# Review Suspicious Domains

Check the lookalike domains your detection rules found, then mark each one as fraudulent or ignore it, one at a time or in bulk.

Source: https://docs.deepinfo.com/guide/brp/review-suspicious-domains/

Last updated: 2026-09-26

---
Every domain your detection rules find lands on the **SUSPICIOUS DOMAINS** list. Check each one, then mark it as
fraudulent if it imitates your brand, or ignore it if it does not.

## Before You Start

- **Package:** Brand Risk Protection (BRP).
- **Role:** Admin or Member.
- **Data:** detection rules; see [Set up detection rules](/guide/brp/detection-rules/).

## Where to Find It

**Sidebar:** **BRAND RISK PROTECTION** › **FRAUDULENT DOMAINS** · **Tab:** **FRAUDULENT DOMAINS** › list tab **SUSPICIOUS DOMAINS** · [https://platform.deepinfo.com/app/brp/fraudulent?tab=suspicious](https://platform.deepinfo.com/app/brp/fraudulent?tab=suspicious)

This is the list the sidebar item opens. The **SUSPICIOUS DOMAINS** card on the **OVERVIEW** tab opens it too.

## Read the Screen

![The SUSPICIOUS DOMAINS list, numbered 1 to 5, with NEW badges and a SEEMS INACTIVE banner.](/img/guide/brp/review-suspicious-domains-01.png)

1. **Header:** the title **Fraudulent Domains**, the **⋮** menu (**IGNORED DOMAINS**) and the in-page tabs
   **OVERVIEW**, **FRAUDULENT DOMAINS** and **SETTINGS**.
2. **Filter bar:** **SEARCH**, the filter chips starting with **DOMAIN**, **TAGS**, **DETECTION DATE** and
   **TYPE**, **SHOW ALL FILTERS** for the rest, and the list view and quick view icons. A filter that holds a
   rule shows its count.
3. **Count line:** how many suspicious domains match, then **EXPORT** and **VIEW SETTINGS** (list view only).
4. **List tabs**, each with its count: **FRAUDULENT DOMAINS** and **SUSPICIOUS DOMAINS**.
5. **The list**, 25 rows per page, newest **DETECTION DATE** first. Select a column header to sort by it.
   - A checkbox on every row.
   - **DOMAIN**: the site icon and the name, with the **NEW** badge (first detected in the last 14 days), the
     **SEEMS INACTIVE** banner and an external-link icon.
   - **RISK SCORE**: the score, its label and a bar.
   - **INDICATORS**: **DNS**, **DNS MX**, **SSL** and **HTTP**.
   - **DETECTION DATE**: the date, the time and how many days ago.
   - **RULES**: the rules that detected the domain.
   - **MARK AS FRAUDULENT** and a **✕** button (ignore) at the end of the row.

[Brand Risk Protection (BRP)](/guide/brp/) explains the risk score, the indicators and the badges.

> [!CAUTION]
> The external-link icon opens the suspicious domain itself in your browser. It may host a phishing page or
> malware. Use the drawer tabs below to check a domain without visiting it.

## Check a Domain Before You Decide

1. Select a row. The domain's drawer opens on the right.
2. The drawer's tabs are icons; the name of the open tab is shown as its heading. Read:
   - **OVERVIEW**: **DETECTION DATE**, **LAST CHECK DATE**, **RISK SCORE**, **INDICATORS** and **RULES**.
   - **WHOIS**: **CREATE DATE**, **EXPIRATION DATE**, **UPDATED DATE**, **NAME SERVER**, **DOMAIN STATUS**,
     **REGISTRAR** and the **Registrant** block.
   - **DNS**: one table per record type (**A**, **AAAA**, **MX**, **NS**, **SOA** and more).
   - **SSL**: **Details**, **Fingerprint** and **Signature**.
   - **WEBSITE INFO**: **Metadata**, **Robots.txt**, **HTML**, **Favicon**, **HTTP Status** (with
     **REDIRECTION HISTORY**) and **HTTP Headers**.
3. Decide with the buttons at the bottom of the drawer: **IGNORE** or **MARK AS FRAUDULENT**.

The **WHOIS**, **DNS**, **SSL** and **WEBSITE INFO** tabs show the data stored for the domain at its last check.
Opening them does not run a new lookup. **LAST CHECK DATE** on **OVERVIEW** tells you when that data was
collected; compare it with today's date to judge how current it is.

