You bought a batch of leads. The phone numbers work. People answer. And almost none of them has any idea who you are. Nothing bounced, nothing looked fake, and the file was clean on every check you ran. That is the signature of co-registration traffic, and it is the hardest bad lead to catch, because a co-reg lead is the one category where nothing in the data is fake. The person is real. The consent box was really checked. The only fiction is the interest, and interest is not a field. This is the buyer’s-eye guide to that problem: how a co-reg lead is made, why every filter you own passes it, what the FTC’s enforcement record shows, and how to buy verified instead. It is a spoke off our ad fraud in lead generation pillar, which maps the whole fraud landscape; here we go deep on this one slice.
- A co-registration lead is a contact captured as a side offer while someone was chasing a reward from a different offer: a survey, a sweepstakes, a gift card.
- Everything on the record is real, including the consent checkbox. The interest is the only fiction, and it never appears as a field.
- That is why bot filters, form validation, email checks, phone lookups and call-duration rules all pass it. They inspect the record, and the record is clean.
- The FTC has prosecuted the machinery behind this. It alleged Fluent, LLC ran a consent farm using fake job and gift-card lures, sold more than 620 million telemarketing leads over two years, and settled for a $2.5 million penalty, data destruction, and a robocall ban.
- You cannot sort this out of a file after the fact. You fix it at capture, with a real-time step tied to your specific offer, plus a written no-incentivized-traffic term in the contract.
Quick answers:
- What is a co-registration lead?
- Are co-registration leads always bad?
- Why do co-registration leads pass fraud filters?
- What did the FTC do about consent farms?
- Does OTP verification stop co-registration leads?
- How do I tell if my lead source is selling me co-registration traffic?
A word on sourcing, because this topic attracts scary numbers. The FTC figures below are confirmed enforcement facts, re-verified against the agency’s own release and corroborated in national press; the aggregate for the wider sweep is labeled reported. We state no vendor fraud percentages at all, because nobody has audited the share of co-registration traffic in the lead market. Nothing here is legal advice. And we write this as an operator: Elevarus buys clicks and runs verified-lead funnels, so the only question that matters to us is whether a lead is a real, reachable person who actually wanted what you sell.
What a co-registration lead actually is
Start with the mechanics, because once you see the path the person walked, everything else follows.
Someone clicks an offer that promises a reward. A job opportunity. A gift card. A sweepstakes entry. They land on a site that has nothing to do with your business and start a survey to claim the thing they came for. Partway through, a secondary prompt appears: check this box for more information about an unrelated offer. They check it, because it is one more step between them and the reward, and saying yes costs them nothing. A lead record is created and delivered to a buyer.
That is a co-registration lead. Note what the industry itself concedes about the format. These placements are non-exclusive by design, so the same record can be sold to several companies at once, and the quality of the consent depends entirely on how clearly the disclosure explained what checking that box meant. Even compliance vendors describing the format neutrally put it in the middle of the quality range, and that is the version where everyone behaved.
The motivation is the part worth sitting with. The person was not evaluating your offer. They were paying a toll. The stronger the incentive on the primary offer, the more completions the placement generates, and the further the resulting interest drifts from anything you sell. That is not an abuse of the format. That is the format working as designed.
The lure
The flow
The side offer
The click
The sale
- A real human being
- A real name
- A real phone number that answers
- A real email address
- A real timestamp and IP address
- A real form URL and consent checkbox
- The interest.
Why nothing about it is fake
Here is the part that makes this category genuinely different from every other kind of bad lead, and it is worth being precise about.
Fraud detection works by finding a mismatch between a record and reality. A phone number that does not exist. An email domain that bounces. A browser signature that says headless automation. A submission from an IP that has filled two hundred forms this hour.
