# Set Up Detection Rules

Create the custom rules that find domains imitating your brand, turn them on or off, let a rule mark its matches as fraudulent automatically, and keep your own domains out.

Source: https://docs.deepinfo.com/guide/brp/detection-rules/

Last updated: 2026-09-26

---
Detection rules tell Brand Risk Protection (BRP) which domain names to look for. Each rule has a keyword and a match type, and can take
further keywords and limits on domain extensions. Every domain a rule finds appears on the suspicious list for
your review, unless the domain is on your **Ignored Assets** list.

## Before You Start

- **Package:** BRP.
- **Role:** Admin or Member.

## Where to Find It

**Sidebar:** **BRAND RISK PROTECTION** › **FRAUDULENT DOMAINS** · **Tab:** **SETTINGS** › **Custom Rules** · [https://platform.deepinfo.com/app/brp/fraudulent/settings/custom-rules](https://platform.deepinfo.com/app/brp/fraudulent/settings/custom-rules)

The **SETTINGS** tab has a menu on the left with **Custom Rules** (opens first) and **Other Settings**. The
breadcrumb reads **BRP / FRAUDULENT DOMAINS / CUSTOM RULES** or **… / OTHER SETTINGS**.

## Read the Rule List

![The Custom Rules list with one rule expanded.](/img/guide/brp/detection-rules-01.png)

1. **Count and action:** how many custom rules you have, and **CREATE RULE**.
2. **The list:**
   - **STATUS**: a toggle with **ACTIVE** or **INACTIVE**.
   - **RULE NAME**.
   - **DETECTED DOMAINS**: how many domains the rule has detected.
   - **CREATE DATE** and **LAST UPDATE DATE**.
   - A chevron at the end of the row.
3. **Expanded rule:** select a row to see its settings:
   - **FQDN TYPE** (whether the rule looks at domains or subdomains), **MATCH TYPE**, **START DETECTION**, **KEYWORD**,
     **HELPER KEYWORDS**, **NEGATIVE KEYWORDS**, **TLD MUST BE** and **TLD MUST NOT BE**. An empty setting shows
     **-**.
   - The **Auto Approval** toggle.
   - **EDIT THIS RULE** and **DELETE THIS RULE**.

## Create a Rule

1. Select **CREATE RULE**. The **Custom Rules** dialog opens.
2. Fill in the rule's settings:
   - **RULE NAME**: a name you will recognize in lists and alerts.
   - **TAGS**: optional labels for the rule.
   - **START DETECTION**: **From Now On** (the default) starts from now; **Include Past** also covers the past.
   - **STATUS**: **Active** (the default) or **Inactive**.
   - **AUTO APPROVAL**: **Disabled** (the default) or **Enabled**. See
     [Mark matches as fraudulent automatically](#mark-matches-as-fraudulent-automatically).
3. Under **Filters**, describe what to look for:
   - **Domain** (the default) or **Subdomain**.
   - **KEYWORD**: the word to look for, usually your brand name.
   - **MATCH TYPE**: how the keyword is matched (see below). The default is **Contains**.
   - **HELPER KEYWORDS** and **NEGATIVE KEYWORDS**: optional further keywords.
   - **TLD MUST BE** and **TLD MUST NOT BE**: optional domain extensions to limit the rule to, or to leave out.
4. Select **CREATE**. To leave without saving, select **CANCEL**.

New domains the rule detects appear on [the suspicious list](/guide/brp/review-suspicious-domains/).

![The Custom Rules dialog with the MATCH TYPE list open.](/img/guide/brp/detection-rules-02.png)

### Match Types

The **MATCH TYPE** list offers these options:

- **Exact**
- **Contains**
- **Fuzzy**
- **Fuzzy Contains**
- **Confusable Exact**
- **Confusable Contains**
- **Confusable Fuzzy**
- **Confusable Fuzzy Contains**

For advice on which match type fits your brand, write to
[support@deepinfo.com](mailto:support@deepinfo.com).

## Change a Rule

- **Turn it on or off:** use the **STATUS** toggle on the rule's row and confirm. An inactive rule stays in the
  list with **INACTIVE**.
- **Edit it:** expand the rule and select **EDIT THIS RULE**. The same dialog opens with the rule's settings.
  **START DETECTION** cannot be changed once the rule exists. Save with **UPDATE**.
- **Delete it:** expand the rule, select **DELETE THIS RULE** and confirm with **REMOVE**. If you may need the
  rule again, set it to inactive instead of deleting it.

## Mark Matches as Fraudulent Automatically

Each rule has an **Auto Approval** setting: **AUTO APPROVAL** in the dialog, or the **Auto Approval** toggle in
the expanded rule. The platform describes it this way: if the option is enabled and any domains waiting for
review match the rule, they are automatically marked as fraudulent.

Use it for rules you trust fully. Domains marked this way skip your review and go straight to
[the fraudulent list](/guide/brp/fraudulent-domains/).

## Keep Your Own Domains Out

**Other Settings** holds the **Ignored Assets** list: domains and subdomains that never appear as detected
domains, even when a detection rule matches them. Use it for your own domains and for other names you know are
legitimate.

**Sidebar:** **BRAND RISK PROTECTION** › **FRAUDULENT DOMAINS** · **Tab:** **SETTINGS** › **Other Settings** · [https://platform.deepinfo.com/app/brp/fraudulent/settings/other-settings](https://platform.deepinfo.com/app/brp/fraudulent/settings/other-settings)

1. Select **Other Settings** in the menu on the left.
2. Type the domains in the box, one per line.
3. Select **SAVE CHANGES**. The button becomes available once you change the list.

![Other Settings with the Ignored Assets box and SAVE CHANGES.](/img/guide/brp/detection-rules-03.png)

## Good to Know

- **Ignored Assets** is not the same as **Ignored Domains**. Ignored Assets keeps names off the detected lists
  altogether; Ignored Domains lists detected domains you dismissed one by one (see
  [Restore ignored domains](/guide/brp/ignored-domains/)).
- A notification rule for **New Suspicious Domain** or **New Fraudulent Domain** can be limited to some of your
  detection rules with its **Rule** filter; see [Create a notification rule](/guide/notifications/create-a-rule/).

## Do This With the API

- List rules: [Fraudulent Rule Search](/reference/brp/fraudulent-rule-search/)
- Get one: [Fraudulent Rule Detail](/reference/brp/fraudulent-rule-detail/)
- Create: [Fraudulent Rule Create](/reference/brp/fraudulent-rule-create/)
- Change (including status and auto approval): [Fraudulent Rule Update](/reference/brp/fraudulent-rule-update/)
- Delete: [Fraudulent Rule Delete](/reference/brp/fraudulent-rule-delete/)
- Ignored Assets: [Fraudulent Settings Detail](/reference/brp/fraudulent-settings-detail/) and
  [Fraudulent Settings Update](/reference/brp/fraudulent-settings-update/)
