# Fraudulent Domain Detail

GET /brp/fraudulent-domains/{fraudulent_id}: Returns one fraudulent domain with its latest data and risk score.

Source: https://docs.deepinfo.com/reference/brp/fraudulent-domain-detail/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/brp/fraudulent-domains/{fraudulent_id}`

Returns one fraudulent domain with its latest data and risk score.

## Authentication

Send your API key in the `apikey` request header.

## Path Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `fraudulent_id` | Required |  | `000000000000000ee94f0001` |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `id` | string |  |
| `fraudulent` | string |  |
| `fraudulent_unicode` | string |  |
| `fraudulent_type` | string | One of `domain`, `subdomain` |
| `detection_history` | array of object |  |
| `first_detection_date` | string | date-time |
| `added_date` | string | date-time |
| `monitoring_indicator` | object |  |
| `risk_score` | integer |  |
| `screenshot` | string |  |
| `thumbnail` | string |  |
| `is_login_page` | boolean |  |
| `seems_inactive` | boolean |  |
| `seems_inactive_first_seen` | string | date-time |
| `seems_inactive_last_seen` | string | date-time |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `id` | string |
| `fraudulent` | string |
| `fraudulent_unicode` | string |
| `fraudulent_type` | string |
| `detection_history` | array<object> |
| `detection_history[].id` | string |
| `detection_history[].rule` | string |
| `detection_history[].detection_date` | string |
| `detection_history[].enabled` | boolean |
| `detection_history[].deleted` | boolean |
| `first_detection_date` | string |
| `added_date` | string |
| `monitoring_indicator` | object |
| `monitoring_indicator.dns` | boolean |
| `monitoring_indicator.dns_mx` | boolean |
| `monitoring_indicator.ssl` | boolean |
| `monitoring_indicator.http` | boolean |
| `risk_score` | number |
| `screenshot` | null |
| `thumbnail` | null |
| `is_login_page` | boolean |
| `seems_inactive` | boolean |
| `seems_inactive_first_seen` | null |
| `seems_inactive_last_seen` | null |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/brp/fraudulent-domains/000000000000000ee94f0001' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "id": "000000000000000ee94f0001",
  "fraudulent": "acme.example",
  "fraudulent_unicode": "acme.example",
  "fraudulent_type": "domain",
  "detection_history": [
    {
      "id": "000000000000000e2f900001",
      "rule": "Brand name",
      "detection_date": "2025-06-01T08:00:00Z",
      "enabled": true,
      "deleted": false
    }
  ],
  "first_detection_date": "2025-06-01T08:00:00Z",
  "added_date": "2025-06-01T08:00:00Z",
  "monitoring_indicator": {
    "dns": true,
    "dns_mx": true,
    "ssl": true,
    "http": true
  },
  "risk_score": 20,
  "screenshot": null,
  "thumbnail": null,
  "is_login_page": false,
  "seems_inactive": false,
  "seems_inactive_first_seen": null,
  "seems_inactive_last_seen": null
}
```

### 404 · Not Found (nonexistent fraudulent_id)

```bash
curl 'https://api.deepinfo.com/v1/brp/fraudulent-domains/ffffffffffffffffffffffff' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 30003,
  "details": [
    "Fraudulent with id=ffffffffffffffffffffffff does not exist."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
