GEThttps://api.deepinfo.com/v1/brp/suspicious-domains/{detected_fraudulent_id}

Returns one suspicious domain with the rule that detected it.

Authentication

Send your API key in the apikey request header.

Path Parameters

ParameterRequiredDescription
detected_fraudulent_idRequired
Example00000000000000000000000e25cc0001

Response Fields

FieldTypeDescription
idstring
fraudulentstring
fraudulent_unicodestring
fraudulent_typestring
One of domain, subdomain
statestring
One of in_review, approved, ignored
detection_historyarray of object
first_detection_datestring
date-time
monitoring_indicatorobject
risk_scoreinteger
monitoringobject
approve_datestring
date-time
ignore_datestring
date-time
seems_inactiveboolean

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
idstring"00000000000000000000000e25cc0001"
fraudulentstring"acme.example"
fraudulent_unicodestring"acme.example"
fraudulent_typestring"domain"
statestring"in_review"
detection_historyarray<object>
detection_history[].idstring"000000000000000e2f900001"
detection_history[].rulestring"Brand name"
detection_history[].detection_datestring"2025-06-01T08:00:00Z"
detection_history[].enabledbooleantrue
detection_history[].deletedbooleanfalse
first_detection_datestring"2025-06-01T08:00:00Z"
monitoring_indicatorobject
monitoring_indicator.dnsbooleantrue
monitoring_indicator.dns_mxbooleantrue
monitoring_indicator.sslnull
monitoring_indicator.httpbooleantrue
risk_scorenumber20
monitoringobject
monitoring.whoisobject
monitoring.whois.domain_namestring"acme.example"
monitoring.whois.rawstring"Raw record text."
monitoring.whois.parsedobject
monitoring.whois.parsed.uidstring"00000000000000000000000e7db60001"
monitoring.whois.parsed.create_datestring"2025-06-01T08:00:00Z"
monitoring.whois.parsed.update_datestring"2025-07-01T08:00:00Z"
monitoring.whois.parsed.expiry_datestring"2026-06-01T08:00:00Z"
monitoring.whois.parsed.registrarstring"Kestrel Domains"
monitoring.whois.parsed.registrantobject
monitoring.whois.parsed.registrant.namestring
monitoring.whois.parsed.registrant.organizationstring
monitoring.whois.parsed.registrant.streetstring
monitoring.whois.parsed.registrant.citystring"Springfield"
monitoring.whois.parsed.registrant.statenull
monitoring.whois.parsed.registrant.postal_codestring
monitoring.whois.parsed.registrant.countrystring"US"
monitoring.whois.parsed.registrant.phonenull
monitoring.whois.parsed.registrant.emailnull
monitoring.whois.parsed.name_serversarray<string>"ns1.acme.example"
monitoring.whois.parsed.domain_statusarray<string>"ok"
monitoring.whois.parsed.whois_serverstring"whois.fernhill.example"
monitoring.whois.check_datestring"2025-07-31T08:00:00Z"
monitoring.whois.parse_codenull
monitoring.dnsobject
monitoring.dns.fqdnstring"acme.example"
monitoring.dns.requested_typesarray<string>"A"
monitoring.dns.responsesarray<object>
monitoring.dns.responses[].typestring"A"
monitoring.dns.responses[].conn_statusstring"success"
monitoring.dns.responses[].rcodestring"NOERROR"
monitoring.dns.responses[].rawstring | null"Raw record text."
monitoring.dns.responses[].valuesarray<string> | null
monitoring.dns.responses[].serverstring
monitoring.dns.serversarray<string>
monitoring.dns.check_datestring"2025-07-31T08:00:00Z"
monitoring.sslnull
monitoring.httpobject
monitoring.http.requested_urlstring"http://acme.example/"
monitoring.http.versionnumber1
monitoring.http.check_datestring"2025-07-31T08:00:00Z"
monitoring.http.connection_statusstring"success"
monitoring.http.requested_domainstring"acme.example"
monitoring.http.final_urlstring"http://acme.example/"
monitoring.http.final_domainstring"acme.example"
monitoring.http.httpobject
monitoring.http.http.redirection_historyarray<object>
monitoring.http.http.redirection_history[].urlstring"http://acme.example/"
monitoring.http.http.redirection_history[].status_codenumber200
monitoring.http.http.headersarray<object>
monitoring.http.http.headers[].namestring"server"
monitoring.http.http.headers[].valuestring"<value>"
monitoring.http.http.cookiesarray
monitoring.http.htmlobject
monitoring.http.html.source_hash_codestring
monitoring.http.final_status_codenumber200
approve_datenull
ignore_datenull
seems_inactivebooleanfalse

Examples

Selecting one loads it into the request and response panels.

Reference updated