> For the complete documentation index, see [llms.txt](https://docs.norrnext.com/norrcompetition/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.norrnext.com/norrcompetition/faq/how-the-protection-from-unfair-voting-is-implemented.md).

# How the protection from unfair voting is implemented?

NorrCompetition implements multi-layered security mechanics to prevent voter fraud, duplicate votes, and automated bot voting.

***

## Protection Levels

### 1. User Authentication (ACL Permissions)

The most robust protection is restricting voting privileges to authenticated members.

* In **Options > Permissions** tab, set **Vote** to *Allowed* strictly for **Registered** (or custom verified) user groups.
* The system checks the user's Joomla ID and blocks duplicate votes according to the configured **Vote Frequency**.
* Learn more in the [Permissions Guide](/norrcompetition/configuration/permissions.md).

### 2. Email Verification Codes (OTP)

When allowing guest/unregistered users to vote, you can require email verification via the **NorrCompetition Token Email** plugin (`plg_competition_token_email`):

* A one-time verification code (OTP) is sent to the voter's email address.
* The vote is confirmed and tallied only after entering the valid verification code.

### 3. IP Address Check

* In **Options > Contest** tab (under **Voting Options**), enable **Check IP**.
* The voter's IP address is verified against existing records.
* *Note:* Because public networks, mobile carriers, and corporate offices often share outbound IP addresses, IP checking is best combined with Browser Fingerprinting.

### 4. Browser Fingerprint Check

* In **Options > Contest** tab (under **Voting Options**), enable **Check Fingerprint**.
* Collects anonymous browser and device characteristics (canvas rendering, screen depth, timezone, user-agent) to uniquely identify devices even when cookies are cleared or private browsing is used.

### 5. Cookie Check

* In **Options > Contest** tab (under **Voting Options**), enable **Check Cookie**.
* Sets a secure browser cookie marking the vote transaction.

### 6. CAPTCHA & Cloudflare Turnstile

* For frontend voting and guest submissions, enable CAPTCHA in **Options > Contest** or contest layout options.
* Supports modern Joomla 5 CAPTCHA plugins (including Cloudflare Turnstile and Invisible CAPTCHA) to filter automated bots without hindering legitimate voters.
* See [Entry Layout Options](/norrcompetition/entries/entry-layout-options.md).

***

{% hint style="info" %}
**Recommended Security Strategy:** For public/guest voting contests, combine **Check IP + Check Fingerprint + CAPTCHA / Email Verification Codes** for optimal fraud prevention. For high-stakes or prize-awarding competitions, require **Registered User Voting**.
{% endhint %}