A co-registration lead has no mismatch anywhere. A human sat there and typed their own name. The phone rings and they pick it up. The email receives. The timestamp is genuine, the IP is a home connection, the form URL exists, and there is a real record of a real box being really checked. The defect is not in any field. It is in what the record means, and meaning is not a column you can validate.
| The check you run | What it actually tests | Why a co-reg lead passes |
|---|---|---|
| Bot and device fingerprinting | Was this submission automated? | It was not. A human filled it out. |
| Form validation | Are the fields well formed and complete? | They are. The person typed their real information. |
| CAPTCHA | Is a human present? | Yes. That is the whole problem. |
| Email verification | Does this mailbox exist and accept mail? | It does. It is their real address. |
| Phone lookup and line type | Is this a real, active, non-VoIP number? | It is. It is the phone in their pocket. |
| Call duration threshold | Did the call last long enough to be real? | A real, confused person talks past any threshold. |
| Consent record on file | Is there documented consent? | There is. A real box was really checked. |
Read that table as one sentence: every tool in the stack is asking whether a real person was present, and a real person was present. The pillar covers why the easy defenses fail across the whole fraud landscape. This is the sharpest version of it, because here the defenses are not being evaded at all. They are being satisfied honestly, by a lead that is worth nothing to you.
The four variants you will actually be sold
“Co-reg” gets used loosely on sales calls, so it helps to separate what a source might be handing you. These overlap, and one bad file often contains all four.
Classic co-registration. The side-box capture described above. Real person, real consent record, byproduct interest, sold non-exclusively.
Incentivized traffic. The broader family: any lead where the motivation was a reward rather than your product. Sweepstakes, gift cards, points programs, gated-content offers. Harder to catch than bots, precisely because these people pass every humanness test by being human.
Aged and recycled data. A real contact captured once and resold months or years later. Sometimes it was co-reg originally, sometimes a genuinely interested person whose project ended long ago. The number is real; the moment has passed.
Multi-sold and reshuffled records. The same person delivered to several buyers, repackaged through intermediaries until you cannot see the original source. This is what turns one indifferent checkbox into five companies calling the same person about five different things. The distribution machinery that makes that routine is worth understanding on its own: how ping-post lead distribution works.
The pillar’s map of who is actually behind the fake leads places these alongside the bot networks and click farms. The distinction that matters here: bots are trying to look human. These four are not trying to look like anything. They are human, and the deception, where there is one, happened at the disclosure, not at the data.
What the FTC record actually shows
This section describes public enforcement actions. It is not legal advice, and your own obligations are a question for your counsel. But the record is worth knowing, because it is the only part of this topic with hard, non-vendor numbers attached.
In July 2023, the FTC and its law enforcement partners announced Operation Stop Scam Calls, which the agency described as more than 180 enforcement actions brought by 48 federal and 54 state agencies (reported). Separately, the FTC reports that courts have ordered defendants to pay more than $2 billion across the 167 robocall and Do Not Call cases the agency has brought (reported). The FTC named a category in that sweep and gave it a phrase: consent farms. Its position is that third-party lead generation for robocalls is illegal under the Telemarketing Sales Rule when the generator falsely represents that consumers agreed to be called.
The case built directly on co-registration mechanics was against Fluent, LLC. The FTC alleged Fluent and affiliated companies lured consumers with deceptive advertising, including false promises of job opportunities and a $1,000 gift card, then used dark patterns to collect personal information and manufacture what looked like consent to be contacted. According to the FTC, between January 2018 and December 2019, Fluent obtained and sold more than 620 million telemarketing leads. Under the proposed order, Fluent agreed to a $2.5 million civil penalty, had to destroy the consumer information it had collected, and was banned from engaging in, assisting, or facilitating robocalls. A second company in the sweep, Viceroy Media Solutions, was charged over a fake job-board operation on the same pattern.
Two things in that record matter to a buyer. The first is scale: more than 620 million leads over two years came out of one operation the FTC characterized as a consent farm. Whatever share of the market that represents, and nobody has audited it, this is not a fringe activity.
