A strong password and logging in
The first line of defence for your account is the password. A long, unique password is worth more than a short string that only looks complicated.
Length is often more important than special characters. A few words that are easy for you to remember but unpredictable to others make for a solution that is both strong and convenient.
Do not use the same password on several sites. If one service is leaked, your other accounts are put at risk too. It is worth using a password manager that generates and stores strong passwords. Where it is available, turn on two-factor authentication as well, because it adds an extra layer of protection.
Never share your login details with anyone. No serious provider will ask for your full password by email or over the phone.
It is worth changing your password from time to time, especially if you notice anything suspicious. And gradually replace old passwords used in several places with unique ones.
The concept of identification (KYC)
Regulated providers verify the identity of their customers. This is called KYC, meaning the "know your customer" principle.
This is not harassment but a legal and security requirement. The aim is to prevent money laundering, to screen out minors and to protect your account. Identification generally requires a document and proof of address; the exact list is set by the provider.
Identification is in your interest too. It makes it harder for someone else to reach the account in your name, and it means the withdrawal goes to the real owner. It is worth doing in good time, so a transaction does not get stuck later.
Upload your documents only on the official, secure interface. Never send them to a third party, by email or in a chat. We cover the payment basics in the payments guide.
Device and network security
Your account is only as secure as your device is. An out-of-date phone or computer is an easier target, which is why updating is not a luxury but a basic.
Keep your browser and operating system up to date, because updates close known gaps. Use a screen lock, and do not leave a logged-in device unattended. Do not carry out financial transactions on public, password-free Wi-Fi, because traffic can be intercepted more easily there.
Only install an app or extension from a trusted source. A dubious add-on can watch what you type without you noticing, so less is sometimes safer.
If you use a shared machine, always log out, and do not save the password in the browser. A little care spares you a lot of trouble.
Phishing and fake sites
Fraudsters often try to win your trust with messages that look genuine. An email with an urgent tone or the promise of a "prize" should always be suspect.
Always check the web address before you log in or enter any details. A difference of a single character can take you to a fake site. Do not click on unsolicited links, and do not download an APK from an unknown source, because on mobile Dukat.bet is reached through the browser version.
A suspicious message often contains grammatical errors, a strange sender or an unusual request. If anything does not add up, do not reply, and under no circumstances enter your login details on a page reached from a link.
If you are unsure, always look for the provider's contact details on the official site, not in a message. The licence check guide shows how to verify the licence step by step.
If something does go wrong
Sometimes even the most careful user runs into trouble. A quick reaction matters a great deal then, so it is worth knowing the steps in advance.
If you notice a suspicious login or an unusual transaction, first change your password. Where possible, turn on two-factor authentication, and review the email address tied to the account. Check that no one has changed your contact details.
After that, get in touch with official customer support, because locking the account and investigating are their responsibility. We cannot act on this, but we can point you in the right direction.
Keep any suspicious messages, because they can help with the investigation. And do not be embarrassed to report the problem: the sooner you speak up, the smaller the damage.
If you used the same password elsewhere too, update those accounts as well. A leaked password spreads quickly, so it is worth closing the gaps all at once.
Only on the official site
The most important rule is simple: for your account, deposits and withdrawals, use only the official site. Avoid intermediaries, "speeded-up" interfaces and unofficial links.
Check that the connection is encrypted, and that the address bar really shows the official address. You can read about the security of your own data on the privacy page, and about responsible limits on the responsible gaming page.
"Speeded-up" or "guaranteed" promises often play the role of bait. A trustworthy service does not rush you, and does not ask you for unusual steps to log in or to withdraw.
A calm head is worth a lot. If no one is rushing you, you have more time to think through your decisions, and there is less chance of a mistake.
It is worth saving the official address to your bookmarks and always starting from there. That way you avoid being led astray by a misleading search result or a fake link.
When you are looking for official, up-to-date information about Dukat.bet's security measures, you will find it here: Dukat.bet security and KYC.