Firstly, I always see who open that threat, official new-account or manage by old-account bounty manager, or fresh newbie account using un-related name or not represents the brand of the project. Then I look at their content, how detail and compact the information they give. Is there any weird thing. I usually observe first about 1-2 days before deciding to fill up the form. And be careful before fill the form. Now, I always consider if they show the spreadsheet publicly.