# Suspicious Domain Detail

GET /brp/suspicious-domains/{detected_fraudulent_id}: Returns one suspicious domain with the rule that detected it.

Source: https://docs.deepinfo.com/reference/brp/suspicious-domain-detail/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/brp/suspicious-domains/{detected_fraudulent_id}`

Returns one suspicious domain with the rule that detected it.

## Authentication

Send your API key in the `apikey` request header.

## Path Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `detected_fraudulent_id` | Required |  | `00000000000000000000000e25cc0001` |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `id` | string |  |
| `fraudulent` | string |  |
| `fraudulent_unicode` | string |  |
| `fraudulent_type` | string | One of `domain`, `subdomain` |
| `state` | string | One of `in_review`, `approved`, `ignored` |
| `detection_history` | array of object |  |
| `first_detection_date` | string | date-time |
| `monitoring_indicator` | object |  |
| `risk_score` | integer |  |
| `monitoring` | object |  |
| `approve_date` | string | date-time |
| `ignore_date` | string | date-time |
| `seems_inactive` | boolean |  |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `id` | string |
| `fraudulent` | string |
| `fraudulent_unicode` | string |
| `fraudulent_type` | string |
| `state` | string |
| `detection_history` | array<object> |
| `detection_history[].id` | string |
| `detection_history[].rule` | string |
| `detection_history[].detection_date` | string |
| `detection_history[].enabled` | boolean |
| `detection_history[].deleted` | boolean |
| `first_detection_date` | string |
| `monitoring_indicator` | object |
| `monitoring_indicator.dns` | boolean |
| `monitoring_indicator.dns_mx` | boolean |
| `monitoring_indicator.ssl` | null |
| `monitoring_indicator.http` | boolean |
| `risk_score` | number |
| `monitoring` | object |
| `monitoring.whois` | object |
| `monitoring.whois.domain_name` | string |
| `monitoring.whois.raw` | string |
| `monitoring.whois.parsed` | object |
| `monitoring.whois.parsed.uid` | string |
| `monitoring.whois.parsed.create_date` | string |
| `monitoring.whois.parsed.update_date` | string |
| `monitoring.whois.parsed.expiry_date` | string |
| `monitoring.whois.parsed.registrar` | string |
| `monitoring.whois.parsed.registrant` | object |
| `monitoring.whois.parsed.registrant.name` | string |
| `monitoring.whois.parsed.registrant.organization` | string |
| `monitoring.whois.parsed.registrant.street` | string |
| `monitoring.whois.parsed.registrant.city` | string |
| `monitoring.whois.parsed.registrant.state` | null |
| `monitoring.whois.parsed.registrant.postal_code` | string |
| `monitoring.whois.parsed.registrant.country` | string |
| `monitoring.whois.parsed.registrant.phone` | null |
| `monitoring.whois.parsed.registrant.email` | null |
| `monitoring.whois.parsed.name_servers` | array<string> |
| `monitoring.whois.parsed.domain_status` | array<string> |
| `monitoring.whois.parsed.whois_server` | string |
| `monitoring.whois.check_date` | string |
| `monitoring.whois.parse_code` | null |
| `monitoring.dns` | object |
| `monitoring.dns.fqdn` | string |
| `monitoring.dns.requested_types` | array<string> |
| `monitoring.dns.responses` | array<object> |
| `monitoring.dns.responses[].type` | string |
| `monitoring.dns.responses[].conn_status` | string |
| `monitoring.dns.responses[].rcode` | string |
| `monitoring.dns.responses[].raw` | string \| null |
| `monitoring.dns.responses[].values` | array<string> \| null |
| `monitoring.dns.responses[].server` | string |
| `monitoring.dns.servers` | array<string> |
| `monitoring.dns.check_date` | string |
| `monitoring.ssl` | null |
| `monitoring.http` | object |
| `monitoring.http.requested_url` | string |
| `monitoring.http.version` | number |
| `monitoring.http.check_date` | string |
| `monitoring.http.connection_status` | string |
| `monitoring.http.requested_domain` | string |
| `monitoring.http.final_url` | string |
| `monitoring.http.final_domain` | string |
| `monitoring.http.http` | object |
| `monitoring.http.http.redirection_history` | array<object> |
| `monitoring.http.http.redirection_history[].url` | string |
| `monitoring.http.http.redirection_history[].status_code` | number |
| `monitoring.http.http.headers` | array<object> |
| `monitoring.http.http.headers[].name` | string |
| `monitoring.http.http.headers[].value` | string |
| `monitoring.http.http.cookies` | array |
| `monitoring.http.html` | object |
| `monitoring.http.html.source_hash_code` | string |
| `monitoring.http.final_status_code` | number |
| `approve_date` | null |
| `ignore_date` | null |
| `seems_inactive` | boolean |

