Paddy Power Ireland: licence, domain and risk checks

A familiar colour scheme or name is not enough to prove that a betting address is genuine. The decisive first check is the hostname shown in the browser: the verified packet identifies paddypower.com as the exact domain associated with the trading name in the relevant Irish Revenue register entry. An address with added words, misspellings, unusual prefixes or a different ending should be treated as unverified, even if its design looks convincing.
The available primary record supports a match between the exact domain, the Paddy Power trading name and PPB Counterparty Services Ltd under remote bookmaker reference 1010107. It does not establish the ownership of every similar-looking address, prove how individual withdrawals are handled or resolve app-user complaints. The overall signal is therefore amber: there is current primary evidence for the named identity, but important service-level questions remain open.
Decision summary: verified identity, open service evidence
| Question | Evidence-led finding | Practical consequence |
|---|---|---|
| Is the exact domain identified? | Yes. The packet ties paddypower.com to the relevant Revenue entry. | Compare the complete hostname before signing in or paying. |
| Is an Irish operator identity recorded? | Yes. PPB Counterparty Services Ltd is listed with the trading name or domain. | The legal name should be used when documenting a dispute. |
| Is there a bookmaker reference? | Yes: 1010107 in the register dated 30 June 2026. | Check the reference, entity and domain together rather than relying on one field. |
| Are payment and withdrawal performance verified? | No transaction test or account-level records were supplied. | Do not treat speed, acceptance or payout claims as established. |
| Are app reviews proof of misconduct? | No. They are unverified user context. | Preserve relevant records, but distinguish allegations from official findings. |
The evidence does not support calling the exact registered identity a scam. It also does not justify an unrestricted “safe” verdict. A genuine registration cannot authenticate a link sent in a message, settle a balance dispute or show that a particular payment will succeed. Those questions require their own records.
Exact domain, operator and licence match
The strongest item is the Revenue register dated 30 June 2026. It lists PPB Counterparty Services Ltd with the Paddy Power trading name or domain under Revenue remote bookmaker reference 1010107. The source was checked on 21 August 2026.
These elements form one identity chain: paddypower.com, the trading name, the legal entity and reference 1010107. A useful verification repeats all four. Finding only the name is weak because a clone can reproduce it. Finding only a company name is also insufficient if the browser is displaying an unrelated hostname.

No licence expiry date was provided. The record establishes what appeared in the dated register; it should not be stretched into a claim of perpetual authorisation. Ireland’s regulatory arrangements are also in transition. The GRAI operator portal says that GRAI began accepting remote and in-person betting applications in February 2026 and notes the Revenue transition. The Gambling Regulation Act 2024 supplies the statutory framework and establishes GRAI. Neither source in this packet supplies a separate GRAI licence decision for this operator.
Suspicious-address test before sign-in
Read the hostname from right to left, stopping before the first single slash. For the supported address, the registrable domain must be exactly paddypower.com. A longer address can contain that text without belonging to it. For example, paddypower.com.example.invalid belongs to example.invalid, while account.paddypower.com would be a subdomain of the supported domain. The latter structural test does not prove that a specific subdomain is currently used or approved; it only explains how hostname ownership is read.
| Address pattern | What the text indicates | Decision |
|---|---|---|
| paddypower.com | Exact domain named in the evidence packet | Continue only after checking the connection and intended action. |
| secure.paddypower.com | Structurally a subdomain of the exact domain | Not independently confirmed by the packet; verify its purpose. |
| paddypower-login.example.invalid | Different registrable domain using familiar words | Do not enter credentials or payment details. |
| paddypower.com.example.invalid | The supported name appears only as a subdomain of another domain | Treat as unrelated and potentially deceptive. |
| paddy-power.example.invalid | Hyphenated lookalike with a different ending | Not covered by the Revenue match. |
Do not rely on a padlock alone. Encryption can protect a connection to a fraudulent destination. Avoid opening account links from unsolicited texts, advertisements or direct messages. Navigate using a previously verified route, inspect the complete hostname again, and stop if a password manager that normally recognises the service does not offer the saved credential.
