How to Spot a Fake Bonus Offer

·

How to Spot a Fake Bonus Offer

Red flags in the offer wording

Wording gives away more than layout does. Three phrasing patterns appear on nearly every fabricated offer, and each one asserts something a regulated firm is not permitted to say.

Guaranteed or "risk-free" profit

The strongest single signal is certainty about outcome. Words like guaranteed, risk-free, sure profit, no-loss and assured return describe something that does not exist in leveraged trading, and a regulated firm is required to move in the opposite direction: firms must display a standardised risk warning stating the percentage of that provider's own retail client accounts that lose money.

The scale of the underlying reality is why that requirement exists. CySEC's own analysis of a sample of 18 major CFD providers for 1 January 2017 to 31 August 2017 found 76% of client accounts made an overall loss, and ESMA's cross-jurisdiction analyses cited 74-89% of retail accounts losing money, with average losses per client from EUR 1,600 to EUR 29,000. Those are industry-wide regulator figures across many providers rather than any single broker's numbers, and no provider gets to publish a promise that sits above them.

So the check is not a matter of taste. A page offering certainty of profit is either not published by a regulated firm or is not describing a real product. Either answer is enough to stop.

Round percentages like 100%

The second pattern is the shape of the number. Fabricated offers use round, memorable figures because they are written to be repeated rather than derived from any commercial term. A doubled deposit, a flat percentage on the first payment, a headline credit that ends in three zeros: the figure reads well and has no origin.

Two questions separate a real commercial term from a written one. Where is it published, and what are its conditions? Real terms live somewhere specific and arrive with the boring parts attached, because the boring parts are what make them enforceable. Invented ones have a headline and nothing behind it, and asking for the conditions produces either silence or a second invented answer. The particular case of the doubled-deposit claim is taken apart in why 100% deposit bonus offers are not official.

Pressure to act immediately

The third pattern is time pressure: a countdown, a claim that the offer closes tonight, a limited allocation of codes, a date that quietly matches today whenever you load the page. Its function is to compress the gap between reading and acting, which is the only gap in which checking happens.

A useful counter-habit is to reload the page and watch what the timer does. If it restarts, it was never tracking anything. More broadly, urgency should be read as a statement about the publisher's intent rather than about the offer's availability, since a real commercial term survives the ten minutes you spend confirming it.

  • Certainty about profit: no regulated firm may promise it.
  • A round headline number with no published conditions.
  • A countdown or scarcity counter that resets or never actually expires.
  • A date that updates itself to today on every visit.
  • Language about being "selected" or "eligible" without any account context.

Certainty of profit, a round unconditioned number and a countdown are the three phrasing tells; any one of them is enough to stop reading.

Warning signs in the web address

An address carries more information than the whole page above it. Fabricated offers have to live somewhere, and where they live is the hardest part of the illusion to fake convincingly.

Misspelled brand domains

The oldest technique is a domain that is nearly the brand: a doubled letter, a missing one, a transposed pair, a hyphen inserted between two words, or characters that look similar at a glance. It works because reading is pattern matching, and a familiar shape is accepted without inspection, particularly on a phone where the address bar is short and often partly hidden.

The defence is a habit rather than an act of vigilance. Read the address left to right and identify the registrable domain, which is the part immediately before the top-level suffix. Everything to the left of it can be set to anything at all by whoever controls the domain, so the words you recognise there prove nothing. If the registrable part is not exactly the broker's own domain, you are not on the broker.

Odd subdomains and suffixes

A related trick puts the brand where it is not load-bearing. The brand name appears as a subdomain of an unrelated domain, or as a path segment, or in front of an unusual country or generic suffix, and the eye reads the brand and stops. Free hosting subdomains, link shorteners and redirect chains all produce the same effect.

Two rules cover this without any technical knowledge. First, the only part of an address that identifies who runs a site is the registrable domain plus its suffix; a brand name anywhere else in the address is decoration. Second, a link that passes through a shortener or a redirect hides the destination until you arrive, which means the destination has to be checked in the address bar after loading rather than trusted beforehand. Neither rule requires you to remember a list of suspicious suffixes.

No valid security certificate

The certificate check is quick and its limits matter as much as its value. A browser warning about a certificate, an expired certificate, or a name mismatch between the certificate and the address is a hard stop, and it should never be clicked through on a page connected to money.

The limit is that a valid certificate proves only that the connection is encrypted and matches the domain you are on. It says nothing about who owns the domain or whether the site is honest, and certificates are freely available to anyone, including operators of impersonation sites. So a padlock confirms you are talking privately to whatever domain is in the bar; it is the domain itself that has to be right. The impersonation side of this is covered in phishing and clone sites using bonus bait.