## Examples

### 200 · OK

```bash
curl 'https://api.deepinfo.com/v1/brp/suspicious-domains/00000000000000000000000e25cc0001' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "id": "00000000000000000000000e25cc0001",
  "fraudulent": "acme.example",
  "fraudulent_unicode": "acme.example",
  "fraudulent_type": "domain",
  "state": "in_review",
  "detection_history": [
    {
      "id": "000000000000000e2f900001",
      "rule": "Brand name",
      "detection_date": "2025-06-01T08:00:00Z",
      "enabled": true,
      "deleted": false
    }
  ],
  "first_detection_date": "2025-06-01T08:00:00Z",
  "monitoring_indicator": {
    "dns": true,
    "dns_mx": true,
    "ssl": null,
    "http": true
  },
  "risk_score": 20,
  "monitoring": {
    "whois": {
      "domain_name": "acme.example",
      "raw": "Raw record text.",
      "parsed": {
        "uid": "00000000000000000000000e7db60001",
        "create_date": "2025-06-01T08:00:00Z",
        "update_date": "2025-07-01T08:00:00Z",
        "expiry_date": "2026-06-01T08:00:00Z",
        "registrar": "Kestrel Domains",
        "registrant": {
          "name": "REDACTED FOR PRIVACY",
          "organization": "REDACTED FOR PRIVACY",
          "street": "REDACTED FOR PRIVACY",
          "city": "Springfield",
          "state": null,
          "postal_code": "REDACTED FOR PRIVACY",
          "country": "US",
          "phone": null,
          "email": null
        },
        "name_servers": [
          "ns1.acme.example",
          "ns2.acme.example"
        ],
        "domain_status": [
          "ok"
        ],
        "whois_server": "whois.fernhill.example"
      },
      "check_date": "2025-07-31T08:00:00Z",
      "parse_code": null
    },
    "dns": {
      "fqdn": "acme.example",
      "requested_types": [
        "A",
        "AAAA"
      ],
      "responses": [
        {
          "type": "A",
          "conn_status": "success",
          "rcode": "NOERROR",
          "raw": "Raw record text.",
          "values": [
            "192.0.2.10"
          ],
          "server": "192.0.2.10"
        },
        {
          "type": "AAAA",
          "conn_status": "success",
          "rcode": "NOERROR",
          "raw": null,
          "values": null,
          "server": "192.0.2.10"
        }
      ],
      "servers": [
        "192.0.2.10"
      ],
      "check_date": "2025-07-31T08:00:00Z"
    },
    "ssl": null,
    "http": {
      "requested_url": "http://acme.example/",
      "version": 1,
      "check_date": "2025-07-31T08:00:00Z",
      "connection_status": "success",
      "requested_domain": "acme.example",
      "final_url": "http://acme.example/",
      "final_domain": "acme.example",
      "http": {
        "redirection_history": [
          {
            "url": "http://acme.example/",
            "status_code": 200
          }
        ],
        "headers": [
          {
            "name": "server",
            "value": "<value>"
          },
          {
            "name": "date",
            "value": "Thu, 31 Jul 2025 08:00:00 GMT"
          }
        ],
        "cookies": []
      },
      "html": {
        "source_hash_code": "c61800abcdef0123456789c61800abcdef0123456789c61800abcdef01234567"
      },
      "final_status_code": 200
    }
  },
  "approve_date": null,
  "ignore_date": null,
  "seems_inactive": false
}
```

### 404 · Not Found (nonexistent detected_fraudulent_id)

```bash
curl 'https://api.deepinfo.com/v1/brp/suspicious-domains/ffffffffffffffffffffffff' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 30003,
  "details": [
    "Detected fraudulent with id=ffffffffffffffffffffffff does not exist."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```
