Suspicious Domain Detail
GET
https://api.deepinfo.com/v1/brp/suspicious-domains/{detected_fraudulent_id}Returns one suspicious domain with the rule that detected it.
Authentication
Send your API key in the apikey request header.
Path Parameters
| Parameter | Required | Description |
|---|---|---|
detected_ | Required | Example 00000000000000000000000e25cc0001 |
Response Fields
| Field | Type | Description |
|---|---|---|
id | string | |
fraudulent | string | |
fraudulent_ | string | |
fraudulent_ | string | One of domain, subdomain |
state | string | One of in_review, approved, ignored |
detection_ | array of object | |
first_ | string | date-time |
monitoring_ | object | |
risk_ | integer | |
monitoring | object | |
approve_ | string | date-time |
ignore_ | string | date-time |
seems_ | boolean |
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
id | string | "00000000000000000000000e25cc0001" |
fraudulent | string | "acme.example" |
fraudulent_unicode | string | "acme.example" |
fraudulent_type | string | "domain" |
state | string | "in_review" |
detection_history | array< | |
detection_history[]. | string | "000000000000000e2f900001" |
detection_history[]. | string | "Brand name" |
detection_history[]. | string | "2025-06-01T08:00:00Z" |
detection_history[]. | boolean | true |
detection_history[]. | boolean | false |
first_detection_date | string | "2025-06-01T08:00:00Z" |
monitoring_indicator | object | |
monitoring_indicator. | boolean | true |
monitoring_indicator. | boolean | true |
monitoring_indicator. | null | |
monitoring_indicator. | boolean | true |
risk_score | number | 20 |
monitoring | object | |
monitoring. | object | |
monitoring. | string | "acme.example" |
monitoring. | string | "Raw record text." |
monitoring. | object | |
monitoring. | string | "00000000000000000000000e7db60001" |
monitoring. | string | "2025-06-01T08:00:00Z" |
monitoring. | string | "2025-07-01T08:00:00Z" |
monitoring. | string | "2026-06-01T08:00:00Z" |
monitoring. | string | "Kestrel Domains" |
monitoring. | object | |
monitoring. | string | |
monitoring. | string | |
monitoring. | string | |
monitoring. | string | "Springfield" |
monitoring. | null | |
monitoring. | string | |
monitoring. | string | "US" |
monitoring. | null | |
monitoring. | null | |
monitoring. | array< | "ns1.acme.example" |
monitoring. | array< | "ok" |
monitoring. | string | "whois.fernhill.example" |
monitoring. | string | "2025-07-31T08:00:00Z" |
monitoring. | null | |
monitoring. | object | |
monitoring. | string | "acme.example" |
monitoring. | array< | "A" |
monitoring. | array< | |
monitoring. | string | "A" |
monitoring. | string | "success" |
monitoring. | string | "NOERROR" |
monitoring. | string | null | "Raw record text." |
monitoring. | array< | |
monitoring. | string | |
monitoring. | array< | |
monitoring. | string | "2025-07-31T08:00:00Z" |
monitoring. | null | |
monitoring. | object | |
monitoring. | string | "http://acme.example/" |
monitoring. | number | 1 |
monitoring. | string | "2025-07-31T08:00:00Z" |
monitoring. | string | "success" |
monitoring. | string | "acme.example" |
monitoring. | string | "http://acme.example/" |
monitoring. | string | "acme.example" |
monitoring. | object | |
monitoring. | array< | |
monitoring. | string | "http://acme.example/" |
monitoring. | number | 200 |
monitoring. | array< | |
monitoring. | string | "server" |
monitoring. | string | "<value>" |
monitoring. | array | |
monitoring. | object | |
monitoring. | string | |
monitoring. | number | 200 |
approve_date | null | |
ignore_date | null | |
seems_inactive | boolean | false |
Examples
Selecting one loads it into the request and response panels.