Only the registrable domain identifies who runs a site; a brand name in a subdomain or path and a padlock on the wrong domain both prove nothing.

Suspicious requested actions

What an offer asks you to do separates a wasted click from a real loss. Marketing wants a click; anything beyond a click belongs to a different category of page.

Deposits to unknown wallets

The clearest disqualifier is a request to send money anywhere other than the broker's own cashier while signed in. Variants include a wallet address given in a chat, an "activation fee" said to unlock a bonus, a request to fund through an intermediary who will apply the promotion for you, or a bank account in a personal name.

The reasoning is simple and does not depend on judging the site. A funded trading account is funded from inside the platform, and every deposit and withdrawal method offered to your account depends on your country and is shown in the cashier. Money sent outside that route has not reached any trading account, and transfers to wallets are generally not reversible. Treat the request as the whole answer.

Sharing passwords or codes

The second disqualifier is any request for something that authenticates you: a password, a one-time code, an authenticator value, remote access to your device, or an offer to log in on your behalf and set the promotion up. These arrive framed as help, and the framing is the technique.

Hold one rule without exceptions. Nothing about a promotion ever requires a third party to hold your credentials, and no legitimate support process asks for a one-time code, since a one-time code exists precisely to prove that the person holding it is you. A request for one is a request to become you.

Installing unofficial apps

The third disqualifier is software from outside the official channels: an installer file sent in a chat, an application package offered as a "bonus version" of the platform, a browser extension promising to apply codes automatically, or a trading assistant that needs your account details. Software installed this way runs with whatever access you grant it, and it can read what you type.

Use official app-store listings and the broker's own site, and nothing else. A modified client offering features the real platform does not have is describing itself accurately: it is not the real platform.

  • Funds requested outside the platform cashier: stop.
  • Password, one-time code or remote access requested: stop.
  • Installer, extension or bot offered outside an official store: stop.
  • Identity documents requested by a site that is not the broker: stop.

None of these four require you to have decided whether the offer is real. That is the point of using the request rather than the appearance as your test.

Marketing asks for a click; requests for funds outside the cashier, for credentials, or for unofficial software put a page in a different category entirely.

Cross-checking before you trust

Checking takes minutes and settles most cases outright. The sequence below is deliberately ordered so that the cheapest checks come first and you stop at the first clear failure.

Comparing with official channels

The first comparison is against the source that would carry the offer if it existed. Anything official is published by the broker on its own properties or is visible inside your logged-in account, and nowhere else. A third-party page cannot know which legal entity your account belongs to, which is the fact that decides whether an inducement may be offered to you at all.

  1. Read the promise. If it guarantees profit or removes risk, stop here. No regulated firm may make that claim.
  2. Read the address. Identify the registrable domain immediately before the suffix. If it is not iqoption.com, you are not on the broker, whatever the page looks like.
  3. Read the request. If the page wants funds outside the cashier, a password, a one-time code, documents or an installer, stop and close it.
  4. Look for the conditions. A real commercial term has published conditions. A headline number with nothing behind it is copy, not a term.
  5. Check the rule. CySEC's national measures prohibit providing a retail client with a payment, monetary or excluded non-monetary benefit in relation to the marketing, distribution or sale of a CFD. An offer of a deposit bonus to an EEA retail client contradicts that.
  6. Check your own account. Reach the platform by typing the address yourself, sign in, and look at the Promo section. Whatever is live for you is there or it is nowhere.
  7. Decide once. If steps one to six leave any doubt, treat the offer as not real and move on. There is no cost to declining an offer that does not exist.

Searching the exact offer text

The second check is a search for the offer's own sentence in quotation marks. Fabricated offers are produced from templates and reused across many sites, so the same wording usually appears on a row of unrelated domains with only the brand name swapped. Seeing the sentence attached to four different brokers is a complete answer.

Watch what the results contain as well as how many there are. A real commercial term produces results on the broker's own properties. A template produces results only on other third-party pages, which is a chain of copies with no original at the end of it.

Reading independent discussion

The third check is other people's experience, used with care. Discussion is useful for one narrow thing: finding out whether an offer or a domain has been encountered before and what happened next. It is not useful as proof that an offer is real, because positive confirmations are the easiest thing in the world to manufacture.