Further warning patterns are covered in the scam-warning checks. A suspected clone should be recorded with the full address, time, message origin and screenshots, without continuing to interact with it.
Scam-or-legitimate and legal-or-not assessment
For the precise domain and entity in the packet, the Irish Revenue record is meaningful primary evidence. It supports the conclusion that the trading identity appeared in the dated remote-bookmaker register. Accordingly, there is no basis here for labelling that exact registered identity a scam.
The conclusion is deliberately narrow. “Legitimate identity” does not mean every promotion is suitable, every account decision is correct or every similar address is genuine. Nor does a licence entry prove the outcome of an individual complaint. The amber signal reflects this division: identity evidence is available, while transaction performance, identity-check handling and complaint outcomes have not been independently tested.
The packet also contains a comparison record: Betfair International plc appears with the Betfair trading name or domain under Revenue remote betting intermediary reference 1010108. That is a different entity, trading identity and regulatory category. It must not be merged with reference 1010107 merely because both entries appear in the same register. This comparison shows why the full row matters.
| Identity element | Relevant service | Comparison entry | Why separation matters |
|---|---|---|---|
| Legal entity | PPB Counterparty Services Ltd | Betfair International plc | The companies are not interchangeable. |
| Trading identity | Paddy Power | Betfair | A shared document does not create a shared identity. |
| Reference | 1010107 | 1010108 | A one-digit difference points to another record. |
| Recorded category | Remote bookmaker | Remote betting intermediary | The packet describes different register categories. |
For a broader explanation of record matching, use the Irish licence checks.
Payments: what can and cannot be confirmed
No accepted deposit methods, currencies, minimum amounts, fees, processing times or payment-provider names were supplied. None should be inferred from familiarity with the service, screenshots, advertisements or another market. Availability can depend on account status, location, product and the checks applied at the time.
Before paying, record the exact domain, the amount, the payment method selected, any displayed fee and the transaction reference. The name appearing on a bank or card record may be useful evidence, but this packet does not establish what descriptor should appear. If the descriptor is unexpected, ask for a written explanation rather than guessing that it proves either fraud or legitimacy.
| Payment-stage check | Record to keep | Unsupported assumption to avoid |
|---|---|---|
| Before deposit | Hostname, amount, displayed terms and timestamp | That every advertised method is available to every account |
| After authorisation | Bank status, receipt and transaction reference | That a pending payment has been finally accepted |
| If duplicated | Both timestamps, amounts and statement entries | That two similar entries necessarily represent two settled charges |
| If refused | Error wording and payment-provider status | That the operator or bank is definitely responsible without records |
Never send funds to a personal account or cryptocurrency address merely because a message uses the brand name. The verified packet provides no basis for such a request. Payment-risk documentation is explained in the payment checks.
Withdrawals and balance disputes
There is no supplied withdrawal test, account statement, verified processing-time sample or competent finding about delayed funds. Consequently, no claim about usual payout speed, withdrawal reliability, reversal rules or limits can be made. A user-review statement may describe an individual’s experience, but it does not establish the cause or a general pattern.
For a withdrawal problem, build a chronology: request time, amount, status shown, requested documents, responses received and any change to the balance. Preserve original emails and screenshots. Do not edit images in a way that removes dates, status text or the address bar. If a payment provider shows a separate status, retain that record as well.
A pending withdrawal, a rejected withdrawal and a returned payment are different events. Use the operator’s exact wording and ask which term or verification requirement is being applied. Do not create repeated withdrawal requests unless instructed through an authenticated channel, as that can complicate the record. If funds appear at immediate risk, contact the relevant payment provider promptly using its independently verified contact route.
Identity checks and account access
The packet supplies no know-your-customer procedure, document list, verification timeframe, age-check outcome or account-restriction policy. It would therefore be unsafe to promise which documents will be accepted or how quickly access will be restored.
If identity material is requested, first confirm the complete hostname and the destination used for upload. Do not send passports, bank statements or selfies to an address copied from an unsolicited message. Ask why each document is required, which details may be obscured, how it will be transmitted and how a failed upload can be challenged. These are prudent questions, not claims about the operator’s actual process.