The second is the FTC’s position on who is responsible. The agency has been explicit that a telemarketer cannot simply rely on a lead generator’s claim that consent exists. Whether that creates an obligation for you is a question for your own counsel. But the commercial implication holds even setting law aside: a consent record you did not witness being collected, on a form you have never seen, from a site the vendor will not name, is a piece of paper, not a fact.
The fix cannot live in the file
If the defect is not in any field, then no amount of post-purchase cleaning gets it out. You can scrub, dedupe, append and score a co-registration file forever, and every record will come back clean, because every record is clean. That is why the fix has to move upstream to the moment of capture.
What works there is a real-time step tied specifically to your offer. In practice that means one-time-passcode lead verification: at submission, a code goes to the number the person just entered, and the lead is not accepted until they receive it and type it back.
Against bots and dead numbers that works for the obvious reason: nobody relays a code from a phone they do not have. Against a co-registration lead the mechanism is different, and it is not a technical defeat. It is a motivational one. The person chasing a gift card has already gotten their reward from the survey. Your verification step gives them nothing. It is pure friction attached to an offer they were not seeking, arriving while they are trying to finish something else. Someone with genuine interest completes it. Someone paying a toll disproportionately does not. The one-click checkbox becomes a deliberate act tied to your product, and that is the only point in the funnel where the difference between real interest and byproduct interest becomes observable.
Be honest about what that is: a sound mechanism, not an audited statistic. We will not hand you a drop-off percentage, because the ones in circulation come from companies selling verification software. The pillar walks through how OTP and real-time verification defeat each fraud vector in full.
Two guardrails. OTP is lead verification, not call tracking; it filters at the conversion event and says nothing about what happens on the call afterward, and those two jobs get conflated constantly. And Elevarus runs this as an operator, inside our own funnels, not as a verification product. One second-order benefit: when only verified leads are fed back as conversions, your bidding stops being trained by indifferent checkboxes. Same discipline as our Performance Max spam-leads guide, and the pillar covers the verified-lead to bidding loop in detail.
What verification will not do
Overselling this would be its own kind of dishonesty, so here are the limits plainly.
A real-time step proves three things: the number is real and in service, the person had live access to it, and they were motivated enough to complete an extra action. That is a high bar against bulk, cheap, farmed traffic. It is not a lie detector for intent. Someone genuinely curious but nowhere near buying passes it and is still a soft lead, and someone deep enough into a reward flow may complete it on momentum alone.
Verification and qualification are complementary layers, not substitutes. Verification removes the floor of farmed noise so your screening, scoring and triage run on real, reachable, consenting humans instead of on a file salted with byproducts. It does not do the qualifying for you. The pillar is candid about the honest limits of OTP verification, including how a determined individual attacker can still work around it.
And the boring truth: the strongest defense against co-registration traffic is not a technology at all. It is a term in a contract, plus the willingness to walk away from a source that will not sign it.
The buyer’s checklist
Five demands. Make them before you spend, not after the first bad batch.
- No incentivized or co-registration traffic, in writing. The load-bearing one, and it belongs in the contract rather than the sales call. Ask specifically whether any lead can originate from a survey router, a sweepstakes, a gift-card or reward offer, or a co-registration placement. Vague reassurance is a no.
- A real-time verification step at capture. Not a certificate emailed after the sale, not a formatting check, not a fraud score. An actual step, at submission, proving a person had live access to the number and chose to complete something tied to your offer.
- Consent provenance on every record. Timestamp, IP, the exact form URL and version, and the verbatim consent language the person saw. Per record, retained. A source that has this hands it over without drama; one that offers a sample or a summary does not have it.
- Source transparency. The real domains and creatives the traffic came from. You are allowed to look at the sites. A partner treating its supply chain as a trade secret is asking you to underwrite a risk you may not inspect.
- Exclusivity terms and a replacement policy. Is this lead sold to anyone else, and how many times? If a contact is unreachable or does not recognize your brand, is it credited or replaced? A source willing to stand behind reachability measured it.
