A tour of the edge filter — what each checker actually inspects, how the signals combine into a score, and why the visitor never notices.
"Antifraud" is a marketing word until you can see exactly what it inspects. Here is every signal the Mask pulls on a lead, in order, and how they roll up into a single accept/divert decision.
IP-intelligence providers resolve geo, connection type, and proxy/VPN/hosting risk. A residential IP in the target geo scores low risk; a datacenter IP or a mismatched country is a strong fraud signal.
An HLR lookup asks the carrier network directly whether the MSISDN is live and which operator owns it. An enrichment layer adds how many services that number is tied to. A dead or freshly-minted number rarely becomes a paying customer.
Real people leave a trail: the email is registered on social and commercial platforms. A throwaway address with zero footprint is a classic junk-lead marker.
Is the phone number actually on Telegram and WhatsApp? Presence correlates strongly with a reachable, real user — which is exactly what the partner's call center needs.
A CreepJS-style fingerprint flags automation, headless browsers, and impossible device profiles before a bot ever reaches your partner.
The visitor sees a spinner. You see a six-line decision log and a routed lead.
Each checker returns a normalized risk contribution; the Mask combines them against your per-flow thresholds and either accepts and routes the lead, or diverts it to Unassigned. You tune the weights per flow — some offers tolerate more risk than others.