Keep a list of every document submitted, including the date and the channel, but avoid retaining unnecessary unprotected copies. If account access is lost, distinguish between a forgotten password, a security lock, identity review, self-exclusion and an operator restriction. The available evidence cannot determine which applies to any particular account.
Complaints, user reports and escalation
The supplied App Store capture shows a venue containing dated user ratings and review statements about the app. Those statements are contextual allegations or opinions, not independently verified findings. They can identify questions worth documenting, but they cannot prove misconduct, payment failure or the cause of an account problem.

Start a complaint with a concise factual record: account identifier, disputed amount if any, event dates, transaction references, the remedy requested and copies of relevant correspondence. Avoid broad accusations that are not necessary to resolve the issue. Request a complaint reference and a final written response.
If the reply does not resolve the matter, consult the complaint route for the appropriate next step. The packet does not identify an alternative dispute-resolution body, response deadline or regulator decision for this case, so none is asserted. Immediate wellbeing or gambling-harm concerns belong with responsible gambling support, not a routine commercial complaint queue.
Evidence chronology and source boundaries
| Date | Record or event | What it supports | What it does not support |
|---|---|---|---|
| 2024 | Gambling Regulation Act 2024 enacted | Statutory framework and establishment of GRAI | A service-level finding about this operator |
| February 2026 | GRAI began accepting specified betting applications | Regulatory transition context | A separate approval for the exact domain |
| 30 June 2026 | Revenue remote-bookmaker register date | Entity, trading identity or domain, and reference 1010107 | Permanent status or transaction quality |
| 21 August 2026 | Supplied sources checked | Currency of the evidence review on that date | Events occurring after the check |
| Date shown within user material | App Store ratings and statements | Existence of user context | Independent proof that each statement is accurate |
Primary records carry the most weight for legal identity and regulatory context. User material is retained only as context. There is no operator statement in the accepted fact list, no direct account evidence and no independent payment or withdrawal test. Silence in the packet is recorded as unknown rather than filled with an assumption.
Method, limitations and correction route
The assessment matches four fields: exact domain, trading name, legal entity and register reference. It then separates primary records from user context and limits each conclusion to what that source can establish. The method does not score popularity, copy promotional claims or treat an app-store rating as a regulatory outcome. Full criteria are available under methodology.
The main limitations are material. There is no expiry date, GRAI decision for the precise entity, payment-method record, withdrawal sample, identity-check policy, complaint determination or verified account correspondence. There is also no evidence authenticating any alternative domain or subdomain. These gaps are why the verdict remains amber despite the clear Revenue identity match.
Corrections should identify the disputed sentence and provide a dated primary record or other verifiable material through the contact route. A changed register, legal entity, reference or domain could alter the assessment. Anonymous assertions or cropped images without dates may be useful leads, but they are not enough on their own to replace a primary record.
Frequently asked questions
Is paddypower.com identified in an Irish official record?
Yes. The supplied Revenue register dated 30 June 2026 links the trading name or domain with PPB Counterparty Services Ltd under remote bookmaker reference 1010107. That finding is limited to the exact identity recorded.
Does the evidence prove that every Paddy Power address is legitimate?
No. Only the exact domain match in the packet is supported. A lookalike, misspelling, added word or different domain ending must be checked separately and should not inherit the registered identity.
Is Paddy Power legal in Ireland?
The dated Revenue register supports the recorded remote-bookmaker identity under reference 1010107. The packet also documents Ireland’s transition to GRAI, but it does not contain a separate GRAI licence decision for the operator.
Are fast withdrawals confirmed?
No. No withdrawal test, processing-time sample or account record was supplied. Keep the request time, amount, status, document requests and correspondence if a withdrawal becomes disputed.
Do App Store reviews prove a complaint?
No. The captured ratings and statements are user context only. They may suggest questions to investigate, but they are not independently verified findings and do not establish the cause of an individual problem.
What should I do if I suspect a clone?
Do not sign in, pay or upload identity documents. Record the full address and message source, compare the registrable domain with paddypower.com, and use an independently verified route for any account-security action.