Notice what is not on the list: a fraud score, a vendor badge, or a promise that the leads are one hundred percent verified. Those are marketing. A written traffic-source term, real-time verification and per-record provenance are the thing itself.
Run this audit on the file you already bought
You do not have to take any of this on faith, and you do not need new software to check. Pull the last batch you bought, because co-registration contamination has a distinctive shape in your own data.
Call a sample and listen for one specific thing: not hostility, but confusion. A person who does not recognize your brand, cannot recall filling out anything related to what you sell, and is neither angry nor interested is the signature. Then look at the file. Contacts scattered across places you never targeted. The same numbers turning up in more than one supposedly independent source. Submission timestamps clustered in tight bursts that do not match how people browse. And the aggregate tell: a high answer rate sitting next to a floor-level conversion rate. Real humans, real phones, no interest. Any one of those has an innocent explanation. Together they are a source-disclosure problem, not a sales problem.
Then ask your source the question from the checklist above: what was the person doing at the moment they became this lead? You will learn more from how fast they answer than from anything in the pitch deck.
If you would rather not run that experiment on your own budget, that is the argument for buying leads someone verified at capture in the first place. That is what we do as an operator: we run the funnels, verify at the conversion event, and work reachable, in-market people. How our lead generation model works lays out the approach, and you can see it applied in ACA and health insurance, HVAC and solar. Or just book a free call and we will look at your current lead file with you.
Frequently Asked Questions
What is a co-registration lead?
A co-registration lead, or co-reg lead, is a contact captured as a side offer while someone is doing something else. They are partway through a survey, a sweepstakes entry, or a gift-card claim when a secondary prompt appears saying something like check this box to get information about an unrelated offer. They check it, finish what they came for, and a lead record is created and sold. The industry’s own definition concedes the key structural point: these leads are non-exclusive, so the same record can be delivered to multiple buyers. The contact information is completely real. What is not real is the interest, because the person was chasing a reward from someone else’s offer, not shopping for yours.
Are co-registration leads always bad?
Not automatically, and it is worth being precise instead of dramatic. A co-registration placement is a capture method, not a crime, and a well-disclosed one on a genuinely relevant site can produce a contact who actually wanted what you sell. The problem is the economics underneath it. When the placement sits inside a reward flow, the person’s motivation is the reward, and the more effective the incentive is at driving completions, the further the resulting interest drifts from your offer. So the honest framing is not that every co-reg lead is worthless. It is that co-registration is a structural bet on a byproduct, and once you are buying at volume you are buying the average of that bet, not the exceptions. If you want to hold the line, the practical answer is to buy leads that were verified in real time against your specific offer rather than to try to sort a co-reg file after the fact.
Why do co-registration leads pass fraud filters?
Because nothing about them is fake. Fraud filters are built to catch a mismatch between a record and reality: a phone number that does not exist, a bot signature in the browser, gibberish in a name field, an email domain that bounces. A co-reg lead has none of those problems. There is a real person with a real name, a real phone that rings, a real email that receives, a real timestamp and IP, and a real checked consent box. Every field is authentic and every check that reads the fields returns clean. The thing that is wrong with the lead, the fact that the interest was a byproduct of chasing a reward, is not a field on the record. You cannot detect it by inspecting the data, which is why the fix has to happen at capture rather than in the file.
What did the FTC do about consent farms?
