POSThttps://api.deepinfo.com/v1/brp/fraudulent-domains/search:export

Exports every record matching filters (no pagination). format=csv returns CSV text; format=json returns a JSON array. Large exports can time out: narrow them with filters.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
formatOptional
One of: json, csv.
Examplecsv

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "fraudulent",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "fraudulent",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in exists

FieldDescription
fraudulent_typeWhether the name is a domain or a subdomain (Domain and Subdomain in the TYPE filter); each detection rule looks at one or the other.
monitoring_indicator.dnsDNS indicator: true when the domain's DNS lookup at its last check returned records (such as A, NS or SOA; an address record is not required); false when the name did not exist (NXDOMAIN); null when there is no DNS result. The INDICATORS filter's DNS option finds the domains where it is true.
monitoring_indicator.dns_mxDNS MX indicator: true when the domain had an MX (mail exchanger) record at its last check; false when it had none; null when there is no DNS result. The INDICATORS filter's DNS MX option finds the domains where it is true.
monitoring_indicator.sslSSL indicator: true when a TLS connection to the domain on port 443 succeeded and returned a certificate at its last check; false when it failed (for example refused or not resolved); null when there is no result for that check. The INDICATORS filter's SSL option finds the domains where it is true.
monitoring_indicator.httpHTTP indicator: true when the domain answered an HTTP request at its last check, after following redirects (in the samples a final 525 error status also counted); false when it did not (for example because the name did not resolve); null when there is no result for that check. The INDICATORS filter's HTTP option finds the domains where it is true.
is_login_pagetrue when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.
seems_inactivetrue when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.

Operators eq in gte lte exists

FieldDescription
first_detection_dateWhen a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest detection_date in detection_history.
risk_scoreThe domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.
added_dateWhen the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.
seems_inactive_first_seenWhen the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with seems_inactive true.
seems_inactive_last_seenWhen the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with seems_inactive true.

Operators eq in startswith endswith wildcard fuzzy contains_any contains_all exists

FieldDescription
fraudulentThe fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with xn--); fraudulent_unicode in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.
tagsTags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.
detection_history.idThe ID of a detection rule that found the domain, a 24-character hexadecimal string; it is the rule's id in Fraudulent Rule Search. Filter on it to list the domains one rule detected.

Sortable Fields

FieldDescription
fraudulentThe fraudulent domain or subdomain name in ASCII form, with internationalized names in punycode (starting with xn--); fraudulent_unicode in the response holds the Unicode form. The DOMAIN filter and the SEARCH box match on it.
tagsTags on the domain, as a list of strings; in the samples they are always the tags of the detection rules that found it (the rule's TAGS setting). The TAGS filter matches them.
detection_historyThe detection rules that found the domain, one entry per rule with the rule's id, its name (rule), the detection_date and the enabled and deleted flags; the lists show it as RULES. It can be sorted on but not filtered: filter on detection_history.id instead.
first_detection_dateWhen a detection rule first found the domain (UTC date-time), shown as DETECTION DATE; in the samples it always equals the earliest detection_date in detection_history.
monitoring_indicatorThe four indicator flags dns, dns_mx, ssl and http as one object (null when there is no check result); the lists show them as the INDICATORS icons. It can be sorted on but not filtered: filter on monitoring_indicator.dns, monitoring_indicator.dns_mx, monitoring_indicator.ssl or monitoring_indicator.http instead.
risk_scoreThe domain's risk score, an integer from 0 to 100 (can be null). The platform labels 1 to 20 INFORMATION, over 20 up to 40 LOW, over 40 up to 60 MEDIUM, over 60 up to 80 HIGH and over 80 CRITICAL; 0 has no label.
added_dateWhen the domain was added to the fraudulent list (UTC date-time), that is when it was marked as fraudulent, by you or by a rule with Auto Approval.
is_login_pagetrue when the domain's site has a login page; the FRAUDULENT DOMAINS list shows a Login Page icon next to its name.
seems_inactivetrue when the domain seems inactive; in the samples, inactive domains had no DNS records and no parsed WHOIS data at their last check. The lists show a SEEMS INACTIVE banner on it.
seems_inactive_first_seenWhen the domain was first found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with seems_inactive true.
seems_inactive_last_seenWhen the domain was most recently found to seem inactive (UTC date-time). In the samples it was empty on every domain, including those with seems_inactive true.

Examples

Selecting one loads it into the request and response panels.

Reference updated