Read for specifics and dates rather than verdicts. An account of what a page asked for, on a named date, is informative; a one-line "it works" is not. And treat pre-2018 material as historical: the product intervention agreed on 23 March 2018 and announced on 27 March 2018 changed what may be offered to retail clients in the EU, so bonus discussions older than that describe a market that no longer exists. The background is set out in the history of IQ Option bonuses.

Run the seven steps in order, search the offer's exact wording to find the template it came from, and read discussion for dated specifics rather than verdicts.

What to do if you spot one

Spotting one is only useful if you know what to do next. The right response is smaller than most people expect, and the biggest mistake is engaging in order to find out more.

Avoiding any interaction

The first response is to stop, not to investigate. Do not enter a code to see what happens, do not reply to the message, do not open the attachment, and do not sign in anywhere to test whether the offer applies. Each of those actions is the step the page was built to obtain, and testing it supplies exactly what testing was meant to avoid.

Two smaller points matter here. Interacting at all can confirm to the operator that a real person is at your address or number, which tends to produce more contact rather than less. And if you want to know whether something exists, the way to find out is to reach the platform by typing the address yourself and look, which answers the question without touching the suspect page.

Reporting where possible

Reporting is worth a couple of minutes even though nothing visible usually happens straight away. Report the page to the search engine or platform where you found it, report impersonation to the broker through its official support channel, and, if funds or card details were involved, contact your payment provider first and quickly, since timing matters more than certainty at that stage.

Keep the details you have: the address, the date, a copy of the message. If a domain that impersonates a brand is reported by enough people, it tends to lose reach faster, and your report costs you nothing beyond the two minutes.

Warning others when you can

The last step is social, and it works. Fabricated offers travel through groups, comment fields and forwarded messages, so a short, factual note in the same place slows the same message down for everyone who sees it after you.

Keep the note specific and unemotional: what the page asked for, what the address was, and what the actual position is. In this case the actual position is short. No publicly verifiable official promo code could be found during research checked on 3 September 2026; EEA retail clients of the CySEC-regulated entity cannot be offered a monetary inducement; and what any individual account can see depends on entity, country and date, which only the platform itself can settle. If you want somewhere useful to send the person instead, the free demo account with $10,000 in virtual funds needs no code and no deposit, and the alternatives that do exist are set out in what you actually get instead of a bonus.

Regulatory permissions and platform offers change, so this page reflects official CySEC, ESMA and IQ Option sources checked on 3 September 2026, and you should confirm anything that matters to you on the broker's own site before you deposit.

Stop rather than test, report the page and keep the details, and replace the false offer with the real alternative when you tell someone else.

Frequently asked questions

What is the single fastest way to tell a fake bonus offer?

Read what it promises and then read the address bar. A promise of guaranteed or risk-free profit cannot lawfully be made by a regulated firm, which are required to display a standardised risk warning stating the percentage of their own retail accounts that lose money. And if the registrable domain immediately before the suffix is not the broker's own, you are not on the broker regardless of how the page looks. Those two checks take about fifteen seconds and settle most cases before any of the finer points matter.

Does a padlock in the address bar mean the offer is safe?

No. A certificate proves that the connection is encrypted and that it matches the domain shown in the bar, and nothing more. It says nothing about who owns the domain or whether the content is honest, and certificates are freely available to anyone, including operators of impersonation sites. Check the domain first and the certificate second: a padlock on a look-alike domain is a secure connection to the wrong party, which is precisely what a well-made clone offers.

Someone offered to apply a promo code to my account for me. Is that normal?

No, and it should end the conversation. Applying a promotion never requires a third party to hold your password, your one-time code or remote access to your device, and a one-time code exists specifically to prove that the person holding it is you. Requests like this arrive framed as helpful support, which is the technique rather than an accident. If a code applies to your account, it is entered inside the platform after you have signed in yourself.

How do I check whether an offer text is a template?

Search a distinctive sentence from the offer in quotation marks. Fabricated offers are produced at volume from templates, so the same wording usually turns up across several unrelated sites with only the broker name changed, which answers the question immediately. Pay attention to where the results sit as well: a real commercial term produces results on the broker's own properties, while a template produces only more third-party copies with no original behind them.

I entered my password on a page that turned out to be fake. What now?

Treat it as a credential exposure and move quickly. Reach the real platform by typing the address yourself rather than through any link you were sent, change the password there, and enable strong authentication. Change that password anywhere else it was reused, since reuse is what turns one exposure into several. If card details were entered, contact your card issuer, and if you sent funds outside the broker's cashier, contact your payment provider promptly. Then report the page to the broker's official support channel and to the platform where you found it.