This is a description of public enforcement, not legal advice. In July 2023 the FTC and its law enforcement partners announced Operation Stop Scam Calls, which the agency described as more than 180 enforcement actions brought by 48 federal and 54 state agencies (reported). Separately, the FTC reports that courts have ordered defendants to pay more than $2 billion across the 167 robocall and Do Not Call cases the agency has brought (reported). The case most directly about co-registration mechanics was against Fluent, LLC, which the FTC alleged operated as a consent farm: it used deceptive advertising, including false promises of job opportunities and a $1,000 gift card, to collect personal information and manufacture consent to be called. Between January 2018 and December 2019, the FTC says Fluent obtained and sold more than 620 million telemarketing leads. Fluent agreed to a $2.5 million civil penalty, was required to destroy the consumer information it had collected, and was banned from engaging in, assisting, or facilitating robocalls. The FTC also made its position on buyers explicit: telemarketers cannot simply rely on a lead generator’s claim that consent exists.
Does OTP verification stop co-registration leads?
It stops most of them, and the reason is motivation rather than technology. A one-time passcode step fired at the moment of submission asks the person to stop, pick up their phone, read a code, and type it back before the lead is accepted. Someone chasing a gift card on an unrelated survey has already gotten, or is about to get, their reward from that survey. Your extra step gives them nothing, so a low-intent participant disproportionately abandons it rather than completing it. That converts a passive one-click checkbox into a deliberate act tied specifically to your offer. Two honest caveats. The drop-off is a mechanism, not an audited statistic, so treat it as sound reasoning rather than a promised percentage. And OTP is lead verification, not call tracking; it filters the lead at the conversion event and says nothing about what happens on a call afterward.
How do I tell if my lead source is selling me co-registration traffic?
Ask one question and listen to the shape of the answer: what was the person doing at the moment they became this lead? A source that owns its traffic can answer in a sentence, name the sites, and hand you the consent record with the timestamp, IP, form version, and the exact language the person saw. A source that pivots to fraud scores, match rates, or a general assurance that everything is compliant has answered you. Beyond the conversation, the pattern shows up in your own pipeline: contacts who answer the phone but do not recognize your brand, who cannot recall filling anything out, who are geographically scattered in places you never targeted, or who appear in more than one supposedly separate source’s file. High answer rates paired with a floor-level conversion rate is the classic signature, because the humans are real and the intent is not.
Sources
- FTC: Operation Stop Scam Calls enforcement sweep announcement (July 2023) (Confirmed, primary; the sweep of more than 180 enforcement actions brought by 48 federal and 54 state agencies, the FTC’s position that third-party lead generation for robocalls is illegal under the Telemarketing Sales Rule, and the Fluent, LLC allegations, penalty, data-destruction requirement and robocall ban. FTC.gov returns 403 to automated fetches; the release text was re-verified this pass through the government mirror below.)
- Office of the Inspector General, SSA: full text of the FTC enforcement sweep release (Confirmed, primary; a government mirror of the same FTC release, used to re-verify the 620 million leads figure, the January 2018 to December 2019 window, the $2.5 million civil penalty, the bans, and the more than $2 billion courts have ordered across the FTC’s 167 robocall and Do Not Call cases, which we label reported.)
- FTC business guidance: Operation Stop Scam Calls targets operators that facilitate illegal robocalls, including consent farms (Confirmed, primary; the FTC’s own use of the term consent farm and its guidance that telemarketers cannot rely on a lead generator’s claim of consent. Direct fetch returned 403; content corroborated via the mirror above and national press coverage.)
- CBS News: consent farms enabled billions of illegal robocalls, feds say (Confirmed, national press; independent corroboration of the Fluent allegations, the fake job and gift-card lures, the 620 million leads sold, the $2.5 million settlement, and the parallel action against Viceroy Media Solutions.)
- ActiveProspect: what is a co-registration lead (Industry definition, compliance vendor; used only for the trade’s own neutral description of the capture format, including the concessions that co-registration leads are non-exclusive, can be sold to multiple buyers, and depend on how clearly the disclosure explained data sharing.)
- Elevarus: Ad fraud in lead generation and OTP verification (pillar) (Internal; the full fraud-actor taxonomy, the channel-by-channel map, why the easy defenses fail, the OTP mechanics, the bidding loop, and the honest limits this spoke links up to rather than re-deriving.)





