Also known as: Shared IP Address, Same IP, IP Collision
A duplicate IP is when two or more trading accounts or affiliate sign-ups originate from the same Internet Protocol address. Because an IP identifies the network a device connects from, matching IPs across accounts is one of the first signals a broker's fraud engine checks for self-dealing or multi-account abuse.
IP addresses are not perfectly unique to a person. A home Wi-Fi router, an office network, a coffee-shop hotspot, or a shared VPN endpoint can put dozens of legitimate users behind one public IP. So a duplicate IP is a suspicion trigger, not proof of fraud — the fraud system combines it with device fingerprints, timing, and payment data before acting.
For partners the risk is specific: if an IB's referred clients repeatedly share the IB's own IP address, the broker reads it as self-rebating — the IB creating accounts to earn rebates on their own trades. Commissions on those accounts are held or rejected, and the partnership is scrutinised. The same flag fires if an IB logs into clients' accounts from the IB's home connection.
Example: an IB runs an in-person onboarding session and helps 20 attendees register over the venue's single Wi-Fi network. All 20 sign-ups land on one IP within an hour. The broker's system raises a duplicate-IP alert and freezes the CPA payouts until the IB explains the event and the manager whitelists the address.
When an account registers or logs in, the broker records the public IP the request came from. The fraud engine indexes accounts by IP and raises a flag when several accounts — especially newly created ones tied to one affiliate — cluster on the same address within a short window.
Because NAT, corporate networks, mobile carriers, and VPNs legitimately share IPs, a duplicate alone rarely blocks an account. It raises the account's risk score and is cross-checked against device fingerprint, KYC data, deposit method, and login timing. A duplicate IP plus a matching device fingerprint plus a shared payment card is a strong self-rebate signature; a duplicate IP with otherwise clean, distinct signals is often cleared after review.
The broker logs the public IP on every registration and login.
Accounts are grouped by IP; several new accounts on one address raise a flag.
The flag is combined with device fingerprint, KYC, payment method, and timing to score real risk.
Genuine cases (a shared venue) are whitelisted; self-rebate patterns have commissions rejected and accounts reviewed.
Why it matters for partnership: Brokers watch IPs to stop self-rebating and multi-account fraud, so clients repeatedly sharing your IP get commissions rejected. Warn your manager before events on shared Wi-Fi, and never sign clients up on your own connection.
An IB hosts a local trading seminar for Exness and helps 20 attendees register on the venue's single Wi-Fi network within an hour. All 20 sign-ups share one public IP, triggering a duplicate-IP alert and a hold on roughly $600 in CPA. After the IB explains the event, the affiliate manager whitelists the venue IP and releases the payouts.
Before any physical event where clients register on the same network, message your affiliate manager with the date and venue so they can whitelist the IP in advance.
Logging into clients' trading accounts from your own computer to 'help them trade' — this violates the terms and triggers duplicate-IP alerts that void your commissions.
Not by itself. It raises your risk score, but brokers cross-check device fingerprint, payment, and timing before rejecting anything. Clean, distinct signals are usually cleared on review.
It can trigger a flag because shared broadband uses one public IP. Tell your manager the situation so the pattern is understood and not read as self-dealing.
Yes. Many users on the same VPN server exit through one IP, so a shared VPN can cluster unrelated clients on a single address.
Trading on accounts you refer, from your own IP or device, is the classic self-rebate pattern and is prohibited. Commissions are voided and the account reviewed.
Whitelist the venue Wi-Fi with your manager beforehand, or have attendees register on their own mobile data instead of the shared network.
Somewhat — home IPs rotate periodically, so a match may be coincidental. Fraud engines account for this by weighting duplicates alongside stronger signals like device fingerprints.