# Fraudulent Rule Search

POST /brp/fraudulent-rules/search: Searches your fraudulent rules.

Source: https://docs.deepinfo.com/reference/brp/fraudulent-rule-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/brp/fraudulent-rules/search`

Searches your fraudulent rules.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | object | Optional | One `{field, order}` object |

```json
{}
```

## Filtering

This search takes `filters` as an object with one key per field, not as a `must` list. Each field takes the operators of its filter type as keys, and fields combine with AND. `sort` is one `{field, order}` object, not a list. Example body:

```json
{
  "filters": {
    "name": {
      "equals": [
        "<value>"
      ]
    }
  },
  "sort": {
    "field": "name",
    "order": "desc"
  }
}
```

Operators by field:

| Field | Operators |
|---|---|
| `name` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |
| `filters.match_type` | `equals`, `not_equals`; each takes a list of values |
| `detected_fraudulent_count` | `gt`, `gte`, `lt`, `lte` |
| `tags` | `equals`, `not_equals`, `contains`, `not_contains`, `startswith`, `endswith`; each takes a list of values |
| `enabled` | a plain boolean value |
| `create_date` | `gt`, `gte`, `lt`, `lte` |
| `last_update_date` | `gt`, `gte`, `lt`, `lte` |

### Searchable Fields

| Field | Description |
|---|---|
| `name` | The fraudulent domain rule's name, as you gave it. |
| `filters.match_type` | How the rule matches domain names to its keyword: `exact`, `contains`, `fuzzy`, `fuzzy_contains` or a `confusable_*` variant (look-alike characters). It sits in a nested `filters` object: `{"filters": {"filters": {"match_type": {"equals": ["contains"]}}}}`. |
| `detected_fraudulent_count` | How many fraudulent domains the rule has detected. |
| `tags` | The tags on the rule. |
| `enabled` | `true` for rules that are switched on, `false` for rules that are switched off. |
| `create_date` | When the rule was created (ISO 8601 date-time). |
| `last_update_date` | When the rule was last changed (ISO 8601 date-time). |

### Sortable Fields

| Field | Description |
|---|---|
| `name` | The fraudulent domain rule's name, as you gave it. |
| `filters_match_type` | The rule's match type (`filters.match_type` in the response), for sorting. |
| `detected_fraudulent_count` | How many fraudulent domains the rule has detected. |
| `tags` | The tags on the rule. |
| `enabled` | `true` for rules that are switched on, `false` for rules that are switched off. |
| `create_date` | When the rule was created (ISO 8601 date-time). |
| `last_update_date` | When the rule was last changed (ISO 8601 date-time). |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].name` | string |  |
| `results[].filters` | object |  |
| `results[].detected_fraudulent_count` | integer |  |
| `results[].tags` | array of string |  |
| `results[].enabled` | boolean |  |
| `results[].create_date` | string | date-time |
| `results[].last_update_date` | string | date-time |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].name` | string |
| `results[].filters` | object |
| `results[].filters.match_type` | string |
| `results[].detected_fraudulent_count` | number |
| `results[].tags` | array |
| `results[].enabled` | boolean |
| `results[].create_date` | string |
| `results[].last_update_date` | string |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/brp/fraudulent-rules/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000e8e040001",
      "name": "Brand name",
      "filters": {
        "match_type": "contains"
      },
      "detected_fraudulent_count": 37,
      "tags": [],
      "enabled": true,
      "create_date": "2025-06-01T08:00:00Z",
      "last_update_date": "2025-07-01T08:00:00Z"
    },
    {
      "id": "000000000000000e8e040002",
      "name": "Product names",
      "filters": {
        "match_type": "contains"
      },
      "detected_fraudulent_count": 38,
      "tags": [],
      "enabled": true,
      "create_date": "2025-05-25T08:00:00Z",
      "last_update_date": "2025-06-24T08:00:00Z"
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/brp/fraudulent-rules/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
