies are loaded.