To give the domain a page of its own, select **OPEN IN NEW TAB** at the top of the drawer. The page opens in a
new browser tab (`/app/brp/fraudulent/detected/<id>`) and has **MARK AS FRAUDULENT** and **IGNORE** at the top,
the tabs **OVERVIEW**, **WHOIS**, **DNS**, **SSL** and **WEBSITE INFO**, an **INFO** card (**RISK SCORE**,
**DETECTION DATE**, **LAST CHECK DATE**, **INDICATORS**) and a **RULES** card. The page has no back button; the
**FRAUDULENT DOMAINS** link in the header breadcrumb returns to the list.

![The drawer of a suspicious domain on OVERVIEW, with IGNORE and MARK AS FRAUDULENT at the bottom.](/img/guide/brp/review-suspicious-domains-02.png)

### Work Through the List in Quick View

Select the quick view icon in the filter bar. The domains are listed on the left (**LOAD MORE** adds more); the
selected domain opens on the right with **OPEN IN NEW TAB**, **MARK AS FRAUDULENT**, **IGNORE**, the same tabs and
the **INFO** and **RULES** cards.

## Mark a Domain as Fraudulent

1. Select **MARK AS FRAUDULENT** on the row, in the drawer, in quick view or on the domain's page.
2. Confirm with **APPROVE**.
3. After a few seconds the list refreshes. The domain is now on the **FRAUDULENT DOMAINS** list; see
   [Track fraudulent domains](/guide/brp/fraudulent-domains/).

## Ignore a Domain

1. Select the **✕** button at the end of the row, or **IGNORE** in the drawer, in quick view or on the domain's
   page.
2. Confirm with **IGNORE**.
3. After a few seconds the list refreshes. The domain is now on **Ignored Domains**, where you can restore it;
   see [Restore ignored domains](/guide/brp/ignored-domains/).

To keep a domain of your own from ever appearing here, add it to **Ignored Assets** instead; see
[Set up detection rules](/guide/brp/detection-rules/#keep-your-own-domains-out).

## Act on Several Domains at Once

1. Tick the rows you want. To tick every row on the page, open the arrow next to the header checkbox and
   select **SELECT THIS PAGE**; **CLEAR SELECTION** starts again.
2. Use **MARK AS FRAUDULENT** or **IGNORE** in the selection bar.
3. The confirmation shows how many domains you selected. Confirm.

## Find Domains

The first filter chips are always visible; **SHOW ALL FILTERS** shows the rest (and becomes **HIDE FILTERS**).

| Filter | What it matches |
|---|---|
| **DOMAIN** | The domain name |
| **TAGS** | Tags on the domain |
| **DETECTION DATE** | When the domain was detected |
| **TYPE** | **Domain** or **Subdomain** |
| **RISK SCORE** | A range from 0 to 100 (**MINIMUM**, **MAXIMUM**) |
| **INDICATORS** | **DNS**, **DNS MX**, **SSL**, **HTTP** |
| **SEEMS INACTIVE** | Whether the domain seems inactive |
| **IGNORED DATE** | When the domain was ignored. On this list, it can find domains that were ignored and later restored |
| **APPROVE DATE** | When the domain was marked as fraudulent |

A date filter takes **AFTER** or **BEFORE** a date; the risk score filter takes a range. Select **APPLY** to
use it. [Search, filter and export lists](/guide/basics/lists-filters-and-exports/) explains the filter
controls every list shares.

Switching between the **SUSPICIOUS DOMAINS** and **FRAUDULENT DOMAINS** tabs clears your filters.

## Export the List

1. Select **EXPORT** above the list.
2. In the **DOWNLOAD** dialog, choose **RECORDS** (**ALL** or **FILTERED**, the current filters) and
   **FILE FORMAT** (**CSV** or **JSON**).
3. Select **DOWNLOAD**.

## Good to Know

- Actions take a few seconds to apply; the list refreshes on its own afterwards.
- Marking and ignoring move the domain to another list. An ignored domain can be restored to this list.

## Do This With the API

- Search suspicious domains: [Suspicious Domain Search](/reference/brp/suspicious-domain-search/)
- Get one: [Suspicious Domain Detail](/reference/brp/suspicious-domain-detail/)
- Mark as fraudulent: [Suspicious Domain Approve](/reference/brp/suspicious-domain-approve/)
- Ignore: [Suspicious Domain Ignore](/reference/brp/suspicious-domain-ignore/)
- Export: [Suspicious Domain Export](/reference/brp/suspicious-domain-export/)
