What makes up a secure account
Security is not a single button but the interplay of several layers. The first is a strong and unique password, the second is extra verification at login, and the third is your own caution towards suspicious messages and links.
The more layers you have switched on, the harder it is for someone to reach your account, even if they got hold of one of them. An attacker who knows your password still runs into the second verification. And if you do not click on fraudulent links, you give them no chance to obtain the password at all.
In the following sections we will go through each layer separately. There is no need to do everything at once, but every step noticeably strengthens your account.
A strong and unique password
Your password is the first line of defence, so it should be long and hard to guess. Rather than a complex jumble of characters, a longer phrase made of a few random words works well, one you can remember but nobody can guess.
The crucial thing is not to use the same password elsewhere too. When it leaks from one service, attackers automatically try it on others. A unique password for Dukat.bet means that a leak from somewhere else will not touch your account.
- Favour length, ideally a longer phrase of several words
- Do not use your name, date of birth or simple sequences
- Have a different password for each service
- Consider a password manager that keeps them safely for you
If you forget your password, there is no need to panic. You restore it using the steps on the forgotten password page. During recovery, set a new password right away, a strong one that is not used anywhere else.
Two-factor authentication
Two-factor authentication, 2FA for short, adds a second step to your password. Besides something you know, that is the password, you confirm the login with something you have with you too, for example a code from an app or a message.
The benefit is fundamental. Even if someone obtained your password, without the second factor they cannot log in. That is exactly why 2FA is considered one of the most effective measures you can take for your account.
The specific verification options may vary, and you will find their current form in your account settings or on the official site. We recommend enabling the second factor as soon as it is available, and keeping any backup codes in a safe place. If you cannot log in even after entering the code, the login issues page will help.
How to spot phishing
Phishing is an attempt to lure your login details out of you with a fraudulent message that looks trustworthy. An email or SMS arrives imitating official communication and pressures you to act quickly, for example under the threat of your account being blocked.
Typical signs are an urgent tone, grammatical errors, an impersonal greeting and a link pointing to an address that merely resembles the official one. The goal is for you to click and enter your password on a fake site.
| Warning sign | How to react |
|---|---|
| An urgent call to act at once | Do not react under stress, verify it independently |
| A link to a similar but different address | Do not click, open the site manually in your browser |
| A request for your password by email or SMS | Ignore it, support never asks for a password |
| An unexpected attachment | Do not open it |
The golden rule is this: never enter your password via a link from an email or message. Open the site yourself directly in your browser and log in there. If you receive a suspicious message posing as Dukat.bet, report it via the contact page.
Protecting your personal data
Security is not only about logging in, but also about how you handle data while playing. Log in from your own devices and avoid entering your password on public computers, where you cannot know what is running on them.
Be more careful on public Wi-Fi networks, because the transfer may be less protected. When you finish playing on someone else's or a shared device, always log out; do not rely on simply closing the window.
Think too about who can see your screen, and never give your password to anyone, not even family or acquaintances. What data is processed and how it is protected is described on the privacy page. It is worth reading so that you know what you control about your account.
Signs of unauthorised access and what to do
Sometimes, despite your caution, someone else gains access to your account. The important thing is to spot it in time. Be alert to logins you did not carry out, changes to details you did not make, or activity on the account without your knowledge.
If you have such a suspicion, act quickly and methodically:
- Change your password at once to a new and unique one via the forgotten password page.
- If you cannot log in, follow the advice on the login issues page.
- Turn on two-factor authentication if it is not already active.
- Check your account details and history to see whether anything has changed.
- Contact support without delay via the contact page and describe what you noticed.
The sooner you react, the less room an attacker gets. A quick password change and alerting support are the first two steps to take every time.